Security event prediction method and apparatus, terminal and computer readable storage medium
By training a pre-defined model and generating a security event prediction model using security event data handled by users, the problem of low efficiency in network security systems when responding to security events is solved, and more efficient and accurate security event prediction is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- BEIJING HONGTENG INTELLIGENT TECH CO LTD
- Filing Date
- 2022-11-16
- Publication Date
- 2026-05-15
AI Technical Summary
Existing cybersecurity systems are inefficient in responding to security incidents and are unable to handle large numbers of incidents quickly and efficiently.
By training a pre-defined model using real cybersecurity incidents and user-verified target attack results, a security incident prediction model is obtained. This model is used to predict the attack results of real-time security incidents and provide response strategies.
It improves the efficiency of responding to security incidents, achieves faster computing speed and higher accuracy, and provides targeted and efficient response strategies.
Smart Images

Figure CN116108931B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network information security, and in particular to a method, apparatus, terminal and computer-readable storage medium for predicting security incidents. Background Technology
[0002] With the advent of the information age, the internet has become ubiquitous. It is now a part of people's daily lives, but at the same time, cybersecurity issues have become increasingly prominent. Numerous security incidents have arisen as a result of these issues, but the lack of effective response strategies often leads to a significant expenditure of effort in dealing with them. Summary of the Invention
[0003] This application provides a security event prediction method, apparatus, terminal, and computer-readable storage medium, which can solve the technical problem of how to efficiently respond to security events.
[0004] In a first aspect, embodiments of this application provide a security event prediction method, the method comprising:
[0005] In response to the triggering of a target security event, security event data on the user's handling of the target security event is obtained; wherein, the security event data includes the security event log of the target security event and the target attack results corresponding to the attack against the target security event;
[0006] The preset model is trained based on the security incident data to obtain a security incident prediction model;
[0007] In response to the triggering of a real-time security event, an attack prediction is performed on the real-time security event based on the security event prediction model to obtain the real-time attack result corresponding to the real-time security event.
[0008] Optionally, the security event log includes at least one of the following: security event title, security event summary, security event content, and security event level; the target attack result includes whether the attack was successful or failed.
[0009] Optionally, the target attack result, including successful or unsuccessful attack, includes:
[0010] When the user intervenes in the target security event, the target attack result is considered successful; otherwise, the target attack result is considered unsuccessful.
[0011] Optionally, training a preset model based on the security incident data to obtain a security incident prediction model includes:
[0012] The preset model is trained based on the security incident data. When the training time of the preset model reaches the preset training period, a security incident prediction model is obtained.
[0013] Optionally, after obtaining the real-time attack result corresponding to the real-time security event, the method further includes:
[0014] Receive the user's feedback on the real-time attack results, and correct the real-time attack results based on the feedback;
[0015] The security event prediction model is updated based on the corrected real-time attack results and the security event logs corresponding to the real-time security events.
[0016] Optionally, the response prior to the triggering of the target security event further includes:
[0017] Receive preset security event learning parameters input by users for the security information and event management platform;
[0018] The security event data obtained by acquiring the user's handling of the target security event includes:
[0019] Based on the preset security event learning parameters, security event data for the user's handling of the target security event is obtained from the security information and event management platform.
[0020] Optionally, obtaining security event data from the security information and event management platform based on the preset security event learning parameters includes:
[0021] Determine whether the target security event level is greater than or equal to the preset security event level. If so, obtain the security event data for the user's handling of the target security event from the security information and event management platform based on the preset security event learning parameters.
[0022] Secondly, embodiments of this application provide a security event prediction device, the device comprising:
[0023] The response module is adapted to respond to the triggering of a target security event and acquire security event data of the user's handling of the target security event; wherein, the security event data includes the security event log of the target security event and the target attack results corresponding to the attack against the target security event;
[0024] The training module is adapted to train a preset model based on the security event data to obtain a security event prediction model;
[0025] The prediction module is adapted to respond to the triggering of a real-time security event, perform attack prediction on the real-time security event based on the security event prediction model, and obtain the real-time attack result corresponding to the real-time security event.
[0026] Optionally, the security event log in the response module includes at least one of the following: security event title, security event summary, security event content, and security event level; the target attack result in the response module includes whether the attack was successful or failed.
[0027] Optionally, the target attack result in the response module includes whether the attack was successful or failed, including:
[0028] When the user intervenes in the target security event, the target attack result is considered successful; otherwise, the target attack result is considered unsuccessful.
[0029] Optionally, the prediction module performs attack prediction on the real-time security event based on the security event prediction model to obtain the real-time attack result corresponding to the real-time security event, including:
[0030] The preset model is trained based on the security incident data. When the training time of the preset model reaches the preset training period, a security incident prediction model is obtained.
[0031] Optionally, the security event prediction device further includes a correction module, which is adapted to perform the following steps:
[0032] Receive the user's feedback on the real-time attack results, and correct the real-time attack results based on the feedback;
[0033] The security event prediction model is updated based on the corrected real-time attack results and the security event logs corresponding to the real-time security events.
[0034] Optionally, the security event prediction device further includes a receiving module, which is adapted to receive preset security event learning parameters input by the user for security information and event management platform;
[0035] The security event data obtained by the response module for the user's handling of the target security event includes:
[0036] Based on the preset security event learning parameters, security event data for the user's handling of the target security event is obtained from the security information and event management platform.
