Index-based Network Security Data Processing Method, Apparatus and Electronic Device
By determining the flow table number in network security data processing and selecting reference data sets for correlation calculation, the problem of difficulty in discovering network security risks in the prior art is solved, and efficient network security analysis and risk detection are achieved.
Patent Information
- Application Number
- CN202310153818.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-17
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2043-02-17
AI Technical Summary
It is difficult for the existing technology to effectively detect potential network security risks and attacks, the network security analysis is under great pressure, the attack methods are diverse, and existing methods are difficult to efficiently process network security data.
By determining the first flow table number of network security data and in the case where the flow table number is not included in the indexable expression chain of the association analysis expression, N-1 reference data sets are selected from the table slot and added to the association calculation table for association calculation, and network security analysis is performed using the equal-value indexable expression chain or dynamic equal-value indexable expression chain.
It realizes network security analysis and detection of multiple data streams, can promptly discover security risks, reduce network security risks, and improves the efficiency and accuracy of network security data processing.
Smart Images

Figure CN116346416B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to an index-based network security data processing method, device and electronic device. Background Art
[0002] The rapid development of Internet technology and the gradual deepening of digital transformation in all walks of life have brought great convenience to people's lives and work. However, with the development of technology and the spread of knowledge, the methods and number of network attacks have also increased significantly, and various new attack methods have emerged in an endless stream, bringing great challenges and pressure to security analysts and products.
[0003] Therefore, how to discover various potential security risks and attacks and reduce network security risks is a technical problem that needs to be solved urgently. Summary of the invention
[0004] In view of the problems in the prior art, embodiments of the present invention provide a network security data processing method, device and electronic device based on indexing.
[0005] Specifically, the embodiment of the present invention provides the following technical solutions:
[0006] In a first aspect, an embodiment of the present invention provides an index-based network security data processing method, comprising:
[0007] Determine a first flow table number corresponding to the network security data; the first flow table number is the number of the first data flow table in the table slot; the table slot stores N data flow tables, where N is an integer greater than or equal to 3;
[0008] In the case that the indexable expression chain corresponding to the association analysis expression does not include the first flow table number, N-1 reference data sets are selected from the other N-1 data flow tables in the table slot except the first data flow table and added to the association calculation table; the network security data is added to the association calculation table; wherein the indexable expression chain includes an expression chain composed of multiple indexable expressions, each indexable expression corresponds to two different data flow tables; each reference data set comes from a different data flow table, and each reference data set includes at least one data;
[0009] An association calculation is performed on the data in the association calculation table to obtain at least one association result; the association result is used to perform network security analysis on the network security data.
[0010] Further, the indexable expression chain includes: an equal-value indexable expression chain or a dynamic equal-value indexable expression chain;
[0011] In the equivalent indexable expression chain, every two indexable expressions are associated through the same attribute information of the row data in the same flow table; in the dynamic equivalent indexable expression chain, every two indexable expressions are associated through the same flow table.
[0012] The left value and the right value of the indexable expression are equal, and the left value and the right value respectively correspond to the attribute information of the row data in two different flow tables; the indexable expression is a key Boolean expression, and the value of the key Boolean expression determines the value of the association expression.
[0013] Further, selecting N - 1 reference data sets from the other N - 1 data flow tables in the table slot except the first data flow table and adding them to the association calculation table includes:
[0014] Traverse the other N - 1 data flow tables in the table slot except the first data flow table. When the equivalent indexable expression chain includes the second data flow table traversed, record the second data flow table into the accessed table set, and add the first data storage table of the second data flow table to the association calculation table;
[0015] Traverse each reference data in the first data storage table. For the first reference data traversed, traverse all the linked data flow tables directly or indirectly linked from the second data flow table, and record the target data flow table traversed into the accessed table set;
[0016] When the equivalent indexable expression chain includes the target data flow table, add the reference data set corresponding to the index value of the first reference data in the data storage table of the target data flow table to the association calculation table.
