Network security incident analysis method, equipment and storage medium

By calculating the hazard coefficient of network security incidents and performing characteristic analysis and early warning, the problem of not being able to identify low-hazard level events in the prior art is solved, effective assessment and early warning of network security incidents are achieved, and the losses of network security incidents are reduced.

CN116170216BActive Publication Date: 2025-08-08SHANGHAI QINGBIAO INFORMATION TECH SERVICE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202310160877.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-23
Publication Date
2025-08-08
Estimated Expiration
2043-02-23

AI Technical Summary

Technical Problem

The existing network security incident analysis methods cannot effectively filter out low-hazard levels of network security incidents, resulting in Internet users being unable to clearly identify real security threats, causing large direct losses.

Method used

By collecting network security incident information, computer infection number, transmission speed and direct loss information, the event hazard coefficient is generated, high, medium and low hazard levels are marked according to the coefficient size, and high-hazard events are characterized and warning notifications are carried out to improve the security software policy level in the infected area, and isolate or prompt suspicious files.

Benefits of technology

Effectively filter low-hazard level events, help users identify real security threats, reduce losses, timely warning of high-risk events, and improve network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116170216B_ABST
    Figure CN116170216B_ABST
Patent Text Reader

Abstract

The present invention belongs to the technical field of network security event analysis and discloses a network security event analysis method, comprising: collecting network security event information, the network security event information including hazard factors; receiving computer infection quantity information, propagation speed information, and direct loss information in the hazard factors, marking the computer infection quantity information, propagation speed information, and direct loss information as Jsi, Csi, and Zsi, respectively, performing a formulaic analysis on the information to obtain an event hazard coefficient Whxi; generating a high hazard mark, a medium hazard mark, and a low hazard mark for a corresponding network security event according to the magnitude of the event hazard coefficient Whxi; and rationally and effectively filtering out network security events with low hazard levels by analyzing the hazard factors of the network security events, thereby enabling Internet users to clearly recognize and understand the real security threats in the target network, drawing sufficient attention thereto, and reducing losses caused by the corresponding network security events.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network security event analysis, and more specifically, to a network security event analysis method, device, and storage medium. Background Art

[0002] Existing network security incident analysis methods cannot reasonably and effectively filter out those network security incidents with low-level hazards. The Internet is full of various network security incidents, which makes it impossible for Internet users to clearly recognize and understand the real security threats in the target network and fail to pay enough attention, resulting in corresponding network security incidents causing large direct losses.

[0003] In view of this, the inventors of the present application invented a network security incident analysis method, device and storage medium. Summary of the Invention

[0004] In order to overcome the above-mentioned defects of the prior art, embodiments of the present invention provide a network security event analysis method, device and storage medium.

[0005] To achieve the above objectives, the present invention provides the following technical solution: a network security incident analysis method, comprising:

[0006] Collecting network security incident information, including hazard factors;

[0007] Receive computer infection quantity information, propagation speed information, and direct loss information from the hazard factor, mark the computer infection quantity information, propagation speed information, and direct loss information as Jsi, Csi, and Zsi, respectively, where i=1, 2, 3...i, and i is the number of network security events. Formulate and analyze them to obtain the event hazard coefficient Whxi; based on the size of the event hazard coefficient Whxi, generate a high hazard mark, a medium hazard mark, and a low hazard mark for the corresponding network security event.

[0008] In a preferred embodiment, the hazard factors include computer infection quantity information, propagation speed information, and direct loss estimation information. The computer infection quantity information is the number of computers infected by computer viruses per unit time; the propagation speed information is the average time value for infecting each computer per unit time; and the direct loss information is the estimated amount of loss directly caused to the unit or individual by all infected computers per unit time.

[0009] In a preferred embodiment, the step of generating a high-risk mark, a medium-risk mark, and a low-risk mark includes setting an event risk coefficient range threshold, and if the event risk coefficient Whxi is greater than or equal to the maximum value of the event risk coefficient range threshold, a high-risk mark is generated for the corresponding network security event;

[0010] If the event hazard coefficient Whxi is less than the maximum value of the event hazard coefficient range threshold and greater than the minimum value of the event hazard coefficient range threshold, a medium hazard mark is generated for the corresponding network security event;

[0011] If the event hazard coefficient Whxi is less than or equal to the minimum value of the event hazard coefficient range threshold, a low hazard mark is generated for the corresponding network security event.

[0012] In a preferred embodiment, a network security event corresponding to a high-risk marker is first obtained, characteristics of the network security event are analyzed, self-characteristic information and attack characteristic information are generated, and the generated self-characteristic information and attack characteristic information are associated with the corresponding network security event and stored;

[0013] The self-characteristic information includes non-standard information of HTTP version field, non-standard information of request header field, and non-standard information of file name suffix;

[0014] The attack feature information includes attack target features, attack methods and attack targets; the attack methods include denial of service attacks, backdoor attacks, vulnerability attacks, network scanning and eavesdropping, and phishing attacks;

[0015] Entering a solution corresponding to the network security incident based on the attack feature information;

[0016] The attack target feature acquisition step includes acquiring the names of attacked enterprises corresponding to the high-risk marked network security events, marking the number of attacked enterprise names as n, where n is an integer greater than 1, and first acquiring administrative region information of the n enterprise names;

[0017] Then, the business scope information that matches the names of the n attacked companies is searched from the enterprise query system;

[0018] Count the number of administrative region information, rank them in descending order based on the number of administrative region information, and generate attack administrative region ranking information;

[0019] Count the number of overlapping business items in the n business scope information, rank them in descending order according to the number of overlapping business items, and generate attack item ranking information;

[0020] According to the descending ranking of the attacking administrative regions, all enterprise information in the attacked administrative regions is obtained in sequence. The enterprise information includes enterprise name and business scope, and forms the first warning notification target;

[0021] Then, the enterprise information in the first warning notification object is ranked in descending order according to the descending ranking in the attack project ranking information to generate a second warning notification object. Then, according to the ranking of the second warning notification object, the corresponding enterprise is informed of the warning information. The warning information includes the above-mentioned self-feature information, attack feature information and corresponding solutions to network security incidents.

