An event detection method and device, electronic equipment and storage medium
By configuring incremental intelligence and backtracking traffic for collision analysis at set collision times, the problem of incomplete network attack chains caused by the lag in threat intelligence is solved, enabling backtracking detection of attack behaviors before intelligence is generated and efficient threat event detection.
Patent Information
- Application Number
- CN202211634738.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-19
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2042-12-19
AI Technical Summary
In existing technologies, the lag in the generation of threat intelligence leads to incomplete network attack chains, making it impossible to effectively detect attack behaviors before the intelligence is generated, thus affecting the security of cyberspace.
By responding to the set collision timing, the system obtains a set of intelligence indicators and a set of traffic indicators. It then uses historical detection time to configure incremental intelligence and backtrack traffic for collision analysis, detecting attack behaviors before the intelligence is generated and improving the integrity of the network attack chain tracing.
It enables retrospective detection of attack behaviors prior to intelligence generation, improves the integrity of network attack chain tracing and threat event detection efficiency, and avoids data duplication and caching requirements.
Smart Images

Figure CN116015823B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of information security, and in particular to an event detection method and device, electronic equipment and a storage medium. BACKGROUND
[0002] Intelligence collision refers to a detection method of searching and comparing threat indicators in the discovered attacker intelligence with threat indicators in the traffic log of the target network, for detecting threat events in the target network and ensuring early warning.
[0003] In the prior art, real-time threat intelligence is usually used to collide with the current traffic, and relevant alarms are given after detecting threat events. However, due to the lag of intelligence generation, this method is prone to miss the attack behavior of the attacker before the intelligence is generated, resulting in incomplete network attack chains and affecting the security of the cyberspace. SUMMARY
[0004] The embodiments of the present application provide an event detection method and device, electronic equipment and a storage medium, which are used to improve the integrity of the network attack chain.
[0005] In a first aspect, the embodiments of the present application provide an event detection method, comprising:
[0006] In response to a set collision time, an intelligence indicator set is obtained, wherein each intelligence indicator is associated with an incremental intelligence in a local intelligence library, and the intelligence record time of each incremental intelligence is not earlier than a set historical detection time.
[0007] From a traffic indicator library, a traffic indicator set for the collision time is obtained, wherein each traffic indicator is associated with a backtracking traffic in a traffic message queue, and each backtracking traffic is obtained by historical log analysis.
[0008] The intelligence indicator set and the traffic indicator set are collided and analyzed to obtain each backtracking threat event.
[0009] The each backtracking threat event is sent to an event message queue to trigger analysis and alarm for the each backtracking threat event.
[0010] In an optional implementation, before the intelligence indicator set is obtained in response to the set collision time, the method further comprises:
[0011] According to the started consumption process, each backtracking traffic in the traffic message queue for the collision time is obtained.
[0012] Each candidate indicator is obtained by performing indicator extraction on the each backtracking traffic, and each traffic indicator is obtained by filtering the each candidate indicator using a filtering rule.
[0013] The flow indicators are sent to the flow indicator library, triggering the flow indicator library to merge and store the flow indicators at a set period and persistently merge and store the flow indicators in the local flow library.
[0014] In an optional implementation, the triggering the flow indicator library to merge and store the flow indicators at a set period includes:
[0015] The flow indicator library is triggered to merge and store each first flow value in the flow indicators at a set period, wherein the first flow value includes address information and a hash value extracted from the corresponding backtracking flow; and
[0016] The flow indicator library is triggered to compress each second flow value in the flow indicators using a compression algorithm, and the obtained second compressed values are merged and stored at the set period, wherein the second flow value includes a uniform resource locator extracted from the corresponding backtracking flow.
[0017] In an optional implementation, the obtaining the intelligence indicator set in response to the set collision opportunity includes:
[0018] In response to the local intelligence library triggering update information, the intelligence indicator set associated with the set indicator type and / or intelligence type is obtained.
[0019] Alternatively,
[0020] In response to a set detection period, the intelligence indicator set associated with the set indicator type and / or intelligence type is obtained.
[0021] In an optional implementation, the obtaining the flow indicator set for the collision opportunity from the flow indicator library includes:
[0022] The flow record time of the corresponding backtracking flow is obtained from the flow indicator library, and the multiple flow indicators belonging to the set backtracking period are the flow indicator set for the collision opportunity.
[0023] And / or,
[0024] The log type of the historical log associated with the corresponding backtracking flow is obtained from the flow indicator library, and the multiple flow indicators of the set backtracking type are the flow indicator set for the collision opportunity.
[0025] In an optional implementation, the flow indicator set is obtained in batches according to the set amount of each backtracking data,
[0026] then the intelligence indicator set is collided with the traffic indicator set to obtain each backtracking threat event, including:
[0027] For each batch of the traffic indicator set, the following operations are performed:
[0028] For each batch of the traffic indicator set, the following operations are performed:
[0029] The subset collision data is analyzed by using an event model to obtain each backtracking threat event in the traffic indicator subset corresponding to the intelligence indicator set.
