A data processing method and device for network security operation

Through the collaborative work of the network security operation client and the server, user requests are processed to determine actual needs and provide service interfaces, which solves the problem of inefficiency of users in the network security operation system and improves service acquisition efficiency and user satisfaction.

CN115865430BActive Publication Date: 2025-07-08ULTRAPOWER SOFTWARE +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211445103.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-18
Publication Date
2025-07-08
Estimated Expiration
2042-11-18

AI Technical Summary

Technical Problem

When users use network security operation services, they need to find target services from a large number of list information, resulting in inefficient access to target services.

Method used

Through the collaborative work of the network security operation client and server, the requests entered by the user are first processed to determine the actual needs, and then the service interface is determined based on the association relationship, providing accurate service data, reducing the amount of data and improving processing efficiency.

Benefits of technology

Optimize the operational convenience of the network security operation system and improve the efficiency and satisfaction of users in obtaining target services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115865430B_ABST
    Figure CN115865430B_ABST
Patent Text Reader

Abstract

The present application provides a data processing method and apparatus for network security operation, which can improve the efficiency of a user in obtaining a target service when using the service of network security operation and optimize the operation convenience of the network security operation system. The method is applied to a network security operation system, which includes a network security operation client and a network security operation server. The method includes: the network security operation client sends a first request to the network security operation server; the network security operation server performs a first processing on the first request according to the service name; the network security operation server obtains a first actual requirement according to the first request after the first processing; the network security operation server determines a first service interface according to the first actual requirement and a first association relationship; the network security operation server sends a first response to the network security operation client according to the first service interface; the network security operation client displays the first response to the user.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technologies, and in particular, to a data processing method and apparatus for network security operation. Background Art

[0002] With the digital transformation of enterprise information and the construction of the national digital economy, technical solutions for network security management have become the focus of research. Network security management involves multiple aspects of services, such as securely querying information, securely configuring services, securely invoking services, and securely accessing document materials, etc. Each service of network security management requires a platform for support. In order to comprehensively manage these platforms that provide services for network security management and enable these platforms to operate collaboratively, network security operation emerges as the times require. Network security operation (which can also be referred to as a network security operation platform or a network security operation system) can provide users with an entrance to manage multiple platforms, invoke services of multiple platforms, and so on.

[0003] However, in the current network security operation solutions, people only focus on improving the management quality and efficiency of the management side for each network security management platform, and ignore the usage requirements of the user side. As a result, when users use the services of network security operation, they have to search for target services from a large amount of list information, making the efficiency of users obtaining target services low.

[0004] Therefore, how to improve the efficiency of users obtaining target services when using the services of network security operation has become an urgent problem to be solved. Summary of the Invention

[0005] This application provides a data processing method and apparatus for network security operation, which can improve the efficiency of users obtaining target services when using the services of network security operation and optimize the operation convenience of the network security operation system.

[0006] In a first aspect, this application provides a data processing method for network security operation, which is applied to a network security operation system. The network security operation system includes a network security operation client and a network security operation server. The network security operation server is used to obtain at least one network security management service interface and provide services corresponding to at least one network security management service interface to users through the network security operation client. The method includes:

[0007] The network security operation client sends a first request to the network security operation server, and the first request is the data input by the user into the network security operation client;

[0008] The network security operation server performs a first processing on the first request according to the service name, and the service name includes the names of services corresponding to at least one network security management service interface;

[0009] The network security operation server obtains the first actual requirement according to the first request after the first processing;

[0010] The network security operation server determines a first service interface according to the first actual requirement and the first association relationship, where the first association relationship is used to associate at least one actual requirement and at least one network security management service interface, the first actual requirement is included in the at least one actual requirement, and the first service interface is included in the at least one network security management service interface;

[0011] The network security operation server sends a first response to the network security operation client according to the first service interface, and the first response includes service data provided by the first service interface;

[0012] The network security operation client displays the first response to the user.

[0013] In one example, the method further includes:

[0014] The network security operation server determines a first permission level of the user according to the identity data of the user, where the network security operation server determines the first service interface according to the first actual requirement and the first association relationship, including:

[0015] The network security operation server determines the first service interface according to the first actual requirement, the first permission level and the first association relationship, where the first association relationship is further used to associate at least one actual requirement and at least one permission level, the first association relationship is further used to associate at least one permission level and at least one network security management service interface, and the first permission level is included in the at least one permission level.

[0016] In one example, the method further includes:

[0017] The network security operation client obtains an operation instruction input by the user regarding the first response, and the operation instruction is used to indicate accessing the service provided by the first service interface;

[0018] The network security operation client sends a call request to the network security operation server, and the call request is used to access the service provided by the first service interface;

[0019] The network security operation server provides the service provided by the first service interface to the user through the network security operation client according to the call request.

[0020] In one example, the method further includes:

[0021] The network security operation server obtains at least one actual requirement based on big data statistical algorithms;

[0022] The network security operation server obtains at least one network security management service interface and at least one permission level.

[0023] The network security operation server determines a first association relationship according to at least one actual requirement, at least one network security management service interface, and at least one permission level.

[0024] In one example, before the network security operation server determines the first association relationship according to at least one actual requirement, at least one network security management service interface, and at least one permission level, the method further includes:

[0025] The network security operation server determines the display style corresponding to each actual requirement according to the type of service called by each actual requirement in at least one actual requirement. The display style is used to specify the way in which the service provided by the network security management service interface corresponding to each actual requirement is presented on the human-computer interaction interface of the network security operation client. Among them,

[0026] The network security operation server determines the first association relationship according to at least one actual requirement, at least one network security management service interface, and at least one permission level, including:

[0027] The network security operation server determines the first association relationship according to at least one actual requirement, at least one network security management service interface, the display style corresponding to each actual requirement, and at least one permission level.

