Security Incident Display Method, Device, Computer Equipment and Readable Storage Medium

By matching security event data with attack target and type tags to create customized display templates, the method addresses the issue of redundant data in security event tagging, improving analysis efficiency and clarity.

CN115801613BActive Publication Date: 2025-07-15HANGZHOU DBAPPSECURITY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211279515.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-19
Publication Date
2025-07-15
Estimated Expiration
2042-10-19

AI Technical Summary

Technical Problem

The redundant data problem caused by the labeling of security events in the prior art makes it difficult to quickly understand the key data information and internal relationships of security events, reducing the efficiency of network security analysis.

Method used

By obtaining security event data, determine the matching results with preset tags, including attack target tags and attack type tags, determine the display templates based on the matching results, and use these templates to display security event data clearly and in an orderly manner, supporting multi-dimensional display and filtering conditions.

Benefits of technology

It improves the efficiency of security incident analysis, helps security analysts quickly understand key data information and internal relationships, and facilitates quick analysis and grasp of the overall picture of security incidents.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115801613B_ABST
    Figure CN115801613B_ABST
Patent Text Reader

Abstract

The present application relates to a method, device, computer device and readable storage medium for displaying security events. The method includes: obtaining security event data; determining a matching result between the security event data and preset tags, where the preset tags at least include an attack target tag and an attack type tag; determining a display template based on the matching result, and displaying the security event data based on the display template. Compared with the direct display method in the traditional technology, the security event display method provided by the present application can help security analysts or systems quickly understand the key data information of security events and the internal relationship between security event data, facilitate the quick analysis of security events by security analysts and quickly grasp the overall picture of security events, and effectively improve the analysis efficiency of security events.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and in particular, to a method and device for displaying security events, a computer device, and a readable storage medium. Background Art

[0002] With the continuous development of network technology, the security problems of the network have become increasingly prominent. There is a risk of malicious attacks when the network and information systems operate in the network environment. For various network security events, the security events can be labeled, so that network security analysts can analyze the attack behaviors based on the labels and formulate corresponding security measures to respond or counter.

[0003] However, in the prior art, the labels obtained based on security events include a large amount of redundant label data in order to include more attack data and attack types, and the analysis value of some labels with relatively low occurrence frequencies is limited. Therefore, if the labels corresponding to security events are directly displayed, it will be difficult to quickly understand the key data information of security events and the internal relationship between security event data, reducing the efficiency of network security analysis. Summary of the Invention

[0004] Based on this, it is necessary to provide a method and device for displaying security events, a computer device, and a readable storage medium that can improve the efficiency of security event analysis for the above technical problems.

[0005] In a first aspect, this application provides a method for displaying security events. The method includes:

[0006] Obtain security event data;

[0007] Determine the matching result between the security event data and a preset label, where the preset label at least includes an attack target label and an attack type label;

[0008] Determine a display template based on the matching result, and display the security event data based on the display template.

[0009] In one of the embodiments, the determining the matching result between the security event data and the preset label includes:

[0010] Match the security event data with the attack target label to obtain a first matching result;

[0011] Determine the corresponding attack type label based on the first matching result;

[0012] Match the security event data with the corresponding attack type label to determine a second matching result.

[0013] In one embodiment, the security event data includes attack target data and attack type data, and the displaying of the security event data based on the display template includes:

[0014] Determine a first display template based on the first matching result;

[0015] Determine a second display template based on the second matching result;

[0016] Display the attack target data column by column based on the first display template, and display the attack type data row by row under the corresponding attack target data based on the second display template.

[0017] In one embodiment, the preset tag further includes an attack sub-type tag, and the determining of the matching result between the security event data and the preset tag includes:

[0018] Determine the corresponding attack sub-type tag based on the second matching result;

[0019] Match the security event data with the corresponding attack sub-type tag to determine a third matching result.

[0020] In one embodiment, the security event data includes attack type data and attack sub-type data, and the displaying of the security event data based on the display template includes:

[0021] Determine a second display template based on the second matching result;

[0022] Determine a third display template based on the third matching result;

[0023] In response to a user instruction, display the attack type data based on the second display template, and display the attack sub-type data based on the third display template.