[0037] Optionally, the step of obtaining security event data from the security information and event management platform based on the preset security event learning parameters in the response module includes:
[0038] Determine whether the target security event level is greater than or equal to the preset security event level. If so, obtain the security event data for the user's handling of the target security event from the security information and event management platform based on the preset security event learning parameters.
[0039] Thirdly, embodiments of this application provide a terminal, the terminal comprising:
[0040] Processor; and
[0041] A memory configured to store computer-executable instructions, which, when executed, cause the processor to perform the security event prediction method according to any one of the preceding claims.
[0042] Fourthly, embodiments of this application provide a computer-readable storage medium that stores one or more programs, which, when executed by a processor, implement the security event prediction method described in any of the preceding claims.
[0043] The beneficial effects of the technical solutions provided in some embodiments of this application include at least the following:
[0044] This application provides a security incident prediction method. It utilizes security incident data from user actions during actual response to target security incidents to train a preset model, thereby obtaining a security incident prediction model. When using this model to predict real-time attack results of real-time security incidents, the security incident prediction model has a faster computation speed than user-generated data, making it more efficient in predicting real-time security incidents. Furthermore, because users handle target security incidents more accurately, the accuracy of security incident data processed by users is higher. Using this security incident data to train the preset model results in a highly accurate security incident prediction model. Attached Figure Description
[0045] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0046] Figure 1 An exemplary system architecture diagram of a security event prediction method provided in this application embodiment;
[0047] Figure 2 A flowchart illustrating a security event prediction method provided in an embodiment of this application;
[0048] Figure 3 A flowchart illustrating another security event prediction method provided in this application embodiment;
[0049] Figure 4 A schematic diagram of the structure of a security event prediction device provided for an exemplary embodiment of this specification;
[0050] Figure 5 This is a schematic diagram of the structure of a terminal provided in an embodiment of this application. Detailed Implementation
[0051] To make the features and advantages of the embodiments of this application more apparent and understandable, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the protection scope of the embodiments of this application.
[0052] In the following description, when referring to the accompanying drawings, the same numbers in different drawings denote the same or similar elements unless otherwise indicated. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0053] With the widespread adoption of the internet, cybersecurity issues have garnered increasing attention, and various cybersecurity systems have become more prevalent. However, these systems often struggle to efficiently handle cybersecurity incidents. For instance, in the context of related technologies, cybersecurity systems such as IDS (Intrusion Detection System) and WAF (Web Application Firewall) generate a large number of alert logs and security incidents when responding to network attacks. Given limited resources, enterprise security operations personnel are often unable to efficiently and quickly address these security incidents.
[0054] To overcome the aforementioned technical problems, this application provides a security event prediction method. This method uses real network security events and user-confirmed target attack results to train a preset model, resulting in a security event prediction model. Then, the security event prediction model is used to predict the real-time attack results corresponding to the real-time security event. Based on the prediction results, it is determined whether the real-time attack in the real-time security event was successful, so as to determine whether human intervention is required. This provides a response strategy for dealing with real-time security events, thereby improving the efficiency of dealing with security events.
[0055] Please see Figure 1 , Figure 1 This is an exemplary system architecture diagram of a security event prediction method provided in an embodiment of this application.
[0056] like Figure 1 As shown, the system architecture may include a terminal 101, a network 102, and a server 103. The network 102 serves as the medium for providing a communication link between the terminal 101 and the server 103. The network 102 may include various types of wired or wireless communication links, such as wired communication links including fiber optic cables, twisted-pair cables, or coaxial cables, and wireless communication links including Bluetooth communication links, Wireless-Fidelity (Wi-Fi) communication links, or microwave communication links, etc.
[0057] Terminal 101 can interact with server 103 via network 102 to receive messages from or send messages to server 103. Alternatively, terminal 101 can interact with server 103 via network 102 to receive messages or data sent to server 103 by other users. Terminal 101 can be hardware or software. When terminal 101 is hardware, it can be various terminals, including but not limited to smartwatches, smartphones, tablets, laptops, and desktop computers. When terminal 101 is software, it can be installed in the terminals listed above, and can be implemented as multiple software programs or software modules (e.g., to provide distributed services) or as a single software program or software module; no specific limitation is made here.
[0058] In this embodiment, terminal 101 can, in response to the triggering of a target security event, acquire security event data on the user's handling of the target security event; wherein, the security event data includes security event logs of the target security event and target attack results corresponding to attacks against the target security event; a preset model is trained based on the security event data to obtain a security event prediction model; in response to the triggering of a real-time security event, attack prediction is performed on the real-time security event based on the security event prediction model to obtain the real-time attack results corresponding to the real-time security event.
[0059] Server 103 can be a business server providing various services. It should be noted that server 103 can be either hardware or software. When server 103 is hardware, it can be implemented as a distributed server cluster consisting of multiple servers, or as a single server. When server 103 is software, it can be implemented as multiple software programs or software modules (e.g., used to provide distributed services), or as a single software program or software module; no specific limitations are made here.
