Alarm data processing method, device, computer equipment and storage medium
By extracting and analyzing the field information and transmission paths of alarm data, the problem of inaccurate determination of attack location and source in the power monitoring system is solved, and fast and accurate attack positioning and response are achieved, improving the efficiency of safe operation and maintenance.
Patent Information
- Application Number
- CN202211181187.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-27
- Publication Date
- 2025-08-26
- Estimated Expiration
- 2042-09-27
AI Technical Summary
In the power monitoring system, when using the matching method to analyze alarm data, it is difficult to accurately determine the attack location and source of the attack, which affects the response accuracy of security operation and maintenance personnel.
By extracting the field information set of alarm data, including alarm time, source address, destination address and area information, and combining the data transmission path, the attack process between multiple alarm data is determined, and the entire attack process is quickly restored.
It realizes rapid and accurate positioning of the attack location and source in the power monitoring system, helping safe operation and maintenance personnel respond in a timely manner and avoid losses.
Smart Images

Figure CN115714710B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of power monitoring technology, and more particularly to a method, device, computer equipment, and storage medium for processing alarm data. Background Art
[0002] With the increasing development of the power system, the power supervision system is becoming increasingly important. The power supervision system is divided into multiple areas. When an attack occurs, security operations personnel need to analyze and confirm the attack location (i.e., the alarm destination address) and the attack source (i.e., the alarm source address) based on the alarm data, so as to respond and avoid losses.
[0003] At present, the matching method is usually used to parse single alarm data to determine the attack location and source. However, there is a problem of inaccurate determination of the attack location and source, which affects the accuracy of security operation and maintenance personnel's response to alarms and urgently needs improvement. Summary of the Invention
[0004] Based on this, it is necessary to provide a method, device, computer equipment, computer-readable storage medium and computer program product for processing alarm data that can associate multi-region attacks and restore the entire attack process of complex attacks across multiple regions in response to the above technical problems.
[0005] In a first aspect, the present application provides a method for processing alarm data. The method comprises:
[0006] Determine, based on at least two target alarm data sent by terminal devices in different areas, a field information set of each target alarm data; wherein the field information set includes at least alarm time field information, alarm source address field information, alarm destination address field information, and alarm area field information;
[0007] An attack process between at least two target alarm data is determined according to the field information set of each target alarm data and the data transmission path between different areas.
[0008] In one embodiment, determining an attack process between at least two target alarm data based on field information sets of each target alarm data and data transmission paths between different regions includes:
[0009] sorting at least two target alarm data according to the alarm time field information of each target alarm data;
[0010] Based on the alarm source address field information, the alarm destination address field information, and the alarm area field information of the sorted target alarm data, as well as the data transmission paths between different areas, the alarm data pairs having an attack transfer relationship are determined from the sorted target alarm data;
[0011] An attack process between at least two target alarm data is determined according to a sorting order corresponding to the target alarm data in the alarm data pair and an attack event.
[0012] In one embodiment, based on the alarm source address field information, the alarm destination address field information, and the alarm area field information of the sorted target alarm data, as well as the data transmission path between different areas, determining the alarm data pairs having an attack transfer relationship from the sorted target alarm data includes:
[0013] For each set of analysis data pairs in the sorted target alarm data, if the alarm source address field information and the alarm destination address field information of the two target alarm data in the set of analysis data pairs satisfy the first rule, then determining whether the two target alarm data are located in different alarm areas based on the alarm area field information corresponding to the two target alarm data in the set of analysis data pairs;
[0014] If so, determining whether there is a data transmission path between different alarm areas based on the data transmission paths between different areas;
[0015] If so, it is determined that the set of analysis data pairs is an alarm data pair having an attack transfer relationship;
[0016] A group of data pairs is composed of two sorted target alarm data; the first rule is that the alarm source address information field information of one target alarm data in a group of data pairs is the same as the alarm destination address information field information of the other target alarm data.
[0017] In one embodiment, the method further comprises:
[0018] For each analysis data pair in the sorted target alarm data, if the alarm source address field information and the alarm destination address field information of the two target alarm data in the analysis data pair satisfy the second rule, then the analysis data pair is determined to be an alarm data pair with an attack transfer relationship.
[0019] The second rule is that the alarm source address field information and the alarm destination address field information of two target alarm data in a data pair are the same.
[0020] In one embodiment, the field information set further includes: attack type field information and terminal device identification field information. Determining the attack process between at least two target alarm data based on the field information sets of each target alarm data and the data transmission path between different areas includes:
[0021] Determine candidate redundant data for each target alarm data according to the alarm time field information of each target alarm data;
[0022] De-redundancy processing is performed on the target alarm data according to other field information of each target alarm data and its candidate redundant data to obtain de-redundant alarm data; wherein the other field information is other field information in the field information set except the alarm time field information;
[0023] An attack process between at least two target alarm data is determined according to the field information set of the redundant alarm data and the data transmission path between different areas.
[0024] In one embodiment, determining an attack process between at least two target alarm data based on field information sets of each target alarm data and data transmission paths between different areas includes:
[0025] According to the matching relationship between the field information set of each target alarm data and the false alarm data information, the target alarm data is checked for false alarms to obtain the real alarm data;
[0026] An attack process between at least two target alarm data is determined based on a field information set of real alarm data and a data transmission path between different areas.