[0024] In one embodiment, the displaying of the security event data based on the display template further includes:

[0025] In response to a user instruction, determine a filtering condition, where the preset filtering condition includes at least one of a hardware operating environment, a software operating environment, and a network working environment;

[0026] Determine a target display template based on the filtering condition, and display the security event data based on the target display template.

[0027] In one embodiment, before determining the display template based on the matching result, it further includes:

[0028] Determine the security events that meet the preset rules as rule events, where the preset rules include that the occurrence frequency of the security event is greater than the preset threshold, and / or the security event level is higher than the preset level;

[0029] Obtain the rule data of the rule event, and determine the preset label based on the matching result between the rule data and the ATT&CK model label.

[0030] In a second aspect, the present application also provides a security event display device. The device includes:

[0031] A data acquisition module, configured to acquire security event data;

[0032] A data matching module, configured to determine the matching result between the security event data and the preset label, where the preset label at least includes an attack target label and an attack type label;

[0033] A data display module, configured to determine a display template based on the matching result, and display the security event data based on the display template.

[0034] In a third aspect, the present application also provides a computer device, including a memory and a processor, where the memory stores a computer program, and when the processor executes the computer program, the steps of the method described in any one of the first aspects above are implemented.

[0035] In a fourth aspect, the present application also provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the method described in any one of the first aspects above are implemented.

[0036] For the above security event display method, device, computer device and readable storage medium, after acquiring the security event data, determine the matching result between the security event data and the preset label, where the preset label at least includes an attack target label and an attack type label; determine a display template based on the matching result, and display the security event data based on the display template. For the acquired security event data, a display template can be determined based on at least two dimensions of the attack target and the attack type, and the security event data can be displayed. Compared with the direct display method in the traditional technology, the security event data can be displayed more clearly and orderly, helping security analysts or systems quickly understand the key data information of the security event and the internal relationship between the security event data, facilitating the quick analysis of the security event by security analysts and quickly grasping the overall picture of the security event, and effectively improving the analysis efficiency of the security event.

[0037] Details of one or more embodiments of the present application are set forth in the following drawings and description to make the other features, objects, and advantages of the present application more concise and understandable. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] The drawings described herein are used to provide a further understanding of the present application and form a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings:

[0039] Figure 1 is an application environment diagram of the security event display method in an embodiment;

[0040] Figure 2 is a schematic flowchart of the security event display method in an embodiment;

[0041] Figure 3 is a schematic diagram showing the attack target data and attack type data in an embodiment;

[0042] Figure 4 is a schematic diagram showing the attack target data, attack type data and attack subclass data in an embodiment;

[0043] Figure 5 is a schematic diagram showing the security events under all selected filtering conditions in an embodiment;

[0044] Figure 6 is a schematic diagram showing the security events under partial selected filtering conditions in an embodiment;

[0045] Figure 7 is a schematic flowchart of the security event display method in a specific embodiment;

[0046] Figure 8 is a structural block diagram of the security event display device in an embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0047] In order to make the objectives, technical solutions and advantages of the present application clearer and more understandable, the present application will be further described in detail below with reference to the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0048] Unless otherwise defined, technical terms or scientific terms involved in this application shall have the ordinary meanings understood by those with ordinary skills in the technical field to which this application pertains. In this application, words such as "a", "an", "one kind", "the", "these", etc. do not indicate a limitation in quantity, and they can be singular or plural. The terms "include", "comprise", "have" and any variants thereof involved in this application are intended to cover non-exclusive inclusion; for example, a process, method, system, product or device that includes a series of steps or modules (units) is not limited to the listed steps or modules (units), but may include unlisted steps or modules (units), or may include other steps or modules (units) inherent in these processes, methods, products or devices. The similar words such as "connect", "be connected", "couple" and the like involved in this application are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. The "plurality" involved in this application means two or more. "And / or" describes the association relationship of associated objects and indicates that three relationships may exist. For example, "A and / or B" may represent: A exists alone, A and B exist simultaneously, and B exists alone. Usually, the character " / " indicates that the objects associated before and after are in an "or" relationship. The terms "first", "second", "third", etc. involved in this application are only used to distinguish similar objects and do not represent a specific order for the objects.

