Alarm aggregation method, device, electronic device and storage medium
By comparing the alarm log fingerprint information of network security equipment and the attack result level, high-value alarms are screened and aggregated, solving the problem of alarm flooding in complex network environments and improving the efficiency of detecting high-risk attacks.
Patent Information
- Application Number
- CN202310128611.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-17
- Publication Date
- 2025-09-26
- Estimated Expiration
- 2043-02-17
AI Technical Summary
When the network environment is complex, network security devices generate a large number of alarms, resulting in an inundation of high-value alarms, making it difficult for operators to detect and deal with high-risk attacks in a timely manner.
By obtaining the fingerprint information and attack result levels of multiple alarm logs, the fingerprint information is compared and verified with the specified fingerprint information of preset successful attack behaviors, the alarm log levels with lower risks are lowered, and high-value alarm logs are aggregated.
Effectively filter out high-value alarm logs, reduce noise alarms, and improve the efficiency of operators in discovering high-risk attacks.
Smart Images

Figure CN116248381B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security, and in particular to an alarm aggregation method, device, electronic device and storage medium. Background Art
[0002] Detecting and providing early warning of potential cyberattacks is a common function of network security devices. However, when network security devices operate in complex environments, they often generate numerous alerts, which can overwhelm high-value alerts and hinder operators from promptly identifying and addressing high-risk attacks. Summary of the Invention
[0003] The purpose of the present invention is to provide an alarm aggregation method, device, electronic device and storage medium, which can use fingerprint information to filter out high-value alarm logs from multiple alarm logs and give priority to aggregating high-value alarm logs, thereby avoiding high-value alarm logs being submerged in a large number of alarms.
[0004] To solve the above technical problems, the present invention provides an alarm aggregation method, comprising:
[0005] Obtain multiple alarm logs from the same alarm source and determine fingerprint information and attack result levels corresponding to each of the alarm logs; the fingerprint information corresponds to the network assets attacked by the attack behavior recorded in the alarm log;
[0006] Comparing and verifying the fingerprint information with the designated fingerprint information corresponding to the preset successful attack behavior, and if it is determined that the fingerprint information fails the comparison and verification, lowering the attack result level corresponding to the alarm log containing the fingerprint information;
[0007] When the comparison and verification of all the alarm logs is completed, the alarm logs with the attack result level greater than or equal to the preset threshold are aggregated.
[0008] Optionally, aggregating the alarm logs whose attack result levels are greater than or equal to a preset threshold includes:
[0009] Setting the alarm logs whose attack result levels are greater than or equal to the preset threshold as logs to be aggregated;
[0010] Determine the target rule triggered by the log to be aggregated, and determine whether the number of alarm logs that have triggered the target rule in the current cycle is less than a preset number;
[0011] If yes, then at every first preset time, the logs to be aggregated that trigger the target rule, are generated within the first preset time, and have the same alarm information and network communication information are aggregated;
[0012] If not, the logs to be aggregated that trigger the target rule, are generated within the second preset time, and have the same alarm information and network communication information are aggregated every second preset time; the first preset time is greater than the first preset time.
[0013] Optionally, before aggregating the alarm logs whose attack result levels are greater than or equal to a preset threshold, the method further includes:
[0014] When it is determined that an alarm log with an attack result level greater than or equal to a preset threshold exists, the alarm logs with an attack result level greater than or equal to the preset threshold are aggregated, and the alarm logs with an attack result level less than the preset threshold are discarded;
[0015] When it is determined that the alarm log with the attack result level greater than or equal to the preset threshold does not exist, the alarm log with the attack result level less than the preset threshold is aggregated.
[0016] Optionally, determining the attack result level of each alarm log record includes:
[0017] The attack result level corresponding to the alarm log is determined according to the attack result recorded in the alarm log.
[0018] Optionally, the alarm log further records the danger level corresponding to the target rule triggered by the attack behavior, and after aggregating the alarm logs with the attack result level greater than or equal to a preset threshold, further includes:
[0019] From the alarm logs whose attack result levels are greater than or equal to a preset threshold, the alarm log with the highest danger level is output.