[0027] In a second aspect, the present application also provides a device for processing alarm data. The device includes:
[0028] An information confirmation module, configured to determine a field information set of each target alarm data based on at least two target alarm data sent by terminal devices in different areas;
[0029] The process analysis module is used to determine the attack process between at least two target alarm data based on the field information set of each target alarm data and the data transmission path between different areas.
[0030] In a third aspect, the present application further provides a computer device. The computer device includes a memory and a processor. The memory stores a computer program. When the processor executes the computer program, the following steps are performed:
[0031] Determine, based on at least two target alarm data sent by terminal devices in different areas, a field information set of each target alarm data; wherein the field information set includes at least alarm time field information, alarm source address field information, alarm destination address field information, and alarm area field information;
[0032] An attack process between at least two target alarm data is determined according to the field information set of each target alarm data and the data transmission path between different areas.
[0033] In a fourth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the following steps:
[0034] Determine, based on at least two target alarm data sent by terminal devices in different areas, a field information set of each target alarm data; wherein the field information set includes at least alarm time field information, alarm source address field information, alarm destination address field information, and alarm area field information;
[0035] An attack process between at least two target alarm data is determined according to the field information set of each target alarm data and the data transmission path between different areas.
[0036] In a fifth aspect, the present application further provides a computer program product. The computer program product includes a computer program that, when executed by a processor, implements the following steps:
[0037] Determine, based on at least two target alarm data sent by terminal devices in different areas, a field information set of each target alarm data; wherein the field information set includes at least alarm time field information, alarm source address field information, alarm destination address field information, and alarm area field information;
[0038] An attack process between at least two target alarm data is determined according to the field information set of each target alarm data and the data transmission path between different areas.
[0039] The above-mentioned alarm data processing method, device, computer equipment, storage medium and computer program product extract the field information from the alarm data of different areas to form a field information set, and then determine the correlation between multiple alarm data based on the field information set and the data transmission path between each area, and determine the entire attack path. This application can associate the attacks suffered by different areas, quickly restore the entire attack process, quickly lock the attack location (i.e., the alarm destination address) and the attack source (i.e., the alarm source address), and help security operation and maintenance personnel respond to alarms quickly and accurately, thereby avoiding losses caused by attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] Figure 1 This is a diagram of an application environment of a method for processing alarm data in one embodiment;
[0041] Figure 2 1 is a flow chart of a method for processing alarm data in one embodiment;
[0042] Figure 3 A schematic diagram of a process for determining an attack by warning information in one embodiment;
[0043] Figure 4 A schematic diagram of a process for confirming an alarm data pair having an attack transfer relationship in one embodiment;
[0044] Figure 5 A schematic diagram of a process for removing redundant alarm data in one embodiment;
[0045] Figure 6 A schematic diagram of a process for removing false alarm data in one embodiment;
[0046] Figure 7 is a flowchart of a method for processing alarm data in another embodiment;
[0047] Figure 8 is a structural block diagram of an alarm data processing device in one embodiment;
[0048] Figure 9 is a structural block diagram of a process analysis module in one embodiment;
[0049] Figure 10 is a structural block diagram of a relationship confirmation unit in one embodiment;
[0050] Figure 11 is a structural block diagram of a relationship confirmation unit in another embodiment;
[0051] Figure 12 It is a structural block diagram of an alarm data processing device in another embodiment;
[0052] Figure 13 It is a structural block diagram of an alarm data processing device in another embodiment;
[0053] Figure 14 FIG. 1 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION
[0054] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.
[0055] The method for processing alarm data provided in the embodiment of the present application can be applied to Figure 1 In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as shown in FIG. Figure 1As shown. The computer device includes a processor, a memory and a network interface connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data required for determining the processing of alarm data. The network interface of the computer device is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, it implements the method for processing alarm data shown in any of the following embodiments.
[0056] In one embodiment, Figure 2 As shown, a method for processing alarm data is provided, which is applied to Figure 1 The computer device in the example is used to illustrate the process, including the following steps:
[0057] S201: Determine a field information set of each target alarm data according to at least two target alarm data sent by terminal devices in different areas.
[0058] The field information set includes at least alarm time field information, alarm source address field information, alarm destination address field information and alarm area field information.
[0059] Among them, the alarm time field information is the time when the alarm occurred recorded in the alarm data, the alarm source address field information is the Internet Protocol Address (IP address) that initiated the attack event in the alarm data, the alarm destination address field information is the IP address of the destination attacked by the attack event in the alarm data, and the alarm area field information is the area to which the terminal device that sent the alarm data belongs.
[0060] It should be noted that the terminal devices in this embodiment may be power safety devices. Typically, the network architecture of a power monitoring system can be divided into security zones such as a control zone, a non-control zone, and a production management zone according to the principles of "security zoning, network dedicating, horizontal isolation, and vertical authentication" as required by pre-set specifications. The terminal devices in this embodiment are located in different zones, which may be control zones, non-control zones, production management zones, and other security zones.
[0061] Target alarm data can be generated and sent to the server by terminal devices in various areas when abnormal attack events are detected.
[0062] Optionally, this embodiment can be to extract the alarm occurrence time in the alarm data as the alarm time field information, extract the attack initiation IP in the alarm data as the alarm source address field information, extract the attack destination IP in the alarm data as the alarm destination address field information, and determine the alarm data occurrence area as the alarm area field information based on the occurrence area of the alarm data.