[0049] The terms "module", "unit", etc. used hereinafter are combinations of software and / or hardware that can achieve a predetermined function. Although the devices described in the following embodiments are preferably implemented in hardware, implementation in software, or a combination of software and hardware, is also possible and contemplated.

[0050] The security event display method provided by the embodiments of this application can be applied to, for example Figure 1In the application environment shown. Among them, the terminal 102 communicates with the server 104 through the network. The data storage system can store the data that the server 104 needs to process. The data storage system can be integrated on the server 104, or placed in the cloud or other network servers. In one embodiment, the server 104 can obtain the security event data and determine the matching result between the security event data and the preset tags, where the preset tags at least include an attack target tag and an attack type tag. In other embodiments, the terminal 102 can also obtain the security event data and determine the matching result between the security event data and the preset tags. Of course, the process of obtaining the security event data and determining the matching result between the security event data and the preset tags can also be achieved by the communication and cooperation between the server 104 and the terminal 102, and this application does not limit this. After determining the matching result, the server 104 can send the matching result to the terminal 102, and the terminal 102 determines the display template based on the matching result and displays the security event data based on the display template. It can be understood that in other embodiments, the server 104 can also determine the display template based on the matching result and send the display template to the terminal 102, and the terminal 102 displays the security event data based on the display template. Among them, the server 104 can be implemented by an independent server or a server cluster composed of multiple servers.

[0051] In one embodiment, as Figure 2 shown, a security event display method is provided. Taking the application environment in Figure 1 as an example, the method includes the following steps:

[0052] S201: Obtain security event data.

[0053] In the embodiments of the present application, the security event includes an event that poses a threat to network or computer security. Specifically, the security event can include harmful program events, network attack events, information destruction events, information content security events, etc. When the security event occurs, the attacking end will generate attack data, such as virus data, vulnerability attack data, etc.; the attacked end may also generate corresponding data, such as response data generated by the attacked end based on malicious attacks. Therefore, the security event data can include the attack data generated by the attacking end and / or the corresponding data generated by the attacked end based on the attack. In other embodiments, the security event data can also include the analysis data of the security event, such as the analysis data obtained by security event analysts or automatic defense systems after analyzing the security event.

[0054] In the embodiments of the present application, the acquisition of security event data may include actively acquiring security event data and / or automatically acquiring security event data. The active acquisition of security event data may include actively intercepting or collecting attack data sent by an attacking end when a security event occurs, or actively acquiring data propagated in an attacked network or terminal. In other embodiments, the active acquisition of security event data may further include acquiring security event data according to a preset rule. The preset rule includes that the occurrence frequency of a security event is greater than a preset threshold, and / or the security event level is higher than a preset level. It can be understood that security events with high frequency or greater harm pose a greater threat to the security system. Therefore, in some embodiments, data of such security events may be preferentially acquired according to actual needs. Of course, the preset rule can also be set according to actual needs by itself, and the present application does not limit this. On the other hand, the automatic acquisition of security event data may include setting a data acquisition module including a preset acquisition rule, and the data acquisition module is used to automatically acquire the security event data. The preset acquisition rule may be set according to the above preset rule, and the data acquisition module may be set based on the data automatic acquisition method in the prior art, which will not be elaborated here.

[0055] S203: Determine the matching result between the security event data and a preset label, where the preset label at least includes an attack target label and an attack type label.