[0020] Optionally, the fingerprint information and the designated fingerprint information are both multi-level fingerprints, and comparing and verifying the fingerprint information with the designated fingerprint information corresponding to a preset successful attack behavior includes:
[0021] Comparing and verifying fingerprints of each level in the fingerprint information with designated fingerprints of corresponding levels in the designated fingerprint information in sequence;
[0022] If it is determined that the first-level fingerprint in the fingerprint information is different from the first-level designated fingerprint in the designated fingerprint information, or the fingerprints at all levels in the fingerprint information are the same as the designated fingerprints at the corresponding levels in the designated fingerprint information, then it is determined that the fingerprint information passes the comparison verification;
[0023] If it is determined that the first-level fingerprint is the same as the first-level designated fingerprint, and there is a fingerprint in the remaining fingerprints of each level in the fingerprint information that is different from the designated fingerprint of the corresponding level in the designated fingerprint information, it is determined that the fingerprint information fails the comparison verification.
[0024] The present invention also provides an alarm aggregation device, comprising:
[0025] An acquisition module is configured to acquire multiple alarm logs from the same alarm source and determine fingerprint information and attack result levels corresponding to each of the alarm logs; the fingerprint information corresponds to the network assets attacked by the attack behavior recorded in the alarm log;
[0026] a fingerprint comparison module, configured to compare and verify the fingerprint information with the predetermined fingerprint information corresponding to the preset successful attack behavior, and, if it is determined that the fingerprint information fails the comparison and verification, to lower the attack result level corresponding to the alarm log containing the fingerprint information;
[0027] The aggregation module is used to aggregate the alarm logs whose attack result levels are greater than or equal to a preset threshold when the comparison and verification of all the alarm logs are completed.
[0028] Optionally, the aggregation module includes:
[0029] A setting submodule, configured to set the alarm logs whose attack result level is greater than or equal to the preset threshold as logs to be aggregated;
[0030] A judgment submodule, configured to determine a target rule triggered by the log to be aggregated, and to determine whether the number of alarm logs that have triggered the target rule in the current cycle is less than a preset number;
[0031] A first aggregation submodule is configured to aggregate the logs to be aggregated that trigger the target rule, are generated within the first preset time, and have the same alarm information and network communication information, at intervals of a first preset time;
[0032] The second aggregation submodule is used to aggregate the logs to be aggregated that trigger the target rule, are generated within the second preset time, and have the same alarm information and network communication information every second preset time; if not, the first preset time is greater than the first preset time.
[0033] The present invention further provides an electronic device, comprising:
[0034] memory for storing computer programs;
[0035] A processor is configured to implement the steps of the alarm aggregation method described above when executing the computer program.
[0036] The present invention also provides a storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the steps of the alarm aggregation method described above are implemented.
[0037] The present invention provides an alarm aggregation method, comprising: obtaining multiple alarm logs from the same alarm source, and determining fingerprint information and attack result levels corresponding to each of the alarm logs; the fingerprint information corresponds to the network assets attacked by the attack behavior recorded in the alarm log; comparing and verifying the fingerprint information with designated fingerprint information corresponding to a preset successful attack behavior, and when it is determined that the fingerprint information fails the comparison and verification, lowering the attack result level corresponding to the alarm log containing the fingerprint information; when the comparison and verification of all the alarm logs is completed, aggregating the alarm logs whose attack result levels are greater than or equal to a preset threshold.
[0038] It can be seen that after obtaining multiple alarm logs from the same alarm source, the present invention can first determine the fingerprint information and attack result level corresponding to these logs, wherein the fingerprint information corresponds to the network assets attacked by the attack behavior recorded in the alarm log, that is, the network assets attacked by the attack behavior will be marked with the corresponding fingerprint, and the attack result level reflects the degree of harm of the alarm log; then, the present invention can compare and verify these fingerprint information with the execution fingerprint information corresponding to the preset successful attack behavior, and when it is determined that the fingerprint information fails the comparison and verification, the attack result level corresponding to the alarm log containing the fingerprint information is lowered, that is, when it is determined that the attack behavior corresponding to the alarm log has a low risk, the attack result level corresponding to the behavior is lowered; finally, after completing the comparison and verification of all alarm logs, the alarm logs with the attack result level greater than or equal to the preset threshold can be aggregated, that is, high-value alarm logs can be screened out from multiple alarm logs, and high-value alarm logs are aggregated first, thereby preventing high-value alarm logs from being submerged in a large number of alarms, thereby facilitating operators to promptly discover and deal with high-risk attacks. The present invention also provides an alarm aggregation device, an electronic device and a storage medium, which have the above-mentioned beneficial effects. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.
