Method, device and storage medium for updating security protection strategy

By considering the similarity calculation and vector distance of word frequency and total word count in security event information, and combining it with a machine learning model to update security protection strategies, the problem of untimely security protection strategy updates in existing technologies is solved, and more accurate and real-time security protection is achieved.

CN116108429BActive Publication Date: 2025-09-05CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111313158.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-08
Publication Date
2025-09-05
Estimated Expiration
2041-11-08

AI Technical Summary

Technical Problem

In the existing technology, the text similarity calculation method based on word frequency cannot accurately determine whether a new security incident has occurred when the text content is large, resulting in untimely updates of security protection strategies and inability to effectively handle security incidents, which in turn leads to network security risks.

Method used

By obtaining the word frequency and total word count of the first security event information, similarity is calculated with the word frequency and total word count of the historical security event information in the database, and the similarity is determined using the similarity weight value and vector distance. When the similarity is less than the preset value, the security protection strategy is updated, and the information is updated in combination with the machine learning model and encrypted transmission strategy.

Benefits of technology

It improves the accuracy and real-time nature of security incident information comparison, ensuring that security equipment can respond to new security incidents in a timely manner and achieve more real-time and reliable security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116108429B_ABST
    Figure CN116108429B_ABST
Patent Text Reader

Abstract

The present disclosure relates to a method, device and storage medium for updating security protection strategies, the method comprising: obtaining first security event information; determining a first word frequency and a first total word quantity of words contained in the first security event information; determining the similarity between the first security event information and the second security event information based on the first word frequency, the first total word quantity and the second word frequency and the second total word quantity of words contained in the second security event information in a database; the second security event information is: processed historical security event information; when the similarity is less than a preset value, determining that the first security event information is used to update the security protection strategy of a preset product. The present disclosure can accurately determine whether the first security event information is new security event information, and to a certain extent improves the real-time performance of updating the security protection strategy of the preset product, so that the security equipment can respond to attacks corresponding to new security events in a timely manner, achieving more real-time and reliable security protection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of network security technology, and in particular to a method, device, and storage medium for updating a security protection strategy. Background Art

[0002] With the promulgation and implementation of the Cybersecurity Law, cybersecurity is receiving increasing attention. Cybersecurity issues frequently occur, with viruses, worms, Trojans, and malware emerging one after another, jeopardizing the information security of online users. Handling security incidents is a key component of cybersecurity technology. Common security incidents include remote Trojans, malicious program attacks, malformed message attacks, distributed services, brute force attacks, and lateral movement. Most users purchase security products and rely on their built-in security strategies for protection.

[0003] To effectively handle security incidents (for example, modifying security product protection policies), it's important to be immediately informed of any new security incidents. This can be done by calculating the similarity between collected security incident information and historical security incident information based on word frequency text similarity. Word frequency-based text similarity constructs word frequency vectors based on word frequency and determines the similarity between texts by calculating the vector distance between word frequency vectors.

[0004] However, when the text contains a lot of content, simply calculating the similarity between texts by the distance between word frequency vectors constructed based on word frequency does not take into account the impact of the total content of the text on the similarity. This will result in a significant reduction in similarity even if only a small amount of content is modified between texts, resulting in low similarity accuracy between texts. Therefore, this similarity calculation method cannot accurately determine whether a new security incident has occurred, and thus will not be able to effectively handle security incidents. This will result in the user's network security being likely to be attacked and unprotected during this period. Summary of the Invention

[0005] Embodiments of the present disclosure provide a method, apparatus, and storage medium for updating a security protection policy.

[0006] The technical solution of the embodiment of the present disclosure is implemented as follows:

[0007] In a first aspect, a method for updating a security protection policy is provided, the method comprising:

[0008] Obtaining first security event information;

[0009] Determining a first word frequency and a first total word count of words included in the first security event information;

[0010] Determining the similarity between the first security event information and the second security event information based on the first word frequency, the first total word count, and a second word frequency and a second total word count of a word contained in second security event information in a database; wherein the second security event information is: processed historical security event information;

[0011] When the similarity is less than a preset value, it is determined that the first security event information is used to update a security protection policy of a preset product.

[0012] In the above technical solution, determining the similarity between the first security event information and the second security event information based on the first word frequency, the first total word count, and the second word frequency and the second total word count of the words contained in the second security event information in the database includes:

[0013] Determining a similarity weight value according to the first total word count and / or the second total word count;

[0014] Determining a vector distance between a first word frequency vector constructed according to the first word frequency and a second word frequency vector constructed according to the second word frequency;

[0015] The similarity between the first security event information and the second security event information is determined according to the similarity weight value and the vector distance.

[0016] In the above technical solution, the similarity weight value is less than or equal to 1, and the product value of the similarity weight value and the vector distance is negatively correlated with the similarity.

[0017] In the above technical solution, the method further includes:

[0018] determining whether a first digest value of the first security event information is the same as a second digest value of the second security event information;

[0019] Determining a first word frequency and a first total word count of words contained in the first security event information includes:

[0020] If the first summary value is different from the second summary value, a first word frequency and a first total word quantity of the words in the first security event information are determined.

[0021] In the above technical solution, the method further includes:

[0022] When the first digest value is the same as the second digest value, the first security event information is discarded.

[0023] In the above technical solution, when the similarity is less than a preset value, after determining that the first security event information is used to update the security protection policy of a preset product, the method further includes:

[0024] Generate policy update information according to the first security event information and the type of the preset product;

[0025] The policy update information is sent to the security device to which the preset product belongs, wherein the policy update information is used for the security device to which the preset product belongs to update the security protection policy.

[0026] In the above technical solution, the step of sending the policy update information to the security device to which the preset product belongs includes:

[0027] The encrypted policy update information is sent to the security device to which the preset product belongs.

[0028] In the above technical solution, the first security event information includes:

[0029] Security incident information obtained based on web search results;

[0030] and / or,

[0031] Security event information determined based on the log information of the preset product.

[0032] In the above technical solution, if the first security event information includes security event information obtained based on network search results, the method further includes:

[0033] The first security event information is sent to the security device to which the preset product belongs, wherein the first security event information is also used by the security device to associate and display the threat content with the first security event information when the threat content is detected according to the updated security protection policy.

[0034] In the above technical solution, if the first security event information includes security event information determined based on log information of the preset product, the method further includes:

[0035] Based on the log information of the preset product, obtaining first threat content detected by the security protection policy of the preset product in response to the first security event information;

[0036] Based on the log information of the preset product, obtaining second threat content detected for the first security event information through a preset machine learning model;

[0037] When the first threat content is inconsistent with the second threat content, policy update information of the security protection policy is generated and sent to the security device to which the preset product belongs.