[0030] In an optional embodiment, the intelligence indicator set is collided with multiple subset thread blocks of the traffic indicator subset by using multiple threads in parallel,
[0031] then the intelligence indicator set is collided with the traffic indicator set to obtain each backtracking threat event, including:
[0032] In the multiple threads, the multiple subset collision data obtained by colliding the intelligence indicator set with the multiple subset thread blocks is analyzed by using the event model in parallel to obtain each backtracking threat event in the traffic indicator subset.
[0033] In a second aspect, the embodiments of the present application provide an event detection device, including:
[0034] The first acquisition module is configured to acquire an intelligence indicator set in response to a set collision time, wherein each intelligence indicator is associated with an incremental intelligence in a local intelligence library, and each incremental intelligence has an intelligence record time not earlier than a set historical detection time.
[0035] The second acquisition module is configured to acquire a traffic indicator set for the collision time from a traffic indicator library, wherein each traffic indicator is associated with a backtracking traffic in a traffic message queue, and each backtracking traffic is obtained by historical log analysis.
[0036] The event generation module is configured to collide and analyze the intelligence indicator set and the traffic indicator set to obtain each backtracking threat event.
[0037] The delivery module is configured to send the each backtracking threat event to an event message queue to trigger analysis and alarm for the each backtracking threat event.
[0038] In an optional embodiment, before the first acquisition module acquires the intelligence indicator set in response to the set collision time, the first acquisition module is further configured to:
[0039] According to the starting consumption process, each backtracking traffic for the collision opportunity in the traffic message queue is acquired.
[0040] Each candidate index is obtained by performing index extraction on the each backtracking traffic, and each traffic index is obtained by performing filtering on the each candidate index by using a filtering rule.
[0041] The each traffic index is sent to the traffic index library, the traffic index library is triggered, the each traffic index is merged and stored according to a set period, and the each traffic index is merged and stored to a local traffic library by using persistence.
[0042] In an optional implementation, the traffic index library is triggered to merge and store each traffic index according to a set period, and the first acquisition module is specifically configured to:
[0043] The traffic index library is triggered to merge and store each first traffic value in the each traffic index according to a set period, wherein the first traffic value includes address information and a hash value extracted from the each backtracking traffic; and
[0044] The traffic index library is triggered to compress each second traffic value in the each traffic index by using a compression algorithm, and each second compressed value obtained is merged and stored according to the set period, wherein the second traffic value includes a uniform resource locator extracted from the each backtracking traffic.
[0045] In an optional implementation, the intelligence index set is acquired in response to a set collision opportunity, and the first acquisition module is specifically configured to:
[0046] The intelligence index set associated with a set index type and / or intelligence type is acquired in response to update information triggered by the local intelligence library.
[0047] Or,
[0048] The intelligence index set associated with a set index type and / or intelligence type is acquired in response to a set detection period.
[0049] In an optional implementation, the traffic index set for the collision opportunity is acquired from the traffic index library, and the second acquisition module is specifically configured to:
[0050] The traffic record time of the each backtracking traffic is acquired from the traffic index library, and a plurality of traffic indexes belonging to a set backtracking period are the traffic index set for the collision opportunity.
[0051] And / or,
[0052] From the traffic index library, a log type of a corresponding backtracking traffic correlation history log is acquired, a plurality of traffic indexes of a set backtracking type are set, and a traffic index set for the collision opportunity is obtained.
[0053] In an optional implementation, the traffic index set is batched according to a set backtracking data volume,
[0054] The collision and analysis of the intelligence index set and the traffic index set obtain each backtracking threat event, and the event generation module is specifically configured to:
[0055] For a plurality of batches of the traffic index set, the following operations are respectively performed:
[0056] For a traffic index subset of a corresponding backtracking data volume acquired in a batch, the collision of the intelligence index set and the traffic index subset obtains subset collision data;
[0057] The analysis of the subset collision data by using an event model obtains each backtracking threat event in the traffic index subset corresponding to the intelligence index set.
[0058] In an optional implementation, the intelligence index set is concurrently collided with a plurality of subset thread blocks of the traffic index subset by using a plurality of threads,
[0059] The analysis of the index collision data by using an event model obtains each backtracking threat event in the traffic index subset, and the event generation module is specifically configured to:
[0060] In the plurality of threads, the analysis of a plurality of block collision data obtained by concurrently colliding the intelligence index set and the plurality of subset thread blocks by using the event model obtains each backtracking threat event in the traffic index subset.
[0061] In a third aspect, an electronic device is provided, which includes a processor and a memory, wherein the memory stores program code, and when the program code is executed by the processor, the processor is caused to execute the steps of the event detection method in the first aspect.
[0062] In a fourth aspect, a computer readable storage medium is provided, which includes program code, and when the program code is run on an electronic device, the program code is used to cause the electronic device to execute the steps of the event detection method in the first aspect.
