An intrusion analysis method, device, equipment and storage medium for a communication device
By collecting and correlating the analysis of traffic, logs and environmental information of the communication system, generating a weak knowledge base and attack path, the problem of being unable to quickly trace the apt attack in the existing technology is solved, and rapid intrusion analysis and reinforcement of the communication system is achieved.
Patent Information
- Application Number
- CN202310161280.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-23
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2043-02-23
AI Technical Summary
In the prior art, when facing advanced sustainable threat attacks (apt attacks), communication systems cannot quickly find the attack source and invasion paths, resulting in the inability to cut off the attacker's continuous attacks in time and the inability to effectively ensure the security of the communication system.
Collect incoming and outgoing traffic, log information and environmental information of key nodes, generate security alarm logs through analysis and processing, and conduct correlation analysis of security alarm logs, log information and environmental information to generate weakness knowledge bases and attack paths, and use feature associations and logical associations to improve analysis accuracy.
It can quickly find attack sources, reduce the degree of damage to the communication system, improve the efficiency and accuracy of intrusion analysis, and generate a detailed weakness knowledge base to strengthen the communication system.
Smart Images

Figure CN116132188B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security, and particularly to an intrusion analysis method, device, equipment and storage medium for a communication device. Background Art
[0002] In the prior art, the attack traceability of intrusion analysis of a communication system is to perform reverse inference through the alarm information of security events that have been successfully attacked, and to reverse the attack source step by step through the associated devices in the attack chain, so as to restore the entire attack process. However, currently common apt attacks (apt attacks are advanced persistent threat attacks) all have extremely strong concealment and pertinence. If the attack chain is very long, then it is impossible to quickly find the attack source through this method, and it is impossible to timely cut off the continuous attack of the attacker, and thus it is impossible to ensure that the damage degree of the communication system is reduced, resulting in the security of the communication system not being effectively guaranteed.
[0003] Therefore, how to propose a method for rapid attack traceability of intrusion analysis of a communication system is a technical problem that those skilled in the art urgently need to solve. Summary of the Invention
[0004] In view of this, the purpose of the present invention is to provide an intrusion analysis method, device, equipment and storage medium for a communication device, which solves the problems in the prior art that when the communication system is attacked, the attack source and intrusion path cannot be quickly found, the continuous attack of the attacker cannot be timely cut off, and prevention cannot be carried out in advance.
[0005] To solve the above technical problems, the present invention provides an intrusion analysis method for a communication device, including:
[0006] Collect the in-and-out traffic, log information and environmental information of key nodes; the log information at least includes application logs, system logs and database logs, and the environmental information at least includes terminal communication sessions, process information, file information and account changes;
[0007] Analyze and process the in-and-out traffic of the key nodes to obtain a security alarm log of the attack behavior;
[0008] Perform correlation analysis on the security alarm log, the log information and the environmental information to obtain a correlation analysis result;
[0009] If the correlation analysis result is a security event, generate a vulnerability knowledge base, and generate an attack portrait and an attack path; the security events at least include events of obtaining internal information of the application environment through vulnerabilities, events of controlling the server, and events of entering the internal network environment for other illegal activities.
[0010] Optionally, the security alert log includes a request header, a request body, a response header, and a response body. The correlation analysis of the security alert log, the log information, and the environment information to obtain a correlation analysis result includes:
[0011] If the attack feature in the HTTP request packet in the alert log matches the log information and the environment information, and the content of the HTTP return packet in the alert log matches the attack feature, then determine the correlation analysis result as a security event; the return packet content includes at least one of service data and application environment information;
[0012] If the attack feature in the HTTP request header in the alert log matches the log information and the environment information and the content of the HTTP return packet in the alert log matching the attack feature cannot be satisfied simultaneously, then determine the correlation analysis result as an attempted attack. Optionally, if the correlation analysis result is a security event, generating a vulnerability knowledge base includes:
[0013] Generating vulnerabilities according to the correlation analysis result; the vulnerabilities include vulnerability locations, vulnerability names, vulnerability descriptions, and reinforcement suggestions;
[0014] Saving the vulnerabilities to the vulnerability knowledge base.
[0015] Optionally, it further includes:
[0016] Obtaining the vulnerabilities collected by a vulnerability scanner; the vulnerabilities are WEB application layer security vulnerabilities, system layer vulnerabilities, and other protocol vulnerabilities;
[0017] Generating the vulnerabilities according to the vulnerabilities.
