Security orchestration and automated response method and device, electronic equipment and storage medium

By identifying security orchestration scenarios and using the target gateway to execute process branches, the high complexity of security orchestration in existing technologies is solved, enabling rapid, convenient, and automated responses to security events.

CN116192440BActive Publication Date: 2026-06-02QI-ANXIN LEGENDSEC INFORMATION TECH (BEIJING) INC +1

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
QI-ANXIN LEGENDSEC INFORMATION TECH (BEIJING) INC
Filing Date
2022-12-12
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

In existing technologies, security orchestration methods based on workflow engines are highly complex, making it difficult to quickly and conveniently automate responses to security events.

Method used

By acquiring the security orchestration script to be executed, determining the security orchestration scenarios for process branches, and executing process branches based on pre-set target gateways, including sequence flow gateways, condition gateways, event gateways, etc., the automated execution of security orchestration scripts can be achieved.

Benefits of technology

It enables rapid and convenient automated response to security incidents, simplifies the scriptwriting requirements of security orchestration and automated response systems, and improves response efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116192440B_ABST
    Figure CN116192440B_ABST
Patent Text Reader

Abstract

The application provides a security arrangement and automatic response method and device, electronic equipment and storage medium, wherein the security arrangement and automatic response method comprises: obtaining a to-be-executed security arrangement script, the to-be-executed security arrangement script comprising a plurality of flow branches, the flow branches comprising a plurality of task nodes, the task nodes corresponding to security capabilities of security products; determining a security arrangement scene of the flow branches, and determining a target gateway corresponding to the security arrangement scene based on the security arrangement scene, wherein the target gateway is obtained through pre-setting; and executing the flow branches based on the target gateway to realize automatic execution of the to-be-executed security arrangement script. Through the application, the to-be-executed security arrangement script is automatically and conveniently executed, so that the security event can be quickly and conveniently responded automatically.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of security operation and maintenance technology, and in particular to a security orchestration and automated response method, apparatus, electronic device and storage medium. Background Technology

[0002] As cybersecurity offense and defense become increasingly intense, it is necessary to respond quickly to security threats and prevent and stop them in a timely manner.

[0003] According to relevant technologies, in the process of executing security orchestration scripts based on workflow engines, the gateway of the workflow engine application is highly complex and has many constraints, which makes it impossible to quickly and conveniently respond to security events automatically. Summary of the Invention

[0004] This invention provides a security orchestration and automated response method, apparatus, electronic device and storage medium, which realizes the automatic and convenient execution of security orchestration scripts to be executed, thereby enabling a fast and convenient automated response to security events.

[0005] This invention provides a security orchestration and automated response method, comprising: acquiring a security orchestration script to be executed, the script including multiple process branches, each process branch including multiple task nodes, the task nodes corresponding to the security capabilities of a security product; determining a security orchestration scenario for each process branch, and based on the security orchestration scenario, determining a target gateway corresponding to the security orchestration scenario, wherein the target gateway is obtained through pre-setting; and executing the process branch based on the target gateway to achieve automated execution of the security orchestration script to be executed.

[0006] According to a secure orchestration and automated response method provided by the present invention, determining the target gateway corresponding to the secure orchestration scenario based on the secure orchestration scenario specifically includes: when the secure orchestration scenario is that the task nodes are executed in a sequential flow manner, determining the target gateway as a sequential flow gateway, wherein the sequential flow gateway is a gateway that controls the task nodes to be executed in a preset order.

[0007] According to a secure orchestration and automated response method provided by the present invention, determining the target gateway corresponding to the secure orchestration scenario based on the secure orchestration scenario specifically includes: when the secure orchestration scenario is that the subsequent task node to be executed is determined based on the data input by the current task node, determining the target gateway as a condition-based gateway, wherein the condition-based gateway is a gateway that controls the execution of the subsequent task node based on the data and preset conditions, and the subsequent task node is the task node after the current task node in the process branch.

[0008] According to a secure orchestration and automated response method provided by the present invention, in the case where the secure orchestration scenario involves determining the subsequent task node to be executed based on the data input by the current task node, determining the target gateway as a condition-based gateway specifically includes: in the case where the secure orchestration scenario involves determining the subsequent task node to be executed based on the data input by the current task node, if the current task node is a single task node and the subsequent task nodes are multiple task nodes, determining the condition-based gateway as a condition-based branch gateway, wherein the condition-based branch gateway is a gateway that controls the execution of the subsequent task node corresponding to a target preset condition, and the target preset condition is a preset condition that satisfies the data.

[0009] According to a secure orchestration and automated response method provided by the present invention, in the case where the secure orchestration scenario involves determining the subsequent task node to be executed based on the data input by the current task node, determining the target gateway as a condition-based gateway specifically includes: in the case where the secure orchestration scenario involves determining the subsequent task node to be executed based on the data input by the current task node, if the current task node consists of multiple task nodes and the subsequent task node is a single task node, determining the condition-based gateway as a condition-based aggregation gateway, wherein the condition-based aggregation gateway is a gateway that controls the execution of the subsequent task node when the number of current task nodes corresponding to a target preset condition is a preset number, and the target preset condition is a preset condition that matches the data.