[0038] In the above technical solution, the machine learning model is trained using log information containing threatening content and a security protection strategy for detecting the threatening content.

[0039] In the above technical solution, the policy update information includes at least one of the following information:

[0040] The rule identifier of the protection rule that needs to be activated by the security protection engine of the preset product;

[0041] The security protection engine of the preset product needs to start the rule content of the protection rules.

[0042] In a second aspect, a device for updating a security protection policy is provided, the device comprising:

[0043] An acquisition module, configured to acquire first security event information;

[0044] a first determining module, configured to determine a first word frequency and a first total word count of words contained in the first security event information;

[0045] a second determining module, configured to determine a similarity between the first security event information and the second security event information based on the first word frequency, the first total word count, and a second word frequency and a second total word count of a word contained in the second security event information in a database; wherein the second security event information is: processed historical security event information;

[0046] The third determining module is configured to determine, when the similarity is less than a preset value, that the first security event information is used to update a security protection policy of a preset product.

[0047] In a third aspect, a computer device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the steps of the method for updating the security protection strategy described in any one of the first aspects are implemented.

[0048] In a fourth aspect, a computer-readable storage medium is provided, on which a computer program is stored, characterized in that when the computer program is executed by a processor, the steps of the method for updating the security protection strategy described in any one of the first aspects are implemented.

[0049] The method, device and storage medium for updating security protection strategies provided by the embodiments of the present disclosure obtain first security event information; determine a first word frequency and a first total word quantity of words contained in the first security event information; and determine the similarity between the first security event information and the second security event information based on the first word frequency, the first total word quantity and the second word frequency and the second total word quantity of words contained in the second security event information in a database; wherein the second security event information is: processed historical security event information; and when the similarity is less than a preset value, determine that the first security event information is used to update the security protection strategy of a preset product.

[0050] Compared with the method of simply calculating the similarity by the distance between word frequency vectors constructed based on word frequency, the embodiment of the present disclosure is based on the word frequency and total word quantity of the words contained in the first security event information and the second security event information respectively. This can improve the comparison effect and accuracy between the security event information to a certain extent, and is conducive to accurately determining whether the first security event information is new security event information (that is, unprocessed security event information).

[0051] By determining that the first security event information is used to update the security protection strategy of the preset product when the similarity is less than a preset value, the security event information can be effectively handled by updating the security protection strategy of the preset product, so that the security product can respond to the attack corresponding to the new security event in a timely manner, achieving more real-time and reliable security protection. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] Figure 1 A flow chart of how to implement security protection for security products;

[0053] Figure 2 A schematic diagram of an application environment for a method for updating a security protection policy provided by an embodiment;

[0054] Figure 3 A flowchart of a method for updating a security protection strategy provided by an embodiment of the present disclosure;

[0055] Figure 4 Another flowchart of a method for updating a security protection policy provided by an embodiment of the present disclosure;

[0056] Figure 5 Another flowchart of a method for updating a security protection policy provided in an embodiment of the present disclosure;

[0057] Figure 6 Another flowchart of a method for updating a security protection policy provided in an embodiment of the present disclosure;

[0058] Figure 7Another flowchart of a method for updating a security protection policy provided in an embodiment of the present disclosure;

[0059] Figure 8 A specific flow chart of a method for updating a security protection strategy provided by an embodiment of the present disclosure;

[0060] Figure 9 A flowchart of the device registration process for the security product provided in an embodiment of the present disclosure;

[0061] Figure 10 A schematic diagram of the structure of an apparatus for updating a security protection strategy provided by an embodiment of the present disclosure;

[0062] Figure 11 A schematic diagram of the structure of a computer device provided in an embodiment of the present disclosure. DETAILED DESCRIPTION

[0063] In order to make the purpose, technical solutions and advantages of the present disclosure clearer, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only part of the embodiments of the present disclosure, not all of the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present disclosure. In the absence of conflict, the embodiments in the present disclosure and the features in the embodiments can be arbitrarily combined with each other. The steps shown in the flowcharts of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions. In addition, although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that here.

[0064] It is understandable that the description of each embodiment in this disclosure focuses on the differences between the embodiments, and the same or similar aspects thereof can be referenced with each other. For the sake of brevity, they will not be described one by one.

[0065] Figure 1 A flowchart of how to implement security protection for security products. Figure 1 As shown, there are two main ways for security products to implement security protection. One is to let the traffic pass through the security device directly to detect threats, and the other is to let the traffic be mirrored to the security device to detect threats. However, both use the preset security detection engine (also called "protection engine") to detect threats and take corresponding protection actions such as generating protection logs, blocking requests, redirecting requests, etc., so that users can perceive the protection effect.

[0066] The protection effect of security products is closely related to the configuration of the protection engine. It is difficult to achieve both accuracy and effectiveness by relying solely on the initial preset configuration of the security product. Overly strict protection configuration will lead to a large number of misjudgments in the detection process, affecting the normal use of back-end services, and excessive logs will make it impossible to further analyze the detection results; overly loose protection configuration will cause many threats to go undetected, posing a security risk to the network.

[0067] If a new security incident occurs, current security products may not be able to protect against it, requiring an upgrade to the security detection engine or special configuration to protect against the new threat. Because security product users lack the ability to gather security intelligence, they are unable to detect new security incidents. To promptly identify new security incidents, security vendors can collect security incident information and then use a text similarity metric based on word frequency to compare the collected information with historical security incident information. However, when texts contain a large amount of content, simply calculating similarity between texts based on the distance between word frequency vectors constructed based on word frequency does not consider the impact of the total text content on similarity. Consequently, even small changes to the texts significantly reduce similarity, resulting in low text similarity accuracy. Therefore, this similarity calculation method cannot accurately detect new security incidents, making it impossible to effectively address them. This makes it difficult to adjust security product protection configurations in a timely manner, potentially leaving users vulnerable to attacks and unprotected during this period.

[0068] Security products can detect threats and display threat details through pre-installed security detection engines. However, when the protection configuration is unreasonable, users can only see what threats are currently detected on the security product. After users learn some security intelligence, they do not know whether the attacks corresponding to this security intelligence can be protected or whether corresponding protection has been taken, making it difficult for users to perceive the effectiveness of security protection.

[0069] To this end, the present disclosure provides a method for updating a security protection strategy. The method can be applied to Figure 2 In the application environment shown. It can be understood that Figure 2 It is intended to more clearly illustrate the technical solutions of the embodiments of the present disclosure and does not constitute a limitation on the technical solutions provided by the embodiments of the present disclosure.

