Compromised host detection method, device, computer equipment, and storage medium

By analyzing the historical and current alarm data of the target host, identifying the first alarm type and time node, the problems of high false alarm rate and low accuracy of the detection of the lost host in the existing technology are solved, and the accurate identification of the lost host is achieved.

CN116032586BActive Publication Date: 2025-08-08SANGFOR TECH INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211658681.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-22
Publication Date
2025-08-08
Estimated Expiration
2042-12-22

AI Technical Summary

Technical Problem

In the prior art, the detection of lost hosts has high false alarm rate and low accuracy rate, making it difficult to accurately identify hosts controlled by network intruders.

Method used

By obtaining the first alarm data of the target host in the historical time period and the second alarm data of the current time period, the first alarm type, number of alarms and alarm time nodes are determined, and based on these information, whether the host is a lost host is determined.

Benefits of technology

Accurate detection of the lost host is achieved, the false alarm rate is reduced, and the accuracy of detection is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116032586B_ABST
    Figure CN116032586B_ABST
Patent Text Reader

Abstract

The present application discloses a method, device, computer equipment and storage medium for detecting a compromised host. The method obtains the first alarm data of the target host in a historical time period and the second alarm data in a current time period; determines the statistical information corresponding to the first alarm from the second alarm data; determines the alarm time node that has not appeared in the first alarm data from the second alarm data as the first alarm time information; and determines whether the target host is a compromised host based on the statistical information and the first alarm time information. By obtaining all the first alarm types, alarm times and the number of first alarm time nodes that appear in the current time period but not in the historical time period, the probability of the target host being a compromised host is determined, thereby achieving accurate judgment of the compromised host.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and more specifically, to a method, apparatus, computer device, and storage medium for detecting a compromised host. Background Art

[0002] A compromised host is a host that an intruder has somehow gained control of. Intruders often use this compromised host as a springboard to attack other hosts on the intranet. However, compromised hosts are often quite hidden. Typically, compromised host detection is performed by generating alerts based on various abnormal host behaviors. However, this approach generates a large number of alerts, most of which are actually normal, resulting in a high false positive rate and low compromised host detection accuracy. Summary of the Invention

[0003] In view of the above problems, the present application proposes a method, apparatus, computer equipment and storage medium for detecting a compromised host, so as to accurately detect whether the target host is compromised.

[0004] In a first aspect, an embodiment of the present application provides a method for detecting a compromised host, the method comprising: obtaining first alarm data of the target host within a historical time period, and second alarm data within a current time period; determining statistical information corresponding to a first-occurring alarm from the second alarm data, wherein the first-occurring alarm is alarm data in the second alarm data that has not appeared in the first alarm data; determining an alarm time node in the second alarm data that has not appeared in the first alarm data as first-occurring alarm time information; and determining whether the target host is a compromised host based on the statistical information and the first-occurring alarm time information.

[0005] In the second aspect, an embodiment of the present application provides a detection device for a compromised host, the device comprising: a data acquisition module, a first occurrence determination module, a node determination module and a host judgment module, wherein the data acquisition module is used to obtain the first alarm data of the target host in a historical time period, and the second alarm data in a current time period; the first occurrence determination module is used to determine the statistical information corresponding to the first alarm from the second alarm data, wherein the first alarm is the alarm data in the second alarm data that has not appeared in the first alarm data; the node determination module is used to determine the alarm time node in the second alarm data that has not appeared in the first alarm data as the first occurrence alarm time information; the host judgment module is used to determine whether the target host is a compromised host based on the statistical information and the first alarm time information.

[0006] In a third aspect, an embodiment of the present application provides a computer device comprising: one or more processors; a memory; and one or more applications, wherein the one or more applications are stored in the memory and configured to be executed by the one or more processors, and the one or more programs are configured to execute the method for detecting a compromised host provided in the first aspect above.

[0007] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, in which a program code is stored. The program code can be called by a processor to execute the method for detecting a compromised host provided in the first aspect above.

[0008] The solution provided by the present application discloses a method, device, computer equipment and storage medium for detecting a compromised host. The method obtains the first alarm data of the target host in the historical time period, and the second alarm data in the current time period; determines the statistical information corresponding to the first alarm from the second alarm data; determines the alarm time node that has not appeared in the first alarm data from the second alarm data as the first alarm time information; and determines whether the target host is a compromised host based on the statistical information and the first alarm time information. By obtaining all the first alarm types, alarm times and the number of first alarm time nodes corresponding to the target host that appeared in the current time period but did not appear in the historical time period, and determining whether the target host is a compromised host accordingly, accurate detection of the compromised host is achieved. BRIEF DESCRIPTION OF THE DRAWINGS

[0009] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative work.

[0010] Figure 1 The following diagram shows an application scenario of the method for detecting a compromised host provided in an embodiment of the present application.

[0011] Figure 2 A flow chart of a method for detecting a compromised host provided by an embodiment of the present application is shown.

[0012] Figure 3 A flow chart of a method for detecting a compromised host provided in another embodiment of the present application is shown.

[0013] Figure 4 A specific flow chart of step S210 in another embodiment of the present application is shown.

[0014] Figure 5A specific flow chart of step S240 in another embodiment of the present application is shown.

[0015] Figure 6 Another specific flow chart of step S240 in another embodiment of the present application is shown.

[0016] Figure 7 A specific flow chart of step S250 in another embodiment of the present application is shown.

[0017] Figure 8 The figure shows a structural block diagram of a device for detecting a compromised host provided in an embodiment of the present application.

[0018] Figure 9 A structural block diagram of a computer device provided in an embodiment of the present application is shown.

[0019] Figure 10 A structural block diagram of a computer-readable storage medium provided in an embodiment of the present application is shown. DETAILED DESCRIPTION

[0020] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application.