[0040] Figure 1 A flowchart of an alarm aggregation method provided by an embodiment of the present invention;
[0041] Figure 2 A flowchart of fingerprint comparison and verification provided by an embodiment of the present invention;
[0042] Figure 3This is a structural block diagram of an alarm aggregation device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0043] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.
[0044] In related technologies, when the network environment in which a network security device is located is relatively complex, the device will generate a large number of alarms, which can easily drown out high-value alarms, making it difficult for operators to promptly detect and handle high-risk attacks. In view of this, the present invention can provide an alarm aggregation method that can use fingerprint information to filter out high-value alarm logs from multiple alarm logs and give priority to aggregating high-value alarm logs, thereby preventing high-value alarm logs from being drowned in a large number of alarms. Please refer to Figure 1 , Figure 1 This is a flow chart of an alarm aggregation method provided by an embodiment of the present invention. The method may include:
[0045] S101. Acquire multiple alarm logs from the same alarm source, and determine fingerprint information and attack result levels corresponding to each alarm log; the fingerprint information corresponds to the network assets attacked by the attack behavior recorded in the alarm log.
[0046] The alarm source is an attack detection device within a network environment, which detects attack behaviors occurring within the network environment and generates corresponding alarm information. Alarm information typically records the attack results, including successful attacks, attempted attacks, and failed attacks. Attempted attacks are a step between successful and failed attacks, primarily involving exploratory operations before conducting a network attack, such as intranet probing. It is understood that of these three attack results, a successful attack carries the highest risk and warrants particular attention; an attempted attack carries the second highest risk; and a failed attack carries the lowest risk. In other words, each of these three attack results is assigned a specific risk level, which in this embodiment of the present invention may be referred to as an attack result level. For this reason, after obtaining an alarm log, embodiments of the present invention can determine the corresponding attack result level based on the recorded attack results.
[0047] Based on this, the attack result level of each alarm log record is determined, which may include:
[0048] Step 11: Determine the attack result level corresponding to the alarm log according to the attack result recorded in the alarm log.
[0049] Furthermore, since the purpose of the embodiments of the present invention is to filter out high-value alarm logs, they prioritize aggregating alarm logs with attack result levels above a preset threshold. For example, they prioritize aggregating alarm logs with successful attack results and attempted attack results. However, alarm logs with attempted attack results contain a significant amount of noise, such as alarm logs that were determined to be attempted attacks but were not successful, which can easily lead to a large number of alarm logs after aggregation. Therefore, the embodiments of the present invention suppress alarms to reduce the number of alarms. Specifically, the embodiments of the present invention can set fingerprints in the network environment, for example, fingerprints can be set on each network asset. Furthermore, if the alarm source detects an attack on a specific network asset, the fingerprint of that network asset can be marked in the corresponding alarm log. Subsequently, the embodiments of the present invention can also preset specific fingerprint information corresponding to successful attacks, that is, marking the attack as successful only when it attacks certain network assets. In this way, after obtaining the alarm log, the fingerprint information recorded therein can be compared and verified with the specified fingerprint information corresponding to the preset successful attack behavior. If the comparison and verification are determined to be successful, the attack behavior corresponding to the alarm log is determined to be a high-risk attack, and its original attack result is retained. If the comparison and verification are determined to be unsuccessful, the attack behavior corresponding to the alarm log is determined to be an unsuccessful attack, and the corresponding attack result level can be lowered, such as modifying the attack result in the alarm log to an attack failure, thereby reducing the aggregation volume of alarm logs. It should be noted that the embodiments of the present invention do not limit the configuration of fingerprints on various network assets, nor do they limit the specific method by which the alarm source marks the fingerprints in the alarm log. These can be set according to actual application requirements.