[0070] like Figure 2As shown, the security intelligence system may include a server and a database. The server and the security device to which the security product belongs may communicate in a wired or wireless manner, and the server and the terminal where the security manufacturer is located may communicate in a wired or wireless manner. The security device to which the security product belongs is a device on which a security product is deployed, wherein there may be multiple security devices deployed with the same type of security product. A security product may be a product with security protection functions implemented by hardware and / or software. According to the product type, security products may include but are not limited to: WAF (Web Application Firewall), IPS (Intrusion Prevention System), NGFW (Next generation firewall) and / or security guards, etc. The server may be implemented as a single server or a server cluster consisting of multiple servers.

[0071] The server can obtain the first security event information in various ways. For example, the first security event information includes: security event information searched from the Internet through a crawler tool, security event information obtained from the intelligence entered by the security vendor through network search on the terminal, and / or security event information obtained from the log information of the security product uploaded from the security device.

[0072] In summary, in the embodiments of the present disclosure, the first security event information may include: in addition to the security event information extracted from the log information on the corresponding security product, it may also be security event information obtained through other means.

[0073] Exemplarily, the security event information may include:

[0074] Security event information obtained from the security logs of other security products, or shared when other security products detect new security event information.

[0075] After obtaining the first security event information, the server determines the similarity between the first security event information and the second security event information by using the word frequency and total word count of the words contained in the first security event information and the second security event information respectively. When the similarity is less than a preset value, the server determines that the first security event information is used to update the security protection policy of the preset product. In this way, it can accurately determine whether the first security event information is new security event information.

[0076] When it is determined that the first security event information is new security event information, the first security event information is used to update the security protection strategy of the preset product, which can make up for the problem of insufficient security intelligence collection capabilities of security product users, and to a certain extent improve the real-time performance of updating the security protection strategy of the preset product, so that the security equipment can respond to the attacks corresponding to the new security event in a timely manner, and achieve more real-time and reliable security protection.

[0077] Figure 3 A flowchart of a method for updating a security protection strategy provided by an embodiment of the present disclosure. Figure 2 The server shown in the figure is used as an example to execute the method. Figure 3 As shown, the method includes:

[0078] S11, obtaining first security event information.

[0079] The first security event information may include security event information obtained based on network search results.

[0080] Web search results can be the result of security vendors or security analysts searching the internet for security incident information, or they can be the result of crawling security incident information from websites corresponding to specified URLs using web crawlers. The websites corresponding to specified URLs are websites that publish security intelligence, such as https: / / apt.360.cn / , https: / / nti.nsfocus.com / threatNotice, and https: / / ti.qianxin.com / .

[0081] The first security event information may include security event information determined based on log information of a preset product. Here, the preset product refers to a security product deployed on a security device, and the log information of the preset product may be obtained from access logs and / or security logs uploaded by the preset product through the security device to which it belongs.

[0082] S12: Determine a first word frequency and a first total word quantity of words contained in the first security event information.

[0083] Specifically, the process may include:

[0084] Performing word segmentation and stop word filtering on the text content of the first security event information to obtain words contained in the first security event information, wherein stop words refer to words that need to be removed, such as punctuation marks, modal particles, personal names, etc.;

[0085] The number of times each word appears in the first security event information is counted to obtain a first word frequency of each word, and the number of all words in the first security event information is counted to obtain a first total word count. The first total word count does not include the number of stop words.

[0086] S13, determining the similarity between the first security event information and the second security event information based on the first word frequency, the first total word count, and the second word frequency and the second total word count of the words contained in the second security event information in the database; wherein the second security event information is: processed historical security event information.

[0087] The database stores the second word frequency and the second total word quantity of the words included in the second security event information.

[0088] Each piece of security event information can be understood as a point in a multidimensional space, and the similarity between security event information is determined based on the distance between points.

[0089] Considering that only vector distance is used to calculate the similarity between security event information (for example, similarity can generally be calculated by 1 ÷ (1 + Euclidean distance)), if both security event information contain a lot of content, a small difference in content will significantly reduce the similarity. In this embodiment, the similarity between the first security event information and the second security event information is determined by the word frequency and total word count of the words contained in the first security event information and the second security event information, respectively. This can improve the comparison effect and accuracy between the security event information to a certain extent, and is conducive to accurately determining whether the first security event information is new security event information.

[0090] S14: When the similarity is less than a preset value, determine that the first security event information is used to update a security protection policy of a preset product.

[0091] The preset value can be set according to actual needs. For example, the preset value is set to 70%, 75%, or 80%. For example, when the similarity between the first security event information and the second security event information is less than 80%, it can be determined that the first security event information is used to update the security protection policy of the preset product.

[0092] In some embodiments, the method may further include:

[0093] The first security event information is added to a database storing processed historical security event information.

[0094] Among them, the first security event information with a similarity less than a preset value is added to the database storing processed historical security event information after completing the security protection strategy of the preset product.

[0095] For the first security event information whose similarity is greater than or equal to the preset value and less than 1, it is directly added to the database storing the processed historical security event information without updating the security protection policy of the preset product based on the first security event information.

[0096] In some embodiments, the method may further include:

[0097] When the similarity between the first security event information and the second security event is less than a preset value, the first word frequency and the first total word quantity of the words contained in the first security event information are associated with the first security event information and saved in the database to improve the efficiency of the subsequent similarity calculation between security event information.

[0098] In the above-mentioned method for updating security protection strategies, since the similarity between the first security event information and the second security event information in the database is based on the word frequency and total word volume of the words contained in the first security event information and the second security event information respectively, this can improve the comparison effect and accuracy between the security event information to a certain extent, and is conducive to accurately determining whether the first security event information is new security event information.

[0099] By determining that the first security event information is used to update the security protection strategy of the preset product when the similarity is less than the preset value, this can make up for the problem of insufficient security intelligence collection capabilities of security product users, and to a certain extent improve the real-time performance of updating the security protection strategy of the preset product, so that security equipment can respond to attacks corresponding to new security events in a timely manner, achieving more real-time and reliable security protection.

[0100] In one embodiment, Figure 4 As shown, in the above step S11, determining the similarity between the first security event information and the second security event information based on the first word frequency, the first total word count, and the second word frequency and the second total word count of the words included in the second security event information in the database may include:

[0101] S111: Determine a similarity weight value according to the first total word count and / or the second total word count.

[0102] Specifically, the reciprocal of the first total word count or the reciprocal of the second total word count can be determined as the similarity weight value, or the reciprocal of the sum of the first total word count and the second total word count can be determined as the similarity weight value. This embodiment does not specifically limit the process of determining the similarity weight value.