[0060] Alternatively, the system architecture may not include server 103. In other words, server 103 may be an optional device in the embodiments of this specification. That is, the method provided in the embodiments of this specification can be applied to a system structure that only includes terminal 101. The embodiments of this application do not limit this.
[0061] It should be understood that Figure 1 The number of terminals, networks, and servers shown is only illustrative; the number can be any number of terminals, networks, and servers depending on the implementation requirements.
[0062] Please see Figure 2 , Figure 2 This is a flowchart illustrating a security event prediction method provided in an embodiment of this application. The execution entity in this embodiment can be a terminal executing the security event prediction method, a processor within the terminal executing the security event prediction method, or a security event prediction method service within the terminal executing the security event prediction method. For ease of description, the following example uses a processor within a terminal as the execution entity to illustrate the specific execution process of the security event prediction method.
[0063] like Figure 2 As shown, security incident prediction methods can include at least:
[0064] S202. In response to the triggering of a target security event, obtain security event data on the user's handling of the target security event; wherein, the security event data includes the security event log of the target security event and the target attack results corresponding to the attack against the target security event.
[0065] When a network attack occurs, a target security event is triggered, and security event data on the user's handling of the target security event is obtained based on this event. Here, the target security event can be a security event occurring within a predetermined time period. The target attack result corresponding to the network attack is generally configured by the user. The user is typically a person responsible for network maintenance, and may include security operations personnel, etc.
[0066] Generally, when a system requiring protection is subjected to a cyberattack, some cyberattacks will be successfully protected, while others will not. Typically, both attacks that can and cannot be successfully protected by the system will trigger their respective security events.
[0067] After a target security event is triggered, when a user processes the security event data, they can determine whether the network attack in that target security event can be successfully protected by the system based on the security event logs. For example, in a certain target security event, if the user determines based on the security event logs that the network attack cannot be successfully protected by the system, then that target security event can be set as the target attack result corresponding to a successful network attack; if the user determines based on the security event logs that the network attack can be successfully protected by the system, then that target security event can be set as the target attack result corresponding to a failed network attack.
[0068] In one feasible implementation, when actually responding to a cybersecurity incident, all security incidents occurring within a predetermined time period can be taken as target security incidents. In this case, the security incident data corresponding to all triggered target security incidents can be acquired by the processor.
[0069] S204. Train the preset model based on security incident data to obtain a security incident prediction model.
[0070] Specifically, a security event prediction model is obtained by training a pre-defined model using security event logs from the target security event and the target attack results corresponding to attacks against the target security event. Here, the pre-defined model includes a machine learning model. The machine learning model can be an untrained model or a pre-trained model; the pre-trained model can be further trained to obtain the security event prediction model.
[0071] Since the security incident prediction model is trained on security incident data from target security incidents handled by users, and this data has high accuracy, the security incident prediction model trained on this data also has high accuracy in predicting security incidents.
[0072] In one feasible implementation, the pre-defined model learns from the target attack results corresponding to attacks made by users based on security event logs within the target security event, thereby gaining the ability to predict network attacks corresponding to security events. Simultaneously, because users handle target security events more accurately, their predictions of security events are more accurate. Therefore, the accuracy of security event data processed by users is higher. This security event data is used to train the pre-defined model, resulting in a high-accuracy security event prediction model. It is easy to understand that the pre-defined model can gradually improve its prediction accuracy by continuously training with acquired security event data.
[0073] S206. In response to the triggering of a real-time security event, attack prediction is performed on the real-time security event based on the security event prediction model to obtain the real-time attack result corresponding to the real-time security event.
[0074] When a real-time network attack occurs, a real-time security event is triggered. At this time, the security event prediction model predicts the network attack corresponding to the real-time security event, thereby predicting whether the network attack will succeed.
[0075] It's easy to understand that cyberattacks can be completed in an instant. Therefore, when a successful cyberattack is predicted, the attack may have already occurred simultaneously with, or occurred earlier than, or not yet occurred at all.
[0076] In one feasible implementation, when the security event prediction model predicts that the network attack corresponding to the real-time security event will succeed, the user will intervene to handle the real-time security event; when the security event prediction model predicts that the network attack corresponding to the real-time security event will fail, the user will not intervene. By accurately predicting the results of real-time attacks through the security event prediction model, users are provided with a targeted and highly accurate response strategy to security events—that is, identifying which security events require attention and which do not, thus enabling accurate, efficient, and rapid response to security events.
[0077] This application provides a security incident prediction method. It utilizes security incident data from user actions during actual response to target security incidents to train a preset model, thereby obtaining a security incident prediction model. When using this model to predict real-time attack results of real-time security incidents, the security incident prediction model has a faster computation speed than user-generated data, making it more efficient in predicting real-time security incidents. Furthermore, because users handle target security incidents more accurately, the accuracy of security incident data processed by users is higher. Using this security incident data to train the preset model results in a highly accurate security incident prediction model.
[0078] In one embodiment provided in this application, the security event log includes at least one of the following: security event title, security event summary, security event content, and security event level.
[0079] The security event title, summary, content, and level can all be automatically generated by the processor after the target security event is triggered. Alternatively, they can be written or modified by the user.
[0080] In one feasible implementation, the security event log may include one of the following: security event title, security event summary, security event content, and security event level; or, the security event log may include any combination of two or three of the following: security event title, security event summary, security event content, and security event level; or, the security event log may include all of the following: security event title, security event summary, security event content, and security event level.