[0063] Optionally, this embodiment extracts time field information, alarm source address field information, and alarm destination address field information from the alarm data. It can first locate the field and then extract the information at the field position as the time field information, alarm source address field information, and alarm destination address field information.
[0064] When determining the alarm region field information, the identification information of the terminal device that sent the alarm data can be parsed to determine the region in which the terminal is located. For example, if the terminal device's identification information includes information about the region in which the terminal is located, the region in which the terminal is located can be determined directly based on the identification information. If not, a mapping table that records the relationship between the terminal device's identification information and the region in which the terminal is located can be maintained locally, and the region corresponding to the terminal device's identification information can be determined by looking up the table.
[0065] S202: Determine an attack process between at least two target alarm data according to the field information set of each target alarm data and the data transmission path between different areas.
[0066] The data transmission path is a path for transmitting data streams between various terminal devices between various areas when the various terminal devices are transmitting data normally.
[0067] Optionally, this embodiment may be to compare the alarm source address field information and the alarm destination address field information in the field information set of each target alarm data with the flow path of the normal data flow between different areas to determine the correlation relationship between each target alarm data, thereby determining the attack process between at least two target alarm data.
[0068] Specifically, the attack path can be preliminarily constructed based on the alarm source address and alarm destination address in the field information set of each target alarm data, and then combined with the transmission path of the data flow between different areas, the attack path between each target alarm data is updated to obtain the attack process between at least two target alarm data.
[0069] In the above-mentioned alarm data processing method, the field information in the alarm data is extracted to form a field information set, and then the correlation between multiple alarm data is determined based on the field information set and the data transmission path between each area, so as to quickly restore the entire attack process, quickly lock the attack location (i.e., the alarm destination address) and the attack source (i.e., the alarm source address), and help security operation and maintenance personnel respond to alarms quickly and accurately, thereby avoiding losses caused by attacks.
[0070] In one embodiment, Figure 3 As shown, based on the above embodiment, how to determine the attack process between at least two target alarms is further defined. Specifically, based on the field information set of each target alarm data and the data transmission path between different areas, determining the attack process between at least two target alarm data includes:
[0071] S301 , sorting at least two target alarm data according to the alarm time field information of each target alarm data.
[0072] Specifically, the target alarm data are sorted according to the alarm time sequence of the target alarm data, with the earlier ones being placed in the front and the later ones being placed in the back.
[0073] S302, based on the alarm source address field information, alarm destination address field information and alarm area field information of the sorted target alarm data, as well as the data transmission path between different areas, determine the alarm data pairs having the attack transfer relationship from the sorted target alarm data.
[0074] The data transmission path between different areas is specifically a path along which data streams are transmitted between the areas during normal data transmission.
[0075] Specifically, the alarm source address field information and the alarm destination address field information in each pair of target alarm data are compared, and two target alarm data with the same alarm source address field information and the same alarm destination address field information are found as a set of alarm data pairs with an attack transfer relationship. For the remaining pair of target alarm data, it is determined whether there is a transmission relationship between the alarm source address field information and the alarm destination address field information, that is, whether the alarm destination address field information of the target alarm data sorted in front is consistent with the alarm source address field information of the target alarm data sorted in the back, and whether the path from the alarm source address field information of the target alarm data sorted in front to the alarm destination address field information of the target alarm data sorted in the back is a normal transmission path of a normal data flow between different areas. If both conditions are yes, the two alarm data are regarded as a set of alarm data pairs with an attack transfer relationship.
[0076] S303: Determine an attack process between at least two target alarm data according to the sorting order corresponding to the target alarm data in the alarm data pair and the attack event.
[0077] Specifically, for each alarm data pair, the attack events corresponding to each target alarm data contained therein are obtained. Then, based on the sorting order of the two target alarm data, the attack path between the attack events corresponding to the two target alarm data is determined. For example, if target alarm data 1 in the alarm data pair is arranged before target alarm data 2, the attack path corresponding to the alarm data pair is: from the attack event of target alarm data 1 to the attack event of target alarm data 2. Then, based on the sorting order of the target alarm data in each alarm data pair, the attack paths corresponding to each alarm data pair are connected to obtain the attack process between the target alarm data.
[0078] In this embodiment, the attack transfer relationship between each target alarm data is confirmed based on the alarm source address, alarm destination address and the normal data flow transmission path between each area in the target alarm data, thereby confirming the entire attack process of each target alarm number. When an abnormal event occurs, it can help operation and maintenance personnel quickly locate the problem.
[0079] like Figure 4 As shown, another embodiment further explains how to identify target alarm data pairs that have an attack transfer relationship based on the above embodiment. Based on the alarm source address field information, alarm destination address field information, and alarm area field information of the sorted target alarm data, as well as the data transmission path between different areas, determining the alarm data pairs that have an attack transfer relationship from the sorted target alarm data includes:
[0080] S401, start.
[0081] S402, for each group of analysis data pairs in the sorted target alarm data, determine whether the alarm source address field information and the alarm destination address field information of the two target alarm data in the group of analysis data pairs meet the first rule, if so, execute S403, if not, execute S404.
[0082] The analysis data pairs are composed of two target alarm data in the target alarm data.