[0018] Optionally, the correlation analysis of the security alert log, the log information, and the environment information to obtain a correlation analysis result includes:
[0019] Performing correlation analysis on the security alert log, the log information, and the environment information using feature correlation and logical correlation to obtain a correlation analysis result; the feature correlation means that the features carried in the attacker's behavior of attacking through the vulnerabilities existing in the system can have a certain keyword feature correlation with the log information and the environment information, and the logical correlation means that the attacker's attack behavior through the vulnerabilities existing in the system has a certain logical relationship correlation with the subsequent log information and environment information of the invaded terminal.
[0020] Optionally, after generating the vulnerabilities according to the correlation analysis result, it further includes:
[0021] Providing a response strategy using the reinforcement suggestions.
[0022] The present invention also provides an intrusion analysis device for a communication device, including:
[0023] A collection module, configured to collect the in-and-out traffic, log information, and environment information of key nodes; the log information includes at least application logs, system logs, and database logs, and the environment information includes at least terminal communication sessions, process information, file information, and account changes;
[0024] An analysis and processing module, configured to perform analysis and processing based on the in-and-out traffic of the key nodes to obtain a security warning log of an attack behavior;
[0025] An association analysis module, configured to perform association analysis on the security warning log, the log information, and the environment information to obtain an association analysis result;
[0026] An attack portrait and attack path generation module, configured to generate a vulnerability knowledge base, and generate an attack portrait and an attack path if the association analysis result is a security event.
[0027] Optionally, the security warning log in the association analysis module includes a request header, a request body, a response header, and a response body. The association analysis module includes:
[0028] A first judgment unit, configured to determine the association analysis result as a security event if the attack feature in the HTTP request packet in the warning log matches the log information and the environment information, and the content of the HTTP return packet in the warning log matches the attack feature; the return packet content includes at least one of service data and application environment information;
[0029] A second judgment unit, configured to determine the association analysis result as an attempted attack if the attack feature in the HTTP request header in the warning log matches the log information and the environment information and the content of the HTTP return packet in the warning log matching the attack feature cannot be satisfied simultaneously.
[0030] The present invention also provides an intrusion analysis device for a communication device, including:
[0031] A memory, configured to store a computer program;
[0032] A processor, configured to execute the computer program to implement the steps of the intrusion analysis method for the communication device as described above.
[0033] The present invention also provides a readable storage medium, configured to store a computer program, wherein the computer program, when executed by a processor, implements the steps of the intrusion analysis method for the communication device as described above.
[0034] It can be seen that the intrusion analysis method for a communication device provided by the present invention includes collecting the inbound and outbound traffic, log information, and environmental information of key nodes. Among them, the log information includes at least application logs, system logs, and database logs, and the environmental information includes at least terminal communication sessions, process information, file information, and account changes. Analyze and process the inbound and outbound traffic of key nodes to obtain security warning logs of attack behaviors, and conduct correlation analysis on the security warning logs, log information, and environmental information to obtain the correlation analysis results. If the correlation analysis result is a security event, generate a vulnerability knowledge base, and generate an attack profile and an attack path. By correlating and analyzing the warning logs, log information, and environmental information, the present invention can accurately determine whether there are system vulnerabilities in the server, generate a vulnerability knowledge base, quickly find the attack source, reduce the damage degree of the communication system, and ensure the security of the communication system.
[0035] In addition, the present invention also provides an intrusion analysis device, equipment, and storage medium for a communication device, which also have the above beneficial effects. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.
[0037] Figure 1 It is a flowchart of an intrusion analysis method for a communication device provided by an embodiment of the present invention;
[0038] Figure 2 It is an example diagram of an intrusion analysis method for a communication device provided by an embodiment of the present invention;
[0039] Figure 3 It is a schematic structural diagram of an intrusion analysis device for a communication device provided by an embodiment of the present invention;
[0040] Figure 4 It is a schematic structural diagram of an intrusion analysis device for a communication device provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0041] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0042] Please refer to Figure 1 , Figure 1 which is a flowchart of an intrusion analysis method for a communication device provided by an embodiment of the present invention. The method may include:
[0043] S101: Collect the incoming and outgoing traffic, log information, and environmental information of key nodes.
[0044] The execution subject of this embodiment is a processor. It should be noted that in this embodiment, the log information at least includes application logs, system logs, and database logs, and the environmental information at least includes terminal communication sessions, process information, file information, and account changes.
[0045] This embodiment does not limit the frequency of collecting the incoming and outgoing traffic, log information, and environmental information of key nodes, as long as the incoming and outgoing traffic, log information, and environmental information of key nodes can be collected in a timely manner. For example, the incoming and outgoing traffic, log information, and environmental information of key nodes can be collected in real time, or the operation of collecting the incoming and outgoing traffic, log information, and environmental information of key nodes can also be performed every first preset acquisition time period. This embodiment does not limit the set value of the first preset acquisition time period. For example, the first preset acquisition time period can be 1 minute, or the first preset acquisition time period can also be 5 minutes, or the first preset acquisition time period can also be 8 minutes. This embodiment does not limit the setting basis of the first preset acquisition time period. For example, the first preset acquisition time period can be set according to the operator's self-definition, or the first preset acquisition time period can also be set according to the priority of the intrusion analysis of the communication device. The higher the priority level of the intrusion analysis of the communication device, the smaller the set value of the first preset acquisition time period.