[0010] According to a secure orchestration and automated response method provided by the present invention, determining the target gateway corresponding to the secure orchestration scenario based on the secure orchestration scenario specifically includes: when the secure orchestration scenario involves determining the subsequent task node to be executed based on the events occurring at the current task node, determining the target gateway as an event-based gateway, wherein the event-based gateway is a gateway that controls the execution of the subsequent task node based on the events and preset conditions, and the subsequent task node is the task node following the current task node in the process branch.

[0011] According to a secure orchestration and automated response method provided by the present invention, in the case where the secure orchestration scenario involves determining the subsequent task node to be executed based on the events occurring at the current task node, determining the target gateway as an event-based gateway specifically includes: in the case where the secure orchestration scenario involves determining the subsequent task node to be executed based on the events occurring at the current task node, if the current task node is a single task node and the subsequent task nodes are multiple task nodes, determining the event-based gateway as an event-based branch gateway, wherein the event-based branch gateway is a gateway that controls the execution of the subsequent task node corresponding to a target preset condition, and the target preset condition is a preset condition that matches the event.

[0012] According to a secure orchestration and automated response method provided by the present invention, in the case where the secure orchestration scenario involves determining the subsequent task node to be executed based on the events occurring at the current task node, determining the target gateway as an event-based gateway specifically includes: in the case where the secure orchestration scenario involves determining the subsequent task node to be executed based on the events occurring at the current task node, if the current task node consists of multiple task nodes and the subsequent task node is a single task node, determining the event-based gateway as an event-based aggregation gateway, wherein the event-based aggregation gateway is a gateway that controls the execution of the subsequent task node when the number of current task nodes corresponding to a target preset condition is a preset number, and the target preset condition is a preset condition that matches the event.

[0013] The present invention also provides a security orchestration and automated response device, comprising: a first module for acquiring a security orchestration script to be executed, the security orchestration script including multiple process branches, each process branch including multiple task nodes, the task nodes corresponding to the security capabilities of a security product; a second module for determining a security orchestration scenario for each process branch, and based on the security orchestration scenario, determining a target gateway corresponding to the security orchestration scenario, wherein the target gateway is obtained through pre-setting; and a third module for executing the process branch based on the target gateway to achieve automated execution of the security orchestration script to be executed.

[0014] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the security orchestration and automated response method as described above.

[0015] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the security orchestration and automated response method as described above.

[0016] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements the security orchestration and automated response method as described above.

[0017] The security orchestration and automated response method, apparatus, electronic device and storage medium provided by the present invention determine the security orchestration scenario of the process branch in the security orchestration script to be executed, determine the corresponding pre-set target gateway based on the security orchestration scenario, and then execute the process branch based on the target gateway, so as to realize the automatic and convenient execution of the security orchestration script to be executed, thereby enabling a fast and convenient automated response to security events. Attached Figure Description

[0018] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0019] Figure 1 This is a flowchart illustrating the secure orchestration and automated response method provided by the present invention;

[0020] Figure 2 This is one of the structural schematic diagrams of the target gateway provided by the present invention;

[0021] Figure 3 This is the second schematic diagram of the target gateway provided by the present invention;

[0022] Figure 4 This is the third schematic diagram of the target gateway provided by the present invention;

[0023] Figure 5 This is the fourth schematic diagram of the target gateway provided by the present invention;

[0024] Figure 6 This is the fifth schematic diagram of the target gateway provided by the present invention;

[0025] Figure 7 This is the sixth schematic diagram of the target gateway provided by the present invention;

[0026] Figure 8 This is a schematic diagram of the structure of the secure orchestration and automated response device provided by the present invention;

[0027] Figure 9 This is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed Implementation

[0028] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0029] The security orchestration and automated response method provided by this invention simplifies and clarifies the script orchestration requirements and application scenarios of the security orchestration and automated response system. It designs and implements the security capabilities of various security products as orchestratable and schedulable task nodes in the process, and designs and implements gateways suitable for security orchestration scenarios to quickly and effectively express the semantics required in the script process. This allows for the automatic and convenient execution of the security orchestration script to be executed, thereby enabling a rapid and convenient automated response to security events.

[0030] To further introduce the secure orchestration and automated response method provided by this invention, the following will be combined with... Figure 1 Please provide an explanation.

[0031] Figure 1 This is a flowchart illustrating the secure orchestration and automated response method provided by the present invention.

[0032] In an exemplary embodiment of the present invention, combined with Figure 1 As can be seen, the security orchestration and automated response method may include steps 110 to 130, and each step will be described below.

[0033] In step 110, a security orchestration script to be executed is obtained. The security orchestration script to be executed includes multiple process branches, and each process branch includes multiple task nodes. The task nodes correspond to the security capabilities of the security product.

[0034] A security orchestration play to be executed can be understood as a process that combines data, technology, and team elements. It includes multiple process branches, each containing multiple task nodes.

[0035] A task node can be understood as a basic orchestration unit on a process branch. Task nodes provide the ability to respond to security events. In addition to their own built-in security capabilities, they can also extend their security response capabilities by interfacing with third-party security devices or integrating services (task plugins). Task nodes can correspond to the security capabilities of security products. In this embodiment, mapping the security capabilities of security products to task nodes facilitates script orchestration and execution.