[0028] In one example, the first processing includes: identifying keywords that match the service name, or supplementing content that matches the service name.

[0029] In one example, the network security operation server obtains a first actual requirement according to the first request after the first processing, including:

[0030] The network security operation server obtains a second association relationship, which is used to associate at least one request and at least one actual requirement, where each actual requirement in at least one actual requirement is associated with one or more requests;

[0031] The network security operation server determines the similarity between the first request after the first processing and each request in at least one request;

[0032] The network security operation server determines whether there is a request that meets the preset condition in at least one request according to the similarity corresponding to each request;

[0033] If there is a request that meets the preset condition in at least one request, the network security operation server determines the first actual requirement according to the request that meets the preset condition and the second association relationship.

[0034] In one example, the method further includes:

[0035] If at least one of the requests does not include a request that meets the preset conditions, the network security operation server inputs the first request after the first processing into the first neural network model, and obtains a predicted request output by the first neural network model. The first neural network model is used to learn the characteristics of the requests input by the user corresponding to each actual demand based on the service data of network security operations, and / or the characteristics of the requests corresponding to the actual demands whose usage times are greater than the first threshold;

[0036] The network security operation server determines the similarity between the predicted request and each request in at least one request;

[0037] The network security operation server determines whether at least one request includes a request that meets the preset conditions according to the similarity corresponding to each request;

[0038] If at least one request includes a request that meets the preset conditions, the network security operation server determines the first actual demand according to the request that meets the preset conditions and the second association relationship.

[0039] In one example, after the network security operation server determines the similarity between the predicted request and each request in at least one request, and the network security operation server determines whether at least one request includes a request that meets the preset conditions according to the similarity corresponding to each request, the method further includes:

[0040] If at least one request does not include a request that meets the preset conditions, the network security operation server sends a response failure indication message to the network security operation client, and the response failure indication message is used to indicate that the acquisition of the network security management service interface fails.

[0041] In a second aspect, the present application provides a data processing device for network security operations, which is applied to a network security operation system. The network security operation system includes a network security operation client and a network security operation server. The network security operation server is used to obtain at least one network security management service interface, and provide services corresponding to at least one network security management service interface to users through the network security operation client. The device includes:

[0042] A first data transmission module, configured to send a first request from the network security operation client to the network security operation server, where the first request is data input by the user to the network security operation client;

[0043] A first request processing module, configured to perform a first processing on the first request by the network security operation server according to the service name, where the service name includes the names of services corresponding to at least one network security management service interface;

[0044] The first actual requirement acquisition module is used for the network security operation server to acquire the first actual requirement according to the first request after the first processing;

[0045] The first service interface acquisition module is used for the network security operation server to determine the first service interface according to the first actual requirement and the first association relationship, wherein the first association relationship is used to associate at least one actual requirement and at least one network security management service interface, the first actual requirement is included in at least one actual requirement, and the first service interface is included in at least one network security management service interface;

[0046] The second data transmission module is used for the network security operation server to send a first response to the network security operation client according to the first service interface, and the first response includes service data provided by the first service interface;

[0047] The human-computer interaction module is used for the network security operation client to display the first response to the user.

[0048] As can be seen from the above embodiments, after the network security operation client in this application obtains the first request (i.e., the data input by the user into the network security operation client), it sends the first request to the network security operation server. The network security operation server performs a first processing on the first request according to the service name, so as to facilitate obtaining the corresponding first actual requirement subsequently. The service name includes the names of the services corresponding to the at least one network security management service service interface. The network security operation server determines the first service interface corresponding to the first actual requirement according to the first actual requirement and the first association relationship. Since the data input by the user on the network security operation client is not standardized enough in content, if the first association relationship directly associates the requests that the user may input and the at least one network security management service service interface, then each network security management service service interface may correspond to a dozen or dozens of requests that the user may input, and the data volume is huge, which will lead to a slow processing speed of the solution involving the first association relationship. Therefore, in this application, after performing the first processing on the first request and then determining the actual requirement according to the first request after the first processing, the determined actual requirement is relatively accurate, and the number of actual requirements corresponding to each network security management service service interface in the first association relationship is controllable, greatly reducing the data volume of the first association relationship. This enables the subsequent network security operation server to greatly improve the efficiency of determining the first service interface according to the first association relationship and the first actual requirement. The network security operation server sends a first response to the network security operation client according to the first service interface. After receiving the first response, the network security operation client displays the first response to the user, avoiding the problem that the user has a low efficiency in obtaining the target service when using the network security operation service because they need to search for the target service from a large amount of list information, optimizing the operation convenience of the network security operation system and improving the user's satisfaction with using the network security operation system. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] In order to more clearly illustrate the technical solutions of this application, the drawings required for use in the embodiments will be briefly introduced below. Obviously, for those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0050] Figure 1 It is a schematic diagram of a data processing method for network security operation provided by an embodiment of this application;

[0051] Figure 2 It is a human-computer interaction interface diagram provided by an embodiment of this application;

[0052] Figure 3 It is a schematic diagram of the architecture of a network security operation system provided by an embodiment of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0053] Embodiments of the present application will be described in detail below. Examples of the embodiments are shown in the accompanying drawings, where the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below by referring to the drawings are exemplary and are only used to explain the present application, and cannot be construed as a limitation of the present application. It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments may be combined with each other.

[0054] Those skilled in the art of the present technology can understand that, unless specifically stated otherwise, the singular forms "a", "an", "the", and "said" used herein may also include the plural forms. It should be further understood that the term "comprising" used in the specification of the present application means the presence of the described features, integers, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. It should be understood that when we say that an element is "connected" or "coupled" to another element, it can be directly connected or coupled to other elements, or there may also be intermediate elements. In addition, the "connection" or "coupling" used herein may include wireless connection or wireless coupling. The term "and / or" used herein includes all or any unit and all combinations of one or more related listed items.