[0063] The technical effects of the embodiments of the present application are as follows:
[0064] The embodiment of the present application provides an event detection method, device, electronic equipment and storage medium. In response to a set collision opportunity, a set of intelligence indexes is acquired, and a set of traffic indexes for the collision opportunity is acquired from a traffic index library, wherein each intelligence index is associated with an incremental intelligence in a local intelligence library, each intelligence record time of the incremental intelligence is not earlier than a set historical detection time, each traffic index is associated with a backtracking traffic in a traffic message queue, each backtracking traffic is obtained through historical log analysis, further, the set of intelligence indexes and the set of traffic indexes are collided and analyzed to obtain each backtracking threat event, so that the attack behavior before the intelligence is generated is backtracked and detected based on the above manner, and the traceability integrity of a network attack chain is improved.
[0065] On the other hand, the historical detection time is used to configure each incremental intelligence for collision, and each backtracking traffic for collision is acquired through the traffic message queue, so that data repetition collision is avoided, and the total amount of data required to be cached during collision is reduced, and further the detection efficiency for threat events is improved. BRIEF DESCRIPTION OF DRAWINGS
[0066] Figure 1 A possible application scenario provided by the embodiment of the present application is shown in a schematic diagram.
[0067] Figure 2 A possible platform provided by the embodiment of the present application is shown in a schematic diagram.
[0068] Figure 3 A flowchart of an event detection method provided by the embodiment of the present application is shown.
[0069] Figure 4 A structural schematic diagram of an event detection device provided by the embodiment of the present application is shown.
[0070] Figure 5 An electronic equipment provided by the embodiment of the present application is shown in a schematic diagram. DETAILED DESCRIPTION
[0071] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the protection scope of the present application.
[0072] It should be noted that in the description of the present application, "multiple" is understood as "at least two". The association relationship of the associated objects described by "and / or" indicates that there can be three relationships, for example, A and / or B can represent the three cases of A existing alone, A and B existing together, and B existing alone. A is connected with B, which can represent two cases: A is directly connected with B and A is connected with B through C. In addition, in the description of the present application, "first", "second", etc. are used only for the purpose of distinguishing the description, and cannot be understood as indicating or implying relative importance, nor can it be understood as indicating or implying order.
[0073] In addition, in the technical solutions of the present application, the collection, transmission, use, etc. of data comply with the requirements of relevant national laws and regulations.
[0074] First, for the convenience of understanding, some of the terms and terminologies involved in the embodiments of the present application are explained as follows:
[0075] Intelligence: refers to evidence-based knowledge, including context, mechanism, indication, meaning and executable recommendations, which provides information support for the response or handling decision of the asset-related subject to the threat or harm. In the present application, the known attack data published on the Internet can be used as incremental intelligence required for event detection.
[0076] Threat indicator (Indicator of Compromise, IOC for short): refers to various attack indicators used for intrusion detection, including IP, URL, DOMAIN, HASH, etc.
[0077] Intelligence collision: refers to the discovery of the same set of black IP / domain name / URL / HASH value in threat intelligence and IP / domain name / URL / HASH value in traffic log, and then finding network attacks and tracing back attack events. In the present application, incremental intelligence IOC is matched with backtracking traffic IOC to detect attack events that occurred before the current intelligence was generated.
[0078] The design idea of the present application is as follows:
[0079] In the prior art, threat intelligence generated in real time is usually used to collide with current traffic, and relevant alarms are given after detecting threat events. However, due to the lag of intelligence generation, this method is easy to miss the attack behavior of the attacker before the intelligence is generated, resulting in incomplete network attack chain traced out, which affects the security of cyberspace.
[0080] To improve the integrity of the network attack chain, the embodiment of the present application provides an event detection method and device, electronic equipment and storage medium. In response to the set collision opportunity, the intelligence index set is obtained, and the traffic index set for the collision opportunity is obtained from the traffic index library. Each intelligence index is associated with an incremental intelligence in the local intelligence library. The intelligence record time of each incremental intelligence is not earlier than the set historical detection time. Each traffic index is associated with a backtracking traffic in the traffic message queue. Each backtracking traffic is obtained by historical log analysis. Further, the intelligence index set and the traffic index set are collided and analyzed to obtain each backtracking threat event. Thus, the attack behavior before the intelligence is generated is backtracked and detected based on the above method, and the integrity of the network attack chain traced is improved.
[0081] On the other hand, the historical detection time is used to configure each incremental intelligence for collision, and each backtracking traffic for collision is obtained through the traffic message queue, so as to avoid data repeated collision and reduce the total amount of data required for collision during the collision, thereby improving the detection efficiency of the threat event.
[0082] Referring to Figure 1 As shown in the figure, the application embodiment provides a possible application scenario diagram. The application scenario includes a platform 1, a cloud intelligence source 2 and a full-flow probe 3. The platform 1 can interact with the cloud intelligence source 2 and the full-flow probe 3 through a communication connection mode. The communication connection mode includes a wired connection mode (hard line, etc.) and / or a wireless connection mode (wireless fidelity technology Wi-Fi, etc.).
[0083] Referring to Figure 2 As shown in the figure, in a specific implementation, the intelligence component 11 in the platform 1 periodically obtains threat intelligence produced by the cloud intelligence source 2. The threat intelligence includes but is not limited to advanced persistent threat (APT), mining, ransom, remote control (C2), etc. Through intelligence analysis, it is stored in the local intelligence library of the platform 1.