[0036] In one embodiment, the business logic can be divided into seven categories (linked processing, approval tasks, message notifications, work orders, context enrichment, log retrieval, and intelligence query), totaling approximately 50 security capabilities. These capabilities are designed and implemented as orchestratable and schedulable task nodes within the workflow. In one example, they are categorized into six types based on technical characteristics: ServiceTask, UserTask, NotificationTask, ManualTask, ScriptTask, and Event-drivenTask. The specific task nodes for each type can be determined according to Table 1.

[0037] Table 1 Task Node Classification Table

[0038]

[0039]

[0040]

[0041]

[0042] In step 120, a security orchestration scenario for the process branch is determined, and based on the security orchestration scenario, a target gateway corresponding to the security orchestration scenario is determined, wherein the target gateway is obtained through pre-setting.

[0043] In step 130, the execution flow branch is based on the target gateway to automate the execution of the security orchestration script to be executed.

[0044] It should be noted that the target gateway is obtained through pre-configuration. During application, since most end-users of security orchestration are security analysts and operations personnel, the design and operation of script flows should focus solely on the core security business itself. To simplify and clarify the script orchestration requirements and application scenarios of the security orchestration and automated response system, a target gateway suitable for security orchestration scenarios can be designed and implemented to accurately and concisely express the semantics required in the script flow.

[0045] In one embodiment, security orchestration scenarios for each process branch in the security orchestration script to be executed can be determined separately, and based on the security orchestration scenarios, a pre-set target gateway corresponding to each security orchestration scenario can be determined. Furthermore, the process branches are executed based on the target gateway to achieve automated execution of the security orchestration script to be executed. Since the target gateway is a concise and clear gateway, and its semantics are explicit in the orchestration script, it is convenient for users to automatically and easily execute the security orchestration script to be executed during the process branch execution based on the target gateway, thereby enabling quick and convenient automated responses to security events.

[0046] The security orchestration and automated response method provided by this invention determines the security orchestration scenario of the process branch in the security orchestration script to be executed, determines the corresponding pre-set target gateway based on the security orchestration scenario, and then executes the process branch based on the target gateway, so as to realize the automatic and convenient execution of the security orchestration script to be executed, thereby enabling a fast and convenient automated response to security events.

[0047] To further illustrate each target gateway and its corresponding security orchestration scenario, the following examples will be used for explanation.

[0048] In an exemplary embodiment of the present invention, determining the target gateway corresponding to the security orchestration scenario based on the security orchestration scenario can be achieved in the following manner:

[0049] In a security orchestration scenario where task nodes are executed in a sequential flow, the target gateway is determined to be a sequential flow gateway, which controls the execution of task nodes in a preset order. The sequential flow gateway is an implicit gateway and does not need to be explicitly added to the process.

[0050] Figure 2 This is one of the structural schematic diagrams of the target gateway provided by the present invention.

[0051] In one embodiment, combined with Figure 2 As can be seen, T1 to T4 represent task nodes. When the security orchestration scenario executes task nodes in a sequential flow manner, such as executing task node T1 first and then other task nodes T2 to T4, the sequential flow gateway can be invoked. The sequential flow gateway is a gateway that controls the execution of task nodes in a preset order.

[0052] It should be noted that the preset order can be adjusted according to the actual situation, and is not specifically limited in this embodiment.

[0053] Figure 3 This is the second schematic diagram of the target gateway provided by the present invention.

[0054] In another embodiment, we will continue to use task nodes T1 to T4 as an example. If the security orchestration scenario executes task nodes in a sequential flow manner, for example, executing task nodes T1 to T3 first and then executing task node T4, we can adopt the following approach: Figure 3 The sequential flow gateway shown.

[0055] Specifically, the completion of task nodes T1, T2, and T3 means that, based on the decisions made at each decision point in the process, all tasks that should have been executed before task node T4 have already been executed. It is possible that due to the data characteristics of the process context, the path to one or two tasks at task nodes T1, T2, and T3 may be invalid. In this case, the tasks on the corresponding path do not need to be executed, and this does not affect the scheduling and execution of task node T4.

[0056] In this embodiment, since the target gateway, such as the sequential flow gateway, corresponds to the security orchestration scenario, once the security orchestration scenario is determined, the corresponding target gateway can be directly invoked for execution. Because the target gateway has clear semantics and is concise and standardized, it can automatically and conveniently execute the security orchestration script to be executed, thereby enabling a quick and convenient automated response to security events.

[0057] In yet another exemplary embodiment of the present invention, determining the target gateway corresponding to the security orchestration scenario based on the security orchestration scenario can be achieved in the following manner:

[0058] In a security orchestration scenario where the subsequent task node to be executed is determined based on the data input from the current task node, the target gateway is determined to be a condition-based gateway. Here, a condition-based gateway is a gateway that controls the execution of subsequent task nodes based on data and preset conditions. The subsequent task node is the task node after the current task node in the process branch.

[0059] In one embodiment, the current task node can be understood as the task node where the process has reached this point. Subsequent task nodes can be the task nodes following the current task node in a process branch.

[0060] In another embodiment, the condition-based gateway is a data-driven gateway that requires explicit declaration and configuration of each branch condition within the process. During application, when the security orchestration scenario is determined to involve determining the subsequent task node to be executed based on the data input from the current task node, the target gateway can be identified as the condition-based gateway. It is understood that the condition-based gateway needs to control the gateway executing in subsequent task nodes based on the data input from the current task node and preset conditions. These preset conditions can be adjusted according to actual circumstances and can be mutually exclusive or compatible conditions; in this embodiment, no specific limitations are imposed on the preset conditions.