[0083] The first rule may be that the alarm source address information field information of one target alarm data in a set of data pairs is the same as the alarm destination address field information of the other target alarm data.
[0084] S403, determining whether the two target alarm data are located in different alarm areas based on the alarm area field information corresponding to the two target alarm data in the set of analysis data, if so, executing S405, if not, executing S406.
[0085] S404, for each group of analysis data pairs in the sorted target alarm data, determine whether the alarm source address field information and the alarm destination address field information of the two target alarm data in the group of analysis data pairs meet the second rule, if so, execute S406, if not, execute S407.
[0086] The second rule may be that the alarm source address field information and the alarm destination address field information of two target alarm data in a group of data pairs are the same.
[0087] When two target alarm data meet the second rule, it is considered that the two target alarms have an attack transfer relationship. It should be noted that since two target alarm data with the same alarm source address, alarm destination address and alarm area will be eliminated as redundant alarms, the alarm areas of the two target alarm information here must be different. Therefore, there is an attack transfer relationship between the two, that is, an area transfer has occurred. It can be determined that this group of analysis data pairs is an alarm data pair with an attack transfer relationship.
[0088] The alarm source addresses and alarm destination addresses of the sorted analysis data pairs are compared. If the first rule is satisfied, their alarm areas are compared to determine whether the two target alarm data are located in different alarm areas.
[0089] S405 , determining whether a data transmission path exists between different alarm areas based on the data transmission path between different areas, if yes, executing S406 , if not, executing S407 .
[0090] If the two target alarm data are located in different alarm areas, it is confirmed whether there is a data transmission path between the two areas according to the normal data flow transmission path.
[0091] Specifically, for example, one target alarm data comes from area A, and another target alarm data comes from area B. If the normal data flow can be transmitted from area A to area B, it proves that there is a data transmission path between area A and area B, then the alarm data can naturally be transferred from area A to area B, that is, it can be determined that this group of analysis data pairs is an alarm data pair with an attack transfer relationship.
[0092] S406: Determine that the group of analysis data pairs is an alarm data pair having an attack transfer relationship.
[0093] S407: Determine whether the set of analysis data pairs is an alarm data pair having an attack transfer relationship.
[0094] The above embodiment provides an optional method for determining alarm data pairs with attack transfer relationships from sorted target alarm data. This method can quickly and accurately determine the complete attack process of the attack event, so that operation and maintenance personnel can quickly confirm and locate the problem and respond in time to avoid losses.
[0095] In order to prevent repeated responses to the same abnormal event corresponding to multiple alarms, this embodiment needs to remove redundant alarm data from the acquired alarm data before determining the attack process of the target alarm data. In another embodiment, Figure 5 As shown in FIG, the process of removing redundant alarms is described.
[0096] It should be noted that the field information set in this embodiment may also include: attack type field information and terminal device identification field information. The attack type field information includes the attack method and attack effect of the abnormal event, such as the failure of part of the power grid function caused by an attack on the network. The terminal device identification field information indicates the device that monitors the abnormal event and issues an alarm when the abnormal event occurs.
[0097] Specifically, determining the attack process between at least two target alarm data according to the field information set of each target alarm data and the data transmission path between different areas includes:
[0098] S501 : Determine candidate redundant data for each target alarm data according to the alarm time field information of each target alarm data.
[0099] Specifically, each target alarm data is sorted according to the alarm time sequence, and one target alarm data is used as a screening object. Alarm data in a preset time period after the alarm time of the target alarm data are all candidate redundant data of the target alarm data.
[0100] S502 , performing de-redundancy processing on each target alarm data and other field information of its candidate redundant data to obtain de-redundant alarm data; wherein the other field information is other field information in the field information set except the alarm time field information.
[0101] Among them, other field information includes alarm source address field information, alarm destination address field information, alarm area field information, attack type field information and terminal device identification field information.
[0102] Specifically, each target alarm data is compared with its candidate redundant data. If other field information of the candidate redundant data is completely identical to that of the target redundant alarm data, the candidate redundant data is determined to be redundant data and is removed from all data.
[0103] S503: Determine an attack process between at least two target alarm data according to the field information set of the redundant alarm data and the data transmission path between different areas.
[0104] It should be noted that the determination of the attack process between the alarm data in this embodiment is similar to the determination process described in the above embodiment, and will not be described in detail here.
[0105] Using this method, the target alarm data after eliminating redundant alarm data is analyzed to determine the attack process between at least two target alarm data, ensuring that no repeated attack events will occur in the determined attack process. As a result, the operation and maintenance personnel only need to respond once to one alarm data, reducing the ineffective work of the operation and maintenance personnel and greatly reducing their labor intensity.
[0106] Considering that there may be false alarms in the alarm data, this embodiment needs to remove false alarms from the acquired alarm data before determining the attack process of the target alarm data, such as Figure 6 As shown, this embodiment describes how to remove false alarm data and determine the attack process between at least two target alarm data based on the field information set of the false alarm data removed and the data transmission path between different areas, including:
[0107] S601 , based on the matching relationship between the field information set of each target alarm data and the false alarm data information, the target alarm data is checked for false alarms to obtain true alarm data.
[0108] The false alarm data information can be obtained by pre-analyzing a large amount of false alarm data to determine the specific field information of the false alarm data.