[0056] In the embodiments of the present application, after acquiring the security event data, determine the matching result between the security event data and a preset label, where the preset label at least includes an attack target label and an attack type label. Among them, the attack target label may include a strategic target label to be achieved by the attacking end or an attack tactic label used by the attacking end. For example, in some embodiments, the strategic target label may include detecting the attacked end, developing resources of the attacked end, etc.; the attack tactic label may include persistent attack, privilege escalation, etc. On the other hand, the attack type label may include an attack method label adopted by the attacking end or a content label obtained by the attacking end when performing an attack action. For example, in some embodiments, corresponding to the above examples, if the attack target label is to detect the attacked end, the corresponding attack method label may include actively scanning the attacked end, collecting identity information of the attacked end, searching for websites / domains opened by the attacked end, etc.; if the attack target label is to develop resources of the attacked end, the corresponding content label may include acquiring the infrastructure of the attacked end. It should be noted that in some other embodiments, some preset labels may be both attack target labels and attack type labels, or attack type labels may also be used as attack target labels.

[0057] In the embodiments of the present application, if the security event data contains data information that is the same as or similar to the preset label, the preset label that matches the data information is used as the matching result. It can be understood that if the security event data contains data information that does not match the preset label, tags can also be added as the matching result according to actual needs, and it can also be selected whether to add the added tags to the preset label. In some other embodiments, in order to obtain a more accurate matching result, determining the matching result between the security event data and the preset label may further include preprocessing the security event data to obtain preprocessed data; determining the matching result between the preprocessed data and the preset label. Wherein, the preprocessing includes processing the security event data into the same form as the preset label. For example, the security event data can be processed into the same data format, the same data type, etc. as the preset label.

[0058] S205: Determine a display template based on the matching result, and display the security event data based on the display template.

[0059] After determining the matching result between the security event data and the preset label, if the matching result is directly displayed, it is difficult to make the display result clear and organized, which is not convenient for subsequent security event analysis work. Based on this, in the embodiments of the present application, a display template is determined based on the matching result, and the security event data is displayed based on the display template to improve the efficiency of subsequent analysis work. In some embodiments, the attack target label can be regarded as the "strategy" of the attacking end, and the attack type label can be regarded as the "tactics" under the corresponding "strategy". Therefore, determining the display template based on the matching result may include setting at least one of a preset display position, a preset display format, and a preset display structure for the preset label. Wherein, the preset display position may include displaying at a custom preset position in the window. The preset display format may include setting colors, shapes, fonts, rendering effects, etc. The preset display structure may include row display, column display, matrix display, mind map display, etc.

[0060] In the embodiments of the present application, the display of the security event data based on the display template may include displaying based on any one of a preset display position, a preset display format, and a preset display structure. Of course, in other embodiments, it may also be displayed based on a combination of any multiple of a preset display position, a preset display format, and a preset display structure. For example, in some embodiments, the security event data may be displayed in a mind map format, with the attack target label as a summary node and the attack type label as a corresponding sub-node under the summary node. In other embodiments, the attack target label of the summary node may also be set to be displayed in a first color, and the attack type label of the sub-node may be set to be displayed in a second color. The method of displaying security events by individually or combining any items in the display template should be within the scope of the display method described in the present application.

[0061] In the above security event display method of the embodiments of the present application, after obtaining the security event data, the matching result between the security event data and a preset label is determined, and the preset label includes at least an attack target label and an attack type label; a display template is determined based on the matching result, and the security event data is displayed based on the display template. For the obtained security event data, a display template can be determined based on at least two dimensions of the attack target and the attack type, and the security event data is displayed. Compared with the direct display method in the traditional technology, the security event data can be displayed more clearly and orderly, helping security analysts or systems quickly understand the key data information of the security event and the internal relationship between the security event data, facilitating the quick analysis of the security event by security analysts and quickly grasping the overall picture of the security event, and effectively improving the analysis efficiency of the security event.

[0062] In the embodiments of the present application, a method for matching the security event data with a preset label is provided. In step S203, the determination of the matching result between the security event data and the preset label includes:

[0063] S301: Matching the security event data with the attack target label to obtain a first matching result.

[0064] S303: Determining the corresponding attack type label based on the first matching result.

[0065] S305: Matching the security event data with the corresponding attack type label to determine a second matching result.