[0050] S102: Compare and verify the fingerprint information with the designated fingerprint information corresponding to the preset successful attack behavior, and when it is determined that the fingerprint information fails the comparison and verification, lower the attack result level corresponding to the alarm log containing the fingerprint information.
[0051] As described above, when it is determined that the fingerprint information of the alarm log fails the comparison verification, the attack result level corresponding to the alarm log can be lowered, thereby reducing the alarm aggregation amount, which is conducive to highlighting high-value alarm logs.
[0052] Furthermore, to facilitate fingerprint matching, the fingerprint information in the embodiments of the present invention, namely the fingerprint information marked in the alarm log and the designated fingerprint information corresponding to the preset successful attack behavior, is all multi-level fingerprints. For example, if a network asset is a component in a system, the multi-level fingerprint can be: the first fingerprint corresponds to the system, and the second fingerprint corresponds to the network asset. This can improve the efficiency of fingerprint matching. Of course, it is understood that the number of levels of multi-level fingerprints can be greater than two, and the specific setting can be based on actual application requirements. For ease of understanding, the embodiments of the present invention will describe the specific implementation of matching verification based on a two-layer fingerprint structure.
[0053] Based on this, the fingerprint information and the designated fingerprint information are both multi-level fingerprints. The fingerprint information is compared and verified with the designated fingerprint information corresponding to the preset successful attack behavior, including:
[0054] Step 21: sequentially compare and verify the fingerprints of each level in the fingerprint information with the designated fingerprints of the corresponding level in the designated fingerprint information;
[0055] Step 22: If it is determined that the first-level fingerprint in the fingerprint information is different from the first-level designated fingerprint in the designated fingerprint information, or if the fingerprints at all levels in the fingerprint information are the same as the designated fingerprints at the corresponding levels in the designated fingerprint information, then it is determined that the fingerprint information passes the comparison verification;
[0056] Step 23: If it is determined that the first-level fingerprint is the same as the first-level designated fingerprint, and there is a fingerprint in the remaining fingerprints of each level in the fingerprint information that is different from the designated fingerprint of the corresponding level in the designated fingerprint information, it is determined that the fingerprint information fails the comparison verification.
[0057] Please refer to Figure 2 , Figure 2 This is a flow chart of fingerprint comparison and verification provided by an embodiment of the present invention. It can be seen that the embodiment of the present invention can first compare the first-level fingerprint in the fingerprint information with the first-level designated fingerprint in the designated fingerprint information. If they are different, the attack result in the alarm log will not be modified; if they are the same, the second-level fingerprint will be compared based on whether the second-level fingerprint is in the fingerprint information, or the fingerprint name will be compared. The process is similar. After the above comparison, the embodiment of the present invention can greatly reduce the number of alarm logs for attempted attacks and can streamline high-value alarm logs, thereby facilitating the highlighting of high-value alarms.
[0058] S103: After the comparison and verification of all alarm logs is completed, the alarm logs with attack result levels greater than or equal to a preset threshold are aggregated.
[0059] After completing the comparison and verification, the present invention can give priority to aggregating alarm logs whose attack result levels are greater than or equal to a preset threshold, wherein the preset threshold can be set according to actual application requirements. For example, when the attack result levels are divided into three levels: high, medium, and low, corresponding to successful attacks, attempted attacks, and failed attacks, respectively, the preset threshold can be set to level two, that is, only alarm logs of successful attacks and attempted attacks are aggregated. Of course, it is understandable that if, after completing the comparison and verification, there are alarm logs that meet the aggregation conditions and low-level alarm logs that do not meet the aggregation conditions, then the alarm logs that meet the conditions can be aggregated, and the alarm logs that do not meet the aggregation conditions can be discarded; of course, if, after completing the comparison and verification, only alarm logs with low attack result levels remain, then these alarm logs can also be aggregated for reference because they can reflect the attack situation in the network environment.