[0021] The inventors have proposed a method, apparatus, computer device, and storage medium for detecting a compromised host, as provided in the embodiments of this application. By obtaining the types, number of alarms, and number of time nodes of all first-appearing alarms corresponding to the target host that appear in the current time period but not in the previous time period, the probability that the target host is a compromised host is determined, thereby accurately determining the compromised host. The specific method for detecting a compromised host is described in detail in the subsequent embodiments.

[0022] The following introduces the application scenarios of the method for detecting a compromised host provided in the embodiments of the present application.

[0023] See also Figure 1The method for detecting a compromised host provided in an embodiment of the present application is applied to a computer device 300, wherein the computer device 300 can be a physical server, a cloud server, or a terminal device with corresponding computing and storage capabilities, such as a computer or a laptop. The computer device 300 can be connected to multiple hosts 100. Generally, the computer device 300 obtains the log data of each host to obtain a variety of different behavioral characteristics of the host, and based on the detection engine and preset rules, determines whether the different behavioral characteristics of the host are abnormal behaviors, and then determines whether to generate corresponding alarm data based on the abnormal behavior, that is, determines whether the host is a compromised host. This judgment method only determines whether the current behavioral characteristics of the host are abnormal, which easily leads to a high false alarm rate of the judgment result. Therefore, in an embodiment of the present application, the computer device 300 determines the alarm type and alarm time node that have not appeared in the historical time period based on the alarm data of the current time period and the alarm data of the historical time period, and determines whether the target host is a compromised host based on this, thereby achieving accurate judgment of whether the host is a compromised host.

[0024] The following will describe in detail the method for detecting a compromised host provided by an embodiment of the present application with reference to the accompanying drawings.

[0025] See also Figure 2 , Figure 2 A flowchart of a method for detecting a compromised host provided by an embodiment of the present application is shown below. Figure 2 The process shown is described in detail. The method for detecting a compromised host may include the following steps:

[0026] Step S110: Acquire the first alarm data of the target host in a historical time period and the second alarm data in a current time period.

[0027] In an embodiment of the present application, the first alarm data of the target host obtained by the computer device can be the alarm data generated by the target host in the historical time period, or the alarm data obtained after detecting the behavior log of the target host in the historical time period; similarly, the second alarm data can be the alarm data generated by the target host in the current time period, or the alarm data obtained after detecting the behavior log of the target host in the current time period; the above first alarm data and second alarm data both include the alarm types that have occurred, the time when each alarm type is generated, and the number of times each alarm type is generated. Among them, the historical time period corresponding to the first alarm data is before the current time period corresponding to the second alarm data. Therefore, the computer device can use the first alarm data in the historical time period as a benchmark, and based on the first alarm type of the target host in the historical time period, determine whether the second alarm type of the target host in the current time period is abnormal, and then obtain an accurate judgment on whether the target host is a trapped host.

[0028] It is understandable that the target host will continuously generate various behavioral actions based on program instructions to achieve the functions required by the instructions, and the target host will record these actions through log statements. If the target host encounters a network intrusion and loses control, then some of the behavioral actions generated by the target host may be abnormal or threaten the security of the target host or even other hosts. In this case, if the target host detects the above dangerous behaviors, then the target host will generate corresponding alarm information after detecting the dangerous behaviors. In an embodiment of the present application, these alarm information generated by the target host can be divided into first alarm data and second alarm data due to the different time periods generated. That is, if the target host generates an alarm based on dangerous behaviors in a historical time period, then the alarm type and the time it is generated will be classified as first alarm data. If the target host generates an alarm based on dangerous behaviors in the current time period, then it will be classified as second alarm data. In addition, all dangerous behaviors are divided into multiple different types, and each different type of dangerous behavior corresponds to a different alarm type. If the target host performs a preset dangerous behavior, then an alarm information of the corresponding alarm type will be generated.

[0029] In some embodiments, the historical time period may be before the current time period and adjacent to the current time period, that is, the end time of the historical time period is the start time of the current time period. For example, if the current time period is 24 hours long and the historical time period is 30 days long, that is, 24*30 hours, and if the current time is 16:00, the computer device may use the time period between 16:00 yesterday and 16:00 today as the current time period of the target host, and the time period within 24*30 hours before 16:00 yesterday as the historical time period of the target host.

[0030] In other embodiments, the historical time period may be before the current time period and not adjacent to the current time period, that is, there is a time period between the end time of the historical time period and the start time of the current time period. For example, assuming that the current time is 16:00 on September 30, the computer device may use the time period between 16:00 on September 29 and the current time as the current time period corresponding to the target host, and the time period between 16:00 on August 15 and 16:00 on September 15 as the historical time period corresponding to the target host. In this manner, since the alarm data generated by the target host or the recorded behavior log may be abnormal, for example, in the aforementioned example, the target host did not record any alarm data or behavior log during the abnormal time period between 16:00 on September 15 and 16:00 on September 29, then the computer device cannot obtain the alarm data for the abnormal time period, or cannot obtain the behavior log for the abnormal time period, and obtain the alarm data for the abnormal time period based on the behavior log detection, the historical time period can be moved forward in time so that the historical time period does not include the abnormal time period.

[0031] Step S120: Determine statistical information corresponding to the first occurring alarm from the second alarm data.