[0022] In a preferred embodiment, the regional hazard coefficient Qxk is calculated for each administrative region according to the administrative region. The step of obtaining the regional hazard coefficient Qxk includes collecting regional hazard factors, wherein the regional hazard factors include regional computer infection quantity information, regional propagation speed information, and regional direct loss estimation information. The regional computer infection quantity information is the number of computer virus infections in each administrative region per unit time. The number of infected computers; the regional transmission speed information is the average time it takes for each computer in the administrative area to be infected per unit time; the regional direct loss information is the estimated amount of loss directly caused to the unit or individual by all infected computers per unit time;

[0023] The regional computer infection number information, regional transmission speed information, and regional direct loss estimation information are marked as Jsk, Csk, and Zsk respectively, and the regional hazard coefficient Qxk is obtained by formulating and analyzing them;

[0024] Set the regional hazard coefficient range reference value WH, substitute the regional hazard coefficient Qxk into the range reference value WH for analysis. If the regional hazard coefficient Qxk is greater than or equal to WH, the corresponding administrative area will be marked as a heavily infected area; if the regional hazard coefficient Qxk is less than WH, the corresponding administrative area will be marked as a lightly infected area;

[0025] Raise the file transfer policy level of all computer security software in administrative regions marked as heavily infected areas to high. File transfer policy levels include high, medium, and general. If a transferred file has the aforementioned characteristic information, delete it, quarantine it, or issue a prompt to run it with caution.

[0026] Obtaining the source address of the file, which is the current file storage address. If the file's source address is from an administrative area marked as a heavily infected area, a prompt is issued, including file deletion, isolation, or a prompt to operate with caution.

[0027] Continue to mark the regional hazard coefficient Qxk of administrative areas with heavily infected areas, obtain s regional hazard coefficients Qxk per unit time, establish a hazard coefficient set, calculate the mean and proximity coefficient within the hazard coefficient set, and if the mean is greater than or equal to WH and the proximity coefficient is less than the proximity coefficient threshold, do not change the current file transfer policy level;

[0028] If the mean is greater than or equal to WH, and the proximity coefficient is greater than or equal to the proximity coefficient threshold, the previous file transfer policy level is lowered to medium;

[0029] If the mean value is less than WH, the previous file transfer policy level is lowered to normal.

[0030] Network security incident analysis equipment, including:

[0031] A data collection module collects network security event information and sends the collected network security event information to the event analysis module, wherein the network security event information includes hazard factors;

[0032] The event analysis module receives the computer infection quantity information, propagation speed information, and direct loss information from the hazard factor, and marks the computer infection quantity information, propagation speed information, and direct loss information as Jsi, Csi, and Zsi, respectively, where i = 1, 2, 3...i, and i is the number of network security events. It performs a formulaic analysis on the information to obtain the event hazard coefficient Whx; according to the size of the event hazard coefficient Whxi, it generates a high hazard mark, a medium hazard mark, and a low hazard mark for the corresponding network security event.

[0033] In a preferred embodiment, the hazard factors include computer infection quantity information, propagation speed information, and direct loss estimation information. The computer infection quantity information is the number of computers infected by computer viruses per unit time; the propagation speed information is the average time value for infecting each computer per unit time; and the direct loss information is the estimated amount of loss directly caused to the unit or individual by all infected computers per unit time.

[0034] In a preferred embodiment, the step of generating a high-risk mark, a medium-risk mark, and a low-risk mark includes setting an event risk coefficient range threshold, and if the event risk coefficient Whxi is greater than or equal to the maximum value of the event risk coefficient range threshold, a high-risk mark is generated for the corresponding network security event;

[0035] If the event hazard coefficient Whxi is less than the maximum value of the event hazard coefficient range threshold and greater than the minimum value of the event hazard coefficient range threshold, a medium hazard mark is generated for the corresponding network security event;

[0036] If the event hazard coefficient Whxi is less than or equal to the minimum value of the event hazard coefficient range threshold, a low hazard mark is generated for the corresponding network security event.

[0037] In a preferred embodiment, it also includes a hazard depth analysis module, an event storage module, and an attack response module;

[0038] The hazard depth analysis module first obtains network security events corresponding to high-hazard labels, analyzes the characteristics of the network security events, generates self-feature information and attack feature information, and associates the generated self-feature information and attack feature information with the corresponding network security events and stores them in the event storage module;

[0039] The self-characteristic information includes non-standard information of HTTP version field, non-standard information of request header field, and non-standard information of file name suffix;

[0040] The attack feature information includes attack target features, attack methods and attack targets; the attack methods include denial of service attacks, backdoor attacks, vulnerability attacks, network scanning and eavesdropping, and phishing attacks;

[0041] An attack response module, which inputs solutions corresponding to network security incidents based on the attack feature information;

[0042] The attack target feature acquisition step includes acquiring the names of attacked enterprises corresponding to the high-risk marked network security events, marking the number of attacked enterprise names as n, where n is an integer greater than 1, and first acquiring administrative region information of the n enterprise names;