[0017] Further, selecting N - 1 reference data sets from the other N - 1 data flow tables in the table slot except the first data flow table and adding them to the association calculation table includes:
[0018] Traverse the other N - 1 data flow tables in the table slot except the first data flow table. When the dynamic equivalent indexable expression chain includes the second data flow table traversed, record the second data flow table into the accessed table set, and add the first data storage table of the second data flow table to the association calculation table;
[0019] Traverse each reference data in the first data storage table. For the first reference data traversed, traverse all the linked data flow tables directly or indirectly linked from the second data flow table, and record the target data flow table traversed into the accessed table set;
[0020] When the target data flow table is included in the equivalent indexable expression chain, add the target data in the data storage table of the target data flow table to the association calculation table; the index value corresponding to the flow table number of the second data flow table saved in the target data is the same as the index value of the first reference data.
[0021] Further, the performing association calculation on the data in the association calculation table to obtain at least one association result includes:
[0022] Traverse the association calculation table, and each time during traversal, select one reference data in sequence from the N - 1 reference data sets to obtain N - 1 reference data, and perform association calculation on the network security data and the N - 1 reference data to obtain the association result.
[0023] Further, the performing association calculation on the network security data and the N - 1 reference data to obtain the association result includes:
[0024] Obtain the association condition in the association analysis expression, where the association condition includes a preset relationship of attribute information of at least two flow table data;
[0025] Judge whether the attribute information of the network security data and the N - 1 reference data conforms to the preset relationship;
[0026] When the attribute information of the network security data and the N - 1 reference data conforms to the preset relationship, determine that the association result is successful association;
[0027] When the attribute information of the network security data and the N - 1 reference data does not conform to the preset relationship, determine that the association result is failed association.
[0028] Further, the method further includes:
[0029] When the association result is successful association, use the network security data and the N - 1 reference data as associated data, and determine that there is a network security risk between the network security data and the N - 1 reference data.
[0030] Further, the method further includes:
[0031] When the association result is successful association, generate a risk prompt message;
[0032] Wherein, the risk prompt message is used to indicate that there is a network security risk between the network security data and the N - 1 reference data.
[0033] Further, the method further includes:
[0034] Determine a listener for the network security data, where the listener is used to monitor whether the network security data is deleted; add the listener to the listener list associated with the network security data.
[0035] In a second aspect, an embodiment of the present invention further provides a network security data processing device based on an index, including:
[0036] A determination module, configured to determine a first flow table number corresponding to network security data; the first flow table number is the number of the first data flow table in the table slot; N data flow tables are stored in the table slot, and N is an integer greater than or equal to 3;
[0037] A processing module, configured to, when the indexable expression chain corresponding to the association analysis expression does not include the first flow table number, select N - 1 reference data sets from the other N - 1 data flow tables in the table slot except the first data flow table and add them to the association calculation table; add the network security data to the association calculation table; wherein, the indexable expression chain includes an expression chain composed of multiple indexable expressions, and each indexable expression corresponds to two different data flow tables; each reference data set comes from a different data flow table, and each reference data set includes at least one piece of data;
[0038] An association module, configured to perform association calculation on the data in the association calculation table to obtain at least one association result; the association result is used to perform network security analysis on the network security data.
[0039] In a third aspect, an embodiment of the present invention further provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the network security data processing method based on an index as described in the first aspect.
[0040] In a fourth aspect, an embodiment of the present invention further provides a non - transient computer - readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the network security data processing method based on an index as described in the first aspect.
[0041] In a fifth aspect, an embodiment of the present invention further provides a computer program product, on which executable instructions are stored. When the instructions are executed by a processor, the processor is caused to implement the network security data processing method based on an index as described in the first aspect.