[0032] In an embodiment of the present application, the first-occurring alarm is the alarm data in the second alarm data that has not appeared in the first alarm data. The computer device can use the first alarm data corresponding to the target host in the historical time period as a standard, and based on the second alarm data of the target host in the current time period, determine whether there is an alarm type that has not appeared in the current time period. That is, the computer device will issue an alarm when the target host implements a dangerous behavior, and generate the first alarm data or the second alarm data based on information such as the type and time of the alarm. Thereafter, the computer device can determine the statistical information corresponding to the first-occurring alarm for all the alarm data respectively included in the first alarm data and the second alarm data, that is, determine all the alarm data that appeared in the second alarm data but did not appear in the first alarm data, wherein the alarm data determined by the computer device may include information such as the time and type of generation of the alarm. For example, the target host generates a function call warning at a certain moment in the current time period, indicating that a dangerous function is called during the program execution at this time, but this function call warning has never been generated in the historical time period. Therefore, after the computer device compares the first alarm data with the second alarm data, it can directly determine the alarm data that has not appeared in the first alarm data, that is, determine the statistical information corresponding to the first alarm, where the statistical information may include information such as the generation time, number of times the alarm data is generated, and the alarm type. It is understandable that under normal circumstances, the host usually does not exhibit behaviors that meet the alarm conditions corresponding to the new alarm type, that is, under normal circumstances, the new alarm type will not appear in the above second alarm data. Therefore, the computer device can obtain the first alarm type that has not appeared in these historical time periods, so as to determine whether the target host is a compromised host based on this.

[0033] In some embodiments, the statistical information corresponding to the first-occurrence alarm includes the type of the first-occurrence alarm and / or the number of occurrences of the first-occurrence alarm. In other words, the statistical information of the first-occurrence alarm determined by the computer device based on the first alarm data and the second alarm data may include all alarm data that appeared in the second alarm data but did not appear in the first alarm data, including information such as the alarm type corresponding to these alarm data, the time when the alarm was generated, and the number of occurrences of the alarm type.

[0034] Step S130: Determine, from the second alarm data, an alarm time node that has not appeared in the first alarm data as the first-occurrence alarm time information.

[0035] In an embodiment of the present application, based on the first alarm data and the second alarm data, the computer device can also obtain the alarm time nodes corresponding to all alarm types generated by the target host in the current time period. Of course, the first alarm data of the target host in the historical time period also records the time node when each alarm type appears (i.e., the alarm time node). Thus, the computer device can also obtain the first alarm time information corresponding to the target host based on the different alarm time nodes of the same alarm type appearing in the first alarm data and the second alarm data. That is to say, if a certain alarm type has been generated in both the historical time period and the current time period, but the alarm time node generated by this alarm type in the historical time period is different from the alarm time node generated in the current time period, then this alarm type can still characterize, to a certain extent, that the target host is in danger of being invaded and controlled. Therefore, the computer device can also determine whether there is first alarm time information based on the first alarm data and the second alarm data, and then determine whether the target host is a compromised host. It can be understood that the computer device determines the operation of determining the statistical information corresponding to the first alarm based on the first alarm data and the second alarm data, and determines the alarm time node that has not appeared in the first alarm data as the first alarm time information. The execution order between the two can be not limited, that is, the two can be performed simultaneously, or step S120 can be executed first and then step S130, or step S130 can be executed first and then step S120.

[0036] In some embodiments, the above alarm time node can be a time period, and the length of the time period can be unlimited, for example, one hour. In this case, the computer device will divide the 24 hours of a day into 24 time periods, and the time period in which the alarm type appears in the alarm data can be used as the alarm time node corresponding to the alarm type. In other embodiments, the computer device can also set the alarm time node to a more specific time period, for example, according to the difference between day and night, the alarm time node can be set to two different time periods, that is, the time period between 7 am and 9 pm is one alarm time node, and the time period between 9 pm and 7 am the next day is another alarm time node. For example, the alarm time node can also be associated with the day of the week, recording the day of the week when each alarm type is generated. If a certain alarm type is generated on Mondays in the historical time period, but is generated on Tuesdays in the current time period, the computer device can use the alarm time node corresponding to this alarm type as the first alarm time information, and use it to determine whether the target host is a compromised host based on the first alarm time information.

[0037] Step S140: Determine whether the target host is a compromised host based on the statistical information and the first alarm time information.

[0038] In an embodiment of the present application, after determining the above first-appearing alarm type and first-appearing alarm time node, the computer device can determine the number of types of all first-appearing alarm types, the number of first-appearing alarm time nodes, and the number of times each first-appearing alarm type appears in the current time period based on the second alarm data, and then determine whether the target host is a trapped host based on these data. It can be understood that the probability that the target host is a trapped host is positively correlated with the number of types of first-appearing alarm types, the number of times each first-appearing alarm type appears, and the number of first-appearing alarm time nodes. Therefore, the computer device can determine the probability that the target host is a trapped host based on the size of these numbers, and then determine whether the target host is a trapped host.

[0039] The method for detecting a compromised host provided in an embodiment of the present application obtains the first alarm data of the target host in a historical time period, and the second alarm data in a current time period; from the second alarm data, determines the alarm type that has not appeared in the first alarm data as the first alarm type; from the second alarm data, determines the alarm time node that has not appeared in the first alarm data as the first alarm time node; based on the number of types of first alarm types, the number of first alarm time nodes, and the number of occurrences of each first alarm type in the second alarm data, determines whether the target host is a compromised host. By obtaining all first alarm types, the number of alarms, and the number of first alarm time nodes corresponding to the target host that appeared in the current time period but did not appear in the historical time period, and determining whether the target host is a compromised host accordingly, accurate detection of the compromised host is achieved.

[0040] See also Figure 3 , Figure 3 A flow chart of a method for detecting a compromised host provided by another embodiment of the present application is shown. Figure 3 The process shown is described in detail. The method for detecting a compromised host may include the following steps:

[0041] Step S210: Acquire the first alarm data of the target host in the historical time period and the second alarm data in the current time period.

[0042] In some embodiments, the computer device may obtain the first alarm data and the second alarm data corresponding to the target host in the following manner:

[0043] The first alarm data of the target host in the historical time period and the second alarm data of the target host in the current time period are determined from all alarm data generated in the historical operation process stored in the target host.

