A threat detection method and device, electronic equipment and storage medium

By identifying and vectorizing the attributes of alarm payloads, matching candidate attack features, generating target vector sequences, and using a threat detection model, the problem of low accuracy in threat detection in existing technologies is solved, achieving more efficient alarm screening and device security assurance.

CN116015763BActive Publication Date: 2025-11-04NSFOCUS INFORMATION TECHNOLOGY CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211577802.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-09
Publication Date
2025-11-04
Estimated Expiration
2042-12-09

AI Technical Summary

Technical Problem

In existing technologies, threat detection methods based on source IP blacklists cannot effectively filter out key alarms, resulting in missed detections and low accuracy in threat detection.

Method used

By identifying the attributes of the alarm payload to be detected, determining the attribute information and undecoded information, performing vectorization processing, matching candidate attack features, generating a target vector sequence, and using a threat detection model to determine the threat level of the alarm payload.

Benefits of technology

It improves the accuracy of threat detection, better assists security operations personnel in alarm analysis and judgment, improves the efficiency of alarm analysis and response, and ensures equipment security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116015763B_ABST
    Figure CN116015763B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of network security, and in particular relates to a threat degree detection method and device, an electronic device and a storage medium. Attribute recognition is performed on alarm load corresponding to an alarm to be detected, each attribute information and each undecoded information contained in the alarm load are determined, each attribute information is subjected to vectorization processing, attribute features corresponding to the corresponding attribute information are obtained, each undecoded information is subjected to vectorization processing, undecoded features corresponding to the corresponding undecoded information are obtained, based on the attribute features, matched target attack features are determined from each candidate attack feature in a preset candidate attack feature, based on the matched target attack features, vector value updating is performed on the corresponding attribute features, a target vector sequence containing the updated attribute features and each undecoded feature is obtained, and based on the target vector sequence, a threat degree detection result of the alarm load is determined. In this way, the accuracy of threat degree detection is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, and in particular to a threat degree detection method and device, electronic equipment and a storage medium. BACKGROUND

[0002] At present, with the development of network technology, a network attack detection system will generate a large number of alarms every day, which need to be investigated. Security operation personnel need to screen out key alarms that cause device security problems and analyze the key alarms. The remaining alarm information will not cause device security problems and only needs to be retained for a period of time for investigation reference. Therefore, in order to improve the security of the device, it is necessary to screen out key alarms that may cause device security problems from a large number of alarms and analyze the key alarms, so as to improve the protection system of the device.

[0003] When monitoring alarm information, security operation personnel adopt certain screening strategies, including focusing on alarms of specific protection rules, focusing on alarms of sensitive business systems, and focusing on alarms triggered by malicious source IPs. These screening strategies cannot effectively reduce the number of alarms and are easy to miss key alarms. In addition, relying on manual screening of key alarms, the screening efficiency is not high. In order to improve the screening efficiency, the threat degree of the alarm is determined to screen out the key alarm from the alarm.

[0004] In related technologies, when determining the threat degree of the to-be-detected alarm, a source IP blacklist is usually preset, and the threat degree of the to-be-detected alarm is determined according to the IP address of the to-be-detected alarm and in combination with the preset source IP blacklist.

[0005] However, since the preset source IP blacklist cannot contain all the IP addresses corresponding to the key alarms, the problem of missed detection will occur. For example, when the key alarm is detected for the first time, since the IP address of the key alarm is not contained in the preset source IP blacklist, the threat degree of the key alarm determined is too low, and the key alarm cannot be screened out.

[0006] Therefore, the threat degree detection accuracy in related technologies is not high. SUMMARY

[0007] The embodiments of the present application provide a threat degree detection method, device, electronic equipment and storage medium to improve the accuracy of threat degree detection.

[0008] The specific technical solutions provided by the embodiments of the present application are as follows:

[0009] A threat degree detection method comprises:

[0010] Attribute identification is performed on an alarm payload corresponding to the alarm to be detected, and each attribute information and each undecoded information contained in the alarm payload is determined;

[0011] Each attribute information is subjected to vectorization processing respectively, and corresponding attribute information corresponding attribute features are obtained, and each undecoded information is subjected to vectorization processing respectively, and corresponding undecoded information corresponding undecoded features are obtained;

[0012] Based on each attribute feature, a matching target attack feature is determined from each candidate attack feature in a preset manner, wherein each candidate attack feature represents a network flow segment in a corresponding type of alarm payload used to determine an attack intention;

[0013] Based on each matching target attack feature, the corresponding attribute feature is subjected to vector value updating, and a target vector sequence containing the updated attribute feature and each undecoded feature is obtained;

[0014] Based on the target vector sequence, a threat degree detection result of the alarm payload is determined.

[0015] Optionally, the attribute identification performed on the alarm payload corresponding to the alarm to be detected to determine each attribute information and each undecoded information contained in the alarm payload comprises:

[0016] For each preset identification mode, the following operations are sequentially performed:

[0017] If it is determined that any one identification mode is used to identify attribute information, the corresponding attribute information and undecoded information are determined from the alarm payload corresponding to the alarm to be detected based on the identification mode, and the undecoded information is used as a new alarm payload;

[0018] If it is determined that the identification mode is used for information decoding, the corresponding decoding string and undecoded information are decoded from the alarm payload based on the identification mode, and the decoding string is used as a new alarm payload, the step of determining the corresponding attribute information and undecoded information from the alarm payload corresponding to the alarm to be detected is re-executed, and the decoding string is determined from the undecoded information based on each other identification mode used for information decoding.

[0019] Optionally, the determination of the corresponding attribute information and undecoded information from the alarm payload corresponding to the alarm to be detected based on the identification mode comprises:

[0020] Attribute information conforming to an attribute element format corresponding to the identification mode is identified from the alarm payload corresponding to the alarm to be detected based on the attribute element format;

[0021] Cutting the attribute information from the alarm payload to obtain undecoded information not containing the attribute information.

[0022] Optionally, the decoding corresponding decoded strings and undecoded information from the alarm payload based on the identification manner comprises:

[0023] Identifying each encoded string conforming to the encoding format from the alarm payload based on the encoding format corresponding to the identification manner;

[0024] Decoding the each encoded string respectively to obtain the decoded string corresponding to the corresponding encoded string;

[0025] Determining undecoded information not containing each decoded string from the alarm payload.