[0081] When training a pre-defined model based on security event logs and the corresponding target attack results for attacks against a target security event, the model can extract target features from the security event logs and the corresponding target attack results for training. Here, target features in the security event logs include, but are not limited to, characters, words, phrases, letters, and symbols. It is easy to understand that target features in security event logs can be extracted from the security event title, security event summary, security event content, or security event level.
[0082] In one embodiment provided in this application, the result of a target attack includes either a successful attack or a failed attack.
[0083] The outcome of a target attack—whether it was successful or failed—can be determined by the user based on the security event logs of the target security event. It's easy to understand that the user's judgment of the target attack outcome based on the security event logs is highly accurate. When the target attack outcome shows a successful attack, it indicates that the network attack could not be successfully protected by the system; when the target attack outcome shows a failed attack, it indicates that the network attack could be successfully protected by the system.
[0084] In one embodiment provided in this application, the target attack result includes whether the attack was successful or failed, including:
[0085] When a user intervenes in a target security event, the attack result is considered successful; otherwise, the attack result is considered unsuccessful.
[0086] Once a target security event is triggered, the user judges the target attack result based on the security event log corresponding to the target security event. When the network attack corresponding to the target security event cannot be successfully protected by the system, the target attack result is considered successful; when the network attack corresponding to the target security event can be successfully protected by the system, the target attack result is considered failed.
[0087] In one feasible implementation, when the preset model is an untrained machine learning model, it can set the target attack results for all user-involved target security events as successful, and simultaneously set the target attack results for all user-uninvolved target security events as unsuccessful. It should be noted that users typically evaluate the target attack results for all target security events to determine whether to intervene.
[0088] In another feasible implementation, when the preset model is a pre-trained machine learning model, the preset model has a certain degree of predictive ability for the target attack results corresponding to the target security event. The user will also judge the target attack results corresponding to all target security events to determine whether to intervene. When the preset model makes a wrong prediction, the prediction result is corrected. The preset model can reduce the workload of the user in judging the target attack results.
[0089] In one embodiment provided in this application, the step S206 of predicting attacks on real-time security events based on a security event prediction model to obtain the real-time attack results corresponding to the real-time security events can be replaced by:
[0090] The preset model is trained based on security incident data. When the training time of the preset model reaches the preset training period, the security incident prediction model is obtained.
[0091] The training duration refers to the training period. However, in practice, when training with security event data, target security events are not always triggered, making it difficult to guarantee the number of events occurring. Therefore, a pre-defined model can be trained using security event data corresponding to all target security events occurring within a specific time period.
[0092] In one feasible implementation, the training period can be set to several weeks or months in the future, which can be set by the user according to the user's actual needs.
[0093] In other feasible implementations, the decision to output a preset model as a security event prediction model can be made by judging the accuracy of the preset model's prediction of the target attack result during the training process. When the preset model's accuracy in predicting the target attack result reaches a preset value, the preset model with the preset accuracy can be used as a security event prediction model.
[0094] Figure 3 This is a flowchart illustrating another security event prediction method provided in an embodiment of this application. Figure 3 As shown, in one embodiment provided in this application, after obtaining the real-time attack result corresponding to the real-time security event in step S206, the method further includes:
[0095] S302. Receive user feedback on real-time attack results and correct the real-time attack results based on the feedback.
[0096] The attack result feedback includes user verification of the real-time attack result, determining whether the real-time attack result is correct. If the real-time attack result is incorrect, it is corrected; otherwise, the real-time attack result is not corrected.
[0097] Here, user feedback on real-time attack results can be random or follow a certain pattern. For example, users can randomly select real-time attack results for verification. Users can also verify real-time attack results after a predetermined number of intervals; or, users can verify real-time attack results for a specific duration after a preset time interval.
[0098] In one feasible implementation, if the security event prediction model predicts a successful attack in real-time, but the user determines the attack has failed, the real-time attack result is corrected to "attack failed." Conversely, if the security event prediction model predicts a failed attack in real-time, but the user determines the attack has succeeded, the real-time attack result is corrected to "attack successful." Of course, no modification is needed if the user's judgment matches the real-time attack result.
[0099] S304. Update the security event prediction model based on the corrected real-time attack results and the corresponding security event logs.
[0100] Specifically, the security event prediction model is retrained using the corrected real-time attack results and the corresponding security event logs to update the security event prediction model.
[0101] In one feasible implementation, the security event prediction model can be trained after each corrected real-time attack result is obtained. Alternatively, the model can be trained after the number of corrected real-time attack results has accumulated to a certain level, or by using a set of all corrected real-time attack results collected within a preset time frame.
[0102] The security event prediction model is retrained using corrected real-time attack results and corresponding security event logs to improve its prediction accuracy. It's easy to understand that as the number of corrected real-time attack results and corresponding security event log samples increases, the prediction accuracy of the updated security event prediction model also increases.
[0103] In one embodiment provided in this application, before the triggering of the target security event in step S202, the method further includes:
[0104] Receive preset security event learning parameters input by the user for the Security Information and Event Management (SIEM) platform.