[0042] The network security data processing method, device, and electronic device based on indexing provided by the embodiments of the present invention determine the first flow table number corresponding to network security data. The first flow table number is the number of the first data flow table in the table slot. When the indexable expression chain corresponding to the correlation analysis expression does not include the first flow table number, N - 1 reference data sets are selected from the other N - 1 data flow tables in the table slot except the first data flow table and added to the correlation calculation table, and the network security data is added to the correlation calculation table. Each reference data set comes from a different data flow table. The data in the correlation calculation table is subjected to correlation calculation to obtain at least one correlation result. Based on the correlation result, network security analysis of network security data can be performed, realizing network security analysis and detection of multiple data flows, being able to discover security risks in a timely manner, and reducing network security risks. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0044] Figure 1 is a flowchart of the network security data processing method based on indexing provided by the embodiments of the present invention;
[0045] Figure 2 is a flowchart of inserting data flow data provided by the embodiments of the present invention;
[0046] Figure 3 is a flowchart of inserting an equivalent value table provided by the embodiments of the present invention;
[0047] Figure 4 is a flowchart of inserting a dynamic equivalent value table provided by the embodiments of the present invention;
[0048] Figure 5 is a flowchart of inserting a regular table provided by the embodiments of the present invention;
[0049] Figure 6 is a flowchart of processing a linked equivalent value table provided by the embodiments of the present invention;
[0050] Figure 7 is a flowchart of processing a linked dynamic equivalent value table provided by the embodiments of the present invention;
[0051] Figure 8 is a flowchart of accessing an equivalent value table provided by the embodiments of the present invention;
[0052] Figure 9It is a schematic flowchart of accessing a dynamic equivalent table provided by an embodiment of the present invention;
[0053] Figure 10 It is a schematic flowchart of accessing a conventional table provided by an embodiment of the present invention;
[0054] Figure 11 It is a schematic flowchart of correlating table data provided by an embodiment of the present invention;
[0055] Figure 12 It is a schematic flowchart of deleting data stream data provided by an embodiment of the present invention;
[0056] Figure 13 It is a schematic flowchart of updating data stream data provided by an embodiment of the present invention;
[0057] Figure 14 It is a schematic flowchart of notifying data stream data timeout provided by an embodiment of the present invention;
[0058] Figure 15 It is a schematic structural diagram of an index-based network security data processing device provided by an embodiment of the present invention;
[0059] Figure 16 It is a schematic entity structure diagram of an electronic device provided by an embodiment of the present invention. Detailed implementation manners
[0060] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0061] Tables 1-10 show the data structure definitions and parameter definitions in the embodiments of the present invention. As shown in Tables 1-10:
[0062] Table 1 Equivalent table node link definition
[0063]
[0064] Table 2 Equivalent table definition
[0065]
[0066] Table 3 Dynamic equivalent table link definition
[0067]
[0068] Table 4 Dynamic equivalent table definition
[0069]
[0070] Table 5 Conventional Table Definition
[0071]
[0072] Table 6 Parameter Definition
[0073]
[0074]
[0075] Table 7 Data Processing Flow Parameter Definition
[0076]
[0077] Table 8 Definition of insertStreamData(data) for Inserting Data Stream
[0078]
[0079] Table 9 Key Process of Inserting Data Stream
[0080]
[0081]
[0082] In the present invention, the structural definition of the association analysis expression is: join [flow table definition] if [association expression definition]. The structure of the association analysis expression includes two parts: the flow table definition and the association expression definition, as shown in Table 10.
[0083] Table 10 Structural Definition of Association Analysis Expression
[0084]
[0085]
[0086] An example is as follows:
[0087] join stream1 as table1, stream2 as table2, stream3 as table3 if table1.sip == table2.sip and table2.sport < table3.sport.
[0088] The expression chain provided in the present invention includes an equivalent expression chain or a dynamic equivalent expression chain. The definitions of the equivalent index, dynamic index, and local index in the present invention are as follows:
[0089] 1. Definition of equivalent index:
[0090] As the name implies, an equivalent index means that the index expression conditions used to construct the table are equivalent, that is, the left and right values of the expression are equal. For the equivalent index of a multi-flow table, an equivalent expression chain is required, and this equivalent expression chain will include all flow tables. The example is as follows:
[0091] The correlation analysis expression is, for example: join stream1 as table1, stream2 as table2, stream3 as table3 if table1.sip == table2.sip and table2.sip == table3.dip.
[0092] In this example, the expressions table1.sip == table2.sip and table2.sip == table3.dip have an equivalent transfer expression table2.sip. Through this equivalent transfer expression, an equivalent expression chain table1.sip == table2.sip == table3.dip that includes all flow tables can be constructed. Then, equivalent indexes can be constructed using table1.sip, table2.sip, and table3.dip (destination IP) for table1, table2, and table3 respectively. By constructing an index on each flow table through this principle, the performance of flow table correlation calculation can be significantly improved.