[0043] Then, the business scope information that matches the names of the n attacked companies is searched from the enterprise query system;

[0044] Count the number of administrative region information, rank them in descending order based on the number of administrative region information, and generate attack administrative region ranking information;

[0045] Count the number of overlapping business items in the n business scope information, rank them in descending order according to the number of overlapping business items, and generate attack item ranking information;

[0046] The early warning notification module obtains information on all enterprises in the attacked administrative region in descending order according to the attack administrative region ranking information. The enterprise information includes the enterprise name and business scope, forming the first early warning notification object;

[0047] Then, the enterprise information in the first warning notification object is ranked in descending order according to the descending ranking in the attack project ranking information to generate a second warning notification object. Then, according to the ranking of the second warning notification object, the corresponding enterprise is informed of the warning information. The warning information includes the above-mentioned self-feature information, attack feature information and corresponding solutions to network security incidents.

[0048] In a preferred embodiment, it also includes an event depth analysis module, a source prompt module, and a continuous monitoring module;

[0049] The event depth analysis module calculates the regional hazard coefficient Qxk for each administrative region according to the administrative region. The step of obtaining the regional hazard coefficient Qxk includes collecting regional hazard factors, which include regional computer infection quantity information, regional transmission speed information, and regional direct loss estimation information. The regional computer infection quantity information is the number of computer virus infections in each administrative region per unit time. The number of infected computers; the regional transmission speed information is the average time it takes for each computer in the administrative area to be infected per unit time; the regional direct loss information is the estimated amount of loss directly caused to the unit or individual by all infected computers per unit time;

[0050] The regional computer infection number information, regional transmission speed information, and regional direct loss estimation information are marked as Jsk, Csk, and Zsk respectively, and the regional hazard coefficient Qxk is obtained by formulating and analyzing them;

[0051] Set the regional hazard coefficient range reference value WH, substitute the regional hazard coefficient Qxk into the range reference value WH for analysis. If the regional hazard coefficient Qxk is greater than or equal to WH, the corresponding administrative area will be marked as a heavily infected area; if the regional hazard coefficient Qxk is less than WH, the corresponding administrative area will be marked as a lightly infected area;

[0052] Raise the file transfer policy level of all computer security software in administrative regions marked as heavily infected areas to high. File transfer policy levels include high, medium, and general. If a transferred file has the aforementioned characteristic information, delete it, quarantine it, or issue a prompt to run it with caution.

[0053] The source prompt module runs in the computer and obtains the source address of the file, which is the current file storage address. If the source address of the file is from an administrative area marked as a heavily infected area, a prompt is issued, including file deletion, isolation, or a prompt to run with caution.

[0054] The continuous monitoring module continuously marks the regional hazard coefficient Qxk of administrative areas with heavily infected areas, obtains the hazard coefficient Qxk of s areas per unit time, establishes a hazard coefficient set, and calculates the mean and proximity coefficient within the hazard coefficient set. If the mean is greater than or equal to WH and the proximity coefficient is less than the proximity coefficient threshold, the current file transfer policy level is not changed;

[0055] If the mean is greater than or equal to WH, and the proximity coefficient is greater than or equal to the proximity coefficient threshold, the previous file transfer policy level is lowered to medium;

[0056] If the mean value is less than WH, the previous file transfer policy level is lowered to normal.

[0057] A storage medium storing a computer program, wherein the program, when executed by a processor, implements any of the methods described above.

[0058] The technical effects and advantages of the network security incident analysis method, device, and storage medium of the present invention are as follows:

[0059] (1) By analyzing the hazard factors of network security incidents, conducting security assessments on corresponding network security incidents, generating different hazard level labels for network security incidents, and reasonably and effectively filtering out those network security incidents with low hazard levels, Internet users can clearly recognize and understand the real security threats in the target network, attract sufficient attention, and provide a quantifiable basis for warnings and other responses. Reduce the losses caused by corresponding network security incidents.

[0060] (2) First, the first warning notification object is generated for the names of the enterprises in the city that are most attacked. Then, the first warning notification object is ranked in descending order according to the number of overlapping business projects. Warnings are given priority to the enterprises with higher rankings. The warning notification method includes sending information or making phone calls to the person in charge of the enterprise. Warnings are given priority to the enterprises in the city that are most attacked. Then, the enterprises in the city are ranked in descending order according to the number of vulnerable business projects. Warnings are given priority to the enterprises with higher rankings. This ensures that the most vulnerable enterprises in the most vulnerable cities are notified of warnings in a timely manner, take defensive measures as soon as possible, and avoid the direct harm caused by security and network security incidents to the greatest extent. BRIEF DESCRIPTION OF THE DRAWINGS

[0061] Figure 1 A schematic diagram of a network security event analysis device according to the present invention;

[0062] Figure 2 Schematic diagram of the network security incident analysis method of the present invention. DETAILED DESCRIPTION

[0063] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0064] Example 1

[0065] See also Figure 1 As shown, the network security event analysis device described in this embodiment includes a data acquisition module 1, an event analysis module 2, a hazard depth analysis module 3, an attack response module 4, an early warning notification module 5, and an event storage module 6.

[0066] The data collection module 1 collects network security event information and sends the collected network security event information to the event analysis module 2; the network security event information includes hazard factors.

[0067] The above-mentioned hazard factors include information on the number of computers infected, information on the speed of transmission, and information on estimated direct losses. The information on the number of computers infected refers to the number of computers infected by computer viruses per unit time; the information on the speed of transmission refers to the average time it takes to infect each computer per unit time; and the information on direct losses refers to the estimated amount of losses directly caused to the unit or individual by all infected computers per unit time, excluding indirect losses.