[0026] Optionally, the vectorizing the each attribute information respectively to obtain the attribute feature corresponding to the corresponding attribute information comprises:

[0027] For the specification string corresponding to each attribute type, the following operations are performed respectively: replacing the attribute information corresponding to any interference attribute type in the each attribute information with the specification string corresponding to the interference attribute type to obtain the each attribute information after replacement;

[0028] Character decomposition is performed on the each attribute information after replacement respectively to obtain the attribute character and the length of the payload character dictionary;

[0029] Mapping the each attribute character obtained to the attribute vector corresponding to the attribute character to obtain the attribute feature corresponding to the corresponding attribute information.

[0030] Optionally, the vector value updating the attribute feature corresponding to the corresponding attribute feature based on the matched each target attack feature to obtain the target vector sequence containing the updated attribute feature and the each undecoded feature comprises:

[0031] Generating the payload vector sequence containing the each attribute feature and the each undecoded feature;

[0032] Determining the value of the corresponding position sequence number of the attribute feature in the payload vector sequence based on the matched each target attack feature and the length of the payload character dictionary respectively;

[0033] Updating the vector value of the attribute feature corresponding to the each target attack feature to the value of the corresponding position sequence number respectively.

[0034] Optionally, the determining the threat degree detection result of the alarm payload based on the target vector sequence comprises:

[0035] Based on the trained threat degree detection model, the threat degree detection result of the alarm payload is determined by taking the target vector sequence as input data.

[0036] A threat degree detection apparatus comprises:

[0037] An identification module is configured to identify attributes of an alarm payload corresponding to an alarm to be detected, and determine attribute information and undecoded information contained in the alarm payload.

[0038] A first processing module is configured to respectively perform vectorization processing on the attribute information to obtain attribute features corresponding to the attribute information, and respectively perform vectorization processing on the undecoded information to obtain undecoded features corresponding to the undecoded information.

[0039] A determination module is configured to determine matched target attack features from preset candidate attack features based on the attribute features, wherein each candidate attack feature represents a network flow segment used to determine an attack intention in an alarm payload of a corresponding type.

[0040] A second processing module is configured to perform vector value updating on the attribute features based on the matched target attack features to obtain a target vector sequence containing the updated attribute features and the undecoded features.

[0041] A generation module is configured to determine a threat degree detection result of the alarm payload based on the target vector sequence.

[0042] Optionally, the identification module is further configured to:

[0043] For each identification manner, the following operations are sequentially performed:

[0044] If it is determined that any one identification manner is used to identify attribute information, the corresponding attribute information and undecoded information are determined from the alarm payload corresponding to the alarm to be detected based on the identification manner, and the undecoded information is taken as a new alarm payload.

[0045] If it is determined that the identification manner is used to decode information, the corresponding decoded string and undecoded information are decoded from the alarm payload based on the identification manner, the decoded string is taken as a new alarm payload, the step of determining the corresponding attribute information and undecoded information from the alarm payload corresponding to the alarm to be detected is re-executed, and the decoded string is determined from the undecoded information based on other identification manners used to decode information.

[0046] Optionally, when the corresponding attribute information and undecoded information are determined from the alarm payload corresponding to the alarm to be detected based on the identification manner, the identification module is further configured to:

[0047] identify attribute information conforming to the attribute element format from the alarm payload corresponding to the to-be-detected alarm based on the attribute element format corresponding to the identification manner;

[0048] cut the attribute information from the alarm payload to obtain undecoded information not containing the attribute information.

[0049] Optionally, when the decoding module decodes the corresponding decoded strings and the undecoded information from the alarm payload based on the identification manner, the identification module is further configured to:

[0050] identify each encoded string conforming to the encoding format from the alarm payload based on the encoding format corresponding to the identification manner;

[0051] decode the each encoded string respectively to obtain a decoded string corresponding to the corresponding encoded string;

[0052] determine undecoded information not containing the each decoded string from the alarm payload.

[0053] Optionally, the first processing module is further configured to:

[0054] respectively perform the following operations on the preset specification strings corresponding to each attribute type: replace attribute information corresponding to any interference attribute type in the each attribute information with a specification string corresponding to the interference attribute type to obtain each attribute information after replacement;

[0055] respectively perform character decomposition on the each attribute information after replacement to obtain corresponding attribute characters and the length of the payload character dictionary;

[0056] map the each attribute character obtained to a corresponding attribute vector to obtain an attribute feature corresponding to the corresponding attribute information.

[0057] Optionally, the second processing module is further configured to:

[0058] generate a payload vector sequence containing each attribute feature and each undecoded feature;

[0059] determine a value of a corresponding position serial number of the corresponding attribute feature in the payload vector sequence based on the each target attack feature matched and the length of the payload character dictionary respectively;

[0060] update a vector value of the corresponding attribute feature of the each target attack feature to a value of the corresponding position serial number respectively.

[0061] Optionally, the generation module is further configured to:

[0062] Based on the trained threat degree detection model, the threat degree detection result of the alarm payload is determined by taking the target vector sequence as input data.

[0063] An electronic device includes a memory, a processor, and a computer program stored on the memory and executable on the processor, and the processor implements the steps of the threat degree detection method when executing the program.

[0064] A computer readable storage medium has a computer program stored thereon, and the computer program implements the steps of the threat degree detection method when executed by a processor.