[0093] 2. Definition of dynamic index:
[0094] The dynamic index is a concept relative to the equivalent index. The scenarios where the equivalent index can be used are relatively limited because it requires an equivalent expression chain that includes all flow tables, and usually there are relatively few cases that can meet this requirement. In order to make more full use of the equivalent expressions in the correlation analysis expression, the conditions of the equivalent index can be relaxed, and the concept of the dynamic index is introduced.
[0095] The dynamic index does not require an equivalent expression chain that includes all flow tables. It only requires an expression chain composed of multiple equivalent expressions, and this expression chain includes all flow tables. At the same time, these expressions can be associated through the same flow table into an interconnected expression chain. The example is as follows:
[0096] The correlation analysis expression is, for example: join stream1 as table1, stream2 as table2, stream3 as table3 if table1.sip == table2.sip and table2.dip == table3.dip. In the above example, there are two equal-value expressions: table1.sip == table2.sip and table2.dip == table3.dip. They are associated through the same flow table table2 and can form a dynamic equal-value expression chain => table1.sip == table2.sip <-> table2.dip == table3.dip. Here, table1.sip == table2.sip and table2.dip == table3.dip form a dynamic equal-value expression chain.
[0097] 3. Local index definition:
[0098] Compared with the equal-value index and the dynamic index, the local index has lower requirements for expressions. The equal-value index and the dynamic index respectively require the existence of an equal-value expression chain and a dynamic equal-value expression chain that contain all flow tables, while the local index does not have this requirement. It only requires at least one equal-value expression chain or dynamic equal-value expression chain, and does not require each expression chain to contain all flow tables. In this way, the equal-value conditions in the expressions can be utilized as much as possible to accelerate the correlation calculation speed. The example is as follows:
[0099] The correlation analysis expression is, for example: join stream1 as table1, stream2 as table2, stream3 as table3, stream4 as table4 if table1.sip == table2.sip and table3.dip == table4.dip. In the expression, table1.sip == table2.sip and table3.dip == table4.dip are neither equal-value indexes nor dynamic indexes, but they can construct two local indexes (table1.sip == table2.sip, table3.dip == table4.dip). Using these two local indexes can also significantly improve the correlation calculation speed.
[0100] Figure 1 It is a schematic flowchart of the network security data processing method based on indexes provided by an embodiment of the present invention. As Figure 1 shown, the network security data processing method based on indexes includes the following steps:
[0101] Step 101: Determine the first flow table number corresponding to the network security data; the first flow table number is the number of the first data flow table in the table slot; N data flow tables are stored in the table slot, and N is an integer greater than or equal to 3.
[0102] It should be noted that the execution subject of the network security data processing method based on index provided in the embodiments of the present invention can be a network security data processing device based on index, such as a network security detection device, a network security analysis device or a network security analysis engine, etc., which are network security data using devices. The network security data processing method based on index provided in the embodiments of the present invention is used for security analysis and detection of multi-data streams.
[0103] Optionally, the network security data may include, for example, logs, emails, programs or files, etc. Different data flow tables are used to store data streams from different servers.
[0104] Step 102: When the first flow table number is not included in the indexable expression chain corresponding to the association analysis expression, select N - 1 reference data sets from the other N - 1 data flow tables in the table slot except the first data flow table and add them to the association calculation table; add the network security data to the association calculation table; wherein, the indexable expression chain includes an expression chain composed of multiple indexable expressions, and each indexable expression corresponds to two different data flow tables; each reference data set comes from a different data flow table, and each reference data set includes at least one piece of data.
[0105] Optionally, the indexable expression chain includes: an equivalent indexable expression chain or a dynamic equivalent indexable expression chain; in the equivalent indexable expression chain, every two indexable expressions are associated through the same attribute information of the row data of the same flow table; in the dynamic equivalent indexable expression chain, every two indexable expressions are associated through the same flow table; wherein, the left value and the right value of the indexable expression are equal, and the left value and the right value respectively correspond to the attribute information of the row data of two different flow tables; the indexable expression is a key Boolean expression, and the value of the key Boolean expression determines the value of the association expression.