[0055] Figure 1 is a schematic flowchart of a data processing method for network security operation provided by an exemplary embodiment of the present application. This embodiment is applied to a network security operation system, which includes a network security operation client and a network security operation server. The network security operation server is used to obtain at least one network security management service interface and provide services corresponding to at least one network security management service interface to users through the network security operation client. As Figure 1 shown, a data processing method for network security operation includes the following steps:

[0056] S110, the network security operation client sends a first request to the network security operation server, and the network security operation server receives the first request.

[0057] Among them, the first request is the data input by the user into the network security operation client.

[0058] Exemplarily, the network security operation client obtains the first request according to the text input by the user, or converts the voice input of the user into text and obtains the first request according to the text.

[0059] For example, the content displayed on the human-computer interaction interface of the network security operation client is as Figure 2As shown, the first request is data such as "resource access", "attack situation", "compliance administrator", or "security operation center operation manual", which is not limited in this application.

[0060] S120, the network security operation server performs a first processing on the first request according to the service name.

[0061] Among them, the service name includes the names of services corresponding to at least one network security management service interface. The services corresponding to at least one network security management service interface include other services such as securely querying information, securely configuring services, securely invoking services, and securely consulting document materials, which are not limited in this application. Correspondingly, the names of each service can be information query, service configuration, service invocation, and consulting document materials, etc., and the names of each service can be set according to actual needs, which are not limited in this application.

[0062] Exemplarily, the first processing includes: identifying keywords in the first request that match the service name, or supplementing content in the first request that matches the service name.

[0063] For example, the first request is "I want to query XX document". According to the service name "consulting document materials", the keyword in this first request is identified as "query XX document", thus excluding redundant content unrelated to the security management service.

[0064] Another example, the first request is "query XX document". According to the service name "consulting document materials", content that matches the service name is supplemented to the first request, and the processed first request is "query XX document materials".

[0065] This application takes into account that the data input by the user to the network security operation client may be redundant or missing in content. The above method improves the adaptability between the content of the first request and the names of services corresponding to at least one network security management service interface through the first processing of the first request according to the service name, so as to facilitate the subsequent rapid and effective positioning of the first actual demand.

[0066] In an example, if the network security operation server fails to perform the first processing on the first request, that is, there is no keyword in the first request that matches the service name, resulting in a failure to identify the keyword, or no content that can be supplemented to the first request is searched, then a response failure indication message is sent to the network security operation client. The response failure indication message is used to indicate that the acquisition of the network security management service interface fails. The network security operation client, according to the response failure indication message, instructs the user to re-enter the data, or prompts the user with information indicating that the input data is incorrect and the service cannot be provided.

[0067] This application considers the situation where the first request input by the user has nothing to do with the network security management service, that is, the content input by the user may be incorrect, or the user may mistake it for a chat window and chat, etc., which are other situations unrelated to the service of accessing the service interface of the network security management service. By adopting the above method, when an event of the above situation occurs, the user can be timely and accurately guided to re-enter the first request or prompted that the input data is incorrect.

[0068] S130. The network security operation service end obtains the first actual requirement according to the first request after the first processing.

[0069] In an example, the network security operation service end first obtains a second association relationship, which is used to associate at least one request and at least one actual requirement, where each actual requirement of the at least one actual requirement is associated with one or more requests. Then, it determines the similarity between the first request after the first processing and each request in the at least one request, and determines whether there is a request that meets the preset conditions in the at least one request according to the similarity corresponding to each request; if there is a request that meets the preset conditions in the at least one request, it determines the first actual requirement according to the request that meets the preset conditions and the second association relationship.

[0070] For example, the content of the second association relationship is shown in Table 1 below:

[0071] Table 1

[0072] Request Actual requirement Query administrator Query compliance administrator Query compliance administrator Query compliance administrator Secure resource access Resource access Current attack situation Attack situation Operation center operation manual Secure operation center operation and maintenance manual Secure operation center manual Secure operation center operation and maintenance manual … …

[0073] In the above second association relationship, the content of the specific request can be determined through manual research and collection, or can be further determined by combining big data statistics technology or web crawler technology.

[0074] It can be seen from Table 1 that an actual requirement may correspond to one request or multiple requests. By setting an actual requirement to correspond to multiple requests, the error tolerance rate of determining the actual requirement is improved.

[0075] Exemplarily, the value of the similarity = the number of characters that are the same in each request and the first request after the first processing / the number of characters of the first request after the first processing, and the characters can be Chinese characters or characters in other languages.

[0076] Among them, the preset conditions can be set according to actual needs, and this application does not limit this. For example, the preset condition is that the similarity needs to be within a preset numerical range.

[0077] In the above method, first, the similarity between the first request after the first processing and each request in the second association relationship is determined, and based on the similarity corresponding to each request, it is determined whether at least one request includes a request that meets the preset conditions. If so, the first actual requirement in the second association relationship can be accurately determined according to the request that meets the preset conditions.

[0078] Further exemplarily, if at least one request does not include a request that meets the preset conditions, the first request after the first processing is input into the first neural network model, and a predicted request output by the first neural network model is obtained. The first neural network model is used to learn the characteristics of the requests input by users corresponding to each actual requirement based on the service data of network security operation, and / or the characteristics of the requests corresponding to the actual requirements whose usage times are greater than the first threshold. The similarity between the predicted request and each request in at least one request is determined; based on the similarity corresponding to each request, it is determined whether at least one request includes a request that meets the preset conditions; if at least one request includes a request that meets the preset conditions, the first actual requirement is determined according to the request that meets the preset conditions and the second association relationship. If at least one request does not include a request that meets the preset conditions, a response failure indication message is sent to the network security operation client. Among them, the usage times are the number of times the network security management service interface corresponding to the actual requirement provides services, and the first threshold can be set according to the actual requirement.