[0103] S112: Determine a vector distance between a first word frequency vector constructed according to the first word frequency and a second word frequency vector constructed according to the second word frequency.

[0104] Here, the first term frequency vector and the second term frequency vector are two vectors with the same number of dimensions.

[0105] Specifically, a first word frequency vector is constructed based on the word vector model and the first word frequency of the word included in the first security event information, and a second word frequency vector is constructed based on the word vector model and the second word frequency of the word included in the second security event information; and the vector distance between the first word frequency vector and the second word frequency vector is determined.

[0106] The above-mentioned word vector model can be constructed based on the words included in the first security event information and the words included in the second security event information.

[0107] The word vector model construction process may include:

[0108] Take the union of the words contained in the first security event information and the words contained in the second security event information to obtain the union result, and deduplicate the words contained in the union result to obtain a deduplicated word set. Encode each word in the word set and map it to each dimension of the vector model to construct a word vector model.

[0109] The above vector distance can be Euclidean distance (ED), which is used to represent the true distance between two points in n-dimensional space. For example, if A(x1, y1) and B(x2, y2) are any two points in a two-dimensional metric space, then their Euclidean distance is: d(A, B) = ((x1-x2) 2 +(y1-y2) 2 )1 / 2. It is understandable that the vector distance may also be other distances used for similarity calculation, such as Manhattan distance, Chebyshev distance, etc., which is not specifically limited in this embodiment.

[0110] Taking the vector distance as Euclidean distance as an example, for information A "I want to drink water" and information B "He wants to drink water", the word frequency of the words contained in information A is: [I: 1, want: 1, drink: 1, water: 1], and the words contained in information B are: [he: 1, want: 1, drink: 1, water: 1]. All the words that appear in information A and information B are: [I, he, want, drink, water]. The constructed vector model dimension is 5, then the word frequency vector of information A is [1, 0, 1, 1, 1], and the word frequency vector of information B is [0, 1, 1, 1, 1]. Then the Euclidean distance between the word frequency vector of information A and the word frequency vector of information B can be calculated as:

[0111] S113: Determine the similarity between the first security event information and the second security event information according to the similarity weight value and the vector distance.

[0112] The similarity weight value is less than or equal to 1, and the product of the similarity weight value and the vector distance is negatively correlated with the similarity.

[0113] Specifically, the similarity between the first security event information and the second security event information may be determined according to a preset similarity calculation formula based on a similarity weight value and a vector distance.

[0114] For example, the preset similarity calculation formula may be as follows:

[0115] similarity=1-w*d

[0116] Wherein, similarity represents the similarity between the first security event information and the second security event information, w represents the similarity weight value, and d represents the vector distance between the first word frequency vector of the first security event information and the second word frequency vector of the second security event information.

[0117] In one embodiment, the method may further include:

[0118] It is determined whether a first digest value of the first security event information is the same as a second digest value of the second security event information.

[0119] The second security event information is processed security event information, and the second summary value of the second security event information can be pre-stored in the database.

[0120] Here, the first digest value and the second digest value can be calculated using a message digest algorithm, such as MD5 (Message-Digest Algorithm 5). This embodiment does not limit the specific message digest algorithm.

[0121] In the above step S12, determining the first word frequency and the first total word quantity of the words contained in the first security event information may include:

[0122] If the first summary value is different from the second summary value, a first word frequency and a first total word quantity of the words included in the first security event information are determined.

[0123] In this embodiment, when the first summary value and the second summary value are different, and the current database does not contain the second security event information that is identical to the first security event information, the first word frequency and the first total word quantity of the words contained in the first security event information are determined so that the similarity between the first security event information and the second security event information can be compared. This can reduce unnecessary similarity calculations and thus reduce the computing resource consumption of the server.

[0124] In one embodiment, the method may further include:

[0125] When the first digest value is the same as the second digest value, the first security event information is discarded.

[0126] In this embodiment, when the first summary value is the same as the second summary value, the first security event information is the same as the second security event information. Since the second security event information is processed historical event information, the first security event information can be discarded, and there is no need to perform the step of determining the similarity between the first security event information and the second security event information. In this way, the deduplication efficiency of security event information can be effectively improved.

[0127] In one embodiment, Figure 5 As shown, after the above step S14 is executed, the method may further include:

[0128] S21: Generate policy update information according to the first security event information and the type of the preset product.

[0129] Different types of security products use different security protection engines, and the content of security protection policies is also different. Security protection policies may include but are not limited to: the rule base version number of the security protection engine, the rule ID of the protection rule, and the rule content of the protection rule. Accordingly, the rule organization method of the security protection policy will also be different. For example, if a WAF product uses the modsecurity security protection engine, the rules of the security protection policy of this WAF product can be expressed in a form similar to this: SecRule REQUEST_HEADERS:Content-Type "(?:application(?: / soap\+| / )|text / )xml" "id:'2000 02',phase:2,t:none,log,deny,status:400,msg:'Failed toparse request body.',logdata:'%{reqbody_error_msg}',severity:2".

[0130] If an ADC product uses the Naxsi security protection engine, the rules of the security protection policy of this ADC product can be expressed in a format similar to this: MainRule "str: / *" "msg:mysql comment( / *)" "mz:BODY|URL|ARGS|$HEADERS_VAR:Cookie" "s:$SQL:8" id:1003.

[0131] If a NIPS product uses the Snort security protection engine, the rules of the security protection policy of this NIPS product can be expressed in a format similar to this: alert tcp $HOME_NET any->$EXTERNAL_NET any(msg:"COMMUNITY BOT Agobot / PhatBot bot.about command";flow:established;flowbits:isset,community_is_proto_irc;content:"bot.about";classtype:trojan-activity;sid:100000242;rev:2).

[0132] Specifically, a protection plan for the first security event information is obtained, and according to the protection plan and the type of the protection engine of the preset product, policy update information of the security protection policy of the preset product is obtained; wherein, the protection plan for the first security event information can be obtained by security analysts analyzing the first security event information, or can be generated by various neural network models based on the first security event information, but the embodiments of the present disclosure are not limited to this.

[0133] S22: Send the policy update information to the security device to which the preset product belongs, wherein the policy update information is used for the security device to which the preset product belongs to update the security protection policy.

[0134] Specifically, the server can actively send policy update information of the security protection policy to the security product based on the device registration information of the security product; or, the server can send policy update information to the security device based on the update request for the security product sent by the security device, wherein the security device can periodically send update requests for the security protection policy of the security product to the server.