[0046] S102: Analyze and process according to the incoming and outgoing traffic of key nodes to obtain a security warning log of attack behavior.
[0047] It should be noted that in this embodiment, the network traffic can be sent to a traffic detection device through the traffic mirroring function of the switch, and then the protocols in the traffic are analyzed to parse and identify whether there is abnormal content or attack characteristics in each field of the protocol packet, so as to achieve the purpose of analyzing and processing according to the incoming and outgoing traffic of key nodes and obtaining a security warning log of attack behavior.
[0048] S103: Perform correlation analysis on the security warning log, log information, and environmental information to obtain a correlation analysis result.
[0049] This embodiment can solve the problem of a certain false alarm rate and inability to determine whether malicious code has been successfully executed on the server when tracing the source based only on security alarm logs, by correlating and analyzing security alarm logs, log information and environmental information. It also solves the problem of low efficiency and possible analysis omissions when tracing the source only through local logs of the server.
[0050] Further, in order to improve the efficiency of intrusion analysis of communication equipment, the above-mentioned security alarm log may include a request header, a request body, a response header and a response body, wherein the security alarm log, the log information and the environment information are correlated and analyzed to obtain the correlation analysis result, which may include the following steps:
[0051] If the attack signature in the HTTP request packet in the alarm log matches the log information and environment information, and the HTTP return packet content in the alarm log matches the attack signature, the correlation analysis result is determined as a security event; the return packet content includes at least one of the business data and application environment information;
[0052] If the attack feature in the HTTP request header in the alarm log matches the log information and the environment information and the HTTP return packet content in the alarm log matches the attack feature, but they cannot be satisfied at the same time, the correlation analysis result is determined as an attempted attack. It should be noted that in this embodiment, the error information is not used as the basis for determining sensitive information, but the specific business system data or server environment information is used as the basis for determining sensitive information.
[0053] S104: If the result of the correlation analysis is a security incident, a vulnerability knowledge base is generated, and an attack profile and attack path are generated.
[0054] It should be noted that, in this embodiment, security events include at least events of obtaining internal information of the application environment through vulnerabilities, events of controlling the server, and events of entering the intranet environment to conduct other illegal activities. In this embodiment, the attack profile may include the attack IP (network protocol), attack means, and attack time. In this embodiment, all identified weaknesses are grouped together to form a weakness knowledge base. This embodiment does not limit the specific content of the weakness knowledge base. For example, the specific content of the weakness knowledge base may include one of the weakness location, weakness name, weakness description, and reinforcement suggestions, or the specific content of the weakness knowledge base may include a combination of any items of the weakness location, weakness name, weakness description, and reinforcement suggestions.
[0055] Furthermore, in order to improve the efficiency of intrusion analysis of communication devices and improve the functionality of the generated vulnerability knowledge base, if the above-mentioned correlation analysis result is a security event, generating a vulnerability knowledge base may include:
[0056] Generate weaknesses based on the association analysis results; the weaknesses include weakness location, weakness name, weakness description, and reinforcement suggestions;
[0057] Save the weaknesses to the weakness knowledge base.
[0058] It should be noted that the content description of each weakness in this embodiment may include the following field contents:
[0059] Weakness location: The specific location for implanting malicious code in the HTTP request header;
[0060] Weakness name: Used to describe the name of the weakness;
[0061] Weakness description: Used to introduce the specific principle of the weakness formation;
[0062] Reinforcement suggestions: Used to put forward reinforcement suggestions for the weakness, which may include at least one of upgrading patches, modifying configurations, and filtering characters.
[0063] This embodiment does not limit the frequency of saving the weaknesses to the weakness knowledge base, as long as the weaknesses can be saved in a timely manner. For example, the weaknesses can be saved to the weakness knowledge base in real time, or the operation of saving the weaknesses to the weakness knowledge base can also be performed every preset interval time period. This embodiment does not limit the set value of the preset interval time period. For example, the set value of the preset interval time period can be 5 seconds, or the set value of the preset interval time period can also be 30 seconds, or the set value of the preset interval time period can also be 2 minutes.
[0064] Furthermore, in order to improve the functionality of intrusion analysis for communication devices, after generating weaknesses based on the association analysis results as described above, it may further include:
[0065] Provide a response strategy using the reinforcement suggestions.