[0105] SIEM supports threat detection and security incident response through real-time collection and historical analysis of security events. Users can obtain corresponding data from SIEM by pre-setting security event learning parameters. These pre-set parameters are generally those available within the SIEM.
[0106] In one feasible implementation, since security operations personnel most frequently use SIEM's event management functions during traditional SIEM security operations, a browser plugin can be installed on the SIEM security event analysis and handling page. This plugin can be a machine learning-based virtual intelligent robot that uses a processor to drive the virtual intelligent robot to execute security event prediction methods.
[0107] In one feasible implementation, the preset security event learning parameters include one of the following: security event title parameters, security event summary parameters, security event content parameters, and security event level parameters; or, the preset security event learning parameters may also include any combination of two or three of the following: security event title parameters, security event summary parameters, security event content parameters, and security event level parameters; or, the preset security event learning parameters may also include all of the following: security event title parameters, security event summary parameters, security event content parameters, and security event level parameters.
[0108] Meanwhile, obtaining security event data for user-handled target security events in step S202 includes at least the following steps:
[0109] Based on preset security event learning parameters, security event data for the user's target security event is obtained from the security information and event management platform.
[0110] Specifically, based on preset security event learning parameters, the system obtains corresponding security event logs from the security information and event management platform. Then, the user judges the target attack results corresponding to the attack on the target security event based on the security event logs, thereby obtaining the security event logs of the target security event and the target attack results corresponding to the attack on the target security event, i.e., security event data.
[0111] In one feasible implementation, when the security event log includes at least one of the following: security event title, security event summary, security event content, and security event level, the security event title parameter can be used to obtain the security event title, the security event summary parameter can be used to obtain the security event summary, the security event content parameter can be used to obtain the security event content, and the security event level parameter can be used to obtain the security event level.
[0112] In one embodiment provided in this application, obtaining security event data from a security information and event management platform based on preset security event learning parameters includes at least the following steps:
[0113] Determine whether the target security event level is greater than or equal to the preset security event level. If so, obtain the security event data for user handling of the target security event from the security information and event management platform based on the preset security event learning parameters.
[0114] The target security event level is generally used to distinguish the severity of cyberattacks within a target security event. A higher target security event level indicates a more severe cyberattack; conversely, a lower target security event level indicates a less severe cyberattack. Here, by filtering target security events with levels higher than a preset security event level, we obtain security event data corresponding to these higher-level events. Using this security event data, we train a preset model to obtain a security event prediction model that can predict cyberattacks with high accuracy.
[0115] It's easy to understand that users tend to prioritize handling high-priority security incidents. Therefore, the security incident prediction model in this embodiment allows users to accurately and quickly locate security incidents involving severe network attacks. Since this response strategy aligns with users' individual handling habits, it enables them to respond quickly, thus allowing for accurate, efficient, and rapid responses to security incidents.
[0116] In one feasible implementation, the target security event level can be classified from high to low severity as severe event, moderately severe event, minor event, etc.
[0117] Please see Figure 4 , Figure 4 This is a schematic diagram of the structure of a security event prediction device provided for an exemplary embodiment of this specification.
[0118] This application provides a security event prediction device 400, which includes:
[0119] The response module 410 is adapted to respond to the triggering of a target security event and obtain security event data of the user's handling of the target security event; wherein, the security event data includes the security event log of the target security event and the target attack results corresponding to the attack against the target security event;
[0120] Training module 420 is suitable for training a preset model based on security incident data to obtain a security incident prediction model;
[0121] The prediction module 430 is adapted to respond to the triggering of real-time security events, perform attack prediction on real-time security events based on the security event prediction model, and obtain the real-time attack results corresponding to the real-time security events.
[0122] In one embodiment provided in this application, the security event log in the response module 410 includes at least one of the following: security event title, security event summary, security event content, and security event level; the target attack result in the response module includes attack success or attack failure.
[0123] In one embodiment provided in this application, the target attack result in the response module 410 includes either attack success or attack failure, including:
[0124] When a user intervenes in a target security event, the attack result is considered successful; otherwise, the attack result is considered unsuccessful.
[0125] In one embodiment provided in this application, the prediction module 430 performs attack prediction on real-time security events based on a security event prediction model to obtain the real-time attack results corresponding to the real-time security events, including:
[0126] The preset model is trained based on security incident data. When the training time of the preset model reaches the preset training period, the security incident prediction model is obtained.
[0127] In one embodiment provided in this application, the security event prediction device 400 further includes a correction module, which is adapted to perform the following steps:
[0128] Receive user feedback on real-time attack results and correct the real-time attack results based on the feedback.
[0129] The security event prediction model is updated based on the corrected real-time attack results and the corresponding security event logs.
[0130] In one embodiment provided in this application, the security event prediction device 400 further includes a receiving module, which is adapted to receive preset security event learning parameters input by the user for security information and event management platform;
[0131] The security event data obtained by the response module 410 for handling the target security event by the user includes:
[0132] Based on preset security event learning parameters, security event data for the user's target security event is obtained from the security information and event management platform.
[0133] In one embodiment provided in this application, the response module 410 obtains security event data from the security information and event management platform based on preset security event learning parameters, including:
[0134] Determine whether the target security event level is greater than or equal to the preset security event level. If so, obtain the security event data for user handling of the target security event from the security information and event management platform based on the preset security event learning parameters.