[0066] In the embodiments of the present application, the security event data is preferentially matched with the attack target tags to obtain a first matching result. Determining the corresponding attack type tags based on the first matching result includes: if among the preset tags, the attack target tags include at least one corresponding attack type tag, then using the at least one corresponding attack type tag as candidate tags; if there is no corresponding attack type tag for the attack target tags in the preset tags, then directly using the attack target tags as candidate tags. Matching the security event data with the corresponding attack type tags to determine a second matching result includes: matching the security event data with the candidate tags, and if the security event data matches an attack type tag, then using the matched attack type tag as the second matching result. If the security event data type does not match an attack type tag, or there is no corresponding attack type tag for the attack target tags in the preset tags, then using the attack target tag matched by the security event as the second matching result. In this case, in other embodiments, it may also be determined that the second matching result is no matching result.

[0067] In the embodiments of the present application, by preferentially matching the security event data with the attack target tags, the strategic or tactical objectives of the attacking end reflected by the security event data can be determined. That is, the first matching result can overall reflect the overall attack tendency and / or attack tactics of the attacking end. Then, based on the first matching result, the security event data is matched with the attack type tags to determine the attack actions executed by the attacking end and / or the content data obtained by the attack actions reflected by the security event data. That is, the second matching result can reflect the specific attack techniques of the attacking end. At the same time, in the process of determining the first matching result and the second matching result, the internal relationship between the attack target tags and the attack type tags is fully considered, making the first matching result and the second matching result have hierarchy and strong relevance.

[0068] Next, the embodiments of the present application provide a specific method for displaying security events. The security event data includes attack target data and attack type data. In step S105, the displaying of the security event data based on the display template includes:

[0069] S401: Determine a first display template based on the first matching result.

[0070] S403: Determine a second display template based on the second matching result.

[0071] S405: Display the attack target data column by column based on the first display template, and display the attack type data row by row under the corresponding attack target data based on the second display template.

[0072] In the embodiments of the present application, security event data including attack target data and attack type data can be obtained directly or through data analysis. The method for determining the first and second display templates based on the first and second matching results can refer to the method in step S205 above, which will not be elaborated here. After determining the first and second display templates, the attack target data can be displayed column by column in the first row according to the first display template, and under the attack target data corresponding to each column, the attack type data can be displayed row by row according to the second display template.

[0073] In a specific embodiment, as Figure 3 shown, the first display template determined based on the first matching result is a rectangular label with a white background color, a preset font size, and black font. Based on the first display template, the attack target data is displayed column by column in the first row, such as Figure 3 shown in the first row of Figure 3 "Reconnaissance", "Resource Development", "Initial Access", etc. The second display template determined based on the second matching result is a rectangular label with a gray background color, a preset font size, and white font. Based on the second display template, the attack type data is displayed row by row under the attack target data in each column, such as

[0074] shown in

[0075] "Command and Script Interpreter", "Server Software Component", etc.

[0076] In the embodiments of the present application, by displaying security events in the form of a row-column matrix, the attack target data and attack type data involved in the security events can be clearly and clearly displayed, and the hierarchical relationship between the attack target data and the attack type data can be intuitively reflected, which is convenient for security analysts to quickly sort out the security event data and improves the efficiency of security event analysis.

[0077] In some embodiments of the present application, the attack type labels in the preset labels can be further refined to make the displayed attack type data more hierarchical. That is, the preset label further includes attack subclass labels. In step S203, the determination of the matching result between the security event data and the preset label includes:

[0078] In the embodiments of the present application, the label in the attack type labels that meets the refinement rule is determined as the attack subclass label. The refinement rule is that if the first attack type can be specifically executed by the second attack type, then the label of the second attack type is used as the attack subclass label. After the attack type labels are divided into the first attack type labels and the attack subclass labels corresponding to the first attack type, the matching result between the security event data and the first attack type labels is the second matching result. Based on the second matching result, the security event data is further matched with the corresponding attack subclass labels to determine the third matching result.

[0079] In the embodiments of the present application, by further refining the attack type labels, security events can be displayed more accurately and meticulously, making the displayed attack type data more hierarchical, and also improving the accuracy and analysis efficiency of security event analysis.

