A method and system for tracing and analyzing information security incidents
By combining real-time monitoring and message analysis with contingency plan database matching, rapid source tracing and processing of information security incidents has been achieved, solving the problem of low source tracing efficiency in existing technologies and improving emergency response capabilities.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-10
- Publication Date
- 2026-03-27
AI Technical Summary
Existing technologies for tracing and identifying information security incidents are inefficient, have long response times, and are difficult to process quickly and efficiently.
By monitoring alarm information of information security incidents in real time, obtaining raw data packets, identifying the attribute information of industrial control protocols, and matching them with malicious operations in the contingency plan database, the process of incident alarm - rapid packet analysis - source tracing is realized.
It significantly shortens the response time of information security incidents, improves the efficiency of emergency tracing and tracking, and can quickly identify and handle malicious operations in industrial control protocol and database attack incidents.
Smart Images

Figure CN116248409B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of industrial information security, and particularly relates to a tracking and tracing analysis method and system for information security events. BACKGROUND
[0002] At present, the threats to industrial information security are increasing. With the extensive integration and wide popularization of the industrial internet, the current industrial information security has attracted widespread attention.
[0003] In practice, information security incidents occur frequently. The first time after a serious security incident is to handle the early warning and alarm. The most important thing in the subsequent processing is to further track and trace the information security event, so as to master the key information of the information security event. However, after the occurrence of an industrial information security event, how to quickly and efficiently trace the source of the information security event is a technical problem that needs to be solved by those skilled in the art. In the prior art, the tracking and tracing of information security events is carried out by using log management, and the response time is long, and the tracing efficiency is relatively low. SUMMARY
[0004] Therefore, the technical problem to be solved by the present application is to overcome the defects of tracking and tracing information security events in the prior art, so as to provide a tracking and tracing analysis method and system for information security events, which can form an entire processing flow and solution of event alarm-quick message analysis-tracking and tracing, significantly shorten the response time, and improve the emergency tracing efficiency.
[0005] The technical solution of the present application to solve the above technical problems is as follows:
[0006] In a first aspect, the present application provides a tracking and tracing analysis method for information security events, comprising the following steps:
[0007] Real-time monitoring of whether there is alarm information of an information security event, when the alarm information is monitored, obtaining the original data message of the information security event;
[0008] Obtaining attribute information of an industrial control protocol of the information security event by identifying the original data message;
[0009] According to the attribute information, the malicious operation of the information security event is searched and matched with the malicious operation in the preplan library, and the information security event is tracked and traced according to the matching result.
[0010] The information security event tracking and tracing analysis method provided by the embodiment of the present application can shorten the response time and improve the emergency tracing efficiency.
[0011] Optionally, the tracking and tracing processing result of the information security event is sent to an upper computer system for storage and display, and an emergency processing plan is determined according to the tracking and tracing result.
[0012] The present application can enrich the matching sample types by storing the tracking and tracing result according to different malicious operations in the upper computer system; the current tracking and tracing result can be displayed through the upper computer, so that the malicious operation of the current information security event can be displayed in a more direct way, and the operator can understand the key information of the current information security event, so as to take targeted follow-up operations.
[0013] Optionally, the industrial control protocol is encapsulated in the TCP protocol for transmission.
[0014] The industrial control protocol of the present application is encapsulated in the TCP protocol, so that the industrial internet system can transmit data according to the format and communication mode of the TCP protocol, and can be connection-oriented to provide end-to-end reliability services.
[0015] Optionally, the information security event includes parameter tampering events and database attack events of the industrial control protocol; and the malicious operation corresponding to the information security event includes a first malicious operation on the industrial control protocol and a second malicious operation on the database.
[0016] The present application can track and trace the malicious operation of the parameter tampering event and the database attack event of the industrial control protocol, which are the more common threats faced by industrial information security. By tracking and tracing these two kinds of malicious operations, the key information of the information security event can be mastered to a certain extent, the response time can be shortened, and the emergency tracing efficiency can be improved.
[0017] Optionally, the plan library includes an industrial control protocol tracing plan library and a database tracing plan library; the industrial control protocol tracing plan library is used for pre-storing the industrial control protocol malicious operation that causes the tampering of each parameter information of the industrial control protocol; and the database tracing plan library is used for pre-storing the database malicious operation associated with the source IP address, the source port, the login username and the used database name.
[0018] The preplan library provided by the present application contains the malicious operation of the industrial control protocol that causes the parameter information of the industrial control protocol to be tampered with and the malicious operation of the database associated with the source IP address, the source port, the login username and the use database name, and the key information of the historical information security event can be classified and stored as matching samples through the preplan library, so that the current information security event can be quickly tracked and traced.