[0084] Further, the data access component 12 in the platform 1 obtains the traffic data from the target network collected by the full-flow probe 3 in real time. The traffic data includes but is not limited to session log, web access log, domain name resolution log, etc. Optionally, the data access component 12 performs normalization processing on the obtained traffic data, and writes it into the traffic message queue and stores it in the local traffic library.
[0085] Based on the above specific embodiments, the platform 1 further comprises an intelligence offline backtracking engine 13 for performing the method process provided in the present application, which comprises a backtracking configuration module 131, an intelligence loading and caching module 132, a threat index collection module 133, and an intelligence collision module 134, and the functions of each module are as follows.
[0086] The backtracking configuration module 131 is configured to configure collision timing, intelligence range, and backtracking range.
[0087] In a specific embodiment, the collision timing is used to indicate the execution time of event detection, including trigger collision [triggered automatically in response to update information] and periodic collision [fixed period of collision].
[0088] The intelligence range is used to indicate the intelligence indicators required for event detection, which can be configured according to the index type [such as IP, DOMAIN, URL, HASH, etc.] or intelligence type [such as mining, ransom, APT, C2, black IP, etc.].
[0089] The backtracking range is used to indicate the traffic indicators required for event detection, which can be configured according to the backtracking period [such as one day ago, the previous three days to the previous day, the recent three days, etc.] and log type [session log, web access log, domain name resolution log, malicious sample log].
[0090] The intelligence loading and caching module 132 is configured to obtain incremental intelligence according to the above-mentioned configured intelligence range.
[0091] In a specific embodiment, the incremental intelligence refers to new intelligence data whose record time is not earlier than the set historical detection time, and the incremental intelligence is used for event detection at each collision timing to avoid repeated collision of data and reduce data redundancy.
[0092] Optionally, the historical detection time can represent the collision record time of the last event detection closest to the current time, or can be any specified time set after the last collision detection time, which is not limited.
[0093] The threat index collection module 133 is configured to obtain backtracking traffic and traffic indicators according to the above-mentioned configured backtracking range.
[0094] In a specific implementation, the threat indicator collection module 133 can collect the backtracking traffic in the traffic message queue connected to the local traffic library according to the configured backtracking range, extract the threat indicators in the backtracking traffic, and send the threat indicators to the traffic indicator library. Optionally, the threat indicator collection module 133 filters each candidate indicator extracted from the backtracking traffic in combination with the set filtering rules, and the filtering rules include but are not limited to filtering the internal network IOCs and the whitelist IOCs in each candidate indicator.
[0095] Notably, in the above implementation, the traffic message queue filters the invalid indicators in each candidate indicator in advance according to the set filtering rules, thereby reducing the data amount of the subsequent traffic indicator set to be collided, avoiding additional resource consumption; the traffic indicator library can be a cache database [such as a remote dictionary service Redis], which merges and stores each traffic indicator delivered by the threat indicator collection module 133 according to the set period, and stores the traffic indicator in the local traffic library using the persistence, thereby reducing the read-write times of the database and improving the query performance for the traffic IOC data.
[0096] The intelligence collision module 134 is configured to obtain the backtracking threat events between the incremental intelligence and the historical log according to the configured collision time trigger event detection.
[0097] In a specific implementation, the intelligence collision module 134 can batch obtain the traffic indicator set in the traffic indicator library according to the set amount of each backtracking data, and use multiple threads to concurrently collide with the corresponding multiple subset thread blocks in one batch of the traffic indicator set, thereby improving the collision speed of the intelligence indicator for the traffic indicator and ensuring the event detection performance.
[0098] Based on the above application scenarios, the event detection method provided by the present application will be further described and explained in combination with the reference drawings, and the reference drawings shown in Figure 3 include:
[0099] S301: In response to the set collision time, obtain the intelligence indicator set.
[0100] Specifically, in the event detection method provided by the present application, the intelligence indicator set extracted from the incremental intelligence in the local intelligence library is collided and analyzed with the traffic indicator set extracted from the backtracking traffic in the traffic message queue, and the backtracking traffic is obtained through historical log analysis, thereby detecting the previous attack behavior related to the intelligence indicator set before the collision time, assisting the complete tracing of the network attack chain; further, the intelligence data with the intelligence record time not earlier than the set historical detection time is used as the incremental intelligence, avoiding the data redundancy caused by repeated collision, and ensuring the detection efficiency for the threat events.
[0101] In an alternative embodiment, before obtaining the set of intelligence indicators, the following steps are further adopted for processing, comprising:
[0102] Step 1: According to the launched consumption process, obtain each backtracking traffic in the traffic message queue for the collision opportunity.
[0103] Step 2: Extract indicators from each backtracking traffic to obtain each candidate indicator, and filter each candidate indicator using a filtering rule to obtain each traffic indicator.
[0104] Step 3: Send each traffic indicator to the traffic indicator library, trigger the traffic indicator library, merge and store each traffic indicator according to the set period, and use persistence to merge and store in the local traffic library.
[0105] Specifically, in the above embodiment, the consumption process is used to consume the backtracking traffic in the traffic message queue in real time, and the candidate indicators of each backtracking traffic are extracted. Further, the set filtering rule is used to filter each candidate indicator to reduce resource consumption.