[0066] This embodiment does not limit the specific content of providing a response strategy using the reinforcement suggestions, as long as the intrusion can be blocked in a timely manner. For example, the specific content of the response strategy can be one of banning an IP, closing permissions, and isolating a file, or the specific content of the response strategy can also be a combination of any items among banning an IP, closing permissions, and isolating a file.
[0067] Furthermore, in order to comprehensively obtain weaknesses, the following steps may further be included:
[0068] Obtain the vulnerabilities collected by the vulnerability scanner; among them, the vulnerabilities are WEB application layer security vulnerabilities, system layer vulnerabilities, and other protocol vulnerabilities;
[0069] Generate weaknesses based on the vulnerabilities.
[0070] This embodiment does not limit the frequency of obtaining the vulnerabilities collected by the vulnerability scanner, as long as the vulnerabilities collected by the vulnerability scanner can be obtained in a timely manner. For example, the vulnerabilities collected by the vulnerability scanner can be obtained in real time, or the operation of obtaining can be performed once every second preset acquisition time period. This embodiment does not limit the set value of the second preset acquisition time period. For example, the second preset acquisition time period can be 1 minute, or the second preset acquisition time period can also be 5 minutes, or the second preset acquisition time period can also be 8 minutes. This embodiment does not limit the basis for setting the second preset acquisition time period. For example, the second preset acquisition time period can be set according to the self-definition of the operator, or the second preset acquisition time period can also be set according to the priority of the intrusion analysis of the communication device. The higher the priority level of the intrusion analysis of the communication device, the smaller the set value of the second preset acquisition time period.
[0071] It should be noted that in this embodiment, since the alarm obtained by analyzing and processing the traffic is based on the feature library, and the feature library is inevitably incomplete and misses alarms, actively obtaining vulnerability information as the weakness knowledge base can make up for the above-mentioned defects, and an alarm is generated when an attack behavior against the vulnerability appears in the traffic.
[0072] Furthermore, in order to improve the accuracy of the correlation analysis result obtained through correlation analysis, the above-mentioned correlation analysis of the security alarm log, log information, and environment information to obtain the correlation analysis result may include the following steps:
[0073] Use feature correlation and logical correlation to perform correlation analysis on the security alarm log, log information, and environment information to obtain the correlation analysis result; feature correlation means that the features carried in the attacker's behavior of attacking through the weaknesses existing in the system can have a certain keyword feature correlation with the log information and environment information, and logical correlation means that the attacker's attack behavior through the weaknesses existing in the system has a certain logical relationship correlation with the subsequent log information and environment information of the invaded terminal.
[0074] It should be noted that in this embodiment, feature correlation refers to the scenario where the attacker directly uses the weaknesses existing in the system to directly execute illegal instructions, upload malicious files such as Trojans or backdoors, and then perform indirect partial or complete control. By correlating the attack features with the collected log information and environment information, it is determined whether a security event exists, and the judgment scenarios are as follows:
[0075] Environmental Information Association: Compare the external IP keyword features in the netstat (a program in the kernel to access network connection status and related information) session of the terminal with the server IP features in the warning logs such as Trojan backconnection and remote control, including time, keywords, etc. If the comparison is successful, confirm the existence of an association relationship, confirm that this session is an abnormal session, and identify the application program file name and path corresponding to the PS (a type of computer instruction) process ID (the process ID is a numerical value used by the kernel of most operating systems to uniquely identify a process) of this session as malicious programs. At the same time, the keyword features of this malicious program name can be further compared with the file name features in the warning such as upload vulnerability exploitation, including time, keywords, etc. If the comparison is successful, further confirm the existence of an association relationship and provide portrait information for the generation of the attack path.
[0076] Log Information Association: According to the log information such as bash_history (the history of Linux commands), tomcat (a Servlet container, where Servlet is a class in the Java programming language), and apache (a web server software, where web is the World Wide Web) in the server, determine whether the log features are compared with the malicious code keyword features in the vulnerability exploitation warning, such as: system command execution, malicious code, SQL (Structured Query Language) statements, WebShell (a code execution environment) path and name, etc. If the comparison is successful, confirm the existence of an association relationship, and then further combine the return packet information to confirm whether it is a security event and whether there are exploitable vulnerabilities.
[0077] Logical Association is judged by whether there is a certain logical association among the warning attack behavior features, log information, and environmental information features. The main scenarios are as follows:
[0078] Through the log information association, it is confirmed that there is an illegal creation of a new operating system account using a vulnerability for the attacker to disguise as a legitimate user to log in, and if the illegal account login behavior appears later, then in the logical relationship, the operation records after login can be identified as illegal operation behaviors, providing portrait information for the generation of the attack path.