[0068] The event analysis module 2 receives the computer infection quantity information, propagation speed information, and direct loss information from the hazard factor, and marks the computer infection quantity information, propagation speed information, and direct loss information as Jsi, Csi, and Zsi, respectively, where i = 1, 2, 3, ... i, and i is the number of network security events. According to the formula, Whxi = e1*Jsi+e2*Csi+e3*Zsi, the event hazard coefficient Whxi is obtained; where e1, e2, and e3 are preset proportional coefficients, e1>e2>e3>0;

[0069] It should be noted that the larger the performance value of the event hazard coefficient Whxi, the greater the harm caused by the network security incident to the corresponding computer virus and to society. The preset proportional coefficient in the formula is used to balance the proportion of various data in the formula, thereby promoting the accuracy of the calculation results.

[0070] Set the event hazard coefficient range threshold. If the event hazard coefficient Whxi is greater than or equal to the maximum value of the event hazard coefficient range threshold, a high hazard mark is generated for the corresponding network security event.

[0071] If the event hazard coefficient Whxi is less than the maximum value of the event hazard coefficient range threshold and greater than the minimum value of the event hazard coefficient range threshold, a medium hazard mark is generated for the corresponding network security event;

[0072] If the event hazard coefficient Whxi is less than or equal to the minimum value of the event hazard coefficient range threshold, a low hazard mark is generated for the corresponding network security event;

[0073] According to the degree of harm, they are high harm mark, medium harm mark, and low harm mark. For example, the network security incidents corresponding to the high harm mark cause more infected computers and direct losses than the network security incidents corresponding to the medium harm mark and low harm mark. The network security incidents corresponding to the low harm mark are the lowest, so the medium harm mark and low harm mark do not need to be analyzed.

[0074] By analyzing the hazard factors of network security incidents, conducting security assessments on the corresponding network security incidents, generating different hazard level labels for network security incidents, and reasonably and effectively filtering out those with lower hazard levels, Internet users can clearly recognize and understand the real security threats in the target network, drawing sufficient attention, and providing a quantifiable basis for alerts and other responses, thereby reducing the losses caused by the corresponding network security incidents.

[0075] The hazard depth analysis module 3 first obtains network security events corresponding to high hazard labels, analyzes the characteristics of the network security events, generates its own characteristic information and attack characteristic information, and associates the generated own characteristic information and attack characteristic information with the corresponding network security events, and stores them in the event storage module 6.

[0076] The above-mentioned characteristic information includes information about non-standard HTTP version fields, non-standard request header fields, and non-standard file name suffixes. Among them, non-standard HTTP version field information includes: descriptions of GET / H / 1.1, GET / HTT / 1.1, GET / HTTP / 1.a, and GET / HTTP / 0.9. Non-standard request header field information includes descriptions of: HTTP request header fields ending with \r\n, for example: GET / HTTP / 1.1\r\nHost:172.16.132.207:12345\rab\r\n\r\n. Non-standard file name suffixes include jsp, php, py, and asp.

[0077] Attack feature information includes attack target characteristics, attack methods used, and attack targets; attack methods used include denial of service attacks, backdoor attacks, vulnerability attacks, network scanning and eavesdropping, phishing attacks, etc.

[0078] Attack response module 4 inputs solutions corresponding to network security incidents based on attack feature information, such as backdoor attacks and vulnerability attacks, and promptly publishes methods for corresponding backdoors and provides patches for maintaining vulnerabilities. Here, technical personnel design maintenance plans based on the attack feature information extracted by the hazard depth analysis module 3.

[0079] The steps for acquiring attack target characteristics include: acquiring the names of attacked enterprises corresponding to high-risk marked network security events, marking the number of attacked enterprise names as n, where n is an integer greater than 1, first acquiring the administrative region information of the n enterprise names, that is, identifying the words "province" or "city" in the enterprises; then querying the business scope information consistent with the n attacked enterprise names from the enterprise query system; counting the number of administrative region information, ranking them in descending order according to the number of administrative region information, and generating attack administrative region ranking information; counting the number of overlapping business items in the n business scope information, ranking them in descending order according to the number of overlapping business items, and generating attack item ranking information.

[0080] The early warning notification module 5 obtains all enterprise information in the attacked administrative area in sequence according to the descending ranking in the attack administrative area ranking information. The enterprise information includes the enterprise name and business scope to form a first early warning notification object. Then, the enterprise information in the first early warning notification object is ranked in descending order according to the descending ranking in the attack project ranking information to generate a second early warning notification object. Then, according to the ranking of the second early warning notification object, the corresponding enterprise is notified of the early warning information. The early warning information includes the above-mentioned self-feature information, attack feature information and corresponding solutions to network security incidents.

[0081] First, the first early warning notification object is generated for the names of enterprises in the city that are most attacked. Then, the first early warning notification objects are ranked in descending order according to the number of overlapping business projects. Warnings are sent first to the enterprises with higher rankings. The early warning notification methods include sending messages or making phone calls to the heads of enterprises. Warnings are given priority to enterprises in the city that are most attacked. Then, the enterprises in the city are ranked in descending order according to the number of vulnerable business projects. Warnings are given priority to the enterprises with higher rankings. This ensures that the most vulnerable enterprises in the most vulnerable cities are notified of warnings in a timely manner, take defensive measures as soon as possible, and avoid the direct harm caused by security and network security incidents to the greatest extent.