[0060] Based on this, before aggregating the alarm logs whose attack result levels are greater than or equal to the preset threshold, the following steps may also be performed:
[0061] Step 31: When it is determined that an alarm log with an attack result level greater than or equal to a preset threshold exists, the alarm logs with an attack result level greater than or equal to the preset threshold are aggregated, and the alarm logs with an attack result level less than the preset threshold are discarded;
[0062] Step 32: When it is determined that the alarm log with the attack result level greater than or equal to the preset threshold does not exist, the alarm log with the attack result level less than the preset threshold is aggregated.
[0063] Finally, after the alarm logs are aggregated, high-risk alarm logs can be output to improve the timely processing of operation and maintenance personnel. Specifically, the alarm log can also record the danger level. This danger level is the danger level (gid) corresponding to the target rule triggered by the attack behavior corresponding to the alarm log. It is marked when the rule is written. Specific vulnerabilities such as CVE number high-level categories have the highest risk, general high-risk categories are second, and uncommon vulnerabilities have the lowest risk. Furthermore, after the alarm logs are aggregated, the alarm log with the highest risk level can be output according to its corresponding risk level.
[0064] Based on this, the alarm log also records the danger level corresponding to the target rule triggered by the attack behavior. After aggregating the alarm logs with attack result levels greater than or equal to the preset threshold, it also includes:
[0065] Step 41: Output the alarm log with the highest danger level from the alarm logs whose attack result levels are greater than or equal to a preset threshold.
[0066] Based on the above embodiment, after obtaining multiple alarm logs from the same alarm source, the present invention can first determine the fingerprint information and attack result level corresponding to these logs, wherein the fingerprint information corresponds to the network assets attacked by the attack behavior recorded in the alarm log, that is, the network assets attacked by the attack behavior will be marked with the corresponding fingerprint, and the attack result level reflects the degree of harm of the alarm log; then, the present invention can compare and verify these fingerprint information with the execution fingerprint information corresponding to the preset successful attack behavior, and if it is determined that the fingerprint information fails the comparison and verification, the attack result level corresponding to the alarm log containing the fingerprint information is lowered, that is, if it is determined that the attack behavior corresponding to the alarm log has a low risk, the attack result level corresponding to the behavior is lowered; finally, after completing the comparison and verification of all alarm logs, the alarm logs with the attack result level greater than or equal to the preset threshold can be aggregated, so that high-value alarm logs can be screened out from the multiple alarm logs and prioritized for aggregation, thereby preventing high-value alarm logs from being submerged in a large number of alarms, thereby facilitating operators to promptly discover and deal with high-risk attacks.
[0067] Based on the above embodiment, the following is a detailed introduction to the aggregation method of alarm logs. In one possible scenario, aggregating alarm logs with attack result levels greater than or equal to a preset threshold may include:
[0068] S201: Set the alarm logs whose attack result levels are greater than or equal to a preset threshold as logs to be aggregated.
[0069] S202, determine the target rule triggered by the log to be aggregated, and judge whether the number of alarm logs that have triggered the target rule in the current cycle is less than the preset number; if so, proceed to step S203; if not, proceed to step S204.
[0070] It should be noted that the embodiment of the present invention does not limit the merging period corresponding to each target rule; for example, it can be 24 hours. It should be noted that within a merging period, each target rule will gradually increase the merging strength in a step-by-step manner to limit the number of alarm logs, and will restore the initial merging strength in the next merging period.
[0071] Furthermore, aggregation will integrate multiple alarm logs with the same information into a total alarm log, thereby further reducing the amount of alarm logs to facilitate the review of operation and maintenance personnel. The embodiment of the present invention does not limit the information based on which the alarm logs are aggregated. For example, aggregation can be performed based on the target rule (such as rule ID) triggered by the alarm log, alarm information (such as alarm result) and network communication information (such as source port, target port, source IP, target IP). Further, as mentioned above, in order to limit the amount of alarm logs as much as possible, the merging strength corresponding to each target rule will be gradually increased. For example, first, only the alarm logs generated within each first preset time (such as 30s) will be aggregated; when it is determined that the amount of alarm logs that have triggered the target rule within the merging period is greater than or equal to the preset number (such as 100,000), the alarm logs generated within the second preset time (such as one hour) will be aggregated, thereby achieving the effect of reducing the amount of alarm logs.