[0079] Through the log information association, it is confirmed that there is an illegal creation of a new database account using a vulnerability for the attacker to disguise as a legitimate user to log in. Through the environmental information association, it is confirmed that the account-related information in the terminal environment has changed accordingly, and if the illegal account login behavior appears later, then in the logical relationship, the operation records after login can be identified as illegal operation behaviors, providing portrait information for the generation of the attack path.
[0080] It is confirmed through log information correlation that there is an illegal modification of the system login account password by exploiting vulnerabilities for attackers to disguise as legitimate users. It is confirmed through environmental information correlation that the account-related information in the terminal environment has changed accordingly, and if the account login behavior occurs afterwards, then logically, the operation records after login can be identified as illegal operation behaviors, providing portrait information for the generation of the attack path.
[0081] It is confirmed through log information correlation that there is an illegal modification of the database login account password by exploiting vulnerabilities for attackers to disguise as legitimate users. It is confirmed through environmental information correlation that the account-related information in the terminal environment has changed accordingly, and if the account login behavior occurs afterwards, then logically, the operation records after login can be identified as illegal operation behaviors, providing portrait information for the generation of the attack path.
[0082] It is confirmed through log information correlation that there are other behaviors of penetration by exploiting vulnerabilities, such as illegal creation or password modification of other accounts other than the above systems and databases, brute-force password cracking, weak passwords, etc. It is confirmed through environmental information correlation that other relevant information in the terminal environment has changed accordingly, such as file changes other than the above account changes. If a login behavior that matches the account keyword, destination IP keyword, etc. in the alarm appears afterwards, then logically, the operation records after login can be identified as illegal operation behaviors, providing portrait information for the generation of the attack path.
[0083] Applying the intrusion analysis method of the communication device provided by the embodiments of the present invention includes collecting the in-and-out traffic, log information, and environmental information of key nodes. Among them, the log information includes at least application logs, system logs, and database logs, and the environmental information includes at least terminal communication sessions, process information, file information, and account changes. Analyze and process the in-and-out traffic of key nodes to obtain security alert logs of attack behaviors, perform correlation analysis on the security alert logs, log information, and environmental information to obtain correlation analysis results. If the correlation analysis result is a security event, generate a vulnerability knowledge base, and generate an attack profile and an attack path. The security events include at least events of obtaining internal information of the application environment through vulnerabilities, events of controlling the server, and events of entering the internal network environment for other illegal activities. By correlating and analyzing the alert logs, log information, and environmental information, the present invention can accurately determine whether there are system vulnerabilities in the server, generate a vulnerability knowledge base, quickly find the attack source, reduce the damage degree of the communication system, and ensure the security of the communication system. In addition, the present invention performs correlation analysis on the security alert logs, log information, and environmental information through the request headers, request bodies, response headers, and response bodies in the security alert logs, improving the efficiency of intrusion analysis of the communication device; the vulnerability content includes the vulnerability location, vulnerability name, vulnerability description, and reinforcement suggestions, improving the efficiency of intrusion analysis of the communication device and further improving the functionality of the generated vulnerability knowledge base; providing response strategies using the above reinforcement suggestions, improving the functionality of intrusion analysis of the communication device; obtaining more comprehensive vulnerabilities by acquiring the vulnerabilities collected by the vulnerability scanner; and improving the accuracy of the correlation analysis results by performing correlation analysis on the security alert logs, log information, and environmental information using feature correlation and logical correlation.
[0084] For the convenience of understanding the present invention, please specifically refer to Figure 2 , Figure 2 which is an example diagram of an intrusion analysis method for a communication device provided by an embodiment of the present invention, and specifically may include:
[0085] Collect the in-and-out traffic, log information, and environmental information of key nodes; among them, the log information includes application logs, system logs, and database logs, and the environmental information includes communication sessions, process information, file information, and account changes. Analyze and process the in-and-out traffic of key nodes to obtain security alert logs of attack behaviors;
[0086] Obtain the vulnerabilities collected by the vulnerability scanner. Since analyzing and processing traffic to obtain alerts is based on a signature database, and the signature database is inevitably incomplete and may miss alerts, actively obtaining vulnerability information as a weakness knowledge base can make up for the above-mentioned defects, and generate alerts when attack behaviors against vulnerabilities occur in the traffic; the vulnerabilities are WEB application layer security vulnerabilities, system layer vulnerabilities, and other protocol vulnerabilities, and weaknesses are generated based on the vulnerabilities.