[0065] In the embodiments of the present application, the attribute recognition is performed on the alarm payload corresponding to the alarm to be detected, the attribute information and the undecoded information contained in the alarm payload are determined, the attribute information is vectorized respectively to obtain the attribute feature corresponding to the attribute information, the undecoded information is vectorized respectively to obtain the undecoded feature corresponding to the undecoded information, the matching target attack feature is determined from the preset candidate attack features based on the attribute features, the attribute feature is updated by vector value based on the matching target attack feature, the target vector sequence containing the updated attribute feature and the undecoded feature is obtained, and the threat degree detection result of the alarm payload is determined based on the target vector sequence. In this way, based on the attribute information and the undecoded information of the alarm payload corresponding to the alarm to be detected, the target attack feature reflecting the attack intention can be determined from the alarm payload, so that the attribute feature is updated by vector value based on the target attack feature, the target vector sequence is obtained, the threat degree detection is performed on the alarm to be detected based on the target vector sequence, the effectiveness of the attack feature reflecting the attack intention for the threat degree detection can be improved, and the threat degree of the alarm to be detected can be better determined, thereby improving the accuracy of the threat degree detection. BRIEF DESCRIPTION OF DRAWINGS

[0066] Figure 1 It is a flowchart of a threat degree detection method in the embodiments of the present application;

[0067] Figure 2 It is an example diagram of the specification string replacement in the embodiments of the present application;

[0068] Figure 3 It is an example diagram of character decomposition in the embodiments of the present application;

[0069] Figure 4 It is an example diagram of the target vector sequence in the embodiments of the present application;

[0070] Figure 5 It is a schematic diagram of the threat degree detection model in the embodiments of the present application;

[0071] Figure 6 Another flowchart of a threat degree detection method in an embodiment of the present application;

[0072] Figure 7 A structural diagram of a threat degree detection device in an embodiment of the present application;

[0073] Figure 8 A structural diagram of an electronic device in an embodiment of the present application. DETAILED DESCRIPTION

[0074] The technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative labor fall within the scope of the present application.

[0075] At present, with the development of network technology, a network attack detection system will generate a large number of alarms every day, which need to be investigated. Security operation personnel need to screen out key alarms causing device security problems and analyze the key alarms. The remaining alarm information will not cause device security problems and only needs to be retained for a period of time for investigation reference. Therefore, in order to improve the security of the device, it is necessary to screen out key alarms that may cause device security problems from a large number of alarms and analyze the key alarms, so as to improve the protection system of the device.

[0076] When monitoring alarm information, security operation personnel adopt certain screening strategies, including: focusing on alarms of specific protection rules, focusing on alarms of sensitive business systems, focusing on alarms triggered by malicious source IPs, etc. These screening strategies cannot effectively reduce the number of alarms and are easy to miss key alarms. In addition, relying on manual screening of key alarms, the screening efficiency is not high. In order to improve the screening efficiency, the threat degree of the alarm is determined to screen out the key alarm from the alarm.

[0077] In the related art, when determining the threat degree of the to-be-detected alarm, a source IP blacklist is usually preset, and the threat degree of the to-be-detected alarm is determined according to the IP address of the to-be-detected alarm and in combination with the preset source IP blacklist.

[0078] However, since the preset source IP blacklist cannot contain all the IP addresses corresponding to the key alarms, the problem of missing detection will occur. For example, when the key alarm is detected for the first time, since the IP address of the key alarm is not contained in the preset source IP blacklist, the threat degree of the key alarm determined is too low, and the key alarm cannot be screened out.

[0079] To solve the above problems, in the embodiments of the present application, the attribute information and the undecoded information contained in the alarm payload corresponding to the alarm to be detected are determined by performing attribute recognition on the alarm payload, the attribute information is vectorized respectively to obtain the attribute features corresponding to the attribute information, the undecoded information is vectorized respectively to obtain the undecoded features corresponding to the undecoded information, the target attack features matching the attribute features are determined from the preset candidate attack features, the attribute features are updated by vector value based on the matching target attack features, the target vector sequence containing the updated attribute features and the undecoded features is obtained, and the threat degree detection result of the alarm payload is determined based on the target vector sequence. In this way, based on the attribute information and the undecoded information of the alarm payload corresponding to the alarm to be detected, the target attack features reflecting the attack intention can be determined from the alarm payload, so that the attribute features are updated by vector value based on the target attack features, the target vector sequence is obtained, and the threat degree detection of the alarm to be detected is performed based on the target vector sequence. The effectiveness of the attack features reflecting the attack intention for threat degree detection can be improved, so that the threat degree of the alarm to be detected can be better determined, the accuracy of threat degree detection is improved, the efficiency of alarm analysis and response is improved, and the safety of the equipment is ensured.

[0080] Based on the above embodiments, refer to Figure 1 The flowchart of a threat degree detection method in the embodiments of the present application is shown in FIG. 1, which specifically includes the following steps.

[0081] Step 100: Perform attribute recognition on the alarm payload corresponding to the alarm to be detected, and determine the attribute information and the undecoded information contained in the alarm payload.

[0082] In the embodiments of the present application, when an alarm is detected, in order to perform threat degree detection on the alarm to be detected, the alarm payload corresponding to the alarm to be detected needs to be obtained, and the attribute recognition is performed on the obtained alarm payload to determine the attribute information and the undecoded information contained in the alarm payload.

[0083] Optionally, in the embodiments of the present application, when step 100 is performed, the attribute information and the undecoded information corresponding to each identification mode need to be obtained respectively, and specifically, taking any one identification mode (referred to as identification mode i) as an example, the process of obtaining the corresponding attribute information and undecoded information is as follows:

[0084] S1: If it is determined that the identification mode i is used to identify the attribute information, the corresponding attribute information and undecoded information are determined from the alarm payload corresponding to the alarm to be detected based on the identification mode i, and the undecoded information is taken as a new alarm payload.

[0085] In the embodiment of the present application, after obtaining the alarm payload to be detected, the type of the identification mode i is determined. When the type of the identification mode i is the identification mode for identifying attribute information, the corresponding attribute information and undecoded information are determined from the alarm payload based on the identification mode i. The undecoded information is taken as a new alarm payload, and the new alarm payload is identified by using the next identification mode.

[0086] It should be noted that the preset identification modes can include at least n types. The identification modes are numbered and sorted from 1 to n. The identification modes for identifying attribute information are sorted in front of the identification modes for identifying decoded strings. The number and order of the preset identification modes are not limited in the embodiment of the present application.

[0087] Optionally, the embodiment of the present application provides a possible implementation for determining the corresponding attribute information and undecoded information. The process of determining the corresponding attribute information and undecoded information in the embodiment of the present application is described below, which specifically includes:

[0088] S11: Based on the attribute element format corresponding to the identification mode i, attribute information conforming to the attribute element format is identified from the alarm payload corresponding to the alarm to be detected.