[0109] Specifically, in one implementable method, for each target alarm data, the field information in its field information set is matched with the false alarm data information. If they are consistent, the target alarm data is determined to be false alarm data; otherwise, the target alarm data is determined not to be false alarm data.
[0110] In another possible implementation, a pre-trained neural network model may be used to parse the field information set of each target alarm data and the false alarm data information to determine whether each target alarm information is a false alarm information.
[0111] S602: Determine an attack process between at least two target alarm data according to the field information set of the real alarm data and the data transmission path between different areas.
[0112] It should be noted that the determination of the attack process between the alarm data in this embodiment is similar to the determination process described in the above embodiment, and will not be described in detail here.
[0113] This embodiment provides an optional method for removing false alarm data. Based on the target alarm data after removing the false alarm data, the attack process between at least two target alarm data is determined to ensure that no false alarm attack events will occur in the determined attack process, thereby ensuring that the operation and maintenance personnel will not make misjudgments when responding to the alarm data, preventing false alarms from affecting the operation and maintenance personnel's judgment of normal alarms, improving the work efficiency of the operation and maintenance personnel, and reducing the workload of the operation and maintenance personnel to a certain extent.
[0114] In order to more comprehensively demonstrate this solution, this embodiment provides an optional method for processing alarm data, such as Figure 7 shown.
[0115] S701: Determine a field information set of each target alarm data according to at least two target alarm data sent by terminal devices in different areas.
[0116] S702: Determine candidate redundant data for each target alarm data according to the alarm time field information of each target alarm data.
[0117] S703 , performing redundancy removal processing on each target alarm data according to other field information of each target alarm data and candidate redundant data to obtain redundancy-removed alarm data.
[0118] S704: According to the matching relationship between the field information set of the de-redundant alarm data and the false alarm data information, the de-redundant alarm data is checked for false alarms to obtain true alarm data.
[0119] S705 , sorting the real alarm data according to the alarm time field information of each real alarm data.
[0120] S706, for each group of analysis data pairs in the sorted target alarm data, determine whether the alarm source address field information and the alarm destination address field information of the two target alarm data in the group of analysis data pairs meet the first rule. If so, execute S707, if not, execute S708.
[0121] S707, based on the alarm area field information corresponding to the two target alarm data in the set of analysis data, determine whether the two target alarm data are located in different alarm areas, if so, execute S709, if not, execute S710.
[0122] S708, for each group of analysis data pairs in the sorted target alarm data, determine whether the alarm source address field information and the alarm destination address field information of the two target alarm data in the group of analysis data pairs meet the second rule, if so, execute S710, if not, execute S711.
[0123] S709, based on the data transmission paths between different areas, determine whether there is a data transmission path between different alarm areas. If yes, execute S710; if not, execute S711.
[0124] S710: Determine that the group of analysis data pairs is an alarm data pair having an attack transfer relationship.
[0125] S711: Determine whether the analysis data pair is an alarm data pair with an attack transfer relationship. The specific process of S701-S7011 can be found in the description of the above method embodiment. The implementation principle and technical effect are similar and will not be repeated here.
[0126] It should be understood that, although the steps in the flowcharts of the above embodiments are shown in sequence as indicated by the arrows, these steps are not necessarily performed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be performed in other orders. Moreover, at least a portion of the steps in the flowcharts of the above embodiments may include multiple steps or multiple stages, and these steps or stages are not necessarily performed at the same time, but can be performed at different times. The execution order of these steps or stages is not necessarily to be performed in sequence, but can be performed in turn or alternately with other steps or at least a portion of steps or stages in other steps.
[0127] Based on the same inventive concept, an embodiment of the present application further provides an alarm data processing device for implementing the aforementioned alarm data processing method. The implementation solution provided by this device is similar to the implementation solution described in the aforementioned method. Therefore, the specific limitations of one or more alarm data processing device embodiments provided below can be found in the limitations of the alarm data processing method described above and will not be repeated here.
[0128] In one embodiment, Figure 8 As shown, a device for processing alarm data is provided, including: an information confirmation module and a process analysis module, wherein:
[0129] An information confirmation module 80 is configured to determine a field information set of each target alarm data according to at least two target alarm data sent by terminal devices in different areas;
[0130] The process analysis module 81 is used to determine the attack process between at least two target alarm data according to the field information set of each target alarm data and the data transmission path between different areas.
[0131] In one embodiment, Figure 9 As shown above Figure 8 The process analysis module 81 may include:
[0132] The data sorting unit 810 is configured to sort at least two target alarm data according to the alarm time field information of each target alarm data.
[0133] The relationship confirmation unit 811 is used to determine the alarm data pairs with attack transfer relationships from the sorted target alarm data based on the alarm source address field information, alarm destination address field information and alarm area field information of the sorted target alarm data, as well as the data transmission path between different areas.
[0134] The process confirmation unit 812 is configured to determine an attack process between at least two target alarm data according to the sorting order corresponding to the target alarm data in the alarm data pair and the attack event.
[0135] In one embodiment, Figure 10 As shown above Figure 9 The relationship confirmation unit 811 in may include:
[0136] The first confirmation sub-unit 8110 is used to determine, for each group of analysis data pairs in the sorted target alarm data, whether the two target alarm data are located in different alarm areas based on the alarm area field information corresponding to the two target alarm data in the group of analysis data pairs if the alarm source address field information and the alarm destination address field information of the two target alarm data in the group of analysis data pairs meet the first rule.