[0087] If there is a certain correlation between the attack signatures in the HTTP request packets in the alert log, the log information, and the environment information, and the content of the HTTP response packet in the alert log is a result matching the attack signature, then determine the correlation analysis result as a security event; otherwise, record it as an alert event for an attack attempt. Among them, the response packet content mainly includes at least one of business data, application environment information, etc. And mark the existence of a weakness, and gather all the identified weaknesses together to form a weakness knowledge base.
[0088] Use feature correlation and logical correlation to perform correlation analysis on security alert logs and environment information to generate an attack portrait and an attack path.
[0089] Next, an intrusion analysis device for a communication device provided by an embodiment of the present invention will be introduced. The intrusion analysis device for a communication device described below can be correspondingly referred to the intrusion analysis method for a communication device described above.
[0090] Specifically, please refer to Figure 3 , Figure 3 which is a schematic structural diagram of an intrusion analysis device for a communication device provided by an embodiment of the present invention, and may include:
[0091] A collection module 100, configured to collect the incoming and outgoing traffic, log information, and environment information of key nodes; the log information includes at least application logs, system logs, and database logs, and the environment information includes at least terminal communication sessions, process information, file information, and account changes.
[0092] An analysis and processing module 200, configured to perform analysis and processing based on the incoming and outgoing traffic of the key nodes to obtain security alert logs of attack behaviors.
[0093] A correlation analysis module 300, configured to perform correlation analysis on the security alert logs, the log information, and the environment information to obtain a correlation analysis result.
[0094] An attack profile and attack path generation module 400, configured to generate a vulnerability knowledge base and generate an attack profile and an attack path if the correlation analysis result is a security incident; the security incident includes at least an incident of obtaining internal information of an application environment through a vulnerability, an incident of controlling a server, and an incident of entering an intranet environment for other illegal activities.
[0095] Further, based on the above embodiment, the security alert log in the correlation analysis module 300 includes a request header, a request body, a response header, and a response body. The correlation analysis module 300 may include:
[0096] A first judgment unit, configured to determine the correlation analysis result as a security incident if the attack feature in the HTTP request packet in the alert log matches the log information and the environment information, and the content of the HTTP return packet in the alert log matches the attack feature; the content of the return packet includes at least one of service data and application environment information;
[0097] A second judgment unit, configured to determine the correlation analysis result as an attempted attack if the attack feature in the HTTP request header in the alert log matches the log information and the environment information and the content of the HTTP return packet in the alert log matching the attack feature cannot be satisfied simultaneously.
[0098] Further, based on the above embodiment, the attack profile and attack path generation module 400 may include:
[0099] A generation unit, configured to generate vulnerabilities according to the correlation analysis result; the vulnerabilities include vulnerability locations, vulnerability names, vulnerability descriptions, and reinforcement suggestions;
[0100] An execution unit, configured to save the vulnerabilities to a vulnerability knowledge base.
[0101] Further, based on the above embodiment, the intrusion analysis device of the communication device may further include:
[0102] An acquisition module, configured to acquire vulnerabilities collected by a vulnerability scanner; the vulnerabilities are WEB application layer security vulnerabilities, system layer vulnerabilities, and other protocol vulnerabilities;
[0103] A vulnerability generation module, configured to generate the vulnerabilities according to the acquired vulnerabilities.
[0104] Further, based on the above embodiment, the correlation analysis module 300 may include:
[0105] An association analysis unit is configured to perform association analysis on the security alert logs, the log information, and the environment information by using feature association and logical association to obtain an association analysis result. The feature association means that the features carried in the attacker's behavior of attacking through the vulnerabilities existing in the system can have a certain keyword feature relevance with the log information and the environment information. The logical association means that the attacker's attack behavior through the vulnerabilities existing in the system has a certain logical relationship relevance with the subsequent log information and environment information of the invaded terminal.
[0106] Further, based on the above embodiments, the attack portrait and attack path generation module 400 may further include:
[0107] A response unit is configured to provide a response strategy by using the reinforcement suggestions.
[0108] It should be noted that the order of the modules and units in the intrusion analysis device of the above communication device can be changed before and after without affecting the logic.