[0106] Illustratively, for each backtracking traffic obtained by consumption, the extracted IOC value of each backtracking traffic is taken as a candidate indicator, and then the internal network IOC and / or the white list IOC are used to filter each candidate indicator to reduce resource consumption caused by subsequent collision analysis.
[0107] Further, for each traffic indicator obtained, it is periodically merged and stored in the traffic indicator library, and is persisted to the local traffic library, thereby reducing the read and write times of the database and reducing resource consumption.
[0108] In an alternative embodiment, each first traffic value in each traffic indicator is merged and stored according to a set period, and each second traffic value in each traffic indicator is compressed using a compression algorithm, and then each obtained second compressed value is merged and stored according to a set period, wherein the first traffic value includes address information and a hash value extracted from the corresponding backtracking traffic, and the second traffic value includes a uniform resource locator extracted from the corresponding backtracking traffic, thereby compressing and storing indicator data with large length spans to ensure the storage efficiency of the traffic indicators.
[0109] Exemplarily, in a specific embodiment, for each filtered flow indicator, the address information and hash value [e.g., IP, DOMAIN, HASH, etc.] contained therein are stored by day, and a compression algorithm is used to compress the uniform resource locator URL contained therein, and the corresponding second compressed value is stored by day, and the local flow library is persisted by day, the compression algorithm includes but is not limited to the message digest algorithm MD5, and the local flow library includes but is not limited to a columnar database or an ES database.
[0110] In an optional implementation, in response to a set collision opportunity, a set of intelligence indicators is obtained, including any one of the following modes:
[0111] 1) In response to local intelligence library triggering update information, a set of intelligence indicators associated with a set indicator type and / or intelligence type is obtained.
[0112] 2) In response to a set detection period, a set of intelligence indicators associated with a set indicator type and / or intelligence type is obtained.
[0113] Specifically, when there is incremental intelligence in the local intelligence library, a corresponding set of intelligence indicators is obtained, or according to a set detection period, a set of intelligence indicators associated with the local intelligence library at the triggering time of the detection period is obtained; the set of intelligence indicators can be associated with a set indicator type and / or intelligence type; the indicator type includes but is not limited to IP, DOMAIN, URL, HASH, etc.; the intelligence type includes but is not limited to mining, ransom, APT, C2, black IP, etc.
[0114] Exemplarily, every other day, a set of IPs extracted from enhanced intelligence is obtained.
[0115] S302: From the flow indicator library, a set of flow indicators for the collision opportunity is obtained.
[0116] In an optional implementation, from the flow indicator library, a set of flow indicators for the collision opportunity is obtained, including any one of the following modes:
[0117] 1) From the flow indicator library, a set of flow records of the corresponding backtracking flow whose record time belongs to a set backtracking period is obtained as a set of flow indicators for the collision opportunity.
[0118] 2) From the flow indicator library, a set of flow indicators of the corresponding backtracking flow associated with a set of log types of historical logs is obtained as a set of flow indicators for the collision opportunity.
[0119] Specifically, a backtracking period is set to obtain a corresponding traffic indicator set, or a backtracking type is set to obtain a corresponding traffic indicator set; the backtracking type includes but is not limited to session logs, web access logs, domain name resolution logs, malicious sample logs, etc.
[0120] Exemplarily, a traffic indicator set extracted from session logs of the last three days is obtained from a traffic indicator library.
[0121] S303: The intelligence indicator set is collided and analyzed with the traffic indicator set to obtain each backtracking threat event.
[0122] In an optional implementation, the traffic indicator set is obtained in batches according to a set backtracking data volume, and the following steps are performed for each batch of the traffic indicator set:
[0123] Step 1: The intelligence indicator set is collided with a traffic indicator subset corresponding to the backtracking data volume obtained in a batch to obtain subset collision data.
[0124] Step 2: The subset collision data is analyzed using an event model to obtain each backtracking threat event in the traffic indicator subset corresponding to the intelligence indicator set.
[0125] Specifically, the traffic indicator set in the traffic indicator library is obtained in batches to maximize the query performance of the database and improve the event generation efficiency. Optionally, the backtracking data volume corresponding to each batch is manually specified, or the batch number required for collision and the backtracking data volume of each batch are set according to the size of the intelligence indicator set.
[0126] Exemplarily, 100 or 1000 traffic indicators are used as a corresponding traffic indicator subset, which is collided with the obtained intelligence indicator set to detect the same data result, and an event model is used to generate each corresponding backtracking threat event. The event model can be as shown in Table 1:
[0127] Table 1
[0128] Event name "Backtracking_{IOC value} hit {intelligence type} intelligence" Event type mining type, APT type, ransom type, etc. Event level corresponding to intelligence threat level
[0129] Among them, the IOC value in the event name represents the same IOC value in the intelligence collision, and the event name contains a backtracking identifier for event identification. Exemplarily, the event name of a backtracking threat event is: “Backtracking_2.2.2.2 hit the mining intelligence”.