[0137] The second confirmation subunit 8111 is configured to determine whether there is a data transmission path between different alarm areas according to the data transmission path between different areas when two target alarm data are located in different alarm areas.
[0138] The third confirmation subunit 8112 is configured to determine that the group of analysis data pairs is an alarm data pair having an attack transfer relationship when it is determined that a data transmission path exists between different alarm areas.
[0139] In another embodiment, Figure 11 As shown above Figure 9 The relationship confirmation unit 811 in the embodiment may further include:
[0140] The fourth confirmation sub-unit 8113 is used to determine, for each group of analysis data pairs in the sorted target alarm data, that the group of analysis data pairs is an alarm data pair with an attack transfer relationship if the alarm source address field information and the alarm destination address field information of the two target alarm data in the group of analysis data pairs meet the second rule.
[0141] In one embodiment, Figure 12 As shown above Figure 8 A device for processing alarm data may further include:
[0142] The redundancy removal module 82 is used to determine the candidate redundant data of each target alarm data according to the alarm time field information of each target alarm data, and to perform redundancy removal processing on the target alarm data according to other field information of each target alarm data and its candidate redundant data to obtain redundancy-removed alarm data.
[0143] In one embodiment, Figure 13 As shown above Figure 8 A device for processing alarm data may further include:
[0144] The false alarm removal module 83 is used to perform false alarm screening on the target alarm data according to the matching relationship between the field information set of each target alarm data and the false alarm data information to obtain the real alarm data.
[0145] Each module in the above-mentioned alarm data processing device can be implemented in whole or in part through software, hardware, or a combination thereof. Each module can be embedded in or independent of a processor in a computer device in the form of hardware, or can be stored in a memory in the computer device in the form of software, so that the processor can call and execute the corresponding operations of each module.
[0146] In one embodiment, a computer device is provided. The computer device may be a terminal, and its internal structure diagram may be as follows: Figure 14As shown. The computer device includes a processor, a memory, a communication interface, a display screen and an input device connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be achieved through WIFI, a mobile cellular network, NFC (near field communication) or other technologies. When the computer program is executed by the processor, a method for processing alarm data is implemented. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covering the display screen, or a button, trackball or touchpad provided on the computer device housing, or an external keyboard, touchpad or mouse.
[0147] Those skilled in the art will understand that Figure 14 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.
[0148] In one embodiment, a computer device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and when the processor executes the computer program, the following steps are implemented:
[0149] Determine, based on at least two target alarm data sent by terminal devices in different areas, a field information set of each target alarm data; wherein the field information set includes at least alarm time field information, alarm source address field information, alarm destination address field information, and alarm area field information;
[0150] An attack process between at least two target alarm data is determined according to the field information set of each target alarm data and the data transmission path between different areas.
[0151] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:
[0152] According to the alarm time field information of each target alarm data, at least two target alarm data are sorted; based on the alarm source address field information, alarm destination address field information and alarm area field information of the sorted target alarm data, as well as the data transmission path between different areas, alarm data pairs with attack transfer relationships are determined from the sorted target alarm data; according to the sorting order and attack events corresponding to the target alarm data in the alarm data pair, the attack process between at least two target alarm data is determined.
[0153] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:
[0154] For each group of analysis data pairs in the sorted target alarm data, if the alarm source address field information and the alarm destination address field information of the two target alarm data in the group of analysis data pairs meet the first rule, then determine whether the two target alarm data are located in different alarm areas based on the alarm area field information corresponding to the two target alarm data in the group of analysis data pairs; if so, determine whether there is a data transmission path between different alarm areas based on the data transmission path between different areas; if so, determine that the group of analysis data pairs is an alarm data pair with an attack transfer relationship; wherein, a group of data pairs is composed of two sorted target alarm data; the first rule is that the alarm source address information field information of one target alarm data in a group of data pairs is the same as the alarm destination address field information of the other target alarm data.
[0155] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:
[0156] For each group of analysis data pairs in the sorted target alarm data, if the alarm source address field information and the alarm destination address field information of the two target alarm data in the group of analysis data pairs meet the second rule, then the group of analysis data pairs is determined to be an alarm data pair with an attack transfer relationship; wherein, the second rule is that the alarm source address field information and the alarm destination address field information of the two target alarm data in a group of data pairs are the same.
[0157] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:
[0158] Based on the alarm time field information of each target alarm data, candidate redundant data of each target alarm data is determined; based on other field information of each target alarm data and its candidate redundant data, the target alarm data is de-redundantly processed to obtain de-redundant alarm data; wherein the other field information is other field information in the field information set except the alarm time field information; based on the field information set of the redundant alarm data and the data transmission path between different areas, the attack process between at least two target alarm data is determined.
[0159] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:
[0160] Based on the matching relationship between the field information set of each target alarm data and the false alarm data information, the target alarm data is checked for false alarms to obtain the real alarm data; based on the field information set of the real alarm data and the data transmission path between different areas, the attack process between at least two target alarm data is determined.
[0161] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:
[0162] Determine, based on at least two target alarm data sent by terminal devices in different areas, a field information set of each target alarm data; wherein the field information set includes at least alarm time field information, alarm source address field information, alarm destination address field information, and alarm area field information;
[0163] An attack process between at least two target alarm data is determined according to the field information set of each target alarm data and the data transmission path between different areas.