[0082] Secondly, there are many recipients of notifications. Classifying them according to the administrative regions and enterprises most vulnerable to attacks makes notifications to the heads of relevant enterprises more targeted and efficient. It also avoids sending early warning notifications in large quantities, which may cause congestion in communication channels and ensures the normal operation of analysis equipment.

[0083] In order to reduce the losses caused by network security incidents and reduce the propagation speed of computer viruses corresponding to network security incidents, the network security incident device also includes an event depth analysis module 7, a source prompt module 8, and a continuous monitoring module 9.

[0084] The event depth analysis module 7 calculates the regional hazard coefficient Qxk for each administrative region according to the administrative region. The step of obtaining the regional hazard coefficient Qxk includes collecting regional hazard factors, the regional hazard factors including regional computer infection quantity information, regional transmission speed information, and regional direct loss estimation information. The regional computer infection quantity information is the number of computer virus infections in each administrative region per unit time. The regional transmission speed information is the average time it takes for each computer to be infected in the administrative area per unit time; the regional direct loss information is the estimated amount of loss directly caused to the unit or individual by all infected computers per unit time.

[0085] The regional computer infection number information, regional transmission speed information, and regional direct loss estimation information are marked as Jsk, Csk, and Zsk respectively. According to the formula, In the formula All are preset proportional coefficients.

[0086] It should be noted that the larger the performance value of the regional hazard coefficient Qxk, the greater the harm caused to the corresponding administrative region by the computer virus corresponding to the network security incident, where k represents the number of administrative regions and k is an integer greater than 1.

[0087] Set the regional hazard coefficient range reference value WH, substitute the regional hazard coefficient Qxk into the range reference value WH for analysis. If the regional hazard coefficient Qxk is greater than or equal to WH, the corresponding administrative area will be marked as a heavily infected area; if the regional hazard coefficient Qxk is less than WH, the corresponding administrative area will be marked as a lightly infected area.

[0088] Improve the file transfer policy level of all computer security software in administrative areas with heavily infected areas and set it to advanced. The file transfer policy levels include advanced, intermediate and general. The file transfer policy corresponding to the advanced level has a higher level of review of transferred files than the file transfer policy corresponding to the intermediate level, and the intermediate level is higher than the general level accordingly. For the identification of transferred files, if the transferred file has the characteristic information of itself, it will be deleted, isolated or prompted to run with caution.

[0089] Different administrative regions are distinguished according to the size of the regional hazard coefficient, and the file transfer policy level of all computer security software in administrative regions with heavily infected areas is improved. Files with the aforementioned characteristic information are deleted, isolated, or prompted to run with caution, so as to attract the attention of users, hinder the continued spread of computer viruses corresponding to network security incidents in heavily infected administrative regions, and reduce their continued harm to the corresponding administrative regions.

[0090] Secondly, by distinguishing different administrative regions according to the size of the regional hazard coefficient, only the file transfer policy level of all computer security software in the administrative regions with heavy infection areas is increased. The increase is made in a small range, reducing the impact of the file transfer policy level increase on computer user habits, and affecting the user's office efficiency in using computers in a small range.

[0091] The above-mentioned computers include computers, mobile phones, and devices with data storage functions.

[0092] The source prompt module 8 runs in the computer and obtains the source address of the file. The source address is the current file storage address, such as the administrative area where the sending device is located, such as the location of the server, computer, and computer. If the source address of the file is obtained from an administrative area marked as a heavily infected area, a prompt is issued, including file deletion, isolation, or a prompt to run with caution.

[0093] By obtaining the source address of the file, a prompt will be issued when the source address of the file is from an administrative area marked as a heavily infected area. This can reduce the probability of the computer virus corresponding to the network security incident spreading to other administrative areas with lightly infected areas, reduce the probability of computer virus mutation caused by cross-transmission, and help improve the efficiency of clearing network security incidents.

[0094] The continuous monitoring module 9 continuously calculates the regional hazard coefficient Qxk of administrative areas marked with heavily infected areas, obtains s regional hazard coefficients Qxk per unit time, establishes a hazard coefficient set, calculates the mean and proximity coefficient in the hazard coefficient set, and if the mean is greater than or equal to WH and the proximity coefficient is less than the proximity coefficient threshold, the current file transfer policy level will not be changed, that is, it will be maintained at a high level.

[0095] If the mean is greater than or equal to WH, and the proximity coefficient is greater than or equal to the proximity coefficient threshold, it means that the spread speed and harm of the computer virus corresponding to the network security incident are under control and are slowing down. In this case, the previous file transfer policy level should be lowered to medium to avoid long-term impact on the user's computer office efficiency.

[0096] If the mean value is less than WH, the previous file transfer policy level is lowered to normal.

[0097] Through continuous monitoring, the regional hazard coefficient of administrative areas with heavy infection areas is marked. According to the changes in the regional hazard coefficient, the file transfer policy level is adjusted in time to avoid long-term impact on the office efficiency of users using computers.

[0098] Example 2

[0099] See also Figure 2As shown, for the parts not described in detail in this embodiment, please refer to the description of embodiment 1. A network security incident analysis method is provided, and the method includes:

[0100] Collecting network security incident information, including hazard factors;

[0101] Receive computer infection quantity information, propagation speed information, and direct loss information from the hazard factor, mark the computer infection quantity information, propagation speed information, and direct loss information as Jsi, Csi, and Zsi, respectively, where i=1, 2, 3...i, and i is the number of network security events. Formulate and analyze them to obtain the event hazard coefficient Whxi; based on the size of the event hazard coefficient Whxi, generate a high hazard mark, a medium hazard mark, and a low hazard mark for the corresponding network security event.