[0135] In this embodiment, by sending policy update information to the security device associated with the pre-set product, the security device can adjust its protection configuration based on the policy update, eliminating the need for the security product user to analyze detection logs and modify the protection configuration. This achieves a balanced approach to security protection accuracy and effectiveness. Furthermore, it also addresses the limited security intelligence gathering capabilities of security product users, improving the real-time nature of security device protection configuration adjustments. This allows the security device to promptly respond to attacks corresponding to the latest security incidents, achieving more timely and reliable security protection.

[0136] In one embodiment, the policy update information includes at least one of the following information:

[0137] The rule identifier of the protection rule that needs to be activated by the security protection engine of the preset product;

[0138] The security protection engine of the preset product needs to start the protection rules.

[0139] Here, protection rules are stored in a pre-set rule base and are uniquely identified by rule identifiers. A newly generated security incident may require more than one protection rule to detect the threat. If the rule base already contains a protection rule that can detect the threat, the rule identifier of the protection rule will be included in the policy update information. If additional protection rules are needed to address the threat, the additional protection rule content will be included in the policy update information.

[0140] In one embodiment, the above step S22 of sending the policy update information to the security device to which the preset product belongs may include:

[0141] Send the encrypted policy update information to the security device to which the preset product belongs.

[0142] Specifically, the policy update information is encoded and encrypted to obtain the encrypted policy update information, the encrypted policy update information is carried in an HTTPS (Hyper Text Transfer Protocol over Secure Socket Layer) request, and the HTTPS request is sent to the security device to which the security product belongs.

[0143] The above encoding and encryption process includes: first performing MD5 message digest calculation on the policy update information to obtain an MD5 value, and then performing base64 encoding on the policy update information and the MD5 value of the policy update information.

[0144] In this embodiment, by sending the encrypted policy update information to the security device, the possibility of data being tampered with during transmission can be reduced, thereby ensuring data security.

[0145] In one embodiment, Figure 6 As shown, based on Figure 5 If the first security event information includes security event information obtained based on network search results, the method may further include:

[0146] S23, sending the first security event information to the security device to which the preset product belongs, wherein the first security event information is also used by the security device to associate and display the threat content with the first security event information when the threat content is detected according to the updated security protection policy.

[0147] Specifically, the first security event information and the policy update information may be included in the security intelligence and sent to the security device to which the security product belongs.

[0148] In this embodiment, after obtaining the first security event information and policy update information, the security product can perform threat detection through the protection rules adjusted according to the policy update information, and search the security log obtained by detection to see whether there is threat content corresponding to the first security event information. If so, the threat content is associated with the first security event information and displayed to better reflect the protection effect and device security status.

[0149] In one embodiment, Figure 7 As shown, if the first security event information includes security event information determined based on log information of a preset product, the method may further include:

[0150] S31 : Based on the log information of the preset product, obtain the first threat content detected by the security protection policy of the preset product in response to the first security event information.

[0151] Here, the log information of the security product can be obtained based on the security log and access log of the security product.

[0152] Security logs are logs of threats detected by security products. They contain information such as security protection policies, detected threats, and associated security events. Security protection policy information includes the product's protection engine version and rule ID.

[0153] Access logs include data flows through security products and may include information such as whether a threat is detected, current protection actions, and device identification (device_id).

[0154] Specifically, the threat content detected by the security protection policy for the first security event information is extracted from the security log of the security product.

[0155] S32: Based on the log information of the preset product, obtain the second threat content detected for the first security event information through the preset machine learning model.

[0156] Among them, the machine learning model is trained using log information containing threat content and security protection strategies for detecting threat content.

[0157] Specifically, a data stream passing through the security product is extracted from the access log of the security product, and the data stream is detected according to the first security event information through a machine learning model to obtain the second threat content.

[0158] It should be noted that the embodiment of the present disclosure does not specifically limit the execution order of step S31 and step S32, and it is preferred to execute step S31 and step S32 simultaneously.

[0159] S33: When the first threat content is inconsistent with the second threat content, policy update information of the security protection policy is generated and sent to the security device to which the preset product belongs.

[0160] Specifically, for the first security event information, the first threat content detected by the security product according to the security protection strategy is compared with the second threat content detected by the machine learning model.

[0161] If there is any inconsistency, it is determined that the security protection policy configured for the security product needs to be adjusted, policy update information is generated, and the policy update information is sent to the security device to which the security product belongs. The security device adjusts the security protection policy of the security product according to the policy update information and loads the adjusted protection configuration to achieve better protection effect.

[0162] The present disclosure will be further described in detail below with reference to specific embodiments.

[0163] Figure 8 A specific flow chart of a method for updating a security protection policy provided by an embodiment of the present disclosure. In this method, the first security event information is obtained by a server in a security intelligence system based on a network search result. The method may include:

[0164] 1. The server obtains the page containing the first security incident crawled by the web crawler;

[0165] The web crawler crawls the website where the security incident occurred and obtains the page where the first security incident occurred;

[0166] 2. Calculate the MD5 value of the crawled page where the first security event is located;

[0167] 3. Compare the MD5 value calculated in step 2 with the MD5 value stored in the first database. If the comparison result is different, execute step 4. If the comparison result is the same, do not process the crawled first security event information.

[0168] 4. Calculate the similarity between the original page where the second security event is located and the crawled page where the first security event is located. If the similarity is less than or equal to a preset value (e.g., 80%), execute step 5. If the similarity is greater than the preset value, do not process the crawled first security event information.

[0169] The similarity between the crawled page and the original page may be the text similarity between the crawled page and the original page. The calculation process is based on steps S12 to S13 in the above embodiment and will not be repeated here.

[0170] 5. Perform at least one of the following steps. After step 5, perform step 7.

[0171] Save the crawled page where the first security event is located to disk;

[0172] Storing information such as the MD5 value of the crawled page and the location of the disk where the crawled page is saved in the first database;

[0173] Generate an alarm log; the alarm log is used to indicate that the first security event is a new security event;

[0174] Send warning information to security analysts through email or other means;

[0175] 6. Obtain security events retrieved from the Internet by security analysts using manual search. After step 6, proceed to step 7.

[0176] 7. Identify new security incident information;

[0177] 8. Analyze the security incident information obtained in step 7 and obtain a protection plan;

[0178] Specifically, a protection plan is obtained based on the analysis results of the security incident information by the security analyst.

[0179] 9. Analyze the currently released security product protection engines based on the protection plan to obtain protection strategy updates for each product;

[0180] Protection strategy update information of each security product that responds to the first security event information may be determined based on the protection solution and the different types of protection engines of each security product.