[0164] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0165] According to the alarm time field information of each target alarm data, at least two target alarm data are sorted; based on the alarm source address field information, alarm destination address field information and alarm area field information of the sorted target alarm data, as well as the data transmission path between different areas, alarm data pairs with attack transfer relationships are determined from the sorted target alarm data; according to the sorting order and attack events corresponding to the target alarm data in the alarm data pair, the attack process between at least two target alarm data is determined.
[0166] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0167] For each group of analysis data pairs in the sorted target alarm data, if the alarm source address field information and the alarm destination address field information of the two target alarm data in the group of analysis data pairs meet the first rule, then determine whether the two target alarm data are located in different alarm areas based on the alarm area field information corresponding to the two target alarm data in the group of analysis data pairs; if so, determine whether there is a data transmission path between different alarm areas based on the data transmission path between different areas; if so, determine that the group of analysis data pairs is an alarm data pair with an attack transfer relationship; wherein, a group of data pairs is composed of two sorted target alarm data; the first rule is that the alarm source address information field information of one target alarm data in a group of data pairs is the same as the alarm destination address field information of the other target alarm data.
[0168] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0169] For each group of analysis data pairs in the sorted target alarm data, if the alarm source address field information and the alarm destination address field information of the two target alarm data in the group of analysis data pairs meet the second rule, then the group of analysis data pairs is determined to be an alarm data pair with an attack transfer relationship; wherein, the second rule is that the alarm source address field information and the alarm destination address field information of the two target alarm data in a group of data pairs are the same.
[0170] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0171] Based on the alarm time field information of each target alarm data, candidate redundant data of each target alarm data is determined; based on other field information of each target alarm data and its candidate redundant data, the target alarm data is de-redundantly processed to obtain de-redundant alarm data; wherein the other field information is other field information in the field information set except the alarm time field information; based on the field information set of the redundant alarm data and the data transmission path between different areas, the attack process between at least two target alarm data is determined.
[0172] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0173] Based on the matching relationship between the field information set of each target alarm data and the false alarm data information, the target alarm data is checked for false alarms to obtain the real alarm data; based on the field information set of the real alarm data and the data transmission path between different areas, the attack process between at least two target alarm data is determined.
[0174] In one embodiment, a computer program product is provided, comprising a computer program, which, when executed by a processor, implements the following steps:
[0175] Determine, based on at least two target alarm data sent by terminal devices in different areas, a field information set of each target alarm data; wherein the field information set includes at least alarm time field information, alarm source address field information, alarm destination address field information, and alarm area field information;
[0176] An attack process between at least two target alarm data is determined according to the field information set of each target alarm data and the data transmission path between different areas.
[0177] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0178] According to the alarm time field information of each target alarm data, at least two target alarm data are sorted; based on the alarm source address field information, alarm destination address field information and alarm area field information of the sorted target alarm data, as well as the data transmission path between different areas, alarm data pairs with attack transfer relationships are determined from the sorted target alarm data; according to the sorting order and attack events corresponding to the target alarm data in the alarm data pair, the attack process between at least two target alarm data is determined.
[0179] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0180] For each group of analysis data pairs in the sorted target alarm data, if the alarm source address field information and the alarm destination address field information of the two target alarm data in the group of analysis data pairs meet the first rule, then determine whether the two target alarm data are located in different alarm areas based on the alarm area field information corresponding to the two target alarm data in the group of analysis data pairs; if so, determine whether there is a data transmission path between different alarm areas based on the data transmission path between different areas; if so, determine that the group of analysis data pairs is an alarm data pair with an attack transfer relationship; wherein, a group of data pairs is composed of two sorted target alarm data; the first rule is that the alarm source address information field information of one target alarm data in a group of data pairs is the same as the alarm destination address field information of the other target alarm data.
[0181] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0182] For each group of analysis data pairs in the sorted target alarm data, if the alarm source address field information and the alarm destination address field information of the two target alarm data in the group of analysis data pairs meet the second rule, then the group of analysis data pairs is determined to be an alarm data pair with an attack transfer relationship; wherein, the second rule is that the alarm source address field information and the alarm destination address field information of the two target alarm data in a group of data pairs are the same.
[0183] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0184] Based on the alarm time field information of each target alarm data, candidate redundant data of each target alarm data is determined; based on other field information of each target alarm data and its candidate redundant data, the target alarm data is de-redundantly processed to obtain de-redundant alarm data; wherein the other field information is other field information in the field information set except the alarm time field information; based on the field information set of the redundant alarm data and the data transmission path between different areas, the attack process between at least two target alarm data is determined.
[0185] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0186] Based on the matching relationship between the field information set of each target alarm data and the false alarm data information, the target alarm data is checked for false alarms to obtain the real alarm data; based on the field information set of the real alarm data and the data transmission path between different areas, the attack process between at least two target alarm data is determined.
[0187] It should be noted that the target alarm data information involved in this application (including but not limited to the alarm occurrence time, alarm area, etc.) are all information and data authorized by the user or fully authorized by all parties.