[0072] S203: If yes, then at every first preset time, aggregate the logs to be aggregated that trigger the target rule, are generated within the first preset time, and have the same alarm information and network communication information.
[0073] S204: If not, then aggregate the logs to be aggregated that trigger the target rule, are generated within the second preset time, and have the same alarm information and network communication information every second preset time; the first preset time is greater than the first preset time.
[0074] It should be noted that the embodiment of the present invention does not limit the specific values of the first preset time and the second preset time, and they can be set according to actual application requirements.
[0075] The following introduces an alarm aggregation device, an electronic device, and a storage medium provided in embodiments of the present invention. The alarm aggregation device, electronic device, and storage medium described below can correspond to the alarm aggregation method described above.
[0076] Please refer to Figure 3 , Figure 3 This is a structural block diagram of an alarm aggregation device provided by an embodiment of the present invention. The device may include:
[0077] The acquisition module 301 is used to obtain multiple alarm logs from the same alarm source and determine the fingerprint information and attack result level corresponding to each alarm log; the fingerprint information corresponds to the network assets attacked by the attack behavior recorded in the alarm log;
[0078] The fingerprint comparison module 302 is configured to compare and verify the fingerprint information with the predetermined fingerprint information corresponding to the successful attack behavior, and if it is determined that the fingerprint information fails the comparison and verification, to lower the attack result level corresponding to the alarm log containing the fingerprint information;
[0079] The aggregation module 303 is configured to aggregate the alarm logs whose attack result levels are greater than or equal to a preset threshold after completing the comparison and verification of all alarm logs.
[0080] Optionally, the aggregation module 303 includes:
[0081] A setting submodule is used to set alarm logs with attack result levels greater than or equal to a preset threshold as logs to be aggregated;
[0082] The judgment submodule is used to determine the target rule triggered by the log to be aggregated and to determine whether the number of alarm logs that have triggered the target rule in the current cycle is less than a preset number;
[0083] A first aggregation submodule is configured to aggregate the logs to be aggregated that trigger the target rule, are generated within the first preset time, and have the same alarm information and network communication information, every first preset time;
[0084] The second aggregation submodule is used to aggregate the logs to be aggregated that trigger the target rule, are generated within the second preset time, and have the same alarm information and network communication information every second preset time; if not, the first preset time is greater than the first preset time.
[0085] Optionally, the aggregation module 303 may further include:
[0086] a first aggregation submodule, configured to aggregate the alarm logs with attack result levels greater than or equal to the preset threshold when it is determined that the alarm logs exist, and discard the alarm logs with attack result levels less than the preset threshold;
[0087] The second aggregation submodule is configured to aggregate the alarm logs whose attack result levels are less than the preset threshold when it is determined that the alarm logs whose attack result levels are greater than or equal to the preset threshold do not exist.
[0088] Optionally, the acquisition module 301 includes:
[0089] The attack result level determination submodule is used to determine the attack result level corresponding to the alarm log according to the attack result recorded in the alarm log.
[0090] Optionally, the alarm log further records the danger level corresponding to the target rule triggered by the attack behavior. The device may further include:
[0091] The output module is used to output the alarm log with the highest danger level from the alarm logs whose attack result levels are greater than or equal to a preset threshold.
[0092] Optionally, the fingerprint information and the designated fingerprint information are both multi-level fingerprints, and the fingerprint comparison module 302 may include:
[0093] The comparison and verification submodule is used to compare and verify the fingerprints of each level in the fingerprint information with the designated fingerprints of the corresponding level in the designated fingerprint information in sequence;
[0094] A first determination submodule is configured to determine that the fingerprint information passes the comparison verification if it is determined that the first-level fingerprint in the fingerprint information is different from the first-level designated fingerprint in the designated fingerprint information, or if the fingerprints at all levels in the fingerprint information are the same as the designated fingerprints at the corresponding levels in the designated fingerprint information;
[0095] The second determination submodule is configured to determine that the fingerprint information fails the comparison verification if it is determined that the first-level fingerprint is the same as the first-level designated fingerprint, and there is a fingerprint in the remaining fingerprints of each level in the fingerprint information that is different from the designated fingerprint of the corresponding level in the designated fingerprint information.