[0109] Applying the intrusion analysis device for a communication device provided by an embodiment of the present invention, the acquisition module 100 is used to acquire the incoming and outgoing traffic, log information, and environmental information of key nodes. Among them, the log information includes at least application logs, system logs, and database logs, and the environmental information includes at least terminal communication sessions, process information, file information, and account changes. The analysis and processing module 200 is used to perform analysis and processing based on the incoming and outgoing traffic of key nodes to obtain a security warning log for attack behaviors. The correlation analysis module 300 is used to perform correlation analysis on the security warning log, log information, and environmental information to obtain a correlation analysis result. The attack portrait and attack path generation module 400 is used to generate a vulnerability knowledge base, an attack portrait, and an attack path if the correlation analysis result is a security event. The security events include at least events of obtaining internal information of the application environment through vulnerabilities, events of controlling the server, and events of entering the internal network environment for other illegal activities. By performing correlation analysis on the warning log, log information, and environmental information, the present invention can accurately determine whether there are system vulnerabilities in the server, generate a vulnerability knowledge base, quickly find the attack source, reduce the damage degree of the communication system, and ensure the security of the communication system. In addition, the present invention performs correlation analysis on the security warning log, log information, and environmental information through the request header, request body, response header, and response body in the security warning log, improving the efficiency of intrusion analysis of the communication device; the vulnerability content includes the vulnerability location, vulnerability name, vulnerability description, and reinforcement suggestions, improving the efficiency of intrusion analysis of the communication device and further improving the functionality of the generated vulnerability knowledge base; providing response strategies using the above reinforcement suggestions improves the functionality of intrusion analysis of the communication device; by obtaining the vulnerabilities collected by the vulnerability scanner, more comprehensive vulnerabilities can be obtained; by performing correlation analysis on the security warning log, log information, and environmental information using feature correlation and logical correlation, the accuracy of the correlation analysis result is improved.
[0110] The following introduces the intrusion analysis device for a communication device provided by an embodiment of the present invention. The intrusion analysis device for a communication device described below can be correspondingly referred to the intrusion analysis method for a communication device described above.
[0111] Please refer to Figure 4 , Figure 4 which is a schematic structural diagram of an intrusion analysis device for a communication device provided by an embodiment of the present invention, and may include:
[0112] A memory 10, configured to store a computer program;
[0113] A processor 20, configured to execute the computer program to implement the above-mentioned intrusion analysis method for a communication device.
[0114] The memory 10, the processor 20, and the communication interface 31 all complete communication with each other through a communication bus 32.
[0115] In an embodiment of the present invention, the memory 10 is used to store one or more programs. The program may include program code, and the program code includes computer operation instructions. In an embodiment of the present application, the memory 10 may store a program for implementing the following functions:
[0116] Collect the in-and-out traffic, log information, and environment information of key nodes; the log information includes at least application logs, system logs, and database logs, and the environment information includes at least terminal communication sessions, process information, file information, and account changes;
[0117] Analyze and process the in-and-out traffic of key nodes to obtain a security warning log of attack behavior;
[0118] Perform correlation analysis on the security warning log, log information, and environment information to obtain a correlation analysis result;
[0119] If the correlation analysis result is a security event, generate a vulnerability knowledge base, and generate an attack profile and an attack path; the security event includes at least an event of obtaining internal information of the application environment through a vulnerability, an event of controlling the server, and an event of entering the intranet environment for other illegal activities.
[0120] In a possible implementation, the memory 10 may include a program storage area and a data storage area. Among them, the program storage area may store an operating system and application programs required for at least one function, etc.; the data storage area may store data created during use.
[0121] In addition, the memory 10 may include a read-only memory and a random access memory, and provide instructions and data to the processor. A part of the memory may also include NVRAM. The memory stores an operating system and operation instructions, executable modules, or data structures, or subsets thereof, or extended sets thereof. Among them, the operation instructions may include various operation instructions for implementing various operations. The operating system may include various system programs for implementing various basic tasks and processing hardware-based tasks.
[0122] The processor 20 may be a central processing unit (CPU), an application-specific integrated circuit, a digital signal processor, a field programmable gate array, or other programmable logic devices. The processor 20 may be a microprocessor or any conventional processor, etc. The processor 20 may call the program stored in the memory 10.
[0123] The communication interface 31 may be an interface of a communication module for connecting to other devices or systems.
[0124] Of course, it should be noted thatFigure 4 The structure shown does not constitute a limitation on the intrusion analysis device of the communication device in the embodiments of the present application. In actual applications, the intrusion analysis device of the communication device may include more or fewer components than those shown, or combine certain components. Figure 4 than those shown.
[0125] Next, the storage medium provided by the embodiments of the present invention will be introduced. The storage medium described below can be correspondingly referred to the intrusion analysis method of the communication device described above.
[0126] The present invention also provides a storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the above-mentioned intrusion analysis method of the communication device are implemented.
[0127] The storage medium may include various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disc.
[0128] In the present specification, the embodiments are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts among the embodiments can be referred to each other. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple. For the related parts, refer to the description of the method part.
[0129] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in this article can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in the form of hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.
[0130] Finally, it should be noted that in this article, relationships such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such process, method, article or device.
[0131] The above has introduced in detail a method, device, equipment and storage medium for intrusion analysis of a communication device provided by the present invention. Specific examples are used in this article to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present invention.