[0061] Figure 4 This is the third schematic diagram of the target gateway provided by the present invention.

[0062] To further introduce the secure orchestration and automated response method provided by this invention, the following will be combined with... Figure 4 This document explains the process of determining the target gateway as a condition-based gateway in a security orchestration scenario where the subsequent task nodes to be executed are determined based on the data input from the current task node.

[0063] In an exemplary embodiment of the present invention, in a security orchestration scenario where the subsequent task node to be executed is determined based on the data input by the current task node, determining the target gateway as a condition-based gateway can be achieved in the following manner:

[0064] In a secure orchestration scenario where the subsequent task node to be executed is determined based on the data input from the current task node, if the current task node is a single task node and the subsequent task nodes are multiple task nodes, the condition-based gateway is determined to be a condition-based branch gateway. Here, the condition-based branch gateway is the gateway that controls the execution of the subsequent task node corresponding to the target preset condition, and the target preset condition is the preset condition that satisfies the data.

[0065] In one embodiment, combined with Figure 4 To clarify, the current task node can be understood as... Figure 4 Task node T1 in the context. Subsequent task nodes can be understood as... Figure 4 The task nodes are T2 to T4. Conditions C1 to C3 (corresponding to preset conditions) correspond to task nodes T2 to T4 respectively. It can be understood that if the data input to task node T1 satisfies condition C1, task node T2 can be executed through the target gateway G1 (corresponding to the condition-based branch gateway). If the data input to task node T1 satisfies condition C2, task node T3 can be executed through the target gateway G1 (corresponding to the condition-based branch gateway). If the data input to task node T1 satisfies condition C3, task node T4 can be executed through the target gateway G1 (corresponding to the condition-based branch gateway).

[0066] Among them, when condition C1, condition C2, or condition C3 satisfies the data, it can be called the target preset condition.

[0067] In another embodiment, if conditions C1 to C3 are mutually exclusive, meaning that the data output by task node T1 can only satisfy one condition, then the number of target preset conditions is one. In this case, the condition-based branch gateway can be understood as a condition-based exclusive branch gateway. Furthermore, only one task node among task nodes T2 to T4 will be executed.

[0068] In another embodiment, if conditions C1 to C3 are compatible conditions, meaning the data input by task node T1 can satisfy multiple conditions simultaneously, then the number of target preset conditions can be multiple. In this case, the condition-based branch gateway can be understood as a condition-based compatible branch gateway. Furthermore, the task nodes on the corresponding paths corresponding to conditions C1 to C3 will be executed.

[0069] In this embodiment, since the target gateway, such as a condition-based branch gateway, corresponds to a security orchestration scenario, once the security orchestration scenario is determined, the corresponding target gateway can be directly invoked for execution. Because the target gateway has clear and concise semantics, it can automatically and conveniently execute the security orchestration script to be executed, thereby enabling a quick and easy automated response to security events.

[0070] Figure 6 This is the fifth schematic diagram of the target gateway provided by the present invention.

[0071] To further introduce the secure orchestration and automated response method provided by this invention, the following will be combined with... Figure 6 This document explains the process of determining the target gateway as a condition-based gateway in a security orchestration scenario where the subsequent task nodes to be executed are determined based on the data input from the current task node.

[0072] In an exemplary embodiment of the present invention, in a security orchestration scenario where the subsequent task node to be executed is determined based on the data input by the current task node, determining the target gateway as a condition-based gateway can be achieved in the following manner:

[0073] In a secure orchestration scenario where the subsequent task node to be executed is determined based on the data input from the current task node, if the current task node consists of multiple task nodes and the subsequent task node is a single task node, the condition-based gateway is determined to be a condition-based aggregation gateway. The condition-based aggregation gateway is the gateway that controls the execution of the subsequent task node when the number of current task nodes corresponding to the target preset condition is a preset number. The target preset condition is a preset condition that matches the data.

[0074] In one embodiment, combined with Figure 6 To clarify, the current task node can be understood as... Figure 6 Task nodes T1 to T3 in the table. Subsequent task nodes can be understood as... Figure 6 Task node T4 is defined in the context of task nodes T1 to T3. Conditions C1 to C3 (corresponding to preset conditions) are defined for task nodes T1 to T3 respectively. Data input to task node T1 is evaluated using condition C1, data input to task node T2 is evaluated using condition C2, and data input to task node T3 is evaluated using condition C3.

[0075] During the application process, if the data input to task node T1 satisfies condition C1, the data input to task node T2 satisfies condition C2, and the data input to task node T3 satisfies condition C3, task node T4 can be executed through target gateway G1 (corresponding to the condition-based aggregation gateway).

[0076] Among them, when condition C1, condition C2, or condition C3 satisfies the data, it can be called the target preset condition.

[0077] In another embodiment, for the target gateway G1, the task nodes T1 to T3 referenced by it execute data and combine it with the business scenario configuration conditions. Task node T4 is only executed when the data input by each task node satisfies conditions T1 to T3. At this time, the number of current task nodes corresponding to the target preset conditions is 3 (corresponding to the preset number). That is, when the preset number is the same as the number of current task nodes, the condition-based aggregation gateway can be understood as a condition-based AND-type aggregation gateway.