[0130] In an alternative implementation, multiple threads are employed, and the intelligence indicator set is concurrently collided with multiple subset thread blocks of the traffic indicator subset, so that in the multiple threads, the event model is respectively employed for analysis to generate the rollback threat events in parallel without conflict, thereby improving the event detection performance.
[0131] For example, in the process of searching the intelligence indicator set for 1000 traffic indicators, it can be further divided into 10 subset thread blocks of 100 each, and the corresponding threads are started for parallel processing.
[0132] S304: Send each rollback threat event to the event message queue to trigger analysis and alarm for each rollback threat event.
[0133] Based on the above method, the incremental intelligence and historical traffic are collided and analyzed to make up for the missing pre-attack behavior in real-time collision, assist in complete tracing of the network attack chain, and use the above method for data configuration to ensure efficient performance of event detection.
[0134] Further, based on the same technical concept, the embodiments of the present application also provide an event detection device for implementing the above method flow of the embodiments of the present application. Referring to Figure 4 The device includes a first acquisition module 401, a second acquisition module 402, an event generation module 403, and a delivery module 404, wherein:
[0135] The first acquisition module 401 is configured to acquire an intelligence indicator set in response to a set collision time, wherein each intelligence indicator is associated with an incremental intelligence in a local intelligence library, and each incremental intelligence has an intelligence record time not earlier than a set historical detection time.
[0136] The second acquisition module 402 is configured to acquire a traffic indicator set for the collision time from a traffic indicator library, wherein each traffic indicator is associated with a rollback traffic in a traffic message queue, and each rollback traffic is obtained by historical log analysis.
[0137] The event generation module 403 is configured to collide and analyze the intelligence indicator set and the traffic indicator set to obtain each rollback threat event.
[0138] The delivery module 404 is configured to send each rollback threat event to the event message queue to trigger analysis and alarm for each rollback threat event.
[0139] In an alternative implementation, before the first acquisition module 401 acquires the intelligence indicator set in response to the set collision time, the first acquisition module 401 is further configured to:
[0140] According to the started consumption process, each backtracking flow for the collision opportunity in the traffic message queue is acquired.
[0141] Index extraction is performed on the each backtracking flow to obtain each candidate index, and a filtering rule is used to filter the each candidate index to obtain each traffic index.
[0142] The each traffic index is sent to the traffic index library, the traffic index library is triggered, the each traffic index is merged and stored according to a set period, and the each traffic index is merged and stored to a local traffic library by using persistence.
[0143] In an optional implementation, the traffic index library is triggered to merge and store the each traffic index according to a set period, and the first acquisition module 401 is specifically configured to:
[0144] The traffic index library is triggered to merge and store each first traffic value in the each traffic index according to a set period, wherein the first traffic value includes address information and a hash value extracted from the corresponding backtracking flow; and
[0145] The traffic index library is triggered to compress each second traffic value in the each traffic index by using a compression algorithm, and each second compressed value obtained is merged and stored according to the set period, wherein the second traffic value includes a uniform resource locator extracted from the corresponding backtracking flow.
[0146] In an optional implementation, the intelligence index set is acquired in response to a set collision opportunity, and the first acquisition module 401 is specifically configured to:
[0147] In response to the local intelligence library triggering update information, an intelligence index set associated with a set index type and / or intelligence type is acquired.
[0148] Alternatively,
[0149] In response to a set detection period, an intelligence index set associated with a set index type and / or intelligence type is acquired.
[0150] In an optional implementation, the traffic index set for the collision opportunity is acquired from the traffic index library, and the second acquisition module 402 is specifically configured to:
[0151] The traffic record time of the corresponding backtracking flow is acquired from the traffic index library, and a plurality of traffic indexes belonging to a set backtracking period are the traffic index set for the collision opportunity.
[0152] And / or,
[0153] From the traffic index library, a log type of a corresponding backtracking traffic correlation history log is acquired, a plurality of traffic indexes of a set backtracking type are set, and a traffic index set for the collision opportunity is acquired.
[0154] In an optional embodiment, the traffic index set is acquired in batches according to a set amount of backtracking data,
[0155] The collision and analysis of the intelligence index set and the traffic index set obtain each backtracking threat event, and the event generation module 403 is specifically configured to:
[0156] The following operations are respectively performed for a plurality of batches of the traffic index set:
[0157] The intelligence index set is collided with a traffic index subset of a corresponding amount of backtracking data acquired in a batch to obtain subset collision data;
[0158] The subset collision data is analyzed by using an event model to obtain each backtracking threat event in the traffic index subset corresponding to the intelligence index set.
[0159] In an optional embodiment, the intelligence index set is collided with a plurality of subset thread blocks of the traffic index subset in a plurality of threads in a concurrent manner,
[0160] The analysis of the index collision data by using the event model obtains each backtracking threat event in the traffic index subset, and the event generation module 403 is specifically configured to:
[0161] In the plurality of threads, the plurality of block collision data obtained by colliding the intelligence index set with the plurality of subset thread blocks by using the event model is analyzed in a concurrent manner to obtain each backtracking threat event in the traffic index subset.