[0096] An embodiment of the present invention further provides an electronic device, including:
[0097] memory for storing computer programs;
[0098] A processor is configured to implement the steps of the above-mentioned alarm aggregation method when executing a computer program.
[0099] Since the embodiments of the electronic device part correspond to the embodiments of the alarm aggregation method part, please refer to the description of the embodiments of the alarm aggregation method part for the embodiments of the electronic device part, and will not be repeated here.
[0100] An embodiment of the present invention further provides a storage medium having a computer program stored thereon. When the computer program is executed by a processor, the steps of the alarm aggregation method of any of the above embodiments are implemented.
[0101] Since the embodiments of the storage medium part correspond to the embodiments of the alarm aggregation method part, please refer to the description of the embodiments of the alarm aggregation method part for the embodiments of the storage medium part, and will not be repeated here.
[0102] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Reference can be made to the common and similar parts between the various embodiments. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple, and the relevant parts can be referred to the method description.
[0103] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the components and steps of each example according to their functions. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present invention.
[0104] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein may be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.
[0105] The above is a detailed introduction to the alarm aggregation method, device, electronic device and storage medium provided by the present invention. Specific examples are used herein to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea. It should be pointed out that for ordinary technicians in this technical field, without departing from the principles of the present invention, the present invention can also be improved and modified in several ways, and these improvements and modifications also fall within the scope of protection of the claims of the present invention.
Claims
1. An alarm aggregation method, characterized in that: include: Obtain multiple alarm logs from the same alarm source, and determine the fingerprint information and attack result level corresponding to each of the alarm logs; The fingerprint information corresponds to the network asset attacked by the attack behavior recorded in the alarm log; when the alarm source detects the attack behavior on the network asset, it marks the fingerprint information of the network asset and records the attack result of the attack behavior in the corresponding alarm log; Comparing and verifying the fingerprint information with designated fingerprint information corresponding to a preset successful attack behavior, and if it is determined that the fingerprint information fails the comparison and verification, lowering the attack result level corresponding to the alarm log containing the fingerprint information; the designated fingerprint information is used to mark the attack behavior as a successful attack when attacking a specific network asset; After completing the comparison and verification of all the alarm logs, aggregating the alarm logs whose attack result levels are greater than or equal to a preset threshold; The fingerprint information and the designated fingerprint information are both multi-level fingerprints, and the fingerprint information is compared and verified with the designated fingerprint information corresponding to the preset successful attack behavior, including: Comparing and verifying fingerprints of each level in the fingerprint information with designated fingerprints of corresponding levels in the designated fingerprint information in sequence; If the fingerprints at all levels in the fingerprint information are identical to the designated fingerprints at the corresponding levels in the designated fingerprint information, then it is determined that the fingerprint information passes the comparison verification; the fingerprint information includes a first-level fingerprint and a second-level fingerprint, the first-level fingerprint corresponds to the system, and the second-level fingerprint corresponds to the network asset in the system; If it is determined that the first-level fingerprint is the same as the first-level designated fingerprint, and there is a fingerprint in the remaining fingerprints of each level in the fingerprint information that is different from the designated fingerprint of the corresponding level in the designated fingerprint information, it is determined that the fingerprint information fails the comparison verification.
2. The alarm aggregation method according to claim 1, characterized in that: The aggregating the alarm logs whose attack result levels are greater than or equal to a preset threshold includes: Setting the alarm logs whose attack result level is greater than or equal to the preset threshold as logs to be aggregated; Determine the target rule triggered by the log to be aggregated, and determine whether the number of alarm logs that have triggered the target rule in the current cycle is less than a preset number; If yes, then at every first preset time, the logs to be aggregated that trigger the target rule, are generated within the first preset time, and have the same alarm information and network communication information are aggregated; If not, the logs to be aggregated that trigger the target rule, are generated within the second preset time, and have the same alarm information and network communication information are aggregated every second preset time; the first preset time is greater than the first preset time.