[0102] In a preferred embodiment, the hazard factors include computer infection quantity information, propagation speed information, and direct loss estimation information. The computer infection quantity information is the number of computers infected by computer viruses per unit time; the propagation speed information is the average time value for infecting each computer per unit time; and the direct loss information is the estimated amount of loss directly caused to the unit or individual by all infected computers per unit time.

[0103] In a preferred embodiment, the step of generating a high-risk mark, a medium-risk mark, and a low-risk mark includes setting an event risk coefficient range threshold, and if the event risk coefficient Whxi is greater than or equal to the maximum value of the event risk coefficient range threshold, a high-risk mark is generated for the corresponding network security event;

[0104] If the event hazard coefficient Whxi is less than the maximum value of the event hazard coefficient range threshold and greater than the minimum value of the event hazard coefficient range threshold, a medium hazard mark is generated for the corresponding network security event;

[0105] If the event hazard coefficient Whxi is less than or equal to the minimum value of the event hazard coefficient range threshold, a low hazard mark is generated for the corresponding network security event.

[0106] In a preferred embodiment, a network security event corresponding to a high-risk marker is first obtained, characteristics of the network security event are analyzed, self-characteristic information and attack characteristic information are generated, and the generated self-characteristic information and attack characteristic information are associated with the corresponding network security event and stored;

[0107] The self-characteristic information includes non-standard information of HTTP version field, non-standard information of request header field, and non-standard information of file name suffix;

[0108] The attack feature information includes attack target features, attack methods and attack targets; the attack methods include denial of service attacks, backdoor attacks, vulnerability attacks, network scanning and eavesdropping, and phishing attacks;

[0109] Entering a solution corresponding to the network security incident based on the attack feature information;

[0110] The attack target feature acquisition step includes acquiring the names of attacked enterprises corresponding to the high-risk marked network security events, marking the number of attacked enterprise names as n, where n is an integer greater than 1, and first acquiring administrative region information of the n enterprise names;

[0111] Then, the business scope information that matches the names of the n attacked companies is searched from the enterprise query system;

[0112] Count the number of administrative region information, rank them in descending order based on the number of administrative region information, and generate attack administrative region ranking information;

[0113] Count the number of overlapping business items in the n business scope information, rank them in descending order according to the number of overlapping business items, and generate attack item ranking information;

[0114] According to the descending ranking of the attacking administrative regions, all enterprise information in the attacked administrative regions is obtained in sequence. The enterprise information includes enterprise name and business scope, and forms the first warning notification target;

[0115] Then, the enterprise information in the first warning notification object is ranked in descending order according to the descending ranking in the attack project ranking information to generate a second warning notification object. Then, according to the ranking of the second warning notification object, the corresponding enterprise is informed of the warning information. The warning information includes the above-mentioned self-feature information, attack feature information and corresponding solutions to network security incidents.

[0116] The regional hazard coefficient Qxk is calculated for each administrative region according to the administrative region. The steps of obtaining the regional hazard coefficient Qxk include collecting regional hazard factors, the regional hazard factors including regional computer infection quantity information, regional transmission speed information, and regional direct loss estimation information. The regional computer infection quantity information is the number of computer virus infections in each administrative region per unit time. The number of infected computers; the regional transmission speed information is the average time it takes for each computer in the administrative area to be infected per unit time; the regional direct loss information is the estimated amount of loss directly caused to the unit or individual by all infected computers per unit time;

[0117] The regional computer infection number information, regional transmission speed information, and regional direct loss estimation information are marked as Jsk, Csk, and Zsk respectively, and the regional hazard coefficient Qxk is obtained by formulating and analyzing them;

[0118] Set the regional hazard coefficient range reference value WH, substitute the regional hazard coefficient Qxk into the range reference value WH for analysis. If the regional hazard coefficient Qxk is greater than or equal to WH, the corresponding administrative area will be marked as a heavily infected area; if the regional hazard coefficient Qxk is less than WH, the corresponding administrative area will be marked as a lightly infected area;

[0119] Raise the file transfer policy level of all computer security software in administrative regions marked as heavily infected areas to high. File transfer policy levels include high, medium, and general. If a transferred file has the aforementioned characteristic information, delete it, quarantine it, or issue a prompt to run it with caution.

[0120] Obtaining the source address of the file, which is the current file storage address. If the file's source address is from an administrative area marked as a heavily infected area, a prompt is issued, including file deletion, isolation, or a prompt to operate with caution.

[0121] Continue to mark the regional hazard coefficient Qxk of administrative areas with heavily infected areas, obtain s regional hazard coefficients Qxk per unit time, establish a hazard coefficient set, calculate the mean and proximity coefficient within the hazard coefficient set, and if the mean is greater than or equal to WH and the proximity coefficient is less than the proximity coefficient threshold, do not change the current file transfer policy level;

[0122] If the mean is greater than or equal to WH, and the proximity coefficient is greater than or equal to the proximity coefficient threshold, the previous file transfer policy level is lowered to medium;

[0123] If the mean value is less than WH, the previous file transfer policy level is lowered to normal.

[0124] The above formulas are all dimensionless and numerical calculations. The formulas are obtained by collecting a large amount of data and performing software simulation to obtain the most recent real situation. The preset parameters and thresholds in the formulas are set by technicians in this field according to actual conditions.

[0125] The above embodiments can be implemented in whole or in part by software, hardware, firmware or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer program are loaded or executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more available media sets. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.