[0181] 10. Store the security event name, security product name, protection strategy update information, etc. as a record in the second database.

[0182] In this embodiment, the server can store the security event name, security product name and protection policy update information as a record in the database, and automatically send the security event information and protection policy update information to the corresponding security product based on the security product name; or, the server can query the security protection policy update information and security event information corresponding to the security product name from the database based on the update request regularly issued by the security product, and return it to the security product.

[0183] In addition to obtaining security event information based on online search results, the first security event information can also be obtained based on security product log information. Through the server-linked security product in the security intelligence system, the security product sends the detected log to the server for analysis.

[0184] The linkage between the server and security products includes: device registration of security products, uploading of log information by security products to the server, sending of security event information and security protection policies by the server to security products, and regular updating of the token number token_ID of security products.

[0185] During device registration for a security product, the device registration request sent by the security product to the server must include device registration information, including the device_id and product type (register_type). The device_id uniquely identifies the security device to which the security product belongs and varies between different security devices. The product type (register_type) specifies the type of security product being registered and is used to distinguish between different products, such as WAF, IPS, and NGFW.

[0186] Furthermore, for security purposes, the device registration information of the security product may be encrypted and sent to a server, which then decrypts the encrypted device registration information to obtain the device registration information.

[0187] like Figure 9 As shown, the device registration process for security products may include:

[0188] 1. The security product carries the device ID and product type register_type in the URL (Uniform Resource Locator) of the device registration request. For example, the URL is:

[0189] https: / / ti.myweb.com.cn / regist? device_id=001_dev_id®ist_type=WAF

[0190] 2. Calculate the MD5 message digest of Device_id and register_type to obtain the MD5 value, and use the MD5 value as the registration verification value (register_check) to transform the URL. For example, if the MD5 value is 7ee3fbe008b8257cb7002267249106d5, the above URL will be transformed to:

[0191] https: / / ti.myweb.com.cn / regist? device_id=001_dev_id®ist_type=WAF®ister_check=7ee3fbe008b8257cb7002267249106d5;

[0192] 3. Perform base64 encoding on all request parameters in the transformed URL to obtain the encrypted device registration information. For example, performing base64 encoding on all request parameters in the above URL yields the following result:

[0193] https: / / ti.myweb.com.cn / regist?registerData=ZGV2aWNlX2lkPTAwMV9kZXZfaWQmcmVnaXN0X3R5cGU9V0FGJnJlZ2lzdGVyX2NoZWNrPTdlZTNmYmUwMDhiODI1N2NiNzAwMjI2NzI0OTEwNmQ1.

[0194] 4. Send the encrypted device registration information to the server via HTTPS for device registration.

[0195] 5. The server performs Base64 decoding on the encrypted device registration information received to obtain the device ID, product type register_type, and registration verification value, and calculates whether the MD5 value of the device ID and product type register_type is consistent with the registration verification value.

[0196] 6. When the calculated MD5 value is consistent with the registration verification value, the device Device_id and product type register_type are stored in the database, and a token number token_ID is returned to the security product.

[0197] The server will regularly update the token number token_ID to ensure security. At the same time, security products need to regularly obtain token_id from the server.

[0198] After the security product device is registered with the server, the security product can request security event information and security protection policies issued by the server, or send log information to the server. The sent parameters need to carry the token_id returned by the successful registration for identity authentication. The process of the security product sending information to the server is similar to the registration process, requiring the security device to encrypt and the server to perform corresponding decryption.

[0199] The server processes the first security event information obtained, determines that the first security event information is used to update the security protection policy of the preset product, and can generate policy update information of the security product based on the first security event information and the type of security product and send it to the security device to which the security product belongs, so that the security device to which the security product belongs can update the security protection policy.

[0200] Furthermore, after obtaining security protection policy update information using the first security event information and the type of security product, the server may generate security intelligence based on the first security event information and the corresponding policy update information and send it to the security device to which the security product belongs.

[0201] For example, the main contents of security intelligence may be shown in Table 1 below:

[0202] Table 1: Security intelligence content

[0203]

[0204]

[0205]

[0206] After obtaining security intelligence, security products can adjust the security protection policies configured in the security protection engine based on the protection policy update information contained in the security intelligence to achieve better defense effectiveness. Based on the contents of rule_id, sig_version, and fix_rule, the security product will make corresponding configuration updates. For example, first, based on sig_version, the security product will determine if the currently configured security protection policy does not meet the rule version, and if so, it will need to upgrade the rule base. Then, based on rule_id, the security product will determine if the currently configured security protection policy does not have the corresponding rule enabled, and if so, it will need to enable the corresponding protection rule. Finally, it will determine if fix_rule is empty. If it is, it will need to add the specified rule content and fill in the data according to the contents of fix_rule.

[0207] After the security product obtains the first security event information and the corresponding policy update information from the security intelligence, it can perform threat detection through the protection rules adjusted according to the policy update information, and search the security log obtained by detection to see whether there is threat content corresponding to the first security event information. If so, the threat content will be associated with the first security event information and displayed to better reflect the protection effect and equipment security status.

[0208] In addition to obtaining security intelligence from the security intelligence system, security products also upload logs to the server in the security intelligence system. The uploaded logs include access logs and security logs.

[0209] After receiving security logs, the server removes false positives, retaining only reliable security logs. After extracting information from the security logs, the server uses this information, along with security intelligence from the security intelligence system, as training samples for a machine learning model used to detect malicious data flows. This training sample is used to train the machine learning model. The log information includes information such as the security product's protection engine version, rule ID, detected threats, and associated security events.

[0210] Access logs include the data streams passing through security products, including fields indicating whether a threat has been detected, the current protection action, the device_id, and information used to analyze whether the current security product configuration needs to be updated. After serializing the access logs, a machine learning model is used to determine the threat situation and compare the model's results with those of the security product. Any discrepancies require adjustments to the security product's protection configuration. Based on the judgment results, the server in the security intelligence system generates policy update information for adjusting enabled rules and rule parameters. This information is then sent to the security product, which receives the policy update and loads the new configuration for improved protection.

[0211] In summary, the technical solutions provided by the embodiments of the present disclosure have at least the following beneficial effects:

[0212] 1. Use crawler tools to crawl key websites to collect security incident information, and filter the crawled information through the improved Euclidean distance similarity algorithm, making the collection of security incident information more convenient, reducing manpower investment to a certain extent, and making the acquisition of security incident information more real-time.

[0213] 2. The security product is linked to the server in the security intelligence system. During the linkage process, data interaction is performed by first encoding the data with MD5 and then with Base64, reducing the possibility of data tampering during transmission and ensuring the validity of the data. In addition, a regularly updated token_id can further improve data security.