Claims
1. An intrusion analysis method for a communication device, characterized in that, Including: Collecting the in - and - out traffic, log information, and environment information of key nodes; the log information includes at least application logs, system logs, and database logs, and the environment information includes at least terminal communication sessions, process information, file information, and account changes; Analyzing and processing the in - and - out traffic of the key nodes to obtain a security alert log of attack behavior; Performing correlation analysis on the security alert log, the log information, and the environment information to obtain a correlation analysis result; If the correlation analysis result is a security event, generating a vulnerability knowledge base, and generating an attack portrait and an attack path; the security events include at least events of obtaining internal information of the application environment through vulnerabilities, events of controlling the server, and events of entering the internal network environment for other illegal activities; The security alert log includes a request header, a request body, a response header, and a response body. The performing correlation analysis on the security alert log, the log information, and the environment information to obtain a correlation analysis result includes: If the attack features in the HTTP request packet in the security alert log match the log information and the environment information, and the content of the HTTP return packet in the security alert log matches the attack features, then determining the correlation analysis result as a security event; the return packet content includes at least one of service data and application environment information; If the attack features in the HTTP request header in the security alert log match the log information and the environment information, and the content of the HTTP return packet in the security alert log matching the attack features cannot be satisfied simultaneously, then determining the correlation analysis result as an attempted attack.
2. The intrusion analysis method of the communication device according to claim 1, characterized in that, The if the correlation analysis result is a security event, generating a vulnerability knowledge base, includes: Generating vulnerabilities according to the correlation analysis result; the vulnerabilities include vulnerability locations, vulnerability names, vulnerability descriptions, and reinforcement suggestions; Saving the vulnerabilities to the vulnerability knowledge base.
3. The intrusion analysis method of the communication device according to claim 2, wherein Also including: Obtaining the vulnerabilities collected by a vulnerability scanner; The vulnerabilities are WEB application layer security vulnerabilities, system layer vulnerabilities, and other protocol vulnerabilities; Generating the vulnerabilities according to the vulnerabilities.
4. The intrusion analysis method of the communication device according to any one of claims 1 to 3, characterized in that, The performing correlation analysis on the security alert log, the log information, and the environment information to obtain a correlation analysis result includes: Performing correlation analysis on the security alert log, the log information, and the environment information using feature correlation and logical correlation to obtain a correlation analysis result; the feature correlation means that the features carried in the attacker's behavior of attacking through vulnerabilities in the system can have a certain keyword feature correlation with the log information and the environment information, and the logical correlation means that the attacker's attack behavior through vulnerabilities in the system has a certain logical relationship correlation with the subsequent log information and environment information of the invaded terminal.
5. The intrusion analysis method of the communication device according to claim 2, characterized in that, After generating the vulnerabilities according to the correlation analysis result, it also includes: Providing a response strategy using the reinforcement suggestions.
6. An intrusion analysis device for a communication device, characterized in that, Including: A collection module, configured to collect the inbound and outbound traffic, log information, and environment information of key nodes; the log information includes at least application logs, system logs, and database logs, and the environment information includes at least terminal communication sessions, process information, file information, and account changes; An analysis and processing module, configured to perform analysis and processing based on the inbound and outbound traffic of the key nodes to obtain a security alert log of attack behaviors; An association analysis module, configured to perform association analysis on the security alert log, the log information, and the environment information to obtain an association analysis result; An attack profile and attack path generation module, configured to generate a vulnerability knowledge base, and generate an attack profile and an attack path if the association analysis result is a security event; the security events include at least events of obtaining internal information of the application environment through vulnerabilities, events of controlling the server, and events of entering the internal network environment for other illegal activities; The security alert log in the association analysis module includes a request header, a request body, a response header, and a response body. The association analysis module includes: A first determination unit, configured to determine the association analysis result as a security event if the attack features in the HTTP request packet in the security alert log match the log information and the environment information, and the content of the HTTP return packet in the security alert log matches the attack features; the content of the return packet includes at least one of service data and application environment information; A second determination unit, configured to determine the association analysis result as an attempted attack if it cannot be satisfied simultaneously that the attack features in the HTTP request header in the security alert log match the log information and the environment information, and the content of the HTTP return packet in the security alert log matches the attack features.
7. An intrusion analysis device for a communication device, characterized in that, Including: A memory, configured to store a computer program; A processor, configured to implement the steps of the intrusion analysis method of the communication device according to any one of claims 1 to 5 when executing the computer program.
8. A storage medium, characterized in that, A computer program is stored on the storage medium, and when the computer program is executed by the processor, the steps of the intrusion analysis method of the communication device according to any one of claims 1 to 5 are implemented.
Citation Information
Patent Citations
Security detection method and system based on attack association
CN104811447A