[0135] This application also provides a computer storage medium that can store multiple instructions adapted for loading by a processor and executing the steps of any of the methods described in the above embodiments.
[0136] Please see Figure 5 , Figure 5 This is a schematic diagram of the structure of a terminal provided in an embodiment of this application. Figure 5 As shown, terminal 500 may include: at least one processor 501, at least one network interface 504, user interface 503, memory 505, and at least one communication bus 502.
[0137] The communication bus 502 is used to enable communication between these components.
[0138] The user interface 503 may include a display screen and a camera. Optionally, the user interface 503 may also include a standard wired interface and a wireless interface.
[0139] The network interface 504 may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface).
[0140] The processor 501 may include one or more processing cores. The processor 501 connects to various parts within the terminal 500 using various interfaces and lines, and performs various functions and processes data by running or executing instructions, programs, code sets, or instruction sets stored in the memory 505, and by calling data stored in the memory 505. Optionally, the processor 501 may be implemented using at least one hardware form of Digital Signal Processing (DSP), Field-Programmable Gate Array (FPGA), or Programmable Logic Array (PLA). The processor 501 may integrate one or a combination of several of the following: Central Processing Unit (CPU), Graphics Processing Unit (GPU), and modem. The CPU primarily handles the operating system, user interface, and applications; the GPU is responsible for rendering and drawing the content required for display; and the modem handles wireless communication. It is understood that the modem may also be implemented as a separate chip without being integrated into the processor 501.
[0141] The memory 505 may include random access memory (RAM) or read-only memory (ROM). Optionally, the memory 505 may include a non-transitory computer-readable storage medium. The memory 505 can be used to store instructions, programs, code, code sets, or instruction sets. The memory 505 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as touch function, sound playback function, image playback function, etc.), instructions for implementing the above-described method embodiments, etc.; the data storage area may store data involved in the above-described method embodiments, etc. Optionally, the memory 505 may also be at least one storage device located remotely from the aforementioned processor 501. Figure 5 As shown, the memory 505, which serves as a computer storage medium, may include an operating system, a network communication module, a user interface module, and a document rendering program.
[0142] exist Figure 5 In the terminal 500 shown, the user interface 503 is mainly used to provide an input interface for the user and to obtain the user's input data; while the processor 501 can be used to call the security event prediction program stored in the memory 505 and specifically perform the following operations:
[0143] In response to the triggering of a target security event, acquire security event data on the user's handling of the target security event; the security event data includes the security event log of the target security event and the target attack results corresponding to the attack against the target security event;
[0144] A security incident prediction model is obtained by training a pre-set model based on security incident data;
[0145] In response to the triggering of real-time security events, attack prediction is performed on the real-time security events based on the security event prediction model to obtain the real-time attack results corresponding to the real-time security events.
[0146] In some embodiments, the security event log executed by the processor 501 includes at least one of the following: security event title, security event summary, security event content, and security event level; the target attack result executed by the processor 501 includes attack success or attack failure.
[0147] In some embodiments, the result of the target attack executed by the processor 501 includes whether the attack was successful or failed, including:
[0148] When a user intervenes in a target security event, the attack result is considered successful; otherwise, the attack result is considered unsuccessful.
[0149] In some embodiments, the processor 501 performs training on a preset model based on security event data to obtain a security event prediction model, including:
[0150] The preset model is trained based on security incident data. When the training time of the preset model reaches the preset training period, the security incident prediction model is obtained.
[0151] In some embodiments, after the processor 501 obtains the real-time attack result corresponding to the real-time security event, it is further configured to execute:
[0152] Receive user feedback on real-time attack results and correct the real-time attack results based on the feedback.
[0153] The security event prediction model is updated based on the corrected real-time attack results and the corresponding security event logs.
[0154] In some embodiments, the processor 501 is further configured to perform the following before executing actions in response to the triggering of a target security event:
[0155] Receive preset security event learning parameters input by users for the security information and event management platform;
[0156] The security incident data obtained for user-managed target security incidents includes:
[0157] Based on preset security event learning parameters, security event data for the user's target security event is obtained from the security information and event management platform.
[0158] In some embodiments, the processor 501 executes security event data based on preset security event learning parameters to obtain security event data from the security information and event management platform for user-managed target security events, including:
[0159] Determine whether the target security event level is greater than or equal to the preset security event level. If so, obtain the security event data for user handling of the target security event from the security information and event management platform based on the preset security event learning parameters.
[0160] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For instance, the division of modules is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple modules or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or modules may be electrical, mechanical, or other forms.
[0161] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical modules; that is, they may be located in one place or distributed across multiple network modules. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
[0162] Furthermore, the functional modules in the various embodiments of this application can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module. The integrated module can be implemented in hardware or as a software functional module.
[0163] If the integrated module is implemented as a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application embodiment, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0164] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that the embodiments of this application are not limited to the described order of actions, because according to the embodiments of this application, some steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also understand that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the embodiments of this application.
[0165] In the above embodiments, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions in other embodiments.