[0126] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0127] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0128] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is only one type. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0129] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0130] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0131] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0132] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

[0133] Finally: The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A network security incident analysis method, characterized in that: include: Collecting network security incident information, including hazard factors; Receive computer infection quantity information, propagation speed information, and direct loss information from the hazard factor, mark the computer infection quantity information, propagation speed information, and direct loss information as Jsi, Csi, and Zsi, respectively, where i=1, 2, 3...i, and i is the number of network security events, perform a formula analysis on the information, and calculate the event hazard coefficient Whxi; based on the size of the event hazard coefficient Whxi, generate a high hazard label, a medium hazard label, and a low hazard label for the corresponding network security event; First, a network security event corresponding to a high-risk marker is obtained, the characteristics of the network security event are analyzed, self-feature information and attack feature information are generated, and the generated self-feature information and attack feature information are associated with the corresponding network security event and stored; The self-characteristic information includes non-standard information of HTTP version field, non-standard information of request header field, and non-standard information of file name suffix; The attack feature information includes attack target features, attack methods and attack targets; the attack methods include denial of service attacks, backdoor attacks, vulnerability attacks, network scanning and eavesdropping, and phishing attacks; Entering a solution corresponding to the network security incident based on the attack feature information; The attack target feature acquisition step includes acquiring the names of attacked enterprises corresponding to the high-risk marked network security events, marking the number of attacked enterprise names as n, where n is an integer greater than 1, and first acquiring administrative region information of the n enterprise names; Then, the business scope information that matches the names of the n attacked companies is searched from the enterprise query system; Count the number of administrative region information, rank them in descending order based on the number of administrative region information, and generate attack administrative region ranking information; Count the number of overlapping business items in the n business scope information, rank them in descending order according to the number of overlapping business items, and generate attack item ranking information; According to the descending ranking of the attacking administrative regions, all enterprise information in the attacked administrative regions is obtained in sequence. The enterprise information includes enterprise name and business scope, and forms the first warning notification target; Then, the enterprise information in the first warning notification object is ranked in descending order according to the descending ranking in the attack project ranking information to generate a second warning notification object. Then, according to the ranking of the second warning notification object, the corresponding enterprise is informed of the warning information. The warning information includes the above-mentioned self-feature information, attack feature information and corresponding solutions to network security incidents.

2. The network security incident analysis method according to claim 1, characterized in that: The computer infection quantity information is the number of computers infected by the computer virus per unit time; the propagation speed information is the average time it takes to infect each computer per unit time; and the direct loss information is the estimated amount of loss directly caused to the unit or individual by all infected computers within the unit time.

3. The network security incident analysis method according to claim 2, characterized in that: The steps of generating a high-risk mark, a medium-risk mark, and a low-risk mark include setting an event risk coefficient range threshold, and if the event risk coefficient Whxi is greater than or equal to the maximum value of the event risk coefficient range threshold, generating a high-risk mark for the corresponding network security event; If the event hazard coefficient Whxi is less than the maximum value of the event hazard coefficient range threshold and greater than the minimum value of the event hazard coefficient range threshold, a medium hazard mark is generated for the corresponding network security event; If the event hazard coefficient Whxi is less than or equal to the minimum value of the event hazard coefficient range threshold, a low hazard mark is generated for the corresponding network security event.

4. The network security incident analysis method according to claim 3, characterized in that: Calculating a regional hazard coefficient Qxk for each administrative region based on the administrative region, the step of obtaining the regional hazard coefficient Qxk includes collecting regional hazard factors, the regional hazard factors including regional computer infection quantity information, regional transmission speed information, and regional direct loss estimation information, the regional computer infection quantity information being the number of computers infected by computer viruses in each administrative region per unit time; the regional transmission speed information being the average time it takes for each computer to be infected within the administrative region per unit time; and the regional direct loss estimation information being the estimated amount of loss directly caused to an organization or individual by all infected computers per unit time; The regional computer infection number information, regional transmission speed information, and regional direct loss estimation information are marked as Jsk, Csk, and Zsk respectively, and the regional hazard coefficient Qxk is obtained by formulating and analyzing them; Set the regional hazard coefficient range reference value WH, substitute the regional hazard coefficient Qxk into the range reference value WH for analysis. If the regional hazard coefficient Qxk is greater than or equal to WH, the corresponding administrative area will be marked as a heavily infected area; if the regional hazard coefficient Qxk is less than WH, the corresponding administrative area will be marked as a lightly infected area; Raise the file transfer policy level of all computer security software in administrative regions marked as heavily infected areas to high. File transfer policy levels include high, medium, and general. If a transferred file has the aforementioned characteristic information, delete it, quarantine it, or issue a prompt to run it with caution. Obtaining the source address of the file, which is the current file storage address. If the file's source address is from an administrative area marked as a heavily infected area, a prompt is issued, including file deletion, isolation, or a prompt to operate with caution. Continue to mark the regional hazard coefficient Qxk of administrative areas with heavily infected areas, obtain s regional hazard coefficients Qxk per unit time, establish a hazard coefficient set, calculate the mean and proximity coefficient within the hazard coefficient set, and if the mean is greater than or equal to WH and the proximity coefficient is less than the proximity coefficient threshold, do not change the current file transfer policy level; If the mean is greater than or equal to WH, and the proximity coefficient is greater than or equal to the proximity coefficient threshold, the previous file transfer policy level is lowered to medium; If the mean value is less than WH, the previous file transfer policy level is lowered to normal.