[0162] Based on the same inventive concept as the above application embodiments, the present application embodiment further provides an electronic device, which can be used for event detection. In an embodiment, the electronic device can be a server, a terminal device or other electronic device. In this embodiment, the structure of the electronic device can be as shown in Figure 5 The electronic device includes a memory 501, a communication interface 503 and one or more processors 502.
[0163] The memory 501 is configured to store a computer program executed by the processor 502. The memory 501 can mainly include a program storage area and a data storage area. The program storage area can store an operating system and programs required for running the instant messaging function, etc. The data storage area can store various instant messaging information and operation instruction sets, etc.
[0164] The memory 501 can be a volatile memory, for example, a random-access memory (RAM). The memory 501 can also be a non-volatile memory, for example, a read-only memory, a flash memory, a hard disk drive (HDD) or a solid-state drive (SSD), or the memory 501 can be any other medium capable of carrying or storing desired program codes in the form of instructions or data structures and capable of being accessed by a computer, but is not limited to this. The memory 501 can be a combination of the above memories.
[0165] The processor 502 can include one or more central processing units (CPUs) or digital processing units, etc. The processor 502 is configured to invoke the computer program stored in the memory 501 to implement the above event detection method.
[0166] The communication interface 503 is configured to communicate with a terminal device and other servers.
[0167] The specific connection medium between the above memory 501, the communication interface 503 and the processor 502 is not limited in the embodiments of the present application. In the embodiments of the present application, the memory 501 and the processor 502 are connected through a bus 504. The bus 504 is represented by a thick line in the embodiments of the present application. The connection mode between other components is only schematically illustrated and is not limited. The bus 504 can be divided into an address bus, a data bus and a control bus. For convenience of representation, only one thick line is used to represent the bus 504 in the embodiments of the present application, but it does not mean that there is only one bus or only one type of bus. Figure 5 Figure 5 Figure 5
[0168] Based on the same inventive concept, the embodiments of the present application also provide a storage medium storing computer instructions. When the computer instructions run on a computer, the computer executes the event detection method discussed above.
[0169] It should be noted that, although several units or sub-units of the apparatus are mentioned in the foregoing detailed description, such division is merely exemplary and not mandatory. Indeed, features and functions of two or more units described above can be embodied in one unit, according to an implementation of the present application. Conversely, a feature or function of one unit described above can be further divided into several sub-units to be embodied by several units.
[0170] Moreover, although the operations of the method(s) herein can be described in a particular, sequential order, this order is not meant to be a limitation and is not intended to imply that the described operations must be performed in the order described nor that all operations must be performed. Certain steps can be performed in an order other than the order described, steps can be performed concurrently, omitted, or added, and / or the order described herein can be reversed. One will further appreciate that a "system" could be understood to include a computer readable storage medium storing computer readable program code, wherein the code in the storage medium is directed to cause a computer to perform any of the methods described herein.
[0171] The embodiments of the present application provide an event detection method and device, electronic equipment and storage medium. In response to a set collision opportunity, a set of intelligence indicators is obtained, and a set of traffic indicators for the collision opportunity is obtained from a traffic indicator library. Each intelligence indicator is associated with an incremental intelligence in a local intelligence library. An intelligence record time of each incremental intelligence is not earlier than a set historical detection time. Each traffic indicator is associated with a backtracking traffic in a traffic message queue. Each backtracking traffic is obtained by historical log analysis. Further, the set of intelligence indicators and the set of traffic indicators are collided and analyzed to obtain each backtracking threat event. Thus, the attack behavior before the intelligence is generated is backtracked and detected based on the above manner, and the traceability integrity of the network attack chain is improved.
[0172] On the other hand, the historical detection time is used to configure each incremental intelligence for collision, and each backtracking traffic for collision is obtained through the traffic message queue, so as to avoid data repeated collision and reduce the total amount of data required to be cached during collision, thereby improving the detection efficiency of the threat event.
[0173] Those skilled in the art will understand that the embodiments of the present application can be provided as a method, system, or computer program product. Therefore, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage, etc.) containing computer-usable program code.
[0174] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks. Figure 1 one or more flowcharts and / or blocks in the flowcharts and / or combination thereof. Figure 1 means for performing the functions specified in the flowchart block or blocks.
[0175] programmable data processing apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks.
[0176] In the case of using a remote computing device, the remote computing device can be connected to the user computing device through any kind of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, by connecting through the Internet using an Internet service provider).
[0177] These computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture including an instruction means that implements the function specified in the flowchart block or blocks. Figure 1 one or more flowcharts and / or blocks in the flowcharts and / or combination thereof. Figure 1 means for performing the functions specified in the flowchart block or blocks.
[0178] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks. Figure 1 one or more flowcharts and / or blocks in the flowcharts and / or combination thereof. Figure 1 means for performing the functions specified in the flowchart block or blocks.
[0179] Obviously, many modifications and variations of the present application are possible in light of the above teachings. It is, therefore, to be understood that within the scope of the appended claims and their equivalents, the application can be practiced otherwise than as specifically described.