[0080] Furthermore, in the embodiments of the present application, a method for displaying security event data based on the second matching result and the third matching result is provided. The security event data includes attack type data and attack subtype data. In step S205, the displaying of the security event data based on the display template includes:

[0081] S601: Determine a second display template based on the second matching result.

[0082] S603: Determine a third display template based on the third matching result.

[0083] S605: In response to a user instruction, display the attack type data based on the second display template, and display the attack subtype data based on the third display template.

[0084] In the embodiments of the present application, the method for determining the second and third display templates based on the second and third matching results can refer to the method in step S205 above, which will not be elaborated here. After determining the second display template and the third display template, in response to a user instruction, display the attack type data based on the second display template, and display the attack subtype data based on the third display template. The user instruction can include any one of single click, double click, or hover.

[0085] In a specific embodiment, as Figure 4 shown, the second display template determined based on the second matching result is a rectangular label with a gray background color, a preset font size, and white font. Display the attack type data row by row based on the second display template. As Figure 4"Command and Script Interpreter", "Server Software Component", etc. shown in . The third display template determined based on the third matching result is a rectangular label with a light gray background color, a preset font size, and black font. If the user clicks on the attack type data, in response to the user's click instruction, based on the third display template, the attack subclass data is displayed row by row under each column of attack type data, such as Figure 4 under the attack type label "Command and Script Interpreter" shown in , the attack subclass labels such as "Visual Basic", "JavaScript", etc. are displayed row by row. If the attack type data does not receive a user instruction, the attack subclass data can be folded and hidden, or it can be defaulted to the expanded state to display the attack subclass data.

[0086] In the embodiments of the present application, by differentially displaying the refined attack subclass data, security events can be displayed more clearly and meticulously. On the other hand, in response to a user instruction, the attack subclass data can be expanded or folded. In security analysis work, the security event data that needs to be displayed can be selected according to actual needs, which brings convenience to the analysis work and further improves the analysis efficiency of security events.

[0087] To further improve the security event analysis efficiency, the present application also provides a security event display method based on filtering conditions. In step S205, the display of the security event data based on the display template further includes:

[0088] S701: In response to a user instruction, determine a filtering condition, where the preset filtering condition includes at least one of a hardware operating environment, a software operating environment, and a network working environment.

[0089] S703: Determine a target display template based on the filtering condition, and display the security event data based on the target display template.

[0090] In the embodiments of the present application, the user instruction may include any one of single-click, double-click, or hover. The hardware operating environment may include the type of operating device, the model of the operating device, etc.; the software operating environment may include the operating system, the type of database, etc.; the network working environment may include perspective selection, interactive server, network bandwidth, data traffic, etc. In response to a user instruction to determine a filtering condition, a target display template can be determined based on the filtering condition, and the security event data can be displayed based on the target display template. Among them, determining the target display template based on the filtering condition includes determining the target display template based on the matching result that meets the filtering condition. Based on the target display template, the security event data can be displayed at a preset position in the window, such as above or to the left of the attack target data row.

[0091] The following shows the screening function through a specific embodiment. For example, Figure 5 as shown, the screening conditions are "viewpoint selection", "device type", and "operating system". When no user instruction is received, it is defaulted that all screening conditions are selected for the user, all preset tags are displayed, and the security event data is displayed based on the display template. For example, the attack type tags in dark gray in the figure. If the user clicks on the corresponding screening condition, such as Figure 6 as shown, the user clicks on "device type", "AiGent", "operating system", and "Linux", determines the selected options after clicking as the screening conditions, determines the target display template as light gray background color, preset font size, and black font based on the screening conditions, and displays the security data events based on the target display template.

[0092] In the embodiment of the present application, by setting the screening conditions, different security event data to be displayed can be screened based on actual needs, which is convenient for security analysts to analyze events from various self-set angles, provides more display forms for security events, effectively improves the analysis efficiency of security events, and also makes the security analysis more comprehensive.