[0089] In the embodiment of the present application, the attribute element format corresponding to the identification mode i is determined. Based on the attribute element format corresponding to the identification mode i, a candidate string conforming to the attribute element format is determined from each candidate string contained in the alarm payload, and the determined candidate string is taken as attribute information.

[0090] The attribute element format includes at least an IP address attribute element format, a domain name attribute element format, a number attribute element format, and a random code attribute element format, which are not limited in the embodiment of the present application.

[0091] For example, assuming that the attribute element format corresponding to the identification mode i is the IP address attribute element format, and the alarm payload is "GET / HTTP / 1.1 r n Host: 192.168.1.1 r n r n", the identified attribute information conforming to the IP address attribute element format is "192.168.1.1".

[0092] S12: The attribute information is cut from the alarm payload to obtain undecoded information not containing the attribute information.

[0093] In the embodiment of the present application, after the attribute information conforming to the attribute element format is identified, the attribute information is cut from the alarm payload, so that the cut independent attribute information is obtained, and each candidate string not containing the attribute information is taken as the undecoded information contained in the alarm payload, and the position information of the attribute information and each candidate string not containing the attribute information in the alarm payload is recorded.

[0094] For example, assuming that the alarm payload is "GET / HTTP / 1.1\r\nHost:192.168.1.1\r\n\r\n", the identified attribute information is "192.168.1.1", the attribute information "192.168.1.1" is cut, so that the independent attribute information is "192.168.1.1", and the undecoded information not containing the attribute information is "GET / HTTP / 1.1\r\nHost:\r\n\r\n".

[0095] S2: if it is determined that the identification mode i is used for information decoding, the corresponding decoding string and undecoded information are obtained by decoding from the alarm payload based on the identification mode, the decoding string is taken as a new alarm payload, and the step of determining the corresponding attribute information and undecoded information from the alarm payload corresponding to the alarm to be detected is re-executed, and the decoding string is determined from the undecoded information based on each other identification mode used for information decoding.

[0096] In the embodiment of the present application, after the alarm payload of the alarm to be detected is obtained, the type of the identification mode i is judged, when the type of the identification mode i is the identification mode used for information decoding, each candidate string contained in the alarm payload is decoded based on the identification mode i, if it is determined that the candidate string can be decoded, the decoding string after the candidate string is decoded is obtained, the decoding string is taken as a new alarm payload, the next identification mode is used, and the step of determining the attribute information and undecoded information from the alarm payload corresponding to the alarm to be detected is re-executed, if it is determined that the candidate string cannot be decoded, the candidate string is not processed, the undecoded information is obtained, and the next identification mode is used to decode the undecoded information, if the next identification mode is the identification mode used for information decoding, each candidate string contained in the undecoded information is decoded, the candidate string that can be decoded and the candidate string that cannot be decoded are determined, the candidate string that cannot be decoded is taken as a new undecoded information, and the decoding of the new undecoded information is obtained by using each other identification mode in turn.

[0097] For example, the alarm payload is "Host:192.168.1.1\r\n\r\nChinese characters 41424344 Chinese characters", the recognition method 1 is the recognition method for identifying IP addresses. Using the recognition method 1 to parse the alarm payload, and the attribute element format corresponding to the recognition method 1 is the IP address attribute element format. Then the attribute information that conforms to the IP address attribute element format identified is "192.168.1.1", and each candidate string that does not contain attribute information is "Host:", "\r\n\r\n", "Chinese characters 41424344 Chinese characters". Take "Host:\r\n\r\nChinese characters 41424344 Chinese characters" as the undecoded information, and record the position information of the attribute information "192.168.1.1" as 1, and record the corresponding position information of each candidate string "Host:", "\r\n\r\n", "Chinese characters 41424344 Chinese characters" that does not contain attribute information as 2, 3, 4 respectively. The recognition method 2 is the recognition method for identifying Base64 encoding. Using the recognition method 2 to decode the undecoded information "Host:\r\n\r\nChinese characters 41424344 Chinese characters", then the candidate string that can be decoded is "41424344". Perform HEX parsing on "41424344" to obtain the corresponding decoded string "ABCD". The candidate strings that cannot be decoded are "Host:\r\n\r\n", "Chinese characters", 'Chinese characters'. Take "Host:\r\n\r\nChinese characters Chinese characters" as the undecoded information, and record the position information of the decoded string "ABCD" as 4.2, and record the corresponding position information of the candidate strings that cannot be decoded "Chinese characters", 'Chinese characters' as 4.1, 4.3 respectively. The recognition method 3 is the recognition method for identifying multiple URL encodings, and the recognition method 4 is the recognition method for identifying the "\\" string escape encoding. Then, successively use the recognition method 3 and the recognition method 4 to decode the new undecoded information to obtain the decoded string corresponding to the undecoded information, and record the position information of each attribute information, decoded string and undecoded information.

[0098] Optionally, in the embodiments of the present application, a possible implementation manner is provided to determine the corresponding decoded string and undecoded information. The process of determining the corresponding decoded string and undecoded information in the embodiments of the present application is described below, which specifically includes:

[0099] S21: Based on the encoding format corresponding to the recognition method i, identify each encoded string that conforms to the encoding format from the alarm payload.

[0100] In the embodiment of the present application, the encoding format corresponding to the identification mode i is determined, and based on the encoding format corresponding to the identification mode i, the candidate string conforming to the encoding format is determined from each candidate string contained in the alarm payload, and the determined candidate string is taken as the encoded string.

[0101] The encoding format includes at least multiple URL encoding format, HEX parsing encoding format, XML encoding format, hexadecimal encoding format, Base64 encoding format, "\" string escape encoding format, and CHR / CHAR encoding format, etc., which are not limited in the embodiment of the present application.

[0102] For example, assuming that the encoding format corresponding to the identification mode i is Base64 encoding format, and the alarm payload is "Chinese character Chinese character 41424344 Chinese character Chinese character", the encoded string conforming to the HEX parsing format is identified as "41424344" from the alarm payload.

[0103] S22: Decoding each encoded string respectively to obtain the decoding string corresponding to the respective encoded string.

[0104] In the embodiment of the present application, after the encoded string conforming to the encoding format is identified, each encoded string identified from the alarm payload corresponding to the alarm to be detected is decoded to obtain the decoding string corresponding to the respective encoded string.