[0079] Among them, the service data of network security operation includes retrieval records and the like when users use the services of network security operation.

[0080] Exemplarily, the method further includes: training the first neural network model with the service data of network security operation as training data based on the method of supervised learning. Among them, the first neural network model uses a classification algorithm, such as a support vector machine algorithm or a proximity algorithm, etc.

[0081] For example, first determine a primary similarity threshold and a secondary similarity threshold, and compare the similarity between each request in at least one request and the first request with the above two thresholds. Requests that are less than or equal to the primary similarity threshold are marked as "0", requests that are greater than the primary similarity threshold and less than or equal to the secondary similarity threshold are marked as "1", and requests that are greater than the secondary similarity threshold are marked as "2". Set a preset condition to filter the request with the largest non-zero mark, and then determine the actual requirement corresponding to the request with the largest non-zero mark as the first actual requirement. If there are multiple requests with the largest non-zero mark, sort these multiple requests according to the similarity magnitude, and determine the actual requirement corresponding to the request with the largest similarity as the first actual requirement. If there are no requests with non-zero marks, input the first request after the first processing into the first neural network model to obtain the predicted request output by the first neural network model. Continue to compare the similarity between each request in at least one request and the first request with the above two thresholds to determine the mark of each request in the second association relationship. If there are multiple requests with the largest non-zero mark, determine the first actual requirement in the foregoing manner. If there are still no requests with non-zero marks, send a response failure indication message to the network security operation client.

[0082] In the above manner, when the first actual requirement in the second association relationship cannot be determined based on the first request after the first processing, by obtaining the predicted request calculated by the neural network model based on the first request after the first processing, and further calculating the similarity between the predicted request and each request in the second association relationship, the subsequent determination of the first actual requirement can be carried out. Compared with directly sending a response failure indication message to the network security operation client when the first actual requirement in the second association relationship cannot be determined based on the first request after the first processing, the above manner further improves the ability to match the first actual requirement according to the first request input by the user.

[0083] S140. The network security operation server determines a first service interface according to the first actual requirement and the first association relationship.

[0084] Among them, the first association relationship is used to associate at least one actual requirement and at least one network security management service interface. The first actual requirement is included in at least one actual requirement, and the first service interface is included in at least one network security management service interface.

[0085] Exemplarily, the first association relationship is also used to associate at least one actual requirement and at least one permission level, and the first association relationship is also used to associate at least one permission level and at least one network security management service interface. The network security management service interface is used to provide corresponding services.

[0086] The permission level is used to perform fine-grained control over the services of the network security management service interfaces that a user can access. The specific content of the permission level can be set as needed. For example, the permission level includes a low-level permission and a high-level permission, and the level of the high-level permission is higher than that of the low-level permission.

[0087] Further exemplarily, the method further includes: the network security operation server determines a first permission level of the user according to the identity data of the user, and the first permission level is included in at least one permission level; the network security operation server determines a first service interface according to the first actual demand, the first permission level, and the first association relationship.

[0088] For example, the first association relationship is shown in Table 2:

[0089] Table 2

[0090]

[0091] It can be seen from Table 2 that the network security management service interfaces corresponding to different permission levels may be the same or different, realizing the function of fine-grained control over the network security management services that a user can access according to the user's permission level.

[0092] In one example, the way for the network security operation server to generate the first association relationship includes:

[0093] The network security operation server obtains at least one actual demand based on a big data statistical algorithm or a web crawler algorithm, and then obtains at least one network security management service interface and at least one permission level. The network security operation server determines the first association relationship according to at least one actual demand, at least one network security management service interface, and at least one permission level.

[0094] Among them, the network security operation server determines the actual demand corresponding to each network security management service interface based on a keyword matching algorithm.

[0095] For example, the network security operation server determines the keywords as "query" and "administrator" according to the network security management service interface "query compliance administrator", then filters out the actual demands that contain both of these two keywords, and finally establishes the corresponding relationship between the actual demands that contain both of these two keywords and "query compliance administrator" to generate the first association relationship.

[0096] Among them, the network security operation server can obtain the network security management service interfaces input manually, and at least one permission level, as well as the corresponding relationship between the two.

[0097] Further exemplarily, the network security operation server determines a first association relationship according to at least one actual requirement, at least one network security management service interface, and at least one permission level, including:

[0098] The network security operation server determines a display style corresponding to each actual requirement according to the type of service called by each actual requirement among at least one actual requirement. The display style is used to stipulate the manner in which the service provided by the network security management service interface corresponding to each actual requirement is presented on the human-computer interaction interface of the network security operation client. The network security operation server determines the first association relationship according to at least one actual requirement, at least one network security management service interface, the display style corresponding to each actual requirement, and at least one permission level. That is, the first association relationship is also used to associate at least one actual requirement and at least one display style.

[0099] For example, the type of service called by each actual requirement includes one of the following types: document type, data list type, service scheduling type, web link type, etc. Services of the document type include providing security operation knowledge documents, providing security operation operation documents, etc. Services of the data list type include providing security operation index information, providing compliance administrator information, providing data information, providing alarm information, etc. Services of the service scheduling type include providing security operation service scheduling, etc. Services of the web link type include providing links to login pages, etc.

[0100] Such as Figure 2 As shown, after the user inputs the first request, the content of the corresponding network security management service is presented on the human-computer interaction interface of the network security operation client, and the display styles corresponding to different types of services are different, and each display style reflects the characteristics of the corresponding type of service. For example, services of the data list type are displayed in the form of a list of corresponding data, and services of the document type display marks such as "pdf" and "word" in the display area.