[0078] In another embodiment, for the target gateway G1, the execution data of the task nodes T1 to T3 are combined with the business scenario configuration conditions. When any task node in the input data of each task node meets the corresponding preset condition, task node T4 can be executed. At this time, the number of current task nodes corresponding to the target preset condition is less than 3 (corresponding to the preset number). That is, when the preset number is greater than the number of current task nodes corresponding to the target preset condition, then the condition-based aggregation gateway can be understood as a condition-based OR-type aggregation gateway.

[0079] In this embodiment, since the target gateway, such as a condition-based aggregation gateway, corresponds to a security orchestration scenario, once the security orchestration scenario is determined, the corresponding target gateway can be directly invoked for execution. Because the target gateway has clear and concise semantics, it can automatically and conveniently execute the security orchestration script to be executed, thereby enabling a quick and easy automated response to security events.

[0080] In yet another exemplary embodiment of the present invention, determining the target gateway corresponding to the security orchestration scenario based on the security orchestration scenario can be achieved in the following manner:

[0081] In a secure orchestration scenario, where the target gateway is determined as an event-based gateway based on the events that occur at the current task node and the subsequent task node needs to be executed, the target gateway is determined as an event-based gateway. Here, the event-based gateway is a gateway that controls the execution of the subsequent task node based on events and preset conditions. The subsequent task node is the task node after the current task node in the process branch.

[0082] In one embodiment, the current task node can be understood as the task node where the process has reached this point. Subsequent task nodes can be the task nodes following the current task node in a process branch.

[0083] In another embodiment, the event-based gateway is a message-driven gateway, requiring explicit declaration and configuration of the events listened to by each branch within the process. During application, when the security orchestration scenario is determined to involve determining the subsequent task node to be executed based on the events occurring at the current task node, the target gateway can be identified as an event-based gateway. It is understood that the event-based gateway needs to control the gateway executing on subsequent task nodes based on the events occurring at the current task node and preset conditions. These preset conditions can be adjusted according to actual circumstances and can be mutually exclusive or compatible conditions; in this embodiment, no specific limitations are imposed on the preset conditions.

[0084] Figure 5 This is the fourth schematic diagram of the target gateway provided by the present invention.

[0085] To further introduce the secure orchestration and automated response method provided by this invention, the following will be combined with... Figure 5 This section explains the process of determining the target gateway as an event-based gateway in a security orchestration scenario where the subsequent task node to be executed is determined based on the events occurring at the current task node that are monitored.

[0086] In an exemplary embodiment of the present invention, in a security orchestration scenario where the subsequent task node to be executed is determined based on the events occurring at the current task node, determining the target gateway as an event-based gateway can be achieved in the following way:

[0087] In a secure orchestration scenario, where the subsequent task node to be executed is determined based on the events that occur in the current task node, if the current task node is a single task node and the subsequent task nodes are multiple task nodes, the event-based gateway is determined to be an event-based branch gateway. The event-based branch gateway is the gateway that controls the execution of the subsequent task node that corresponds to the target preset condition, and the target preset condition is a preset condition that matches the event.

[0088] In one embodiment, combined with Figure 6 To clarify, the current task node can be understood as... Figure 6 Task node T1 in the context. Subsequent task nodes can be understood as... Figure 6 Task nodes T2 to T4 are defined in the table. Conditions E1 to E3 (corresponding to preset conditions) correspond to task nodes T2 to T4 respectively.

[0089] Understandably, if the event of task node T1 that is monitored satisfies condition E1, it means that condition E1 matches the event. During application, task node T2 can be executed through the target gateway G1 (corresponding to the event-based branch gateway). If the event of task node T1 that is monitored satisfies condition E2, task node T3 can be executed through the target gateway G1 (corresponding to the event-based branch gateway). If the event of task node T1 that is monitored satisfies condition E3, task node T4 can be executed through the target gateway G1 (corresponding to the event-based branch gateway).

[0090] Among them, when condition E1, condition E2, or condition E3 matches the event of the monitored task node T1, it can be called the target preset condition.

[0091] In another embodiment, if conditions E1 to E3 are mutually exclusive, meaning that only one condition can be met for the monitored event of task node T1, then the number of target preset conditions is one. In this case, the condition-based branch gateway can be understood as an event-based exclusive branch gateway. Furthermore, only one task node among task nodes T2 to T4 will be executed.

[0092] In another embodiment, if conditions E1 to E3 are compatible conditions, meaning the monitored event of task node T1 can satisfy multiple conditions simultaneously, then the number of target preset conditions can be multiple. In this case, the condition-based branch gateway can be understood as an event-based compatible branch gateway. Furthermore, the task nodes on the corresponding paths corresponding to conditions E1 to E3 will be executed.

[0093] In this embodiment, since the target gateway, such as an event-based branch gateway, corresponds to a security orchestration scenario, once the security orchestration scenario is determined, the corresponding target gateway can be directly invoked for execution. Because the target gateway has clear and concise semantics, it can automatically and conveniently execute the security orchestration script to be executed, thereby enabling a quick and easy automated response to security events.