[0105] For example, assuming that the encoding format corresponding to the identification mode i is HEX parsing format, and the alarm payload is "Chinese character Chinese character 41424344 Chinese character Chinese character", and the identified encoded string is "41424344", the Base64 decoding of the encoded string "41424344" is performed, and the decoding string is "ABCD".

[0106] S23: Determining the undecoded information not containing each decoding string from the alarm payload.

[0107] In the embodiment of the present application, after each encoded string is decoded, the decoding string corresponding to each encoded string is cut out from the alarm payload, thereby obtaining the cut independent decoding string, and each candidate string not containing the decoding string is taken as the undecoded information contained in the alarm payload, and the position information of the decoding string and each candidate string not containing the decoding string in the alarm payload is recorded.

[0108] For example, assuming that the alarm payload is "Chinese characters Chinese characters 41424344 Chinese characters Chinese characters", the identified encoding string is "41424344", the encoding string is parsed by using the HEX, the decoding string corresponding to the encoding string is "ABCD", and the undecoded information not containing the decoding string is "Chinese characters Chinese characters Chinese characters Chinese characters".

[0109] In step 110, the attribute information is vectorized respectively to obtain the attribute feature corresponding to the attribute information, and the undecoded information is vectorized respectively to obtain the undecoded feature corresponding to the undecoded information.

[0110] In the embodiment of the present application, after obtaining the attribute information and the undecoded information of the alarm payload, the attribute information is vectorized respectively to obtain the attribute feature corresponding to the attribute information, and the undecoded information is vectorized respectively to obtain the undecoded feature corresponding to the undecoded information.

[0111] Optionally, in the embodiment of the present application, a possible implementation manner for the vectorization is provided, and the process of the vectorization in the embodiment of the present application is described below, which specifically includes:

[0112] A1: for the preset standard string corresponding to each attribute type, the following operations are performed respectively: the attribute information corresponding to any interference attribute type in the attribute information is replaced by the standard string corresponding to the interference attribute type to obtain the replaced attribute information.

[0113] In the embodiment of the present application, after obtaining the attribute information, for the preset standard string corresponding to each attribute type, the following operations are performed respectively: the attribute information corresponding to any interference attribute type in the attribute information is determined, the standard string corresponding to the interference attribute type is determined, the attribute information corresponding to the interference attribute type is replaced by the standard string corresponding to the interference attribute type to obtain the replaced attribute information.

[0114] For example, the standard string corresponding to each interference attribute type can be, for example, the standard string "ipaddress" corresponding to the IP address interference attribute, the standard string "website" corresponding to the website interference attribute, the standard string "webpage" corresponding to the webpage interference attribute, the standard string "version" corresponding to the version number interference attribute, the standard string "number" corresponding to the number interference attribute, and the standard string "time" corresponding to the timestamp interference attribute, and the present application is not limited thereto.

[0115] For example, referring to Figure 2As shown, it is an example diagram of the string replacement in the embodiment of the present application. Assuming that the attribute information corresponding to the IP address interference attribute in each attribute information is "221.122.70.1", the attribute information corresponding to the website interference attribute is "weixin.mysrmyy.com", the attribute information corresponding to the version number interference attribute is "1.1", the attribute information corresponding to the number interference attribute is "1052", and the attribute information corresponding to the webpage interference attribute is " / module / payment / FCKeditor / editor / admin.php", the attribute information "221.122.70.1" is replaced by the standard string "ipaddress", the attribute information "weixin.mysrmyy.com" is replaced by the standard string "website", the attribute information "1.1" is replaced by the standard string "version", the attribute information "1052" is replaced by the standard string "number", and the attribute information " / module / payment / FCKeditor / editor / admin.php" is replaced by the standard string "webpage".

[0116] It should be noted that in the embodiment of the present application, when the string replacement is performed, if there are at least two same attribute information in each attribute information, the at least two same attribute information is replaced by the same standard string.

[0117] For example, the attribute information corresponding to the IP address interference attribute in each attribute information is "221.122.70.1", "221.122.70.2", and "221.122.70.3". The "221.122.70.1" is replaced by the standard string "ipaddress", the "221.122.70.2" is replaced by the standard string "ipaddress", and the "221.122.70.3" is replaced by the standard string "ipaddress".

[0118] A2: respectively performing character decomposition on each attribute information after the replacement to obtain the corresponding attribute character and the length of the payload character dictionary.

[0119] In the embodiment of the present application, after obtaining each attribute information after the replacement, the following operations are performed on each attribute information after the replacement: performing character decomposition on any attribute information after the replacement to obtain the attribute character corresponding to the attribute information, composing the attribute characters to obtain the payload character dictionary, and obtaining the length of the payload character dictionary.

[0120] In the embodiment of the present application, the character decomposition is performed on each attribute information after the replacement to obtain the attribute character corresponding to the attribute information. Figure 3As shown, the example diagram of character decomposition in the embodiment of the present application is shown, and each attribute information is "get", "zh", "cn", "live tile", "preinstall", "variable", "threshold", "http", "version", "connection", "website", etc. Each attribute information is subjected to character decomposition, and the corresponding attribute character is "g e t", "z h", "c n", "l i v e t i l e", "p r e i n s t a l l", "variable", "threshold", "http", "version", "connection", "website", etc.

[0121] A3: Each attribute character obtained is mapped to a corresponding attribute vector, and an attribute feature corresponding to the corresponding attribute information is obtained.

[0122] In the embodiment of the present application, after obtaining each attribute character corresponding to the alarm payload, each attribute character obtained is mapped to a corresponding attribute vector based on the mapping relationship between each candidate character and the corresponding attribute vector pre-stored, and an attribute feature corresponding to the corresponding attribute information is obtained.

[0123] In the embodiment of the present application, the attribute character is mapped to the attribute vector in the word embedding manner, and the present application is not limited thereto.

[0124] Step 120: Based on each attribute feature, a matching target attack feature is determined from each candidate attack feature pre-set.

[0125] Each candidate attack feature represents a network flow segment in the corresponding type of alarm payload used to determine the attack intention.

[0126] In the embodiment of the present application, for each attribute feature obtained, the following operation is performed: based on the attribute feature, a target attack feature matching the attribute feature is found from each candidate attack feature pre-set.