[0044] Specifically, during the operation of the target host, the generated behavior is detected. If the target host performs a preset dangerous behavior, an alarm of the corresponding alarm type will be generated. In other words, during the operation of the target host itself, when the corresponding dangerous behavior is detected, an alarm of the alarm type corresponding to the dangerous behavior is generated, and the alarm information of all alarm types and the time of the generated alarm are recorded (i.e., the alarm data is recorded). Therefore, when the computer device detects whether the target host is a compromised host, it can directly obtain the first alarm data recorded in the historical time period during the operation process from the target host, as well as the second alarm data in the current time period, and then determine whether the target host is a compromised host based on the first alarm data and the second alarm data.

[0045] In other embodiments, Figure 4 As shown, the method in which the computer device obtains the first alarm data and the second alarm data corresponding to the target host may also include:

[0046] Step S211: Acquire all historical behavior logs of the target host in the historical time period, and all current behavior logs of the target host in the current time period.

[0047] In an embodiment of the present application, the target host will record the detailed information of each step executed during the program execution, including the triggering of the action, the execution process, and the execution result, etc., to form a behavior log, so that after the step execution is completed, the computer device can determine which actions the target host has performed in the past and what effects have been achieved based on the behavior log, thereby facilitating the troubleshooting of problems in the program operation. Among them, the target host will not detect its behavior and generate an alarm during the operation of the program, but only record all behavior logs during the operation. When the computer device needs to detect whether the target host is a compromised host, the computer device can obtain all historical behavior logs of the target host in the historical time period and all current behavior logs in the current time period from the target host, and then the computer device will detect all historical behavior logs and current behavior logs to detect behavior logs that meet the alarm.

[0048] Step S212: Based on the preset detection engine and all the historical behavior logs, determine the first alarm data within the historical time period.

[0049] Step S213: Determine second alarm data within the current time period based on the preset detection engine and all current behavior logs.

[0050] In an embodiment of the present application, the preset detection engine includes detection rules written according to the behavioral characteristics of dangerous behaviors (such as attacked behaviors, etc.), and the detection rules may include behavioral characteristic conditions corresponding to each alarm type. The computer device determines the first alarm data of the target host in the historical time period based on the preset detection engine and the historical behavior log, which means that the detection engine is used to detect whether the behavioral characteristics corresponding to each log statement in the historical behavior log match the above behavioral characteristic conditions. If a certain behavior log can match the behavioral characteristic conditions of any of the alarm types, it indicates that the behavioral characteristics corresponding to this log statement are abnormal. The computer device can determine that at the time when the behavior log was generated, an alarm message of this alarm type appeared, and record the alarm type of the alarm message and the alarm time generated (i.e., the time when the behavior log was generated). Thus, the computer device can traverse the historical behavior log of the target host based on the preset detection engine to obtain the above first alarm data corresponding to the target host. Similarly, the computer device can determine the above second alarm data corresponding to the target host in the current time period based on the preset detection engine and the current behavior log of the target host.

[0051] Step S220: Determine statistical information corresponding to a first-occurring alarm from the second alarm data, wherein the first-occurring alarm is alarm data in the second alarm data that has not appeared in the first alarm data.

[0052] Step S230: Determine, from the second alarm data, an alarm time node that has not appeared in the first alarm data as the first-occurrence alarm time information.

[0053] In the embodiment of the present application, step S220 and step S230 can refer to the contents of other embodiments and will not be repeated here.

[0054] Step S240: Based on the number of types of the first-appearing alarm, the number of occurrences of the first-appearing alarm, and the time information of the first-appearing alarm, determine the compromise score corresponding to the target host, and the compromise score is used to represent the probability that the target host is a compromised host.

[0055] In an embodiment of the present application, in order to facilitate accurate measurement of the probability of the target host being trapped, the computer device can obtain the corresponding trap score of the target host based on the number of types of the first-appearing alarm type, the number of times each first-appearing alarm type appears, and the number of first-appearing alarm time nodes. It can be understood that the trap score is used to characterize the probability that the target host is a trapped host. The larger the trap score, the greater the probability that the target host is a trapped host. It can be understood that according to the definition of the first-appearing alarm type and the judgment of the first-appearing alarm time node in the above embodiment, the trap score of the target host is positively correlated with the number of types, the number of occurrences, and the number of first-appearing alarm time nodes, that is, the more the number of types and the number of occurrences of the first-appearing alarm type, the more likely the target host is a trapped host, the more the number of first-appearing alarm time nodes, the more abnormal behaviors of the target host in the current time period, and the greater the probability that it is a trapped host.

[0056] In some embodiments, as Figure 5 As shown, the method for determining the compromise score corresponding to the target host in step S240 can be implemented by the following steps:

[0057] Step S241: Based on the number of types and the number of occurrences, determine a first reference score corresponding to the target host, where the first reference score is positively correlated with the number of types and the number of occurrences.

[0058] In an embodiment of the present application, among the three different parameters, namely, the number of types of first-appearing alarm types, the number of first-appearing alarm time nodes, and the number of occurrences of each first-appearing alarm type, the number of types and the number of occurrences are both related to the first-appearing alarm type, while the number of alarm time nodes is related to the time of occurrence of the alarm type. Therefore, in terms of the weight of the judgment of whether the target host is a compromised host, the relevant parameters of the first-appearing alarm type are more important. Therefore, the computer device can first calculate the first reference score corresponding to the target host based on the number of types of first-appearing alarm types and the number of occurrences of the first-appearing alarm types (i.e., the sum of the number of occurrences of all first-appearing alarm types). The first reference score is related to all first-appearing alarm types of the target host and can reflect the probability that the target host is a compromised host to a certain extent. Thus, the computer device can adjust the size of the first reference score according to the number of first-appearing alarm time nodes on the basis of the first reference score determined based on the number of types and the number of occurrences, so that the final result can more accurately reflect the probability of the target host being compromised.