[0214] 3. The server in the security intelligence system sends the latest security event information and corresponding policy update information to the security product. The security product automatically adjusts the protection configuration based on the policy update information and uploads the access log and the security log containing the threat content to the server. The server improves the machine learning model through the uploaded security log containing the threat content, and judges the protection effect through the access log to further improve the protection configuration.

[0215] 4. Security products obtain security intelligence, deduce related threat information through security intelligence, and better demonstrate protection effects.

[0216] Figure 10 A schematic diagram of a structure of a device for updating a security protection strategy provided by an embodiment of the present disclosure; Figure 10 As shown, the device includes:

[0217] An acquisition module 101 is configured to acquire first security event information;

[0218] A first determining module 102 is configured to determine a first word frequency and a first total word count of a word included in the first security event information;

[0219] A second determining module 103 is configured to determine a similarity between the first security event information and the second security event information based on the first word frequency, the first total word count, and a second word frequency and a second total word count of a word contained in the second security event information in a database; wherein the second security event information is: processed historical security event information;

[0220] The third determining module 104 is configured to determine, when the similarity is less than a preset value, whether the first security event information is used to update a security protection policy of a preset product.

[0221] In one embodiment, the second determining module 103 is specifically configured to:

[0222] Determining a similarity weight value according to the first total word count and / or the second total word count;

[0223] Determining a vector distance between a first word frequency vector constructed based on the first word frequency and a second word frequency vector constructed based on the second word frequency;

[0224] The similarity between the first security event information and the second security event information is determined according to the similarity weight value and the vector distance.

[0225] In one embodiment, the similarity weight value is less than or equal to 1, and the product of the similarity weight value and the vector distance is negatively correlated with the similarity.

[0226] In one embodiment, the first determining module 102 is specifically configured to:

[0227] determining whether a first digest value of the first security event information is the same as a second digest value of the second security event information;

[0228] If the first summary value is different from the second summary value, a first word frequency and a first total word quantity of the words included in the first security event information are determined.

[0229] In one embodiment, the first determining module 102 is further configured to:

[0230] When the first digest value is the same as the second digest value, the first security event information is discarded.

[0231] In one embodiment, the apparatus further comprises:

[0232] A generation module, configured to generate policy update information based on the first security event information and the type of the preset product;

[0233] The first sending module is used to send the policy update information to the security device to which the preset product belongs, wherein the policy update information is used for the security device to which the preset product belongs to update the security protection policy.

[0234] In one embodiment, the sending module is specifically configured to:

[0235] Send the encrypted policy update information to the security device to which the preset product belongs.

[0236] In one embodiment, the first security event information includes:

[0237] Security incident information obtained based on web search results;

[0238] and / or,

[0239] Security event information determined based on log information of preset products.

[0240] In one embodiment, if the first security event information includes security event information obtained based on a network search result, the apparatus further includes:

[0241] The second sending module is used to send the first security event information to the security device to which the preset product belongs, wherein the first security event information is also used by the security device to associate and display the threat content with the first security event information when the threat content is detected according to the updated security protection strategy.

[0242] In one embodiment, if the first security event information includes security event information determined based on log information of a preset product, the apparatus further includes a detection module, a generation module, and a third sending module:

[0243] The acquisition module is further configured to acquire, based on the log information of the preset product, the first threat content detected by the security protection policy of the preset product in response to the first security event information;

[0244] A detection module, configured to obtain, based on log information of a preset product, second threat content detected for the first security event information using a preset machine learning model;

[0245] a generating module, configured to generate policy update information of the security protection policy when the first threat content is inconsistent with the second threat content;

[0246] The third sending module is used to send policy update information of the security protection policy to the security device to which the preset product belongs.

[0247] In one embodiment, the machine learning model is trained using log information containing threatening content and security protection strategies for detecting threatening content.

[0248] In one embodiment, the policy update information includes at least one of the following information:

[0249] The rule identifier of the protection rule that needs to be activated by the security protection engine of the preset product;

[0250] The security protection engine of the preset product needs to start the protection rules.

[0251] It should be noted that the device for updating security protection strategies provided in the above embodiments only uses the division of the above-mentioned program modules as an example when implementing the method for updating security protection strategies. In actual applications, the above-mentioned processing can be assigned to different program modules as needed, that is, the internal structure of the device can be divided into different program modules to complete all or part of the processing described above. In addition, the device provided in the above embodiments and the embodiments of the corresponding methods are based on the same concept. The specific implementation process is detailed in the method embodiments and will not be repeated here.

[0252] Figure 11 A schematic diagram of the structure of a computer device provided in an embodiment of the present disclosure; Figure 11 As shown, the computer device 110 includes: a processor 1101 and a memory 1102 for storing a computer program that can be run on the processor; wherein, when the processor 1101 is used to run the computer program, it performs the following steps:

[0253] Obtaining first security event information;

[0254] Determine a first word frequency and a first total word count of a word included in the first security event information;

[0255] Determining the similarity between the first security event information and the second security event information based on the first word frequency, the first total word count, and the second word frequency and the second total word count of the words contained in the second security event information in the database; wherein the second security event information is: processed historical security event information;

[0256] When the similarity is less than a preset value, it is determined that the first security event information is used to update the security protection policy of the preset product.

[0257] When the processor runs the computer program, the corresponding processes in the various methods of the embodiments of the present invention are implemented, which will not be described here for the sake of brevity.

[0258] In actual application, the computer device 110 may further include: at least one network interface 1103. The various components in the computer device 110 are coupled together via a bus system 1104. It is understood that the bus system 1104 is used to achieve connection and communication between these components. In addition to the data bus, the bus system 1104 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, Figure 11 In the figure, various buses are labeled as bus system 1104. There may be at least one processor 1101. The network interface 1103 is used for wired or wireless communication between the computer device 110 and other devices.

[0259] The memory 1102 in the embodiment of the present disclosure is used to store various types of data to support the operation of the computer device 110 .

[0260] The methods disclosed in the above embodiments of the present disclosure can be applied to or implemented by processor 1101. Processor 1101 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by hardware integrated logic circuits in processor 1101 or by software instructions. The above processor 1101 may be a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Processor 1101 can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present disclosure. A general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in conjunction with the embodiments of the present disclosure can be directly implemented as being executed by a hardware decoding processor, or can be executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium located in memory 1102. Processor 1101 reads the information in memory 1102 and, in conjunction with its hardware, completes the steps of the above method.

[0261] In an exemplary embodiment, the computer device 110 may be implemented by one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontrollers (MCUs), microprocessors, or other electronic components to execute the aforementioned method.