[0127] Each candidate attack feature pre-set may be, for example, an eval attack feature and a chmod attack feature corresponding to a system command execution related function, a fopen attack feature and a fwrite attack feature corresponding to a system file operation related function, and ROT13 encoding corresponding to a strong encryption and decryption function, and the present application is not limited thereto.

[0128] For example, assuming that the obtained attribute features include the attribute feature "djksfjksd", and the preset candidate attack features include the eval attack feature "djksfjksd", it is determined that the attribute features include the eval attack feature, and the eval attack feature in the attribute features is taken as the target attack feature.

[0129] Step 130: Based on the matched target attack features, the corresponding attribute features are updated in vector value, and a target vector sequence including the updated attribute features and the undecoded features is obtained.

[0130] In the embodiment of the application, after the matched target attack features are obtained, the attribute features corresponding to the target attack features are updated in vector value based on the target attack features, and a target vector sequence including the updated attribute features and the undecoded features is obtained.

[0131] Optionally, in the embodiment of the application, a possible implementation of the vector value updating is provided, and the process of the vector value updating in the embodiment of the application is described below, which specifically includes:

[0132] B1: A payload vector sequence including the attribute features and the undecoded features is generated.

[0133] In the embodiment of the application, the attribute features corresponding to the attribute information and the undecoded features corresponding to the undecoded information are obtained, and based on the recorded position information of the attribute information, the decoded string and the undecoded information, a payload vector sequence including the attribute features and the undecoded features is generated.

[0134] B2: Based on the matched target attack features and the length of the payload character dictionary respectively, the corresponding position sequence number values of the corresponding attribute features in the payload vector sequence are determined.

[0135] In the embodiment of the application, for the matched target attack features, the following operations are performed respectively: based on any one of the matched target attack features, the value of the position sequence number of the attribute feature corresponding to the target attack feature in the payload vector sequence is determined.

[0136] For example, assuming that there are M preset candidate attack features, the length of the payload character dictionary is L, and the length of the payload vector sequence is N, when the matched target attack feature is the i th one of the candidate attack features, the value of the position sequence number N+i of the attribute feature corresponding to the target attack feature in the payload vector sequence is L+i.

[0137] B3: The vector values of the attribute features corresponding to the target attack features are updated to the values of the corresponding position sequence numbers respectively.

[0138] After determining the value of the corresponding position sequence number of the attribute feature corresponding to each target attack feature in the payload vector sequence, the following operations are performed for each target attack feature: the vector value of the attribute feature corresponding to the target attack feature is updated to the value of the corresponding position sequence number.

[0139] For example, referring to FIG. 2, Figure 4 As shown in FIG. 2, which is an example diagram of the target vector sequence in the embodiments of the present application, the length L of the payload character dictionary is 40, the length N of the payload vector sequence is 100, the preset candidate attack feature is 5, the target attack feature is attack feature 2, and the vector value corresponding to the attack feature 2 is updated to the value of the corresponding position sequence number 102 (N+2) which is 42 (L+2).

[0140] In the payload vector sequence, the 0 value at the back indicates that the number of vectors in the payload vector sequence is only 95, and the remaining 5 are filled with 0, so that the length of the payload vector sequence reaches N, that is, 100.

[0141] Step 140: determining a threat degree detection result of the alarm payload based on the target vector sequence.

[0142] Specifically, when step 140 is performed, it includes: based on the trained threat degree detection model, taking the target vector sequence as input data, determining the threat degree detection result of the alarm payload.

[0143] In the embodiments of the present application, after obtaining the target vector sequence, the target vector sequence is input into the trained threat degree detection model, the threat degree detection model is used to detect the threat degree of the target vector sequence, and the threat degree detection result of the alarm payload is determined.

[0144] For example, referring to FIG. 2, Figure 5As shown in the figure, the threat degree detection model in the embodiment of the present application extracts high-dimensional abstract features of the target vector sequence through a convolutional neural network (CNNS). The CNNS can automatically extract features of the target vector sequence by determining parameters of each convolution kernel, and can extract effective information from the alarm payload. A local response normalization (LRN) layer is introduced. The LRN simulates the inhibition phenomenon of adjacent neurons in a biologically active neuron, can increase neurons with a larger feedback value, and suppress neurons with a smaller feedback value in different feature maps at the same position to achieve the purpose of lateral inhibition and improve the generalization degree. A double-layer long-short term memory (LSTM) model with an attention mechanism is introduced to detect the threat degree of the payload. The LSTM model has a long-term memory function when processing sequence data, and can solve the problems of gradient disappearance and gradient explosion in the long sequence training process. In order to avoid the performance of the LSTM model from being reduced when processing longer sequence data and to make it difficult to learn a reasonable vector representation, an attention mechanism is introduced to improve the accuracy of the alarm payload threat degree detection. The attention mechanism focuses on the data more critical to the current task among the numerous input data, reduces the attention to other data, and even filters out irrelevant data to solve the data overload problem and improve the efficiency and accuracy of task processing. The attention mechanism selectively learns the input of the target vector sequence, associates the output sequence with it at the output, and realizes threat degree detection through a fully connected output layer.

[0145] In the embodiment of the present application, based on the attribute information and the undecoded information of the alarm payload corresponding to the alarm to be detected, the target attack features reflecting the attack intention can be determined from the alarm payload, so as to update the vector values of the corresponding attribute features based on the target attack features, obtain the target vector sequence, and then detect the threat degree of the alarm to be detected based on the target vector sequence. This can improve the effectiveness of the attack features reflecting the attack intention for threat degree detection, so as to better determine the threat degree of the alarm to be detected and improve the accuracy of threat degree detection. In addition, by replacing the attribute information corresponding to any attribute type in the attribute information with a standardized string corresponding to the attribute type, the interference of irrelevant semantics on threat degree detection can be reduced.

[0146] Based on the above embodiment, refer to Figure 6 As shown in the figure, another flowchart of a threat degree detection method in the embodiment of the present application is shown. Specifically, the method comprises the following steps:

[0147] Step 600: Collect the alarm payload corresponding to the alarm to be detected.

[0148] Step 601: nested decoding is performed on the alarm payload to obtain attribute information and undecoded information of the alarm payload.