Claims
1. An event detection method, characterized by, The method comprises the following steps: in response to a set collision time, obtaining an intelligence indicator set required for event detection indicated by an intelligence range, wherein the intelligence range is pre-configured according to an indicator type or an intelligence type; each intelligence indicator is associated with an incremental intelligence in a local intelligence library, and an intelligence record time of each incremental intelligence is not earlier than a set historical detection time; each incremental intelligence is obtained by intelligence analysis on threat intelligence produced by a cloud intelligence source; from a traffic indicator library, obtaining a traffic indicator set required for event detection indicated by a backtracking range for the collision time, wherein each traffic indicator is associated with a backtracking traffic in a traffic message queue, and each backtracking traffic is obtained by historical log analysis; the backtracking range is pre-configured according to a backtracking period and a log type; colliding and analyzing the intelligence indicator set and the traffic indicator set to obtain each backtracking threat event; sending the each backtracking threat event to an event message queue to trigger analysis and alarm for the each backtracking threat event.
2. The method of claim 1, wherein, Before the step of obtaining the intelligence indicator set required for event detection indicated by the intelligence range in response to the set collision time, the method further comprises the following steps: obtaining each backtracking traffic in the traffic message queue for the collision time according to a started consumption process; extracting indicators from the each backtracking traffic to obtain each candidate indicator, and filtering the each candidate indicator by using a filtering rule to obtain each traffic indicator; sending the each traffic indicator to the traffic indicator library to trigger the traffic indicator library to store the each traffic indicator by merging according to a set period, and to store the each traffic indicator by merging in a local traffic library by using persistence.
3. The method of claim 2, wherein, The step of triggering the traffic indicator library to store the each traffic indicator by merging according to the set period comprises the following steps: triggering the traffic indicator library to store each first traffic value in the each traffic indicator by merging according to the set period, wherein the first traffic value comprises address information and a hash value extracted from the corresponding backtracking traffic; and triggering the traffic indicator library to compress each second traffic value in the each traffic indicator by using a compression algorithm, and storing each second compressed value obtained by merging according to the set period, wherein the second traffic value comprises a uniform resource locator extracted from the corresponding backtracking traffic.
4. The method according to any one of claims 1 to 3, characterized in that, The step of obtaining the intelligence indicator set required for event detection indicated by the intelligence range in response to the set collision time comprises the following steps: in response to the local intelligence library triggering update information, obtaining an intelligence indicator set associated with a set indicator type and / or intelligence type; or in response to a set detection period, obtaining an intelligence indicator set associated with a set indicator type and / or intelligence type.
5. The method according to any one of claims 1 to 3, wherein The step of obtaining the traffic indicator set required for event detection indicated by the backtracking range for the collision time from the traffic indicator library comprises the following steps: obtaining traffic record times of the corresponding backtracking traffic from the traffic indicator library, and obtaining a plurality of traffic indicators belonging to a set backtracking period as the traffic indicator set for the collision time; and / or, From the traffic index library, the log type of the corresponding backtracking traffic correlation history log is obtained, and a plurality of traffic indexes of a set backtracking type are set.
6. The method according to any one of claims 1 to 3, wherein The traffic index set is batched according to the set backtracking data volume, Then the intelligence index set and the traffic index set are collided and analyzed to obtain each backtracking threat event, including: For each batch of the traffic index set, the following operations are performed: For a subset of traffic indexes of a corresponding backtracking data volume obtained in a batch, the intelligence index set and the subset of traffic indexes are collided to obtain subset collision data; An event model is used to analyze the subset collision data to obtain each backtracking threat event in the subset of traffic indexes corresponding to the intelligence index set.
7. The method of claim 5, wherein, The intelligence index set uses multiple threads to concurrently collide with multiple subset thread blocks of the subset of traffic indexes, Then the event model is used to analyze the index collision data to obtain each backtracking threat event in the subset of traffic indexes, including: In the multiple threads, the event model is concurrently used to analyze multiple block collision data obtained by colliding the intelligence index set with the multiple subset thread blocks to obtain each backtracking threat event in the subset of traffic indexes.
8. An event detection apparatus characterized by comprising: Including: The first acquisition module is configured to acquire an intelligence index set required for event detection according to an intelligence range in response to a set collision opportunity, wherein the intelligence range is pre-configured according to an index type or an intelligence type; each intelligence index is associated with an incremental intelligence in a local intelligence library, and each incremental intelligence has an intelligence record time not earlier than a set historical detection time; and each incremental intelligence is obtained by intelligence analysis on threat intelligence produced by a cloud intelligence source; The second acquisition module is configured to acquire a traffic index set required for event detection according to a backtracking range from a traffic index library in response to the collision opportunity, wherein each traffic index is associated with a backtracking traffic in a traffic message queue, and each backtracking traffic is obtained by historical log analysis; and the backtracking range is pre-configured according to a backtracking period and a log type. The event generation module is configured to collide and analyze the intelligence index set and the traffic index set to obtain each backtracking threat event. The delivery module is configured to send the each backtracking threat event to an event message queue to trigger analysis and alarm for the each backtracking threat event.
9. An electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, The processor executes the computer program to implement the method of any one of claims 1-7.
10. A computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the method of any one of claims 1-7.
Citation Information
Patent Citations
Network security event backtracking method and system
CN114900359A