[0262] The present disclosure also provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the computer program executes:

[0263] Obtaining first security event information;

[0264] Determine a first word frequency and a first total word count of a word included in the first security event information;

[0265] Determining the similarity between the first security event information and the second security event information based on the first word frequency, the first total word count, and the second word frequency and the second total word count of the words contained in the second security event information in the database; wherein the second security event information is: processed historical security event information;

[0266] When the similarity is less than a preset value, it is determined that the first security event information is used to update the security protection policy of the preset product.

[0267] When the computer program is executed by the processor, the corresponding processes in the various methods of the embodiments of the present invention are implemented, and for the sake of brevity, they are not described here in detail.

[0268] In the several embodiments provided in the present disclosure, it should be understood that the disclosed apparatus and method can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of units is merely a logical function division. In actual implementation, there may be other division methods, such as: multiple units or components can be combined, or can be integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the components shown or discussed can be through some interfaces, and the indirect coupling or communication connection of devices or units can be electrical, mechanical or other forms.

[0269] The units described above as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units; some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0270] In addition, all functional units in the embodiments of the present disclosure may be integrated into one processing unit, or each unit may be separately used as a unit, or two or more units may be integrated into one unit; the above-mentioned integrated units may be implemented in the form of hardware or in the form of hardware plus software functional units.

[0271] Those skilled in the art will appreciate that all or part of the steps of the above-mentioned method embodiments may be implemented by hardware associated with program instructions, and the aforementioned program may be stored in a computer-readable storage medium. When the program is executed, the program executes the steps of the above-mentioned method embodiments. The aforementioned storage medium includes various media that can store program codes, such as mobile storage devices, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical disks.

[0272] Alternatively, if the above-mentioned integrated unit of the present disclosure is implemented in the form of a software function module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiment of the present disclosure is essentially or the part that contributes to the prior art can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the methods of each embodiment of the present disclosure. The aforementioned storage medium includes: various media that can store program codes, such as mobile storage devices, ROM, RAM, magnetic disks or optical disks.

[0273] It should be noted that: "first", "second", etc. are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.

[0274] In addition, the technical solutions described in the embodiments of the present disclosure can be arbitrarily combined without conflict.

[0275] The above are only specific embodiments of the present disclosure, but the scope of protection of the present disclosure is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this disclosure should be included in the scope of protection of the present disclosure. Therefore, the scope of protection of the present disclosure should be based on the scope of protection of the claims.

Claims

1. A method for updating a security protection strategy, characterized in that: The method comprises: Obtaining first security event information; Determining a first word frequency and a first total word count of words included in the first security event information; Determine a similarity weight value based on the first total word count and / or the second total word count of the second security event information in the database; determine a vector distance between a first word frequency vector constructed based on the first word frequency and a second word frequency vector constructed based on the second word frequency of the second security event information; determine the similarity between the first security event information and the second security event information based on the similarity weight value and the vector distance; wherein, the second security event information is: processed historical security event information; the similarity weight value is less than or equal to 1, and the product value of the similarity weight value and the vector distance is negatively correlated with the similarity; When the similarity is less than a preset value, it is determined that the first security event information is used to update a security protection policy of a preset product.

2. The method according to claim 1, characterized in that The method further comprises: determining whether a first digest value of the first security event information is the same as a second digest value of the second security event information; Determining a first word frequency and a first total word count of words contained in the first security event information includes: If the first summary value is different from the second summary value, a first word frequency and a first total word quantity of the words in the first security event information are determined.

3. The method according to claim 2, characterized in that The method further comprises: When the first digest value is the same as the second digest value, the first security event information is discarded.

4. The method according to claim 1, wherein When the similarity is less than a preset value, after determining that the first security event information is used to update the security protection policy of a preset product, the method further includes: Generate policy update information according to the first security event information and the type of the preset product; The policy update information is sent to the security device to which the preset product belongs, wherein the policy update information is used for the security device to which the preset product belongs to update the security protection policy.

5. The method according to claim 4, characterized in that The sending of the policy update information to the security device to which the preset product belongs includes: The encrypted policy update information is sent to the security device to which the preset product belongs.

6. The method according to claim 1, characterized in that The first security event information includes: Security incident information obtained based on web search results; and / or, Security event information determined based on the log information of the preset product.

7. The method according to claim 4, characterized in that If the first security event information includes security event information obtained based on network search results, the method further includes: The first security event information is sent to the security device to which the preset product belongs, wherein the first security event information is also used by the security device to associate and display the threat content with the first security event information when the threat content is detected according to the updated security protection policy.

8. The method according to claim 1, characterized in that If the first security event information includes security event information determined based on log information of the preset product, the method further includes: Based on the log information of the preset product, obtaining first threat content detected by the security protection policy of the preset product in response to the first security event information; Based on the log information of the preset product, obtaining second threat content detected for the first security event information through a preset machine learning model; When the first threat content is inconsistent with the second threat content, policy update information of the security protection policy is generated and sent to the security device to which the preset product belongs.

9. The method according to claim 8, characterized in that The machine learning model is trained using log information containing threatening content and a security protection strategy for detecting the threatening content.

10. The method according to claim 4 or 8, characterized in that The policy update information includes at least one of the following information: The rule identifier of the protection rule that needs to be activated by the security protection engine of the preset product; The security protection engine of the preset product needs to start the rule content of the protection rules.

11. A device for updating a security protection strategy, characterized in that: The device comprises: An acquisition module, configured to acquire first security event information; a first determining module, configured to determine a first word frequency and a first total word count of words contained in the first security event information; A second determination module is configured to determine a similarity weight value based on the first total word count and / or the second total word count of the second security event information in the database; determine a vector distance between a first word frequency vector constructed based on the first word frequency and a second word frequency vector constructed based on the second word frequency of the second security event information; determine the similarity between the first security event information and the second security event information based on the similarity weight value and the vector distance; wherein the second security event information is: processed historical security event information; the similarity weight value is less than or equal to 1, and the product value of the similarity weight value and the vector distance is negatively correlated with the similarity; The third determining module is configured to determine, when the similarity is less than a preset value, that the first security event information is used to update a security protection policy of a preset product.

12. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the steps of the method for updating the security protection strategy according to any one of claims 1 to 10 are implemented.

13. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method for updating the security protection strategy according to any one of claims 1 to 10 are implemented.

Citation Information

Patent Citations

  • Relational database information security enhancement method and system, terminal and storage medium

    CN113065151A

  • Security information processing method and device, equipment and storage medium

    CN113452700A