[0093] In the embodiment of the present application, the preset conditions can be obtained according to experience or data summary analysis, or can be obtained by referring to the prior art. Before determining the display template based on the matching result in step S205, it further includes:

[0094] S801: Determine the security events that meet the preset rules as rule events, where the preset rules include that the occurrence frequency of the security event is greater than the preset threshold, and / or, the security event level is higher than the preset level.

[0095] S803: Obtain the rule data of the rule events, and determine the preset tags based on the matching result between the rule data and the ATT&CK model tags.

[0096] In the embodiments of the present application, first, the obtained security events are screened according to rules, and the security events that meet the preset rules are determined as rule events. The preset rules include that the occurrence frequency of the security event is greater than the preset threshold, and / or the security event level is higher than the preset level. It can be understood that for security events with a higher occurrence frequency or a higher security event level, their security event data also has stronger universality or importance. Among them, the security event level can be determined based on industry standards or by means of expert scoring, etc. Obtain the rule data of the rule event, and determine the preset label based on the matching result between the rule data and the ATT&CK model label. The ATT&CK model (Adversarial Tactics, Techniques, and Common Knowledge) is a comprehensive cybersecurity knowledge base. By observing the actual situation in each stage of the attack life cycle, the behavior of attackers can be understood and classified, and it has become a basic tool for researching threat models and methods. Based on the matching of the rule data with the ATT&CK model label, the successfully matched ATT&CK model label is used as the preset label according to the matching result.

[0097] In the embodiments of the present application, by classifying security events according to preset rules, representative or highly important rule events can be selected from a large amount of security event data. Then, based on the rule data of the rule event and referring to the ATT&CK model label, the preset label can be quickly determined, and the implementation conditions of the security event display method in the embodiments of the present application can be rapidly established, and the analysis results of security events are also made more representative.

[0098] The following uses a specific embodiment to illustrate the security event display method of the present application. As Figure 7 shown, first construct a display framework, including multiple display styles, etc. After obtaining the security event data, preprocess the security event data to facilitate the subsequent matching process. For example, the form of a certain security event data after processing is:

[0099] {

[0100] name:‘’,

[0101] value:‘’,

[0102] code:‘’,

[0103] level:‘’,

[0104] children:‘’,

[0105] color:‘’,

[0106] show:‘’,

[0107] condition1: '',

[0108] condition2: '',

[0109] condition3: '',

[0110] }

[0111] Among them, name, value, and code are the basic information of the security event data. Level represents the data level and the corresponding display template. For example, if the security event data is attack target data, it is level 1, and the display template is the display template of the attack target data. Similarly, the attack type data is level 2, and the attack subclass data is level 3. Children is the subset and also the flag of the recursive algorithm. Color is the matrix color. Show indicates whether to display this display template. Condition1, condition2, and condition3 are filtering conditions and can be customized. When displaying the security event data based on the display template, the system will default to display the data related to the current security event data filtered by the filtering conditions and hide the irrelevant items. If configured to display (show: true), all security event data can also be displayed. Subsequently, interaction events can also be added to the display template so that the security event display matrix can be displayed in response to user instructions, such as determining the filtering conditions in response to user instructions. After the security event display matrix is drawn, it can be displayed according to the security event data to be displayed.

[0112] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are shown in sequence according to the arrows, these steps do not necessarily have to be executed in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps does not have a strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages do not necessarily have to be executed at the same time, but can be executed at different times. The execution order of these steps or stages does not necessarily have to be sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.

[0113] Based on the same inventive concept, the embodiment of the present application also provides a security event display device 900 for implementing the security event display method described above. The implementation solution provided by this device to solve the problem is similar to the implementation solution described in the above method. Therefore, the specific limitations in one or more embodiments of the security event display device 900 provided below can refer to the limitations on the security event display method in the above text and will not be repeated here.

[0114] In one embodiment, as Figure 8 shown, a security event display device 900 is provided, including:

[0115] A data acquisition module 901, configured to acquire security event data.

[0116] A data matching module 902, configured to determine a matching result between the security event data and a preset label, where the preset label at least includes an attack target label and an attack type label.