3. The alarm aggregation method according to claim 1, characterized in that: Before aggregating the alarm logs whose attack result levels are greater than or equal to a preset threshold, the method further includes: When it is determined that an alarm log with an attack result level greater than or equal to a preset threshold exists, the alarm logs with an attack result level greater than or equal to the preset threshold are aggregated, and the alarm logs with an attack result level less than the preset threshold are discarded; When it is determined that the alarm log with the attack result level greater than or equal to the preset threshold does not exist, the alarm log with the attack result level less than the preset threshold is aggregated.
4. The alarm aggregation method according to claim 1, characterized in that: Determining the attack result level of each alarm log record includes: The attack result level corresponding to the alarm log is determined according to the attack result recorded in the alarm log.
5. The alarm aggregation method according to claim 1, characterized in that: The alarm log also records the danger level corresponding to the target rule triggered by the attack behavior. After aggregating the alarm logs with the attack result level greater than or equal to the preset threshold, the following is also included: From the alarm logs whose attack result levels are greater than or equal to a preset threshold, the alarm log with the highest danger level is output.
6. An alarm aggregation device, characterized in that: include: An acquisition module is used to obtain multiple alarm logs from the same alarm source and determine the fingerprint information and attack result level corresponding to each of the alarm logs; The fingerprint information corresponds to the network asset attacked by the attack behavior recorded in the alarm log; when the alarm source detects the attack behavior on the network asset, it marks the fingerprint information of the network asset and records the attack result of the attack behavior in the corresponding alarm log; a fingerprint comparison module, configured to compare and verify the fingerprint information with designated fingerprint information corresponding to a preset successful attack behavior, and, if it is determined that the fingerprint information fails the comparison and verification, to lower the attack result level corresponding to the alarm log containing the fingerprint information; the designated fingerprint information is used to mark the attack behavior as a successful attack when attacking a specific network asset; an aggregation module, configured to aggregate the alarm logs whose attack result level is greater than or equal to a preset threshold upon completing comparison and verification of all the alarm logs; The fingerprint comparison module includes: a comparison and verification submodule, configured to sequentially compare and verify fingerprints of each level in the fingerprint information with designated fingerprints of corresponding levels in the designated fingerprint information; a first determination submodule, configured to determine that the fingerprint information passes the comparison verification if all fingerprints at each level in the fingerprint information are identical to the designated fingerprints at the corresponding level in the designated fingerprint information; the fingerprint information includes a first-level fingerprint and a second-level fingerprint, the first-level fingerprint corresponding to the system, and the second-level fingerprint corresponding to the network asset in the system; The second determination submodule is configured to determine that the fingerprint information fails the comparison verification if it is determined that the first-level fingerprint is the same as the first-level designated fingerprint, and there is a fingerprint in the remaining fingerprints of each level in the fingerprint information that is different from the designated fingerprint of the corresponding level in the designated fingerprint information.
7. The alarm aggregation device according to claim 6, characterized in that: The aggregation module includes: A setting submodule, configured to set the alarm logs whose attack result level is greater than or equal to the preset threshold as logs to be aggregated; A judgment submodule, configured to determine a target rule triggered by the log to be aggregated, and to determine whether the number of alarm logs that have triggered the target rule in the current cycle is less than a preset number; A first aggregation submodule is configured to aggregate the logs to be aggregated that trigger the target rule, are generated within the first preset time, and have the same alarm information and network communication information, at intervals of a first preset time; The second aggregation submodule is used to aggregate the logs to be aggregated that trigger the target rule, are generated within the second preset time, and have the same alarm information and network communication information every second preset time; if not, the first preset time is greater than the first preset time.
8. An electronic device, characterized in that: include: memory for storing computer programs; A processor, configured to implement the steps of the alarm aggregation method according to any one of claims 1 to 5 when executing the computer program.
9. A storage medium, characterized in that: The storage medium stores a computer program, which, when executed by a processor, implements the steps of the alarm aggregation method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Vulnerability attack state detection method and device, computer equipment and storage medium
CN113472803A
Alarm aggregation method, device and equipment and computer storage medium
CN113904815A