5. Network security incident analysis equipment, characterized in that include: A data collection module (1) collects network security event information and sends the collected network security event information to an event analysis module (2), wherein the network security event information includes hazard factors; The event analysis module (2) receives the computer infection quantity information, propagation speed information, and direct loss information in the hazard factor, and marks the computer infection quantity information, propagation speed information, and direct loss information as Jsi, Csi, and Zsi, respectively, where i=1, 2, 3...i, and i is the number of network security events, and performs a formula analysis on the information to obtain the event hazard coefficient Whxi; according to the size of the event hazard coefficient Whxi, a high hazard mark, a medium hazard mark, and a low hazard mark are generated for the corresponding network security event; The hazard depth analysis module (3) first obtains network security events corresponding to high hazard marks, analyzes the characteristics of the network security events, generates self-feature information and attack feature information, and associates the generated self-feature information and attack feature information with the corresponding network security events, and stores them in the event storage module (6); The self-characteristic information includes non-standard information of HTTP version field, non-standard information of request header field, and non-standard information of file name suffix; The attack feature information includes attack target features, attack methods and attack targets; the attack methods include denial of service attacks, backdoor attacks, vulnerability attacks, network scanning and eavesdropping, and phishing attacks; An attack response module (4) inputs a solution corresponding to a network security incident based on the attack feature information; The attack target feature acquisition step includes acquiring the names of attacked enterprises corresponding to the high-risk marked network security events, marking the number of attacked enterprise names as n, where n is an integer greater than 1, and first acquiring administrative region information of the n enterprise names; Then, the business scope information that matches the names of the n attacked companies is searched from the enterprise query system; Count the number of administrative region information, rank them in descending order based on the number of administrative region information, and generate attack administrative region ranking information; Count the number of overlapping business items in the n business scope information, rank them in descending order according to the number of overlapping business items, and generate attack item ranking information; The early warning notification module (5) sequentially obtains information on all enterprises in the attacked administrative region according to the descending ranking of the attacking administrative region ranking information, wherein the enterprise information includes the enterprise name and business scope, and forms the first early warning notification object; Then, the enterprise information in the first warning notification object is ranked in descending order according to the descending ranking in the attack project ranking information to generate a second warning notification object. Then, according to the ranking of the second warning notification object, the corresponding enterprise is informed of the warning information. The warning information includes the above-mentioned self-feature information, attack feature information and corresponding solutions to network security incidents.

6. The network security event analysis device according to claim 5, characterized in that: The computer infection quantity information is the number of computers infected by the computer virus per unit time; the propagation speed information is the average time it takes to infect each computer per unit time; and the direct loss information is the estimated amount of loss directly caused to the unit or individual by all infected computers within the unit time.

7. The network security event analysis device according to claim 6, characterized in that: The steps of generating a high-risk mark, a medium-risk mark, and a low-risk mark include setting an event risk coefficient range threshold, and if the event risk coefficient Whxi is greater than or equal to the maximum value of the event risk coefficient range threshold, generating a high-risk mark for the corresponding network security event; If the event hazard coefficient Whxi is less than the maximum value of the event hazard coefficient range threshold and greater than the minimum value of the event hazard coefficient range threshold, a medium hazard mark is generated for the corresponding network security event; If the event hazard coefficient Whxi is less than or equal to the minimum value of the event hazard coefficient range threshold, a low hazard mark is generated for the corresponding network security event.

8. The network security event analysis device according to claim 7, characterized in that: It also includes an event depth analysis module (7), a source prompt module (8), and a continuous monitoring module (9); The event depth analysis module (7) calculates the regional hazard coefficient Qxk for each administrative region according to the administrative region. The step of obtaining the regional hazard coefficient Qxk includes collecting regional hazard factors, wherein the regional hazard factors include regional computer infection quantity information, regional propagation speed information, and regional direct loss estimation information. The regional computer infection quantity information is the number of computers infected by computer viruses in each administrative region within a unit time; the regional propagation speed information is the average time value of each computer infected within the administrative region within a unit time; and the regional direct loss estimation information is the estimated value of the loss amount directly caused to the unit or individual by all infected computers within a unit time. The regional computer infection number information, regional transmission speed information, and regional direct loss estimation information are marked as Jsk, Csk, and Zsk respectively, and the regional hazard coefficient Qxk is obtained by formulating and analyzing them; Set the regional hazard coefficient range reference value WH, substitute the regional hazard coefficient Qxk into the range reference value WH for analysis. If the regional hazard coefficient Qxk is greater than or equal to WH, the corresponding administrative area will be marked as a heavily infected area; if the regional hazard coefficient Qxk is less than WH, the corresponding administrative area will be marked as a lightly infected area; Raise the file transfer policy level of all computer security software in administrative regions marked as heavily infected areas to high. File transfer policy levels include high, medium, and general. If a transferred file has the aforementioned characteristic information, delete it, quarantine it, or issue a prompt to run it with caution. The source prompt module (8) runs in the computer and obtains the source address of the file, which is the current file storage address. If the source address of the file is from an administrative area marked as a heavily infected area, a prompt is issued, including file deletion, isolation, or a prompt to run with caution; The continuous monitoring module (9) continuously measures the regional hazard coefficient Qxk of administrative areas marked with heavily infected areas, obtains s regional hazard coefficients Qxk per unit time, establishes a hazard coefficient set, calculates the mean and proximity coefficient within the hazard coefficient set, and if the mean is greater than or equal to WH and the proximity coefficient is less than the proximity coefficient threshold, then the current file transfer policy level is not changed; If the mean is greater than or equal to WH, and the proximity coefficient is greater than or equal to the proximity coefficient threshold, the previous file transfer policy level is lowered to medium; If the mean value is less than WH, the previous file transfer policy level is lowered to normal.

9. A storage medium storing a computer program, characterized in that: When the program is executed by a processor, the method according to any one of claims 1 to 4 is implemented.