[0019] Optionally, the process of searching and matching the malicious operation of the information security event with the malicious operation in the preplan library according to the attribute information and tracking and tracing the information security event according to the matching result includes: judging whether the attribute information exists malicious tampering through the port information of the attribute information, if the attribute information exists malicious tampering, searching in the industrial control protocol tracing preplan library according to the port information to obtain the first malicious operation matched with the current information security event, searching in the database tracing preplan library according to at least one of the source IP address, the source port, the login username or the use database name of the attribute information to obtain the second malicious operation matched with the current information security event, and tracking and tracing the malicious operation of the information security event according to the matching result.
[0020] The present application tracks and traces the malicious operation of the current information security event through the attribute information of the industrial control protocol. When the malicious operation of the industrial control protocol occurs, the port information can be parsed to the parameter information of the industrial control protocol, so that the parameter information of the industrial control protocol is found to be tampered with, and it is determined that there is malicious tampering. Meanwhile, the industrial control protocol tracing preplan library is called to search and match, and the malicious operation of the industrial control protocol of the user is restored. When the malicious operation of the database occurs, at least one of the source IP address, the source port, the login username or the use database name can be matched to the malicious operation of the user to the database from the historical events of the database tracing preplan library. Through searching and matching the attribute information of the industrial control protocol of the information security event with the historical information in the preplan library, the efficiency of tracking and tracing can be improved.
[0021] In a second aspect, an embodiment of the present application provides a tracking and tracing analysis system for information security events, which comprises:
[0022] A packet acquisition module is configured to monitor whether an alarm information exists in the information security event in real time, and acquire original data packets of the information security event when the alarm information is monitored.
[0023] An attribute identification module is configured to acquire attribute information of an industrial control protocol of the information security event by identifying the original data packets.
[0024] The tracking and tracing module is configured to search and match the malicious operation of the information security event with the malicious operation in the preplan library according to the attribute information, and track and trace the information security event according to the matching result.
[0025] The tracking and tracing analysis system for the information security event provided by the embodiment of the present application can shorten the response time and improve the emergency tracing efficiency.
[0026] In a third aspect, the embodiment of the present application provides a computer device, including a memory and a processor, which are communicatively connected with each other, and the memory stores computer instructions, and the processor executes the computer instructions to perform the method in the first aspect or any optional implementation manner of the first aspect.
[0027] In a fourth aspect, the embodiment of the present application provides a computer readable storage medium, which stores computer instructions, and the computer instructions are used to make the computer execute the method in the first aspect or any optional implementation manner of the first aspect. BRIEF DESCRIPTION OF DRAWINGS
[0028] In order to more clearly illustrate the specific embodiments of the present application or the technical solutions in the prior art, the drawings needed in the specific embodiments or the prior art description will be briefly introduced as follows. Obviously, the drawings in the following description are some embodiments of the present application, and those skilled in the art can also obtain other drawings according to these drawings without creative labor.
[0029] Figure 1 The flowchart of the tracking and tracing analysis method for the information security event provided by the embodiment of the present application is shown in the figure.
[0030] Figure 2 The structural diagram of the tracking and tracing analysis system for the information security event provided by the embodiment of the present application is shown in the figure.
[0031] Figure 3 The structural diagram of the computer device provided by the embodiment of the present application is shown in the figure. DETAILED DESCRIPTION
[0032] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0033] Furthermore, the technical features involved in the different embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.
[0034] This invention provides a method for tracing and analyzing the source of information security incidents, such as... Figure 1 As shown, the method specifically includes the following steps:
[0035] Step S1: Monitor in real time whether there are alarm messages for information security events. When the alarm message is detected, obtain the original data message of the information security event.
[0036] Specifically, in this embodiment of the invention, the Industrial Internet will issue early warnings and alarms immediately when an information security incident occurs during information transmission. Therefore, real-time monitoring of information security incidents and the presence of alarm information enables rapid response when such incidents occur. During data transmission, data packets are data units exchanged and transmitted in the network, i.e., data blocks that a station sends at one time. The original packet data not only contains the complete data information to be sent but also necessary additional information, such as: destination IP, destination port, source address, source port, data length, protocol used, encryption information, etc. Therefore, obtaining the original packet data of an information security incident allows for tracing and identifying the source of the incident based on the necessary additional information in the packet data.
[0037] The information security events involved in the embodiments of the present invention include: parameter tampering events of industrial control protocols and database attack events. Therefore, the malicious operations corresponding to the information security events include: a first malicious operation on the industrial control protocol and a second malicious operation on the database.
[0038] Step S2: Obtain the industrial control protocol attribute information of the information security event by identifying the original data packet.