[0149] Step 602: attribute information corresponding to any attribute type in each attribute information is replaced by a standard string corresponding to the attribute type to obtain replaced attribute information.

[0150] Step 603: character decomposition is performed on the replaced attribute information to obtain corresponding attribute characters.

[0151] Step 604: each attribute character obtained is mapped to a corresponding attribute vector to obtain attribute features corresponding to the corresponding attribute information.

[0152] Step 605: each undecoded information is subjected to vectorization processing to obtain undecoded features corresponding to the corresponding undecoded information.

[0153] In the embodiments of the present application, steps 602-604 and step 605 can be executed synchronously.

[0154] Step 606: based on the attribute features, a matching target attack feature is determined from preset candidate attack features.

[0155] Step 607: based on the matching target attack features, vector value updating is performed on the corresponding attribute features to obtain a target vector sequence containing the updated attribute features and the undecoded features.

[0156] Step 608: the target vector sequence is input into a trained threat degree detection model.

[0157] Step 609: a threat degree detection result corresponding to the to-be-detected alarm is determined.

[0158] Based on the same inventive concept, the embodiments of the present application also provide a threat degree detection device, which can be a server, for example, and the image detection device can be a hardware structure, a software module, or a hardware structure plus a software module. Based on the above embodiments, refer to Figure 7 As shown in FIG. 7, which is a structural schematic diagram of a threat degree detection device in the embodiments of the present application, and specifically includes:

[0159] The identification module 700 is configured to perform attribute identification on the alarm payload corresponding to the to-be-detected alarm, and determine attribute information and undecoded information contained in the alarm payload.

[0160] The first processing module 701 is configured to perform vectorization processing on each attribute information respectively to obtain an attribute feature corresponding to the attribute information, and perform vectorization processing on each undecoded information respectively to obtain an undecoded feature corresponding to the undecoded information.

[0161] The determining module 702 is configured to determine a matched target attack feature from each candidate attack feature based on each attribute feature, where each candidate attack feature represents a network flow segment in a corresponding type of alarm payload used to determine an attack intention.

[0162] The second processing module 703 is configured to perform vector value updating on the corresponding attribute feature based on each matched target attack feature to obtain a target vector sequence containing the updated attribute feature and each undecoded feature.

[0163] The generating module 704 is configured to determine a threat degree detection result of the alarm payload based on the target vector sequence.

[0164] Optionally, the identifying module 700 is further configured to:

[0165] For each preset identification manner, the following operations are sequentially performed:

[0166] If it is determined that any one of the identification manners is used to identify attribute information, the corresponding attribute information and undecoded information are determined from the alarm payload corresponding to the to-be-detected alarm based on the identification manner, and the undecoded information is taken as a new alarm payload.

[0167] If it is determined that the identification manner is used to perform information decoding, the corresponding decoded string and undecoded information are decoded from the alarm payload based on the identification manner, the decoded string is taken as a new alarm payload, the step of determining the corresponding attribute information and undecoded information from the alarm payload corresponding to the to-be-detected alarm is re-executed, and the decoded string is determined from the undecoded information based on each other identification manner used to perform information decoding.

[0168] Optionally, when the corresponding attribute information and undecoded information are determined from the alarm payload corresponding to the to-be-detected alarm based on the identification manner, the identifying module 700 is further configured to:

[0169] Attribute information conforming to an attribute element format corresponding to the identification manner is identified from the alarm payload corresponding to the to-be-detected alarm based on the attribute element format;

[0170] The attribute information is cut from the alarm payload to obtain undecoded information that does not contain the attribute information.

[0171] Optionally, when the identification module 700 decodes the corresponding decoded string and the undecoded information from the alarm payload based on the identification manner, the identification module 700 is further configured to:

[0172] identify each encoded string conforming to the encoding format corresponding to the identification manner from the alarm payload;

[0173] decode each encoded string respectively to obtain a decoded string corresponding to the corresponding encoded string;

[0174] determine undecoded information not containing each decoded string from the alarm payload.

[0175] Optionally, the first processing module 701 is further configured to:

[0176] for each attribute type corresponding to a preset specification string, perform the following operations respectively: replace attribute information corresponding to any interference attribute type in the attribute information with a specification string corresponding to the interference attribute type to obtain replaced attribute information;

[0177] perform character decomposition on the replaced attribute information respectively to obtain corresponding attribute characters and the length of a payload character dictionary;

[0178] map each attribute character obtained to a corresponding attribute vector to obtain an attribute feature corresponding to the corresponding attribute information.

[0179] Optionally, the second processing module 703 is further configured to:

[0180] generate a payload vector sequence containing each attribute feature and each undecoded feature;

[0181] determine a value of a corresponding position serial number of the corresponding attribute feature in the payload vector sequence based on each target attack feature matched and the length of the payload character dictionary respectively;

[0182] update the vector value of the corresponding attribute feature of each target attack feature to a value of a corresponding position serial number respectively.

[0183] Optionally, the generation module 704 is further configured to:

[0184] determine a threat degree detection result of the alarm payload based on the trained threat degree detection model and taking the target vector sequence as input data.

[0185] Based on the above embodiments, refer to Figure 8 FIG. 1 shows a structural schematic diagram of an electronic device in the embodiments of the present application.

[0186] The electronic device can include a processor 810 (Center Processing Unit, CPU), a memory 820, an input device 830, and an output device 840, etc. The input device 830 can include a keyboard, a mouse, a touch screen, etc. The output device 840 can include a display device, such as a Liquid Crystal Display (LCD), a Cathode Ray Tube (CRT), etc.

[0187] The memory 820 can include a Read Only Memory (ROM) and a Random Access Memory (RAM), and provide the processor 810 with program instructions and data stored in the memory 820. In the embodiments of the present application, the memory 820 can be used to store the program of any threat degree detection method in the embodiments of the present application.

[0188] The processor 810 processes the program instructions stored in the memory 820, and the processor 810 is used to execute any threat degree detection method in the embodiments of the present application according to the obtained program instructions.

[0189] Based on the above embodiments, in the embodiments of the present application, a computer readable storage medium is provided, and the computer readable storage medium stores a computer program. The computer program is executed by a processor to implement the threat degree detection method in any method embodiment.