[0059] It is understandable that if the target host does not have a first-appearing alarm type, that is, the number of types and the number of occurrences of the first-appearing alarm type are both zero, that is, all alarm types of the target host in the current time period have been generated in the historical time period, then even if there are some alarm time nodes corresponding to the alarm types that do not match the alarm time nodes in the historical time period, that is, the number of first-appearing alarm time nodes is not zero, but at this time the probability that the target host is a compromised host is still very low. In other words, among the above three parameters, the weight of the number of first-appearing alarm time nodes for the judgment that the target host is a compromised host is lower than the number of types and the number of occurrences of the first-appearing alarm type. Therefore, when the computer device calculates the compromise score corresponding to the target host, it can first obtain a first reference score based on the number of types and the number of occurrences, and then adjust the first reference score based on the number of first-appearing alarm time nodes.

[0060] In a possible implementation, the first reference score can be determined according to the following formula:

[0061] The first reference score = log (1 + the number of types of the first-appearing alarm type) * log (1 + the number of occurrences of all first-appearing alarm types). Therefore, the determined first reference score can be positively correlated with the above number of types and number of occurrences.

[0062] Step S242: If the number of the first-appearance alarm time information is greater than a first value, obtain the product of the first reference score and a first preset value as the trap score corresponding to the target host.

[0063] Step S243: If the number of the first alarm time information is less than or equal to a first value, obtain the product of the first reference score and a second preset value as the compromise score of the target host, and the first preset value is greater than the second preset value.

[0064] In an embodiment of the present application, after determining the first reference score, the computer device can further adjust the first reference score based on the number of first-appearance alarm time nodes to obtain the target host's loss score. That is, when the number of first-appearance alarm time nodes is greater than the first value, the product of the first reference score and a larger first preset value is used as the target host's loss score; when the number of first-appearance alarm time nodes is less than or equal to the first value, the product of the first reference score and a smaller second preset value is used as the target host's loss score. In other words, if the number of first-appearance alarm time nodes is large, then the calculated loss score corresponding to the target host is also correspondingly large; if the number of first-appearance alarm time nodes is small, then the loss score is also correspondingly small. Specifically, in an embodiment of the present application, the computer device converts the adjustment of the size of the loss score by the number of first-appearance alarm time nodes into an adjustment of the size of the first reference score by the first preset value or the second preset value. That is to say, the number of first-appearance alarm time nodes has only two effects on the adjustment of the loss score, namely, the effect produced by the product of the first preset value or the second preset value and the first reference score. The computer device can determine the size of the first preset value and the second preset value based on the expected range of the loss score of the target host, and can also determine the size of the first number based on the expected range of the number of first-appearance alarm time information. Among them, the computer device can set a larger first number to reserve more fault tolerance intervals for the target host, or set a smaller first number to promptly discover the abnormal alarm type of the target host.

[0065] In some embodiments, when the number of first-appearance alarm time nodes is greater than the first value, in order to enhance the influence of the number of first-appearance alarm time nodes on the loss score, the computer device can also set the size of the first preset value to be positively correlated with the number of first-appearance alarm time nodes. That is, when the number of first-appearance alarm time nodes is greater than the first value, the more the number of first-appearance alarm time nodes is, the larger the calculated loss score will be. At this time, the loss score corresponding to the target host is positively correlated with the number of first-appearance alarm time nodes. Of course, when the number of first-appearance alarm time nodes is less than or equal to the first value, since the number of first-appearance alarm time nodes has little influence on the judgment of the lost host, the adjustment of the loss score by the number of first-appearance alarm time nodes is still based on the fixed second preset value.

[0066] In some embodiments, when the number of first-appearance alarm time nodes is less than or equal to the first value, the computer device may consider that the number of first-appearance alarm time nodes has close to no effect on the size of the loss score, and then the computer device may set the second preset value to 1, that is, directly use the first reference score as the loss score corresponding to the target host. When the number of first-appearance alarm time nodes is greater than the first value, it indicates that the number of first-appearance alarm time nodes is large, and the probability that the target host is a lost host is large. The calculation of the loss score should take into account the number of first-appearance alarm time nodes. Therefore, the computer device may set the first preset value to 1.5, so as to increase the size of the loss score when the number of first-appearance alarm time nodes is large.

[0067] Exemplarily, the above first value is 0, the first preset value is 1, and the second preset value is 1.5. That is to say, if the number of first alarm time nodes is 0 (there is no first alarm time node), the above first reference score is directly used as the loss score; if the number of first alarm time nodes is greater than 0 (there is a first alarm time node), the product of the first reference score and 1.5 is obtained, and the product is used as the loss score of the target host.

[0068] In some embodiments, as Figure 6 As shown, the method for determining the compromise score corresponding to the target host in step S240 can be implemented by the following steps:

[0069] Step S244: Determine a second reference score based on the number of types, where the second reference score is positively correlated with the number of types.

[0070] Step S245: determining a third reference score based on the number of the first-occurrence alarm time information, wherein the third reference score is positively correlated with the number of the first-occurrence alarm time information.

[0071] Step S246: Determine a fourth reference score based on the number of occurrences, where the fourth reference score is positively correlated with the number of occurrences.

[0072] In an embodiment of the present application, the computer device can also calculate the degree of influence of each parameter on the loss score based on parameters such as the number of types of the first-appearance alarm type, the number of occurrences of each first-appearance alarm type, and the number of first-appearance alarm time nodes, that is, based on the number of types, determine the second reference score, based on the number of first-appearance alarm time nodes, determine the third reference score, and based on the number of occurrences, determine the fourth reference score. The second reference score, the third reference score, and the fourth reference score can respectively characterize the degree of influence of the number of types, the number of first-appearance alarm time nodes, and the number of occurrences on the loss score. Therefore, the computer device can determine the numerical values of the second reference score, the third reference score, and the fourth reference score in advance based on the influence of the above parameters on the loss score. The larger the reference score, the greater its influence on the loss score. Based on the actual meaning represented by the number of types, the number of first-appearance alarm time nodes, and the number of occurrences, the reference scores corresponding to the number of types, the number of first-appearance alarm time nodes, and the number of occurrences should also be positively correlated with the number of types, the number of first-appearance alarm time nodes, and the number of occurrences.