[0094] Figure 7 This is the sixth schematic diagram of the target gateway provided by the present invention.

[0095] To further introduce the secure orchestration and automated response method provided by this invention, the following will be combined with... Figure 7 This section explains the process of determining the target gateway as an event-based gateway in a security orchestration scenario where the subsequent task node to be executed is determined based on the events occurring at the current task node that are monitored.

[0096] In an exemplary embodiment of the present invention, in a security orchestration scenario where the subsequent task node to be executed is determined based on the events occurring at the current task node, determining the target gateway as an event-based gateway can be achieved in the following way:

[0097] In a secure orchestration scenario, where the execution of a subsequent task node is determined based on events observed in the current task node, if the current task node consists of multiple task nodes and the subsequent task node is a single task node, the event-based gateway is determined to be an event-based aggregation gateway. The event-based aggregation gateway is the gateway that controls the execution of the subsequent task node when the number of current task nodes corresponding to the target preset conditions is a preset number. The target preset conditions are preset conditions that match the events.

[0098] In one embodiment, combined with Figure 7 To clarify, the current task node can be understood as... Figure 7 Task nodes T1 to T3 in the table. Subsequent task nodes can be understood as... Figure 7 Task node T4 is defined in the context of task nodes T1 to T3. Conditions E1 to E3 (corresponding to preset conditions) are defined for task nodes T1 to T3, respectively. Events detected at task node T1 are evaluated using condition E1, events detected at task node T2 are evaluated using condition E2, and events detected at task node T3 are evaluated using condition E3.

[0099] During the application process, if the event of the monitored task node T1 satisfies condition E1, the event of the monitored task node T2 satisfies condition E2, and the event of the monitored task node T3 satisfies condition E3, the task node T4 can be executed through the target gateway G1 (corresponding to the event-based aggregation gateway).

[0100] Among them, when condition E1, condition E2, or condition E3 satisfies the data, it can be called the target preset condition.

[0101] In another embodiment, for the target gateway G1, it listens for specific events dispatched by task nodes T1 to T3 and combines them with business scenario configuration conditions. Task node T4 is only executed when the events dispatched by each task node satisfy conditions E1 to E3. At this time, the number of current task nodes corresponding to the target preset conditions is 3 (corresponding to the preset number). That is, when the preset number is the same as the number of current task nodes, the event-based aggregation gateway can be understood as an event-based AND-type aggregation gateway.

[0102] In another embodiment, for the target gateway G1, it listens for specific events dispatched by task nodes T1 to T3 and combines this with business scenario configuration conditions. When any event dispatched by any of the detected task nodes meets the corresponding preset conditions, task node T4 can be executed. In this case, if the number of current task nodes corresponding to the target preset conditions is less than 3 (corresponding to a preset number), that is, if the preset number is greater than the number of current task nodes corresponding to the target preset conditions, then the event-based aggregation gateway can be understood as an event-based OR-type aggregation gateway.

[0103] In this embodiment, since the target gateway, such as an event-based aggregation gateway, corresponds to the security orchestration scenario, once the security orchestration scenario is determined, the corresponding target gateway can be directly invoked for execution. Because the target gateway has clear and concise semantics, it can automatically and conveniently execute the security orchestration script to be executed, thereby enabling a quick and easy automated response to security events.

[0104] As described above, the security orchestration and automated response method provided by the present invention determines the security orchestration scenario of the process branch in the security orchestration script to be executed, determines the corresponding pre-set target gateway based on the security orchestration scenario, and then executes the process branch based on the target gateway, so as to realize the automatic and convenient execution of the security orchestration script to be executed, thereby enabling a quick and convenient automated response to security events.

[0105] Based on the same concept, the present invention also provides a secure orchestration and automated response device.

[0106] The following describes the secure orchestration and automated response apparatus provided by the present invention. The secure orchestration and automated response apparatus described below can be referred to in correspondence with the secure orchestration and automated response method described above.

[0107] Figure 8 This is a schematic diagram of the structure of the security orchestration and automated response device provided by the present invention.

[0108] In an exemplary embodiment of the present invention, combined with Figure 8 As can be seen, the safety orchestration and automated response device may include the first module 810 to the third module 830, and each module will be described below.

[0109] The first module 810 can be configured to obtain a security orchestration script to be executed. The security orchestration script to be executed includes multiple process branches, and each process branch includes multiple task nodes. The task nodes correspond to the security capabilities of the security product.

[0110] The second module 820 can be configured to determine the security orchestration scenario of the process branch, and based on the security orchestration scenario, determine the target gateway corresponding to the security orchestration scenario, wherein the target gateway is obtained through pre-setting;

[0111] The third module 830 can be configured to execute flow branches based on the target gateway to automate the execution of pending security orchestration scripts.

[0112] In an exemplary embodiment of the present invention, the second module 820 can determine the target gateway corresponding to the security orchestration scenario based on the security orchestration scenario in the following manner:

[0113] In a security orchestration scenario where task nodes are executed in a sequential flow manner, the target gateway is determined to be a sequential flow gateway, which is a gateway that controls the execution of task nodes in a preset order.