[0101] In the above manner, the display styles of services of the same type can be standardized, improving the user's visual experience.

[0102] S150, the network security operation server sends a first response to the network security operation client according to the first service interface. The network security operation client receives the first response.

[0103] Among them, the first response includes service data provided by the first service interface.

[0104] Specifically, the network security operation server determines the first response according to the first service interface, then sends the first response to the network security operation client, and the network security operation client receives the first response.

[0105] Exemplarily, the service data provided by the first service interface is the service name or the content corresponding to the service. For example, "Security Operations Service Scheduling", "User Logging in to the Webpage", "Security Operations Center Operation Manual", "Zhang San, Li Si, Wang Wu", etc.

[0106] S160, the network security operations client displays the first response to the user.

[0107] In one example, the method further includes:

[0108] S170, the network security operations client obtains an operation instruction input by the user regarding the first response, and the operation instruction is used to indicate accessing the service provided by the first service interface.

[0109] Exemplarily, the network security operations client includes an intelligent assistant module. The intelligent assistant module displays the first response to the user in the form of a chat window, and then obtains the click instruction of the user on the first response. The user's click on the first response indicates accessing the service provided by the first service interface.

[0110] S180, the network security operations client sends a call request to the network security operations server, and the call request is used to access the service provided by the first service interface.

[0111] S190, the network security operations server provides the service provided by the first service interface to the user through the network security operations client according to the call request.

[0112] This application takes into account that the network security operations client is vulnerable to malicious attacks. Compared with the network security operations client directly calling the first service interface according to the operation instruction, after receiving the call request, the network security operations server provides the service provided by the first service interface to the user through the network security operations client, that is, the main body calling the first service interface is only the network security operations server, which improves the security of the first service interface.

[0113] As can be seen from the above embodiments, after the cybersecurity operation client in this application obtains the first request (i.e., the data input by the user into the cybersecurity operation client), it sends the first request to the cybersecurity operation server. The cybersecurity operation server performs a first processing on the first request according to the service name, so as to facilitate obtaining the corresponding first actual requirement subsequently. The service name includes the names of the services corresponding to the at least one cybersecurity management service interface. The cybersecurity operation server determines the first service interface corresponding to the first actual requirement according to the first actual requirement and the first association relationship. Since the data input by the user on the cybersecurity operation client is not standardized enough in content, if the first association relationship directly associates the requests that the user may input and the at least one cybersecurity management service interface, then each cybersecurity management service interface may correspond to a dozen or dozens of requests that the user may input, and the data volume is huge, which will lead to a slow processing speed of the solution involving the first association relationship. Therefore, in this application, after performing the first processing on the first request and then determining the actual requirement according to the first request after the first processing, the determined actual requirement is more accurate, and the number of actual requirements corresponding to each cybersecurity management service interface in the first association relationship is controllable, greatly reducing the data volume of the first association relationship. This enables the subsequent cybersecurity operation server to greatly improve the efficiency of determining the first service interface according to the first association relationship and the first actual requirement. The cybersecurity operation server sends a first response to the cybersecurity operation client according to the first service interface. After receiving the first response, the cybersecurity operation client displays the first response to the user, avoiding the problem that the user has a low efficiency in obtaining the target service when using the cybersecurity operation service because they need to search for the target service from a large amount of list information, optimizing the operation convenience of the cybersecurity operation system and improving the user's satisfaction with using the cybersecurity operation system.

[0114] This application also provides an example of a data processing method for cybersecurity operations, which specifically includes the following steps:

[0115] S210. The cybersecurity operation server determines a first association relationship according to at least one actual requirement and at least one cybersecurity management service interface. The first association relationship is used to associate at least one actual requirement and at least one cybersecurity management service interface.

[0116] Exemplarily, the cybersecurity operation server obtains at least one actual requirement based on a big data statistical algorithm or a web crawler algorithm.

[0117] In one example, the cybersecurity operation server determines the actual requirement corresponding to each cybersecurity management service interface based on a keyword matching algorithm.

[0118] Further exemplarily, the network security operation server determines a first association relationship according to at least one actual requirement, at least one network security management service interface, and at least one permission level. The permission level is used to perform fine-grained control over the services of the network security management service interfaces that a user can obtain. The specific content of the permission level can be set as needed. For example, the permission level includes a low-level permission and a high-level permission, and the level of the high-level permission is higher than that of the low-level permission.

[0119] Further exemplarily, before S210, the network security operation server determines a display style corresponding to each actual requirement according to the type of service called by each actual requirement in at least one actual requirement. The display style is used to specify the manner in which the services provided by the network security management service interfaces corresponding to each actual requirement are presented on the human-computer interaction interface of the network security operation client. The network security operation server determines the first association relationship according to at least one actual requirement, at least one network security management service interface, and at least one permission level, including:

[0120] The network security operation server determines the first association relationship according to at least one actual requirement, at least one network security management service interface, the display style corresponding to each actual requirement, and at least one permission level.

[0121] For the exemplary content of the first association relationship, refer to the description in method S140, which will not be elaborated here.

[0122] S220, the network security operation server determines a second association relationship according to at least one request and at least one actual requirement.

[0123] The second association relationship is used to associate the at least one request and the at least one actual requirement, where each actual requirement in the at least one actual requirement is associated with one or more requests.

[0124] For the exemplary content of the second association relationship, refer to the description in method S130, which will not be elaborated here.

[0125] S230, the network security operation server obtains a first neural network model, which is used to learn the characteristics of the requests input by users corresponding to each actual requirement based on the service data of network security operations, and / or the characteristics of the requests corresponding to the actual requirements whose usage times are greater than a first threshold.