[0166] The above is a description of a security event prediction method, apparatus, terminal, and computer-readable storage medium provided in the embodiments of this application. For those skilled in the art, based on the ideas of the embodiments of this application, there will be changes in the specific implementation methods and application scope. Therefore, the content of this specification should not be construed as a limitation on the embodiments of this application.
[0167] Embodiments of this application disclose A1, a method for predicting security events, wherein the method includes:
[0168] In response to the triggering of a target security event, acquire security event data on the user's handling of the target security event; the security event data includes the security event log of the target security event and the target attack results corresponding to the attack against the target security event;
[0169] A security incident prediction model is obtained by training a pre-set model based on security incident data;
[0170] In response to the triggering of real-time security events, attack prediction is performed on the real-time security events based on the security event prediction model to obtain the real-time attack results corresponding to the real-time security events.
[0171] A2. The security incident prediction method as described in A1, wherein the security incident log includes at least one of the following: security incident title, security incident summary, security incident content, and security incident level; the target attack result includes whether the attack was successful or failed.
[0172] A3. The security incident prediction method as described in A2, wherein the target attack result includes whether the attack was successful or failed, including:
[0173] When a user intervenes in a target security event, the attack result is considered successful; otherwise, the attack result is considered unsuccessful.
[0174] A4. The security incident prediction method as described in A1, wherein training a preset model based on security incident data to obtain a security incident prediction model includes:
[0175] The preset model is trained based on security incident data. When the training time of the preset model reaches the preset training period, the security incident prediction model is obtained.
[0176] A5. The security event prediction method as described in A1, wherein after obtaining the real-time attack result corresponding to the real-time security event, it further includes:
[0177] Receive user feedback on real-time attack results and correct the real-time attack results based on the feedback.
[0178] The security event prediction model is updated based on the corrected real-time attack results and the corresponding security event logs.
[0179] A6. The security event prediction method as described in A1, wherein, in response to the triggering of the target security event, it further includes:
[0180] Receive preset security event learning parameters input by users for the security information and event management platform;
[0181] The security incident data obtained for user-managed target security incidents includes:
[0182] Based on preset security event learning parameters, security event data for the user's target security event is obtained from the security information and event management platform.
[0183] A7. The security incident prediction method as described in A6, wherein security incident data for user-managed target security incidents is obtained from a security information and incident management platform based on preset security incident learning parameters, including:
[0184] Determine whether the target security event level is greater than or equal to the preset security event level. If so, obtain the security event data for user handling of the target security event from the security information and event management platform based on the preset security event learning parameters.
[0185] Embodiments of this application also disclose B8, a security event prediction device, wherein the device includes:
[0186] The response module is adapted to respond to the triggering of a target security event and acquire security event data for the user's handling of the target security event; wherein, the security event data includes the security event log of the target security event and the target attack results corresponding to the attack against the target security event;
[0187] The training module is suitable for training a preset model based on security incident data to obtain a security incident prediction model;
[0188] The prediction module is suitable for responding to the triggering of real-time security events. Based on the security event prediction model, it performs attack prediction on real-time security events and obtains the real-time attack results corresponding to the real-time security events.
[0189] B9. The security event prediction device as described in B8, wherein the security event log in the response module includes at least one of the following: security event title, security event summary, security event content, and security event level; and the target attack result in the response module includes whether the attack was successful or failed.
[0190] B10. The security incident prediction device as described in B9, wherein the target attack result in the response module includes whether the attack was successful or failed, including:
[0191] When a user intervenes in a target security event, the attack result is considered successful; otherwise, the attack result is considered unsuccessful.
[0192] B11. The security event prediction device as described in B8, wherein the prediction module performs attack prediction on real-time security events based on a security event prediction model, and obtains the real-time attack results corresponding to the real-time security events, including:
[0193] The preset model is trained based on security incident data. When the training time of the preset model reaches the preset training period, the security incident prediction model is obtained.
[0194] B12. The security event prediction device as described in B8, wherein the security event prediction device further includes a correction module adapted to perform the following steps:
[0195] Receive user feedback on real-time attack results and correct the real-time attack results based on the feedback.
[0196] The security event prediction model is updated based on the corrected real-time attack results and the corresponding security event logs.
[0197] B13. The security event prediction device as described in B8, wherein the security event prediction device further includes a receiving module, which is adapted to receive preset security event learning parameters input by the user for security information and event management platform;
[0198] The security event data obtained by the response module for handling target security events includes:
[0199] Based on preset security event learning parameters, security event data for the user's target security event is obtained from the security information and event management platform.
[0200] B14. The security incident prediction device as described in B13, wherein the response module obtains security incident data from the security information and incident management platform based on preset security incident learning parameters, including:
[0201] Determine whether the target security event level is greater than or equal to the preset security event level. If so, obtain the security event data for user handling of the target security event from the security information and event management platform based on the preset security event learning parameters.
[0202] Embodiments of this application also disclose C15, a terminal, wherein the terminal includes:
[0203] Processor; and
[0204] The memory is configured to store computer-executable instructions, which, when executed, cause the processor to perform a method according to any one of A1 to A7.
[0205] Embodiments of this application also disclose D16, a computer-readable storage medium, wherein the computer-readable storage medium stores one or more programs, which, when executed by a processor, implement the method of any one of A1 to A7.