[0073] In some embodiments, the computer device can directly use the number of first-appearing alarm types as the second reference score, the number of first-appearing alarm time nodes as the third reference score, and the number of occurrences of each first-appearing alarm type as the fourth reference score. Thus, the second reference score, the third reference score, and the fourth reference score can all positively correlate the number of first-appearing alarm types, the number of first-appearing alarm time nodes, and the number of occurrences of each first-appearing alarm type.

[0074] Step S247: Based on the first weight corresponding to the number of types, the second weight corresponding to the number of first-appearance alarm time information, and the third weight corresponding to the number of occurrences, the second reference score, the third reference score, and the fourth reference score are weightedly calculated to obtain the compromise score corresponding to the target host.

[0075] In an embodiment of the present application, the computer device can set different weights for the three parameters of the number of first-appearing alarm types, the number of first-appearing alarm time nodes, and the number of occurrences of each first-appearing alarm type, respectively, to reflect the importance of different parameters in determining whether the target host is a compromised host. For example, it can be understood that the number of first-appearing alarm types should be more important for determining whether the target host is a compromised host. If the target host has a large number of alarm types that have not appeared in historical time periods within the current time period, then the probability that the target host is a compromised host is higher. Therefore, the computer device can assign a larger weight to the number of first-appearing alarm types, that is, set a larger first weight, and relatively smaller second and third weights, to reduce the impact of the number of first-appearing alarm time information and the number of occurrences of the first-appearing alarm type on the target host's compromised score. Therefore, the computer device can determine in advance the numerical values of the corresponding first weight, third weight and second weight based on the degree of influence of parameters such as the number of types of first-appearing alarm types, the number of occurrences and the amount of first-appearing alarm time information on the target host's compromise score, and then determine the compromise score based on each weight, that is, determine the probability that the target host is a compromised host.

[0076] Step S250: Determine whether the target host is a compromised host based on the compromise score corresponding to the target host.

[0077] In an embodiment of the present application, after the computer device determines the compromise score corresponding to the target host based on the number of first-appearing alarm types corresponding to the target host, the number of first-appearing alarm time nodes, and the number of occurrences of each first-appearing alarm type, it can make a judgment on whether the target host is a compromised host based on the size of the compromise score.

[0078] In some implementations, the method of determining whether the target host is a compromised host based on the compromise score in step S250 may be implemented in the following manner:

[0079] If the compromised score corresponding to the target host is greater than a preset score, the target host is determined to be a compromised host.

[0080] In an embodiment of the present application, if the compromise score corresponding to the target host is greater than a preset score, the computer device can determine that the target host is a compromised host. The preset score can be determined by the computer device based on the compromise scores corresponding to multiple hosts, or it can be determined by quantifying the number of types, the number of first-appearance alarm time nodes, and the number of occurrences to obtain the compromise score, which is not limited here. It should be understood that the compromise score corresponding to the target host is used to characterize the probability that the target host is a compromised host. Even if the compromise score is large, it does not necessarily determine that the target host is a compromised host. The computer device determines that the target host is a compromised host based on the compromise score to avoid irreparable losses if the target host is indeed compromised and prompts the programmer to manually investigate the target host. In other words, if the compromise score corresponding to the target host is less than or equal to the preset score, it does not necessarily mean that the target host has not been compromised. It simply means that the computer device determines that the probability of the target host being a compromised host is low based on the operations performed by the target host in the current time period.

[0081] In some embodiments, as Figure 7 As shown, the method of determining whether the target host is a compromised host based on the compromise score in step S250 can be implemented in the following ways:

[0082] Step S251: Obtain the corresponding compromise scores of other hosts.

[0083] In an embodiment of the present application, the computer device can simultaneously perform compromise determinations on multiple hosts. Specifically, the computer device simultaneously obtains the number of first-appearing alarm types, the number of first-appearing alarm time nodes, and the number of occurrences of each first-appearing alarm type for each of the multiple hosts, and then determines the compromise score corresponding to each host based on the same algorithm. At this point, the computer device can determine all potentially compromised hosts among the multiple hosts based on the compromise scores corresponding to the multiple hosts.

[0084] Step S252: Sort the vulnerability scores corresponding to the target host and the vulnerability scores corresponding to the other hosts in descending order of the vulnerability scores to obtain a sorting result.

[0085] In an embodiment of the present application, a computer device can sort multiple hosts, including a target host, from high to low based on the size of their corresponding compromise scores to obtain a sorting result. It is understandable that since the compromise scores of each host are calculated in the same way, in this sorting result, the probability of the hosts from high to low being compromised hosts gradually decreases. In the sorting result, the closer the host is to the front, the higher the probability of it being a compromised host. It is understandable that most of the hosts among all the hosts are normal hosts, so the compromise scores corresponding to these majority of hosts will be very small. The computer device can determine the compromised hosts that may have been invaded based on the distribution of the compromise scores corresponding to all the hosts.

[0086] Step S253: If the compromise score corresponding to the target host is in the top N positions in the sorting result, the target host is determined to be a compromised host.

[0087] In the embodiment of the present application, in the ranking results obtained by multiple hosts, the computer device can determine the first N hosts in the ranking results as compromised hosts. In other words, if the compromise score corresponding to the target host is in the first N in the ranking results, then the target host will also be determined as a compromised host. Where N is a positive integer; the specific value of N is not limited, for example, it can be 1, 3, 5, etc.

[0088] The method for detecting a compromised host provided in an embodiment of the present application quantifies the probability that the target host is a compromised host into a compromise score based on the number of first-appearing alarm types corresponding to the target host, the number of first-appearing alarm time nodes, and the number of occurrences of each first-appearing alarm type, so that the compromise score is positively correlated with the above number of types, the number of first-appearing alarm time nodes, and the above number of occurrences, so that whether the target host is a compromised host can be accurately determined based on the compromise score.