[0126] The network security operation server trains the first neural network model in a supervised learning manner, using the data generated during the service process of network security operations as training data. The first neural network model uses a classification algorithm, such as a support vector machine algorithm or a nearest neighbor algorithm, etc.

[0127] S240, the network security operation server receives a first request from the network security operation client, and the first request is the data input by the user into the network security operation client.

[0128] S250, the network security operation server performs a first processing on the first request according to the service name.

[0129] Among them, the service name includes the names of services corresponding to at least one network security management service interface. The services corresponding to at least one network security management service interface include other services such as securely querying information, securely configuring services, securely invoking services, and securely consulting document materials, etc., and this application does not make any limitations in this regard. Correspondingly, the names of each service can be information query, service configuration, service invocation, and consulting document materials, etc., and the names of each service can be set according to actual needs, and this application does not make any limitations in this regard.

[0130] Exemplarily, the first processing includes: identifying the keywords in the first request that match the service name, or supplementing the content in the first request that matches the service name. For specific example content, refer to the description in method S120, and this application will not elaborate here.

[0131] S260, the network security operation server obtains the first actual requirement according to the first request after the first processing and the second association relationship.

[0132] Exemplarily, the network security operation server determines the similarity between the first request after the first processing and each request in at least one request, and determines whether there is a request that meets the preset condition in at least one request according to the similarity corresponding to each request; if there is a request that meets the preset condition in at least one request, the first actual requirement is determined according to the request that meets the preset condition and the second association relationship.

[0133] Exemplarily, the value of the similarity = the number of characters in each request that are the same as those in the first request after the first processing / the number of characters in the first request after the first processing, and the characters can be Chinese characters or characters in other languages.

[0134] Among them, the preset condition can be set according to actual needs, and this application does not make any limitations in this regard. For example, the preset condition is that the similarity needs to be within a preset numerical range.

[0135] Further exemplarily, if at least one request does not include a request that meets the preset conditions, input the first request after the first processing into the first neural network model to obtain a predicted request output by the first neural network model. Determine the similarity between the predicted request and each request among the at least one request; according to the similarity corresponding to each request, determine whether there is a request that meets the preset conditions among the at least one request; if there is a request that meets the preset conditions among the at least one request, determine the first actual demand according to the request that meets the preset conditions and the second association relationship. If there is no request that meets the preset conditions among the at least one request, send a response failure indication message to the network security operation client. Wherein, the usage times is the number of times of providing services through the service interface of the network security management service corresponding to the actual demand, and the first threshold can be set according to the actual demand.

[0136] For other implementation contents of the network security operation server to obtain the first actual demand, refer to method S130, which will not be elaborated here.

[0137] S270. The network security operation server determines a first service interface according to the first actual demand and the first association relationship.

[0138] Exemplarily, the network security operation server determines the first permission level of the user according to the identity data of the user, and the first permission level is included in at least one permission level; the network security operation server determines the first service interface according to the first actual demand, the first permission level and the first association relationship, and can also determine the display style corresponding to the first service interface.

[0139] S280. The network security operation server determines a first response according to the first service interface.

[0140] Wherein, the first response includes service data provided by the first service interface.

[0141] S290. The network security operation server sends the first response to the network security operation client.

[0142] In one example, the method further includes:

[0143] S2100. The network security operation server receives a call request from the network security operation client, and the call request is used to access the service provided by the first service interface.

[0144] S2110. The network security operation server provides the service provided by the first service interface to the user through the network security operation client according to the call request.

[0145] For other implementation manners and effects in the above embodiments, refer to methods S110-S190, which will not be elaborated in this application.

[0146] Based on the data processing method for network security operation provided in the above embodiments, the present application provides a data processing device for network security operation, which is applied to a network security operation system. The network security operation system includes a network security operation client and a network security operation server. The network security operation server is used to obtain at least one network security management service interface and provide the services of the at least one network security management service interface to users through the network security operation client. The following will be described in combination with Figure 3 this device:

[0147] A first data transmission module, configured to send a first request from the network security operation client to the network security operation server, where the first request is data input by the user into the network security operation client;

[0148] A first request processing module, configured to perform a first processing on the first request by the network security operation server according to the service name, where the service name includes the names of the services of at least one network security management service interface;

[0149] A first actual requirement obtaining module, configured to obtain a first actual requirement by the network security operation server according to the first request after the first processing;

[0150] A first service interface obtaining module, configured to determine a first service interface by the network security operation server according to the first actual requirement and a first association relationship, where the first association relationship is used to associate at least one actual requirement and at least one network security management service interface, the first actual requirement is included in at least one actual requirement, and the first service interface is included in at least one network security management service interface;

[0151] A second data transmission module, configured to send a first response from the network security operation server to the network security operation client according to the first service interface, where the first response includes service data provided by the first service interface;

[0152] A human-computer interaction module, configured to display the first response to the user by the network security operation client.

[0153] In one example, the device further includes:

[0154] A permission level obtaining module, configured to determine a first permission level of the user by the network security operation server according to the identity data of the user. The first service interface obtaining module is configured to determine a first service interface by the network security operation server according to the first actual requirement, the first permission level and the first association relationship, where the first association relationship is further used to associate at least one actual requirement and at least one permission level, the first association relationship is further used to associate at least one permission level and at least one network security management service interface, and the first permission level is included in at least one permission level.

[0155] In one example, the apparatus further includes:

[0156] A human-computer interaction module, further configured to obtain, for the network security operation client, an operation instruction input by a user regarding a first response, where the operation instruction is used to indicate accessing the service provided by the first service interface;

[0157] A first data transmission module, further configured to send, for the network security operation client, a call request to the network security operation server, where the call request is used to access the service provided by the first service interface;

[0158] A second data transmission module, further configured to provide, for the network security operation server according to the call request, the service provided by the first service interface to the user through the network security operation client.