[0039] Specifically, in the embodiment of the present application, the industrial internet industrial control protocol is encapsulated in the TCP protocol, data transmission is carried out according to the format and communication mode of the TCP protocol, face-to-face connection can be realized, and end-to-end reliability service is provided. The common point of the abnormal behavior of the common TCP stream is the clustering information in the TCP stream, such as abnormal phenomena of source / destination IP address, port, network segment, etc., therefore, the present application adopts a network transmission layer abnormal message tracing method to track and trace the current information security event, and through analyzing and identifying the original message data, the attribute information of the information security event is obtained.
[0040] Step S3: according to the attribute information, the malicious operation of the information security event is searched and matched with the malicious operation in the preplan library, and the information security event is tracked and traced according to the matching result.
[0041] Specifically, in the embodiment of the present application, the pre-set preplan library includes an industrial control protocol tracing preplan library and a database tracing preplan library. The industrial control protocol tracing preplan library is used to pre-store the industrial control protocol malicious operation causing the tampering of the industrial control protocol parameter information, and the database tracing preplan library is used to pre-store the database malicious operation associated with the source IP address, source port, login username and use database name. Therefore, after obtaining the attribute information of the industrial control protocol, the malicious operation of the information security event is searched and matched with the malicious operation in the preplan library.
[0042] In the embodiment of the present application, the process of tracking and tracing the malicious operation of the user on the industrial control protocol according to the attribute information of the industrial control protocol of the current information security event is: judging whether the attribute information exists malicious tampering through the port information of the attribute information, if the malicious tampering exists, searching in the industrial control protocol tracing preplan library according to the port information, and obtaining the first malicious operation matched with the current information security event. The process of tracking and tracing the malicious operation of the user on the database according to the attribute information of the industrial control protocol of the current information security event is: searching in the database tracing preplan library according to at least one of the source IP address, source port, login username or use database name of the attribute information, and obtaining the second malicious operation matched with the current information security event. The malicious operation of the current information security event is tracked and traced according to the matching result obtained by the above operation.
[0043] In addition, the embodiment of the present application also includes sending the tracking and tracing processing result to the host computer system for storage and display, and determining the emergency treatment preplan according to the tracking and tracing result, and carrying out targeted and continuous monitoring and setting safety protection measures.
[0044] The information security event tracking and tracing analysis method provided by the embodiment of the present application provides an information security event tracking and tracing processing procedure of event alarm-quick message analysis-tracing and tracking, which can shorten the response time and improve the emergency tracing and tracking efficiency.
[0045] The embodiment of the present application provides an information security event tracking and tracing analysis system. Figure 2 As shown in the figure, the system comprises:
[0046] The message acquisition module 1 is used for monitoring whether there is alarm information of the information security event in real time, and acquiring original data messages of the information security event when the alarm information is monitored.
[0047] The attribute identification module 2 is used for acquiring attribute information of the industrial control protocol of the information security event by identifying the original data messages.
[0048] The tracking and tracing module 3 is used for searching and matching the malicious operation of the information security event and the malicious operation in the preplan library according to the attribute information, and tracking and tracing the information security event according to the matching result.
[0049] The information security event tracking and tracing analysis system provided by the embodiment of the present application provides an information security event tracking and tracing processing procedure of event alarm-quick message analysis-tracing and tracking, which can shorten the response time and improve the emergency tracing and tracking efficiency.
[0050] Figure 3 The structure schematic diagram of the computer device in the embodiment of the present application is shown, which comprises a processor 901 and a memory 902, wherein the processor 901 and the memory 902 can be connected through a bus or other manners, Figure 3 For example, the bus connection is taken as an example.
[0051] The processor 901 can be a central processing unit (CPU). The processor 901 can also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, or a combination thereof.
[0052] The memory 902, as a non-transitory computer-readable storage medium, can be used to store non-transitory server programs, non-transitory computer-executable programs and modules, such as program instructions / modules corresponding to the methods in the above method embodiments. The processor 901 performs various functional applications and data processing of the processor by running the non-transitory server programs, instructions and modules stored in the memory 902, that is, implements the methods in the above method embodiments.
[0053] The memory 902 can include a program storage area and a data storage area, wherein the program storage area can store an operating system, at least one application required by a function; and the data storage area can store data created by the processor 901 and the like. In addition, the memory 902 can include a high-speed random access memory, and can also include a non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state memory device. In some embodiments, the memory 902 can optionally include a memory disposed remotely with respect to the processor 901, and these remote memories can be connected to the processor 901 through a network. Examples of the above network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.
[0054] One or more modules are stored in the memory 902, and when executed by the processor 901, the method in the above method embodiments is performed.