[0114] In an exemplary embodiment of the present invention, the second module 820 can determine the target gateway corresponding to the security orchestration scenario based on the security orchestration scenario in the following manner:

[0115] In a security orchestration scenario where the subsequent task node to be executed is determined based on the data input from the current task node, the target gateway is determined to be a condition-based gateway. Here, a condition-based gateway is a gateway that controls the execution of subsequent task nodes based on data and preset conditions. The subsequent task node is the task node after the current task node in the process branch.

[0116] In an exemplary embodiment of the present invention, the second module 820 can determine the target gateway as a condition-based gateway in the case where the subsequent task node to be executed is determined based on the data input by the current task node in a security orchestration scenario:

[0117] In a secure orchestration scenario where the subsequent task node to be executed is determined based on the data input from the current task node, if the current task node is a single task node and the subsequent task nodes are multiple task nodes, the condition-based gateway is determined to be a condition-based branch gateway. Here, the condition-based branch gateway is the gateway that controls the execution of the subsequent task node corresponding to the target preset condition, and the target preset condition is the preset condition that satisfies the data.

[0118] In an exemplary embodiment of the present invention, the second module 820 can determine the target gateway as a condition-based gateway in the case where the subsequent task node to be executed is determined based on the data input by the current task node in a security orchestration scenario:

[0119] In a secure orchestration scenario where the subsequent task node to be executed is determined based on the data input from the current task node, if the current task node consists of multiple task nodes and the subsequent task node is a single task node, the condition-based gateway is determined to be a condition-based aggregation gateway. The condition-based aggregation gateway is the gateway that controls the execution of the subsequent task node when the number of current task nodes corresponding to the target preset condition is a preset number. The target preset condition is a preset condition that matches the data.

[0120] In an exemplary embodiment of the present invention, the second module 820 can determine the target gateway corresponding to the security orchestration scenario based on the security orchestration scenario in the following manner:

[0121] In a secure orchestration scenario, where the target gateway is determined as an event-based gateway based on the events that occur at the current task node and the subsequent task node needs to be executed, the target gateway is determined as an event-based gateway. Here, the event-based gateway is a gateway that controls the execution of the subsequent task node based on events and preset conditions. The subsequent task node is the task node after the current task node in the process branch.

[0122] In an exemplary embodiment of the present invention, the second module 820 may determine the target gateway as an event-based gateway in the following manner when the security orchestration scenario involves determining the subsequent task node to be executed based on the events occurring at the current task node:

[0123] In a secure orchestration scenario, where the subsequent task node to be executed is determined based on the events that occur in the current task node, if the current task node is a single task node and the subsequent task nodes are multiple task nodes, the event-based gateway is determined to be an event-based branch gateway. The event-based branch gateway is the gateway that controls the execution of the subsequent task node that corresponds to the target preset condition, and the target preset condition is a preset condition that matches the event.

[0124] In an exemplary embodiment of the present invention, the second module 820 may determine the target gateway as an event-based gateway in the following manner when the security orchestration scenario involves determining the subsequent task node to be executed based on the events occurring at the current task node:

[0125] In a secure orchestration scenario, where the execution of a subsequent task node is determined based on events observed in the current task node, if the current task node consists of multiple task nodes and the subsequent task node is a single task node, the event-based gateway is determined to be an event-based aggregation gateway. The event-based aggregation gateway is the gateway that controls the execution of the subsequent task node when the number of current task nodes corresponding to the target preset conditions is a preset number. The target preset conditions are preset conditions that match the events.

[0126] Figure 9 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 9 As shown, the electronic device may include a processor 910, a communications interface 920, a memory 930, and a communication bus 940, wherein the processor 910, the communications interface 920, and the memory 930 communicate with each other via the communication bus 940. The processor 910 can call logical instructions in the memory 930 to execute a security orchestration and automated response method. The security orchestration and automated response method includes: obtaining a security orchestration script to be executed, the script including multiple process branches, each process branch including multiple task nodes, the task nodes corresponding to the security capabilities of a security product; determining a security orchestration scenario for each process branch, and based on the security orchestration scenario, determining a target gateway corresponding to the security orchestration scenario, wherein the target gateway is obtained through pre-setting; and executing the process branch based on the target gateway to achieve automated execution of the security orchestration script to be executed.

[0127] Furthermore, the logical instructions in the aforementioned memory 930 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, essentially, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0128] On the other hand, the present invention also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the security orchestration and automated response methods provided by the above methods. The security orchestration and automated response methods include: obtaining a security orchestration script to be executed, the security orchestration script including multiple process branches, the process branches including multiple task nodes, the task nodes corresponding to the security capabilities of a security product; determining a security orchestration scenario for the process branches, and based on the security orchestration scenario, determining a target gateway corresponding to the security orchestration scenario, wherein the target gateway is obtained through pre-setting; and executing the process branches based on the target gateway to achieve automated execution of the security orchestration script to be executed.

[0129] In another aspect, the present invention also provides a non-transitory computer-readable storage medium storing a computer program thereon. When executed by a processor, the computer program implements the execution security orchestration and automated response method provided by the above methods. The security orchestration and automated response method includes: obtaining a security orchestration script to be executed, the security orchestration script including multiple process branches, each process branch including multiple task nodes, the task nodes corresponding to the security capabilities of a security product; determining a security orchestration scenario for the process branches, and based on the security orchestration scenario, determining a target gateway corresponding to the security orchestration scenario, wherein the target gateway is obtained through pre-setting; and executing the process branches based on the target gateway to achieve automated execution of the security orchestration script to be executed.