[0089] See also Figure 8, which shows a structural block diagram of a device 200 for detecting a compromised host provided in an embodiment of the present application, the device 200 for detecting a compromised host includes: a data acquisition module 210, a first occurrence determination module 220, a node determination module 230, and a host judgment module 240. The data acquisition module 210 is used to obtain the first alarm data of the target host in a historical time period, and the second alarm data in a current time period; the first occurrence determination module 220 is used to determine the statistical information corresponding to the first occurrence alarm from the second alarm data, wherein the first occurrence alarm is the alarm data in the second alarm data that has not appeared in the first alarm data; the node determination module 230 is used to determine the alarm time information in the second alarm data that has not appeared in the first alarm data as the first occurrence alarm time node; the host judgment module 240 is used to determine whether the target host is a compromised host based on the statistical information and the first occurrence alarm time information.

[0090] As a possible implementation manner, the statistical information corresponding to the first alarm includes the number of types of the first alarm and / or the number of occurrences of the first alarm.

[0091] As a possible implementation, the host determination module 240 includes a score determination unit and a host determination unit. The score determination unit is configured to use the compromise score to characterize the probability that the target host is a compromised host based on the number of types of the first-appearing alarm, the number of occurrences of the first-appearing alarm, and the time information of the first-appearing alarm; and the host determination unit is configured to determine whether the target host is a compromised host based on the compromise score corresponding to the target host.

[0092] As a possible implementation, the score determination unit is also used to determine a first reference score corresponding to the target host based on the number of types and the number of occurrences, and the first reference score is positively correlated with the number of types and the number of occurrences; if the number of the first alarm time information is greater than the first value, the product of the first reference score and the first preset value is obtained as the loss score corresponding to the target host; if the number of the first alarm time information is less than or equal to the first value, the product of the first reference score and the second preset value is obtained as the loss score of the target host, and the first preset value is greater than the second preset value.

[0093] As a possible implementation, the score determination unit is also used to determine a second reference score based on the number of types, and the second reference score is positively correlated with the number of types; determine a third reference score based on the number of first-appearance alarm time information, and the third reference score is positively correlated with the number of first-appearance alarm time information; determine a fourth reference score based on the number of occurrences, and the fourth reference score is positively correlated with the number of occurrences; and perform a weighted calculation on the second reference score, the third reference score, and the fourth reference score based on the first weight corresponding to the number of types, the second weight corresponding to the number of first-appearance alarm time information, and the third weight corresponding to the number of occurrences to obtain the compromise score corresponding to the target host.

[0094] As a possible implementation method, the host judgment unit is also used to determine that the target host is a compromised host if the compromise score corresponding to the target host is greater than a preset score; or to obtain the compromise scores corresponding to other hosts; and to sort the compromise scores corresponding to the target host and the compromise scores corresponding to the other hosts in descending order of the compromise scores to obtain a sorting result; and if the compromise score corresponding to the target host is in the top N positions in the sorting result, the target host is determined to be a compromised host.

[0095] As a possible implementation, the data acquisition module 210 is also used to obtain all historical behavior logs of the target host within the historical time period, and all current behavior logs of the target host within the current time period; based on the preset detection engine and all the historical behavior logs, determine the first alarm data within the historical time period; based on the preset detection engine and all the current behavior logs, determine the second alarm data within the current time period.

[0096] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described devices and modules can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0097] In several embodiments provided in this application, the coupling between modules may be electrical, mechanical or other forms of coupling.

[0098] In addition, the functional modules in the various embodiments of the present application may be integrated into a processing module, or each module may exist physically separately, or two or more modules may be integrated into a single module. The above-mentioned integrated modules may be implemented in the form of hardware or software functional modules.

[0099] In summary, the solution provided by the present application obtains the first alarm data of the target host in the historical time period, and the second alarm data in the current time period; determines the statistical information corresponding to the first alarm from the second alarm data; determines the alarm time node that has not appeared in the first alarm data from the second alarm data as the first alarm time information; and determines whether the target host is a compromised host based on the statistical information and the first alarm time information. By obtaining all the first alarm types, alarm times, and the number of first alarm time nodes corresponding to the target host that appeared in the current time period but did not appear in the historical time period, and determining whether the target host is a compromised host based on this, accurate detection of the compromised host is achieved.

[0100] Please refer to Figure 9 , which shows a structural block diagram of a computer device 300 provided in an embodiment of the present application. The computer device 300 may be a physical server, a cloud server, or the like. The computer device 300 in the present application may include one or more of the following components: a processor 310, a memory 320, and one or more application programs, wherein the one or more application programs may be stored in the memory 320 and configured to be executed by the one or more processors 310, and the one or more programs may be configured to execute the method described in the aforementioned method embodiment.

[0101] The processor 310 may include one or more processing cores. The processor 310 utilizes various interfaces and circuits to connect various components within the computer device. It executes instructions, programs, code sets, or instruction sets stored in the memory 320, as well as accesses data stored in the memory 320, to perform various functions of the computer device and process data. Optionally, the processor 310 may be implemented using at least one of the following hardware forms: a digital signal processing (DSP), a field-programmable gate array (FPGA), or a programmable logic array (PLA). The processor 310 may integrate one or a combination of a central processing unit (CPU), a graphics processing unit (GPU), and a modem. The CPU primarily processes the operating system, user interface, and application programs; the GPU is responsible for rendering and drawing display content; and the modem handles wireless communications. It is understood that the modem may not be integrated into the processor 310 and may be implemented separately via a communications chip.

[0102] The memory 320 may include a random access memory (RAM) or a read-only memory (ROM). The memory 320 may be used to store instructions, programs, codes, code sets, or instruction sets. The memory 320 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for implementing at least one function (such as a touch function, a sound playback function, an image playback function, etc.), instructions for implementing the following various method embodiments, etc. The data storage area may also store data created by the computer device during use (such as a phone book, audio and video data, chat history data, etc.).