[0159] In one example, the apparatus further includes:

[0160] A first association relationship determination module, configured to obtain, for the network security operation server, at least one actual requirement based on a big data statistical algorithm;

[0161] The first association relationship determination module is further configured to obtain, for the network security operation server, at least one network security management service interface and at least one permission level;

[0162] The first association relationship determination module is further configured to determine, for the network security operation server, a first association relationship according to at least one actual requirement, at least one network security management service interface, and at least one permission level.

[0163] In one example, the apparatus further includes:

[0164] A display style determination module, configured to determine, for the network security operation server, a display style corresponding to each actual requirement according to the type of service called by each actual requirement in at least one actual requirement, where the display style is used to specify the manner in which the service provided by the network security management service interface corresponding to each actual requirement is presented on the human-computer interaction interface of the network security operation client, where

[0165] The first association relationship determination module is further configured to determine, for the network security operation server, a first association relationship according to at least one actual requirement, at least one network security management service interface, the display style corresponding to each actual requirement, and at least one permission level.

[0166] In one example, the apparatus further includes:

[0167] The second association relationship determination module is used for the network security operation server to obtain a second association relationship, which is used to associate at least one request and at least one actual requirement, where each actual requirement of the at least one actual requirement is associated with one or more requests;

[0168] The similarity matching module is used for the network security operation server to determine the similarity between the first request after the first processing and each request in the at least one request;

[0169] The similarity matching module is also used for the network security operation server to determine whether there is a request that meets the preset conditions in the at least one request according to the similarity corresponding to each request;

[0170] If there is a request that meets the preset conditions in the at least one request, the first actual requirement acquisition module is also used for the network security operation server to determine the first actual requirement according to the request that meets the preset conditions and the second association relationship.

[0171] In one example, the device further includes a predicted request acquisition module, and the predicted request acquisition module is used to store and run the first neural network model.

[0172] If there is no request that meets the preset conditions in the at least one request, the first actual requirement acquisition module is also used for the network security operation server to input the first request after the first processing into the first neural network model, and obtain the predicted request output by the first neural network model. The first neural network model is used to learn the characteristics of the requests input by users corresponding to each actual requirement based on the service data of network security operations, and / or the characteristics of the requests corresponding to the actual requirements whose usage times are greater than the first threshold.

[0173] The similarity matching module is also used for the network security operation server to determine the similarity between the predicted request and each request in the at least one request;

[0174] The similarity matching module is also used for the network security operation server to determine whether there is a request that meets the preset conditions in the at least one request according to the similarity corresponding to each request;

[0175] If there is a request that meets the preset conditions in the at least one request, the first actual requirement acquisition module is also used for the network security operation server to determine the first actual requirement according to the request that meets the preset conditions and the second association relationship.

[0176] In one example, if there is no request that meets the preset conditions in the at least one request, the second data transmission module is also used for the network security operation server to send a response failure indication message to the network security operation client, and the response failure indication message is used to indicate that the acquisition of the network security management service interface fails.

[0177] For other implementation manners and effects of the device, refer to the embodiments of the data processing method for network security operation described above, which will not be elaborated herein.

[0178] The basic principles of the present application have been described above in conjunction with specific embodiments. However, it should be noted that the advantages, benefits, effects, etc. mentioned in the present application are only examples and not limitations. It cannot be considered that these advantages, benefits, effects, etc. are essential for each embodiment of the present application. Additionally, the specific details disclosed above are only for illustrative and facilitating understanding purposes, rather than limitations. These details do not limit the present application to necessarily adopt the above specific details for implementation.

[0179] It should be understood that although the steps in the flowchart of the drawings are shown sequentially in the direction of the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear indication in this document, the execution of these steps has no strict order limitation, and they can be executed in other orders. Moreover, at least a part of the steps in the flowchart of the drawings may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or sub-steps or stages of other steps.

[0180] The block diagrams of the devices, apparatuses, equipment, and systems involved in the present application are only illustrative examples and do not intend to require or imply that they must be connected, arranged, and configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, equipment, and systems can be connected, arranged, and configured in any way. Words such as "including", "comprising", "having", etc. are open-ended terms, meaning "including but not limited to", and can be used interchangeably with each other. The word "or" and "and" used herein refer to the word "and / or", and can be used interchangeably with each other, unless the context clearly indicates otherwise. The word "such as" used herein refers to the phrase "such as but not limited to", and can be used interchangeably with each other.

[0181] It also needs to be pointed out that in the devices, equipment, and methods of the present application, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent solutions of the present application.

[0182] The above description of the disclosed aspects enables any person skilled in the art to make or use the present application. Various modifications to these aspects are very obvious to those skilled in the art, and the general principles defined herein can be applied to other aspects without departing from the scope of the present application. Therefore, the present application is not intended to be limited to the aspects shown herein, but rather to the broadest scope consistent with the principles and novel features disclosed herein.

[0183] The foregoing description has been presented for purposes of illustration and description. Furthermore, this description is not intended to limit embodiments of the present application to the form disclosed herein. Although several example aspects and embodiments have been discussed above, those skilled in the art will recognize some variations, modifications, alterations, additions, and sub-combinations thereof.