[0190] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can be in the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can be in the form of a computer program product implemented on one or more computer usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer usable program code.

[0191] The present application is described with reference to flowcharts and / or block diagrams according to the methods, devices (systems), and computer program products of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to produce a machine, so that the instructions executed by the computer or other programmable data processing devices produce a device that implements the functions specified in the flowcharts and / or block diagrams. Figure 1 The functions specified in one flow or multiple flows and / or blocks Figure 1 The device that implements the functions specified in one flow or multiple flows and / or blocks.

[0192] These computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture including instructions which implement the Figure 1 function specified in the flow or flows and / or blocks Figure 1 of the block or blocks.

[0193] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions that are executed on the computer or other programmable apparatus provide steps for implementing the Figure 1 function specified in the flow or flows and / or blocks Figure 1 of the block or blocks.

[0194] Obviously, numerous modifications and variations of the present application are possible in light of the above teachings. It is therefore to be understood that within the scope of the apparent to those skilled in the art that the application can be practiced otherwise than as specifically described herein. Accordingly, any modification and variation that can occur to those skilled in the art is to be considered as falling within the scope of the application as defined by the appended claims and their equivalents.

Claims

1. A threat level detection method characterized by, The method comprises the following steps: attribute identification is performed on the alarm load corresponding to the alarm to be detected, and each attribute information and each undecoded information contained in the alarm load are determined; vectorization processing is performed on each attribute information respectively to obtain attribute features corresponding to the attribute information, and vectorization processing is performed on each undecoded information respectively to obtain undecoded features corresponding to the undecoded information; based on each attribute feature, a matched target attack feature is determined from each candidate attack feature in a preset manner, wherein each candidate attack feature represents a network flow segment in a corresponding type of alarm load used to determine an attack intention; based on each matched target attack feature, vector value updating is performed on the corresponding attribute feature to obtain a target vector sequence containing the updated attribute feature and each undecoded feature; based on the target vector sequence, a threat degree detection result of the alarm load is determined.

2. The method of claim 1, wherein, The attribute identification performed on the alarm load corresponding to the alarm to be detected, and each attribute information and each undecoded information contained in the alarm load are determined, comprising: for each preset identification mode, the following operations are sequentially performed: if it is determined that any one identification mode is used to identify attribute information, then based on the determined identification mode, corresponding attribute information and undecoded information are determined from the alarm load corresponding to the alarm to be detected, and the undecoded information is taken as a new alarm load; if it is determined that the determined identification mode is used for information decoding, then based on the determined identification mode, a corresponding decoding string and undecoded information are decoded from the alarm load, and the decoding string is taken as a new alarm load, the step of determining corresponding attribute information and undecoded information from the alarm load corresponding to the alarm to be detected is re-executed, and a decoding string is determined from the undecoded information based on each other identification mode used for information decoding.

3. The method of claim 2, wherein, The determination of corresponding attribute information and undecoded information from the alarm load corresponding to the alarm to be detected based on the determined identification mode comprises: based on the attribute element format corresponding to the determined identification mode, attribute information conforming to the attribute element format is identified from the alarm load corresponding to the alarm to be detected; the attribute information is cut from the alarm load to obtain undecoded information not containing the attribute information.

4. The method of claim 2, wherein, The decoding of a corresponding decoding string and undecoded information from the alarm load based on the determined identification mode comprises: based on the encoding format corresponding to the determined identification mode, each encoding string conforming to the encoding format is identified from the alarm load; each encoding string is decoded respectively to obtain a decoding string corresponding to the corresponding encoding string; from the alarm load, undecoded information not containing each decoding string is determined.

5. The method of claim 1, wherein, The vectorization processing performed on each attribute information respectively to obtain attribute features corresponding to the attribute information comprises: For the preset attribute type corresponding to the specification string, the following operations are performed respectively: the attribute information corresponding to any interference attribute type in the attribute information is replaced by the specification string corresponding to the interference attribute type, and the replaced attribute information is obtained; Respectively, the replaced attribute information is character decomposed to obtain the corresponding attribute character and the length of the payload character dictionary; Respectively, the obtained attribute character is mapped to the corresponding attribute vector to obtain the attribute feature corresponding to the corresponding attribute information.

6. The method of claim 1, wherein, The attribute feature is updated based on the matched target attack feature, and a target vector sequence containing the updated attribute feature and the undecoded feature is obtained, including: Generating a payload vector sequence containing the attribute feature and the undecoded feature; Based on the matched target attack feature and the length of the payload character dictionary, the corresponding position sequence number value of the corresponding attribute feature in the payload vector sequence is determined; Respectively, the vector value of the attribute feature corresponding to the target attack feature is updated to the value of the corresponding position sequence number.

7. The method of claim 1, wherein, The threat degree detection result of the alarm payload is determined based on the target vector sequence, including: Based on the trained threat degree detection model, the target vector sequence is used as input data to determine the threat degree detection result of the alarm payload.

8. A threat detection apparatus characterized by comprising: Including: The recognition module is used for attribute recognition of the alarm payload corresponding to the alarm to be detected, and the attribute information and the undecoded information contained in the alarm payload are determined; The first processing module is used for vectorizing the attribute information to obtain the attribute feature corresponding to the corresponding attribute information, and vectorizing the undecoded information to obtain the undecoded feature corresponding to the corresponding undecoded information; The determination module is used for determining the matched target attack feature from the preset candidate attack feature based on the attribute feature, wherein each candidate attack feature represents a network flow segment in the corresponding type of alarm payload used to determine the attack intention; The second processing module is used for updating the vector value of the attribute feature based on the matched target attack feature to obtain a target vector sequence containing the updated attribute feature and the undecoded feature. The generation module is used for determining the threat degree detection result of the alarm payload based on the target vector sequence.

9. An electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, The processor executes the program to realize the steps of the method of any one of claims 1-7.

10. A computer readable storage medium having stored thereon a computer program, characterized in that: The computer program is executed by the processor to realize the steps of the method of any one of claims 1-7.

Citation Information

Patent Citations

  • Attack intention identification method and device

    CN112131249A

  • Method and device for detecting attack alarm, detection equipment and storage medium

    CN114363148A