[0130] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0131] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0132] It is further understood that although the operations are described in a specific order in the accompanying drawings in the embodiments of the present invention, this should not be construed as requiring these operations to be performed in the specific order or serial order shown, or requiring all the operations shown to obtain the desired result. In certain environments, multitasking and parallel processing may be advantageous.

[0133] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for secure orchestration and automated response, characterized in that, The secure orchestration and automated response method includes: Obtain a security orchestration script to be executed, which includes multiple process branches, each process branch including multiple task nodes, and the task nodes corresponding to the security capabilities of the security product. The process branch security orchestration scenario is determined, and based on the security orchestration scenario, a target gateway corresponding to the security orchestration scenario is determined. The target gateway is obtained through pre-setting, and includes a sequence flow gateway, a condition-based gateway, and an event-based gateway. The condition-based gateway includes a condition-based branch gateway and a condition-based aggregation gateway; the event gateway includes an event-based branch gateway and an event-based aggregation gateway. Specifically, determining the target gateway corresponding to the security orchestration scenario includes: In the security orchestration scenario where the task nodes are executed in a sequential flow manner, the target gateway is determined to be a sequential flow gateway, wherein the sequential flow gateway is a gateway that controls the task nodes to be executed in a preset order; or In the security orchestration scenario where the subsequent task node to be executed is determined based on the data input from the current task node, the target gateway is determined to be a condition-based gateway. The condition-based gateway is a gateway that controls the execution of the subsequent task node based on the data and preset conditions. The subsequent task node is the task node following the current task node in the process branch; or In the security orchestration scenario where the subsequent task node to be executed is determined based on the events that occur at the current task node, the target gateway is determined to be an event-based gateway. The event-based gateway is a gateway that controls the execution of the subsequent task node based on the events and preset conditions. The subsequent task node is the task node after the current task node in the process branch. The process branch is executed based on the target gateway to automate the execution of the security orchestration script to be executed.

2. The secure orchestration and automated response method according to claim 1, characterized in that, In the security orchestration scenario where the subsequent task node to be executed is determined based on the data input by the current task node, determining the target gateway as a condition-based gateway specifically includes: In the secure orchestration scenario where the subsequent task node to be executed is determined based on the data input by the current task node, if the current task node is a single task node and the subsequent task node is multiple task nodes, the condition-based gateway is determined to be a condition-based branch gateway. The condition-based branch gateway is a gateway that controls the execution of the subsequent task node corresponding to the target preset condition, and the target preset condition is a preset condition that satisfies the data.

3. The secure orchestration and automated response method according to claim 1, characterized in that, In the security orchestration scenario where the subsequent task node to be executed is determined based on the data input by the current task node, determining the target gateway as a condition-based gateway specifically includes: In the secure orchestration scenario where the subsequent task node to be executed is determined based on the data input by the current task node, if the current task node consists of multiple task nodes and the subsequent task node is a single task node, the condition-based gateway is determined to be a condition-based aggregation gateway. The condition-based aggregation gateway is a gateway that controls the execution of the subsequent task node when the number of current task nodes corresponding to a target preset condition is a preset number. The target preset condition is a preset condition that matches the data.

4. The secure orchestration and automated response method according to claim 1, characterized in that, In the security orchestration scenario, where the subsequent task node to be executed is determined based on the events occurring at the current task node, determining the target gateway as an event-based gateway specifically includes: In the secure orchestration scenario where the subsequent task node to be executed is determined based on the events occurring at the current task node, if the current task node is a single task node and the subsequent task nodes are multiple task nodes, the event-based gateway is determined to be an event-based branch gateway. The event-based branch gateway is a gateway that controls the execution of the subsequent task node corresponding to a target preset condition, and the target preset condition is a preset condition that matches the event.

5. The secure orchestration and automated response method according to claim 1, characterized in that, In the security orchestration scenario, where the subsequent task node to be executed is determined based on the events occurring at the current task node, determining the target gateway as an event-based gateway specifically includes: In the secure orchestration scenario where the subsequent task node to be executed is determined based on the events occurring at the current task node, if the current task node consists of multiple task nodes and the subsequent task node is a single task node, the event-based gateway is determined to be an event-based aggregation gateway. The event-based aggregation gateway is the gateway that controls the execution of the subsequent task node when the number of current task nodes corresponding to a target preset condition is a preset number. The target preset condition is a preset condition that matches the event.

6. A security orchestration and automated response device, characterized in that, The secure orchestration and automated response apparatus is used to implement the secure orchestration and automated response method according to any one of claims 1 to 5, and the apparatus includes: The first module is used to obtain a security orchestration script to be executed. The security orchestration script to be executed includes multiple process branches, and each process branch includes multiple task nodes. The task nodes correspond to the security capabilities of the security product. The second module is used to determine the security orchestration scenario of the process branch, and based on the security orchestration scenario, determine the target gateway corresponding to the security orchestration scenario, wherein the target gateway is obtained through pre-setting; The third module is used to execute the process branch based on the target gateway to automate the execution of the security orchestration script to be executed.

7. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the secure orchestration and automated response method as described in any one of claims 1 to 5.

8. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the secure orchestration and automated response method as described in any one of claims 1 to 5.