[0117] A data display module 903, configured to determine a display template based on the matching result, and display the security event data based on the display template.

[0118] Each module in the above security event display device can be implemented in whole or in part by software, hardware, and their combination. Each of the above modules can be embedded in or independent of a processor in a computer device in the form of hardware, or stored in a memory in the computer device in the form of software, so that the processor can call and execute the operations corresponding to each of the above modules.

[0119] In one embodiment, a computer device is provided, including a memory and a processor, where the memory stores a computer program, and when the processor executes the computer program, the steps in any one of the above security event display methods are implemented.

[0120] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored, and when the computer program is executed by a processor, the steps in any one of the above security event display methods are implemented.

[0121] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data that have been authorized by the user or fully authorized by all parties.

[0122] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., without limitation.

[0123] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

[0124] The above-described embodiments only represent several implementation manners of the present application. Their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of the patent of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.

Claims

1. A method for displaying security events, characterized in that The method includes: Obtaining security event data; Determining a matching result between the security event data and preset tags, where the preset tags at least include an attack target tag and an attack type tag; The determining the matching result between the security event data and the preset tags includes: Matching the security event data with the attack target tag to obtain a first matching result; Determining a corresponding attack type tag based on the first matching result; Matching the security event data with the corresponding attack type tag to determine a second matching result; Determining a display template based on the matching result, and displaying the security event data based on the display template; the security event data includes attack target data and attack type data; The determining a display template based on the matching result includes setting at least one of a preset display position, a preset display format, and a preset display structure for the preset tags; The displaying the security event data based on the display template includes: Determining a first display template based on the first matching result; Determining a second display template based on the second matching result; Displaying the attack target data column by column based on the first display template, and displaying the attack type data row by row under the corresponding attack target data based on the second display template.

2. The method according to claim 1, wherein The preset tags further include an attack sub-type tag, and the determining the matching result between the security event data and the preset tags includes: Determining a corresponding attack sub-type tag based on the second matching result; Matching the security event data with the corresponding attack sub-type tag to determine a third matching result.

3. The method according to claim 2, wherein The security event data includes attack type data and attack sub-type data, and the displaying the security event data based on the display template includes: Determining a second display template based on the second matching result; Determining a third display template based on the third matching result; In response to a user instruction, displaying the attack type data based on the second display template, and displaying the attack sub-type data based on the third display template.

4. The method according to claim 1, characterized in that The displaying the security event data based on the display template further includes: In response to a user instruction, determining a screening condition, where the screening condition includes at least one of a hardware operating environment, a software operating environment, and a network working environment; Determining a target display template based on the screening condition, and displaying the security event data based on the target display template.

5. The method according to claim 1, wherein Before the determining a display template based on the matching result, it further includes: Determining security events that meet a preset rule as rule events, where the preset rule includes that the occurrence frequency of the security event is greater than a preset threshold, and / or, the security event level is higher than a preset level; Obtaining rule data of the rule events, and determining the preset tags based on a matching result between the rule data and ATT&CK model tags.

6. A security event display device, characterized in that, The device includes: A data acquisition module, configured to obtain security event data; A data matching module, configured to determine a matching result between the security event data and preset tags, where the preset tags at least include an attack target tag and an attack type tag; determining the matching result between the security event data and the preset tags includes: Matching the security event data with the attack target tag to obtain a first matching result; Determining a corresponding attack type tag based on the first matching result; Matching the security event data with the corresponding attack type tag to determine a second matching result; A data display module, configured to determine a display template based on the matching result, and display the security event data based on the display template; the security event data includes attack target data and attack type data; Determining the display template based on the matching result includes setting at least one of a preset display position, a preset display format, and a preset display structure for the preset tags; Displaying the security event data based on the display template includes: Determining a first display template based on the first matching result; Determining a second display template based on the second matching result; Displaying the attack target data column by column based on the first display template, and displaying the attack type data row by row under the corresponding attack target data based on the second display template.

7. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 5.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Attack event display system

    CN111988322A

  • Traffic data display method and device, electronic equipment and storage medium

    CN114124744A