Claims

1. A data processing method for network security operation, characterized in that, Applied to a network security operation system, the network security operation system includes a network security operation client and a network security operation server. The network security operation server is used to obtain at least one network security management service interface and provide the service corresponding to the at least one network security management service interface to the user through the network security operation client. The method includes: The network security operation client sends a first request to the network security operation server, and the first request is the data input by the user into the network security operation client; The network security operation server performs a first processing on the first request according to the service name, and the service name includes the name of the service corresponding to the at least one network security management service interface; The network security operation server obtains a first actual requirement according to the first request after the first processing; The network security operation server determines a first service interface according to the first actual requirement and a first association relationship, wherein the first association relationship is used to associate at least one actual requirement and the at least one network security management service interface, the first actual requirement is included in the at least one actual requirement, and the first service interface is included in the at least one network security management service interface; The network security operation server sends a first response to the network security operation client according to the first service interface, and the first response includes the service data provided by the first service interface; The network security operation client displays the first response to the user.

2. The method according to claim 1, wherein The method further includes: The network security operation server determines a first permission level of the user according to the identity data of the user, wherein the network security operation server determines a first service interface according to the first actual requirement and the first association relationship, including: The network security operation server determines a first service interface according to the first actual requirement, the first permission level and the first association relationship, wherein the first association relationship is further used to associate the at least one actual requirement and at least one permission level, the first association relationship is further used to associate the at least one permission level and the at least one network security management service interface, and the first permission level is included in the at least one permission level.

3. The method according to claim 1 or 2, characterized in that, The method further includes: The network security operation client obtains an operation instruction input by the user regarding the first response, and the operation instruction is used to indicate accessing the service provided by the first service interface; The network security operation client sends a call request to the network security operation server, and the call request is used to access the service provided by the first service interface; The network security operation server provides the service provided by the first service interface to the user through the network security operation client according to the call request.

4. The method according to claim 2, characterized in that, The method further includes: The network security operation server obtains the at least one actual requirement based on a big data statistical algorithm; The network security operation server obtains the at least one network security management service interface and the at least one permission level; The network security operation server determines the first association relationship according to the at least one actual requirement, the at least one network security management service interface, and the at least one permission level.

5. The method according to claim 4, characterized in that, Before the network security operation server determines the first association relationship according to the at least one actual requirement, the at least one network security management service interface, and the at least one permission level, the method further includes: The network security operation server determines a display style corresponding to each actual requirement according to the type of service called by each actual requirement in the at least one actual requirement, where the display style is used to specify the manner in which the service provided by the network security management service interface corresponding to each actual requirement is presented on the human-computer interaction interface of the network security operation client, where The network security operation server determines the first association relationship according to the at least one actual requirement, the at least one network security management service interface, and the at least one permission level, including: The network security operation server determines the first association relationship according to the at least one actual requirement, the at least one network security management service interface, the display style corresponding to each actual requirement, and the at least one permission level.

6. The method according to claim 1 or 2, characterized in that, The first processing includes: identifying keywords matching the service name, or supplementing content matching the service name.

7. The method according to claim 2, wherein The network security operation server obtains a first actual requirement according to the first request after the first processing, including: The network security operation server obtains a second association relationship, where the second association relationship is used to associate at least one request and the at least one actual requirement, and each actual requirement in the at least one actual requirement is associated with one or more of the requests; The network security operation server determines the similarity between the first request after the first processing and each request in the at least one request; The network security operation server determines whether there is a request that meets a preset condition in the at least one request according to the similarity corresponding to each request; If there is a request that meets the preset condition in the at least one request, the network security operation server determines a first actual requirement according to the request that meets the preset condition and the second association relationship.

8. The method according to claim 7, characterized in that The method further includes: If there is no request that meets the preset condition in the at least one request, the network security operation server inputs the first request after the first processing into a first neural network model to obtain a predicted request output by the first neural network model, where the first neural network model is used to learn the characteristics of the requests input by users corresponding to each actual requirement according to the service data of network security operations, and / or the characteristics of the requests corresponding to the actual requirements whose usage times are greater than a first threshold; The network security operation server determines the similarity between the predicted request and each request in the at least one request; The network security operation server determines whether the at least one request includes a request that meets the preset condition according to the similarity corresponding to each request; If the at least one request includes a request that meets the preset condition, the network security operation server determines a first actual requirement according to the request that meets the preset condition and the second association relationship.

9. The method according to claim 8, characterized in that, After the network security operation server determines the similarity between the predicted request and each request in the at least one request, and the network security operation server determines whether the at least one request includes a request that meets the preset condition according to the similarity corresponding to each request, the method further includes: If the at least one request does not include a request that meets the preset condition, the network security operation server sends a response failure indication message to the network security operation client, and the response failure indication message is used to indicate that the acquisition of the network security management service interface fails.

10. A data processing device for network security operation, characterized in that, Applied to a network security operation system, the network security operation system includes a network security operation client and a network security operation server. The network security operation server is used to obtain at least one network security management service interface, and provide services corresponding to the at least one network security management service interface to a user through the network security operation client. The device includes: A first data transmission module, configured to send a first request from the network security operation client to the network security operation server, where the first request is data input by the user to the network security operation client; A first request processing module, configured to perform a first processing on the first request by the network security operation server according to the service name, where the service name includes the names of the services corresponding to the at least one network security management service interface; A first actual requirement acquisition module, configured to obtain a first actual requirement by the network security operation server according to the first request after the first processing; A first service interface acquisition module, configured to determine a first service interface by the network security operation server according to the first actual requirement and a first association relationship, where the first association relationship is used to associate at least one actual requirement and the at least one network security management service interface, the first actual requirement is included in the at least one actual requirement, and the first service interface is included in the at least one network security management service interface; A second data transmission module, configured to send a first response from the network security operation server to the network security operation client according to the first service interface, where the first response includes service data provided by the first service interface; A human-computer interaction module, configured to display the first response to the user by the network security operation client.

Citation Information

Patent Citations

  • Method for establishing relevance relation among services under opened network

    CN102685242A

  • User authority management method and user authority management device

    CN107196896A