[0055] The above computer device specific details can be understood by referring to the corresponding related descriptions and effects in the above method embodiments, which will not be repeated here.
[0056] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program. The implemented program can be stored in a computer readable storage medium. When the program is executed, it can include the processes of the above-mentioned embodiment methods. The storage medium can be a magnetic disc, an optical disc, a read-only memory (ROM), a random access memory (RAM), a flash memory, a hard disk drive (HDD) or a solid-state drive (SSD), etc. The storage medium can also include a combination of the above-mentioned types of memories.
[0057] Although the embodiments of the present application are described in conjunction with the drawings, various modifications and changes can be made by those skilled in the art without departing from the spirit and scope of the present application, and such modifications and changes fall within the scope defined by the appended claims.
Claims
1. A method for tracing and analyzing the source of information security incidents, characterized in that, Includes the following steps: The system monitors in real time whether there are alarm messages for information security events. When an alarm message is detected, the system obtains the original data message of the information security event. The information security event includes: parameter tampering events of industrial control protocols and database attack events. The malicious operation corresponding to the information security event includes: a first malicious operation on the industrial control protocol and a second malicious operation on the database. The attribute information of the industrial control protocol of the information security event is obtained by identifying the original data packets. Based on the attribute information, the malicious operations of the information security incident are searched and matched with the malicious operations in the contingency plan database, and the information security incident is traced and its source is tracked based on the matching results; The contingency plan library includes: an industrial control protocol tracing contingency plan library and a database tracing contingency plan library; the industrial control protocol tracing contingency plan library is used to pre-store malicious operations of the industrial control protocol that cause the modification of various parameters of the industrial control protocol; the database tracing contingency plan library is used to pre-store malicious database operations associated with the source IP address, source port, login username and database name used. The process of searching and matching the malicious operations of the information security event with malicious operations in the contingency plan database based on the attribute information, and tracing the source of the information security event based on the matching results, includes: determining whether the attribute information has been maliciously tampered with based on the port information of the attribute information; if malicious tampering exists, searching the industrial control protocol tracing contingency plan database based on the port information to obtain a first malicious operation matching the current information security event; searching the database tracing contingency plan database based on at least one of the source IP address, source port, login username, or database name used in the attribute information to obtain a second malicious operation matching the current information security event; and tracing the source of the malicious operations of the information security event based on the matching results.
2. The method for tracing and analyzing the source of information security incidents according to claim 1, characterized in that, Also includes: The results of the tracking and tracing of the information security incident are sent to the host computer system for storage and display, and an emergency response plan is determined based on the tracking and tracing results.
3. The method for tracing and analyzing the source of information security incidents according to claim 1, characterized in that, The industrial control protocol is encapsulated in the TCP protocol for transmission.
4. A system for tracing and analyzing the source of information security incidents, characterized in that, include: The message acquisition module is used to monitor in real time whether there are alarm messages for information security events. When the alarm message is detected, the module acquires the original data message of the information security event. The information security event includes: parameter tampering events of industrial control protocols and database attack events. The malicious operations corresponding to the information security event include: a first malicious operation on the industrial control protocol and a second malicious operation on the database. The attribute recognition module is used to obtain the attribute information of the industrial control protocol of the information security event by recognizing the original data packet; The tracing and source-tracing module is used to search and match the malicious operations of the information security event with the malicious operations in the contingency plan database based on the attribute information, and to trace and source the information security event based on the matching results; The contingency plan library includes: an industrial control protocol tracing contingency plan library and a database tracing contingency plan library; the industrial control protocol tracing contingency plan library is used to pre-store malicious operations of the industrial control protocol that cause the modification of various parameters of the industrial control protocol; the database tracing contingency plan library is used to pre-store malicious database operations associated with the source IP address, source port, login username and database name used. The process of searching and matching the malicious operations of the information security event with malicious operations in the contingency plan database based on the attribute information, and tracing the source of the information security event based on the matching results, includes: determining whether the attribute information has been maliciously tampered with based on the port information of the attribute information; if malicious tampering exists, searching the industrial control protocol tracing contingency plan database based on the port information to obtain a first malicious operation matching the current information security event; searching the database tracing contingency plan database based on at least one of the source IP address, source port, login username, or database name used in the attribute information to obtain a second malicious operation matching the current information security event; and tracing the source of the malicious operations of the information security event based on the matching results.
5. An electronic device, characterized in that, include: A memory and a processor are interconnected, the memory stores computer instructions, and the processor executes the computer instructions to perform the information security event tracing and source analysis method according to any one of claims 1-3.
6. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing the computer to execute the information security incident tracing and analysis method according to any one of claims 1-3.
Citation Information
Patent Citations
Network security event analysis method and device and storage medium
CN115484100A