Claims
1. A method for predicting security incidents, wherein, The method includes: In response to the triggering of a target security event, security event data on the user's handling of the target security event is obtained; wherein, the security event data includes the security event log of the target security event and the target attack results corresponding to the attack against the target security event, so that the user can determine whether the network attack in the target security event can be successfully protected by the system based on the security event log of the target security event, and the target security event is all security events that occur within a predetermined time period; The preset model is trained based on the security incident data to obtain a security incident prediction model; In response to the triggering of a real-time security event, an attack prediction is performed on the real-time security event based on the security event prediction model to obtain the real-time attack result corresponding to the real-time security event; The step of training a preset model based on the security incident data to obtain a security incident prediction model includes: The preset model is trained based on the security event data. When the training time of the preset model reaches the preset training period, a security event prediction model is obtained. The preset model learns the target attack results corresponding to the attacks made by users based on the security event logs in the target security event, thereby having the ability to predict network attacks corresponding to the security event. At the same time, the preset model gradually improves the accuracy of security event prediction by continuously acquiring security event data for training.
2. The security incident prediction method as described in claim 1, wherein, The security event log includes at least one of the following: security event title, security event summary, security event content, and security event level; the target attack result includes whether the attack was successful or failed.
3. The security incident prediction method as described in claim 2, wherein, The target attack result includes whether the attack was successful or failed, including: When the user intervenes in the target security event, the target attack result is considered successful; otherwise, the target attack result is considered unsuccessful.
4. The security incident prediction method as described in claim 1, wherein, After obtaining the real-time attack result corresponding to the real-time security event, the method further includes: Receive the user's feedback on the real-time attack results, and correct the real-time attack results based on the feedback; The security event prediction model is updated based on the corrected real-time attack results and the security event logs corresponding to the real-time security events.
5. The security incident prediction method as described in claim 1, wherein, The response prior to the triggering of the target security event also includes: Receive preset security event learning parameters input by users for the security information and event management platform; The security event data obtained by acquiring the user's handling of the target security event includes: Based on the preset security event learning parameters, security event data for the user's handling of the target security event is obtained from the security information and event management platform.
6. The security incident prediction method as described in claim 5, wherein, The process of obtaining security event data from the security information and event management platform based on the preset security event learning parameters includes: Determine whether the target security event level is greater than or equal to the preset security event level. If so, obtain the security event data for the user's handling of the target security event from the security information and event management platform based on the preset security event learning parameters.
7. A security incident prediction device, wherein, The device includes: The response module is adapted to respond to the triggering of a target security event and acquire security event data for the user's handling of the target security event; wherein, the security event data includes the security event log of the target security event and the target attack results corresponding to the attack against the target security event, so that the user can determine whether the network attack in the target security event can be successfully protected by the system based on the security event log of the target security event, and the target security event is all security events that occur within a predetermined time period; The training module is adapted to train a preset model based on the security event data to obtain a security event prediction model; The prediction module is adapted to respond to the triggering of a real-time security event, perform attack prediction on the real-time security event based on the security event prediction model, and obtain the real-time attack result corresponding to the real-time security event. The prediction module performs attack prediction on the real-time security event based on the security event prediction model, and obtains the real-time attack result corresponding to the real-time security event, including: The preset model is trained based on the security event data. When the training time of the preset model reaches the preset training period, a security event prediction model is obtained. The preset model learns the target attack results corresponding to the attacks made by users based on the security event logs in the target security event, thereby having the ability to predict network attacks corresponding to the security event. At the same time, the preset model gradually improves the accuracy of security event prediction by continuously acquiring security event data for training.
8. The security event prediction device as described in claim 7, wherein, The security event log in the response module includes at least one of the following: security event title, security event summary, security event content, and security event level; the target attack result in the response module includes whether the attack was successful or failed.
9. The security event prediction device as described in claim 8, wherein, The target attack result in the response module includes whether the attack was successful or failed, including: When the user intervenes in the target security event, the target attack result is considered successful; otherwise, the target attack result is considered unsuccessful.
10. The security event prediction device as described in claim 7, wherein, The security event prediction device further includes a correction module, which is adapted to perform the following steps: Receive the user's feedback on the real-time attack results, and correct the real-time attack results based on the feedback; The security event prediction model is updated based on the corrected real-time attack results and the security event logs corresponding to the real-time security events.
11. The security event prediction device as described in claim 7, wherein, The security event prediction device further includes a receiving module, which is adapted to receive preset security event learning parameters input by the user for security information and event management platform; The security event data obtained by the response module for the user's handling of the target security event includes: Based on the preset security event learning parameters, security event data for the user's handling of the target security event is obtained from the security information and event management platform.
12. The security event prediction device as described in claim 11, wherein, The security event data obtained from the security information and event management platform based on the preset security event learning parameters in the response module includes: Determine whether the target security event level is greater than or equal to the preset security event level. If so, obtain the security event data for the user's handling of the target security event from the security information and event management platform based on the preset security event learning parameters.
13. A terminal, wherein, The terminal includes: Processor; and A memory configured to store computer-executable instructions, which, when executed, cause the processor to perform the method according to any one of claims 1 to 6.
14. A computer-readable storage medium, wherein, The computer-readable storage medium stores one or more programs that, when executed by a processor, implement the method of any one of claims 1 to 6.