[0188] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, database or other media used in the embodiments provided in this application may include at least one of non-volatile and volatile memory. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory may include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, distributed databases based on blockchains. The processor involved in the various embodiments provided herein may be, but are not limited to, a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic unit, a data processing logic unit based on quantum computing, and the like.
[0189] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0190] The above embodiments merely illustrate several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person skilled in the art may make various modifications and improvements without departing from the spirit of the present invention, all of which fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.
Claims
1. A method for processing alarm data, characterized in that: The method comprises: Determine, based on at least two target alarm data sent by terminal devices in different areas, a field information set of each target alarm data; wherein the field information set includes at least alarm time field information, alarm source address field information, alarm destination address field information, and alarm area field information; sorting the at least two target alarm data according to the alarm time field information of each target alarm data; Based on the alarm source address field information, the alarm destination address field information, and the alarm area field information of the sorted target alarm data, as well as the data transmission paths between different areas, the alarm data pairs having an attack transfer relationship are determined from the sorted target alarm data; For each alarm data pair, obtaining an attack event corresponding to each target alarm data included in the alarm data pair, and determining an attack path between the attack events corresponding to each target alarm data according to the sorting order of each target alarm data; According to the sorting order of the target alarm data in each of the alarm data pairs, the attack paths corresponding to each of the alarm data pairs are connected to obtain the attack process between each of the target alarm data.
2. The method according to claim 1, characterized in that The step of determining alarm data pairs having an attack transfer relationship from the sorted target alarm data based on the alarm source address field information, the alarm destination address field information, and the alarm area field information of the sorted target alarm data, as well as the data transmission paths between different areas, includes: For each set of analysis data pairs in the sorted target alarm data, if the alarm source address field information and the alarm destination address field information of the two target alarm data in the set of analysis data pairs meet the first rule, determining whether the two target alarm data are located in different alarm areas based on the alarm area field information corresponding to the two target alarm data in the set of analysis data pairs; If so, determining whether there is a data transmission path between the different alarm areas according to the data transmission paths between the different areas; If so, it is determined that the set of analysis data pairs is an alarm data pair having an attack transfer relationship; The group of analysis data pairs is composed of two sorted target alarm data; the first rule is that the alarm source address information field information of one target alarm data in the group of analysis data pairs is the same as the alarm destination address information field information of the other target alarm data.
3. The method according to claim 2, characterized in that The method further comprises: For each analysis data pair in the sorted target alarm data, if the alarm source address field information and the alarm destination address field information of the two target alarm data in the analysis data pair satisfy the second rule, then the analysis data pair is determined to be an alarm data pair with an attack transfer relationship. The second rule is that the alarm source address field information and the alarm destination address field information of two target alarm data in a set of analysis data pairs are the same.
4. The method according to any one of claims 1 to 3, characterized in that The field information set further includes: attack type field information and terminal device identification field information, and the method further includes: Determine candidate redundant data for each target alarm data according to the alarm time field information of each target alarm data; De-redundancy processing is performed on the target alarm data according to other field information of each target alarm data and its candidate redundant data to obtain de-redundant alarm data; wherein the other field information is other field information in the field information set except the alarm time field information; An attack process between the at least two target alarm data is determined according to the field information set of the redundant alarm data and the data transmission path between different areas.
5. The method according to any one of claims 1 to 3, characterized in that The method further comprises: According to the matching relationship between the field information set of each target alarm data and the false alarm data information, the target alarm data is checked for false alarms to obtain the real alarm data; An attack process between the at least two target alarm data is determined according to the field information set of the real alarm data and the data transmission path between different areas.
6. A device for processing alarm data, characterized in that: The device comprises: An information confirmation module, configured to determine a field information set of each target alarm data based on at least two target alarm data sent by terminal devices in different areas; The process analysis module is used to sort the at least two target alarm data according to the alarm time field information of each target alarm data; based on the alarm source address field information, alarm destination address field information and alarm area field information of the sorted target alarm data, as well as the data transmission path between different areas, determine the alarm data pairs with attack transfer relationships from the sorted target alarm data; for each alarm data pair, obtain the attack event corresponding to each target alarm data included in the alarm data pair, and determine the attack path between the attack events corresponding to each target alarm data according to the sorting order of each target alarm data; according to the sorting order of the target alarm data in each alarm data pair, connect the attack paths corresponding to each alarm data pair to obtain the attack process between each target alarm data.
7. The device according to claim 6, characterized in that The process analysis module includes a relationship confirmation unit, and the relationship confirmation unit includes: a first confirmation subunit, configured to, for each set of analysis data pairs in the sorted target alarm data, determine, based on the alarm area field information corresponding to the two target alarm data in the set of analysis data pairs, whether the two target alarm data are located in different alarm areas if the alarm source address field information and the alarm destination address field information of the two target alarm data in the set of analysis data pairs satisfy a first rule; The second confirmation subunit is used to determine whether there is a data transmission path between the different alarm areas according to the data transmission path between the different areas when the two target alarm data are located in different alarm areas; The third confirmation subunit is configured to, when it is determined that a data transmission path exists between different alarm areas, determine that the group of analysis data pairs is an alarm data pair having an attack transfer relationship.
8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 5 are implemented.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 5 are implemented.
10. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 5 are implemented.
Citation Information
Patent Citations
Network inbreak event association detecting method
CN101272286A
Network intrusion scene chart generation method based on cluster analysis
CN101499928A