[0103] Please refer to Figure 10 , which shows a block diagram of a computer-readable storage medium provided in an embodiment of the present application. The computer-readable medium 800 stores program code, which can be called by a processor to execute the method described in the above method embodiment.

[0104] The computer-readable storage medium 800 can be an electronic memory such as a flash memory, an EEPROM (Electrically Erasable Programmable Read-Only Memory), an EPROM, a hard disk, or a ROM. Alternatively, the computer-readable storage medium 800 includes a non-transitory computer-readable storage medium. The computer-readable storage medium 800 has storage space for program code 810 for executing any of the method steps described above. These program codes can be read from or written to one or more computer program products. The program code 810 can be compressed, for example, in a suitable form.

[0105] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A method for detecting a compromised host, characterized in that: The method comprises: Obtain the target host's first alarm data in the historical time period and the second alarm data in the current time period; Determining statistical information corresponding to a first-occurring alarm from the second alarm data, wherein the first-occurring alarm is alarm data in the second alarm data that has not appeared in the first alarm data; Determining, from the second alarm data, an alarm time node that has not appeared in the first alarm data as first-occurrence alarm time information; Determine whether the target host is a compromised host based on the statistical information and the first-appearance alarm time information, wherein the statistical information corresponding to the first-appearance alarm includes the number of types of the first-appearance alarm and the number of occurrences of the first-appearance alarm; Determining whether the target host is a compromised host based on the statistical information and the first alarm time information includes: Based on the number of types of the first-appearing alarm, the number of occurrences of the first-appearing alarm and the time information of the first-appearing alarm, the corresponding compromise score of the target host is determined, and the compromise score is used to characterize the probability that the target host is a compromised host; based on the corresponding compromise score of the target host, determine whether the target host is a compromised host.

2. The method according to claim 1, characterized in that The determining, based on the number of types of the first-occurring alarms, the number of occurrences of the first-occurring alarms, and the time information of the first-occurring alarms, a vulnerability score corresponding to the target host includes: Determining a first reference score corresponding to the target host based on the number of types and the number of occurrences, where the first reference score is positively correlated with the number of types and the number of occurrences; If the number of the first-appearance alarm time information is greater than a first value, obtaining the product of the first reference score and a first preset value as the trap score corresponding to the target host; If the number of the first alarm time information is less than or equal to a first value, the product of the first reference score and a second preset value is obtained as the loss score of the target host, and the first preset value is greater than the second preset value.

3. The method according to claim 1, characterized in that The determining, based on the number of types of the first-occurring alarms, the number of occurrences of the first-occurring alarms, and the time information of the first-occurring alarms, a vulnerability score corresponding to the target host includes: determining a second reference score based on the number of types, wherein the second reference score is positively correlated with the number of types; Determining a third reference score based on the number of the first-occurrence alarm time information, wherein the third reference score is positively correlated with the number of the first-occurrence alarm time information; determining a fourth reference score based on the number of occurrences, wherein the fourth reference score is positively correlated with the number of occurrences; Based on the first weight corresponding to the number of types, the second weight corresponding to the number of first-appearance alarm time information, and the third weight corresponding to the number of occurrences, the second reference score, the third reference score, and the fourth reference score are weightedly calculated to obtain the compromise score corresponding to the target host.

4. The method according to claim 1, wherein The determining whether the target host is a compromised host based on the compromise score corresponding to the target host includes: If the compromised score corresponding to the target host is greater than a preset score, the target host is determined to be a compromised host; or Get the corresponding compromise scores of other hosts; Sort the vulnerability scores corresponding to the target host and the vulnerability scores corresponding to the other hosts in descending order of the vulnerability scores to obtain a sorting result; If the compromise score corresponding to the target host is in the top N positions in the sorting result, the target host is determined to be a compromised host.

5. The method according to any one of claims 1 to 4, characterized in that The obtaining of the first alarm data of the target host in a historical time period and the second alarm data in a current time period includes: Obtain all historical behavior logs of the target host within the historical time period, and all current behavior logs of the target host within the current time period; Determining first alarm data within the historical time period based on a preset detection engine and all the historical behavior logs; Based on the preset detection engine and all the current behavior logs, second alarm data within the current time period is determined.

6. A device for detecting a compromised host, characterized in that: The device includes: a data acquisition module, a first occurrence determination module, a node determination module and a host judgment module, wherein: The data acquisition module is used to acquire the first alarm data of the target host in a historical time period and the second alarm data in a current time period; The first occurrence determination module is used to determine statistical information corresponding to a first occurrence alarm from the second alarm data, wherein the first occurrence alarm is alarm data in the second alarm data that has not appeared in the first alarm data; The node determination module is used to determine, from the second alarm data, an alarm time node that has not appeared in the first alarm data as the first-occurrence alarm time information; The host judgment module is used to determine whether the target host is a trapped host based on the statistical information and the first-appearance alarm time information, wherein the statistical information corresponding to the first-appearance alarm includes the number of types of the first-appearance alarm and the number of occurrences of the first-appearance alarm; The host judgment module is also used to determine the corresponding compromise score of the target host based on the number of types of the first-appearing alarm, the number of occurrences of the first-appearing alarm, and the time information of the first-appearing alarm. The compromise score is used to characterize the probability that the target host is a compromised host; based on the compromise score corresponding to the target host, determine whether the target host is a compromised host.

7. A computer device, characterized in that: The computer device comprises: one or more processors; Memory; One or more application programs, wherein the one or more application programs are stored in the memory and configured to be executed by the one or more processors, and the one or more programs are configured to execute the method according to any one of claims 1 to 5.

8. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores program code, which can be called by a processor to execute the method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Lost host detection method and device, electronic equipment and storage medium

    CN115118464A