[0106] Table 11 shows the data structure definition and parameter definition in the embodiments of the present invention. As shown in Table 11:
[0107] Table 11 Expression Definition
[0108]
[0109]
[0110]
[0111] Optionally, when the first flow table number is not included in the indexable expression chain corresponding to the association analysis expression, the data type of the first data flow table is GeneralTable.
[0112] When the first flow table number is included in the equivalent indexable expression chain corresponding to the association analysis expression, the data type of the first data flow table is EqualTable.
[0113] When the first flow table number is included in the dynamic equivalent indexable expression chain corresponding to the association analysis expression, the data type of the first data flow table is DynamicEqualTable.
[0114] Optionally, whether a local index exists for an association analysis expression must satisfy one of the following conditions:
[0115] 1. It contains at least one [equivalent indexable expression chain] or [dynamic equivalent indexable expression chain];
[0116] 2. All [indexable expressions] in these [equivalent indexable expression chains] or [dynamic equivalent indexable expression chains] are [key boolean expressions] at the same time;
[0117] It can be seen that the only difference between the local index and the equivalent index and the dynamic index is that the local index does not require all flow tables in the [flow table definition] to be included in the same index expression chain, which is also the meaning of the word "local", that is, the local index does not require all flow tables to participate in the construction.
[0118] An example is as follows:
[0119] join stream1 as table1, stream2 as table2, stream3 as table3, stream4 as table4 if table1.sip == table2.sip and (table1.sport < table2.sport or table1.dport == table3.dport) and table3.dip == table4.dip
[0120] In the above expression, table1.sip == table2.sip and table3.dip == table4.dip are [indexable expressions] and are [key boolean expressions], table1.dport == table3.dport (destination port) is an [indexable expression], but not a [key boolean expression]
[0121] The two expressions "table1.sip == table2.sip" and "table3.dip == table4.dip" are two [equivalent indexable expression chains]. Each expression chain can neither construct an equivalent index nor a dynamic index, but the local indexes can be constructed using "table1.sip == table2.sip" and "table3.dip == table4.dip", that is, "table1.sip == table2.sip" is a local index and "table3.dip == table4.dip" is another local index.
[0122] In summary, the indexes of the example expressions are "table1.sip == table2.sip" and "table3.dip == table4.dip". When constructing, "table1.sip == table2.sip" and "table3.dip == table4.dip" are respectively used to construct the local indexes of table1<->table2 and table3<->table4.
[0123] Step 103: Perform association calculation on the data in the association calculation table to obtain at least one association result; the association result is used to perform network security analysis on the network security data.
[0124] Optionally, store the network security data, and determine a listener for the network security data; the listener is used to monitor whether the network security data is deleted; add the listener to the listener list associated with the network security data.
[0125] The method for processing network security data based on index provided by the embodiment of the present invention determines the first flow table number corresponding to the network security data. The first flow table number is the number of the first data flow table in the table slot. When the indexable expression chain corresponding to the association analysis expression does not include the first flow table number, select N-1 reference data sets from the other N-1 data flow tables in the table slot except the first data flow table and add them to the association calculation table, and add the network security data to the association calculation table. Each reference data set comes from a different data flow table. Perform association calculation on the data in the association calculation table to obtain at least one association result. Based on the association result, network security analysis can be performed on the network security data, realizing network security analysis and detection of multiple data flows, being able to discover security risks in time, and reducing network security risks.
[0126] Optionally, the implementation manner of selecting N-1 reference data sets from the other N-1 data flow tables in the table slot except the first data flow table and adding them to the association calculation table may include:
[0127] Step a: Traverse the other N - 1 data flow tables in the table slots except the first data flow table. When the second data flow table encountered during the traversal is included in the equivalent indexable expression chain, record the second data flow table into the set of visited tables, and add the first data storage table of the second data flow table to the associated calculation table.
[0128] Optionally, when the second data flow table encountered during the traversal is included in the equivalent indexable expression chain, the data type of the second data flow table is EqualTable.
[0129] Step b: Traverse each reference data in the first data storage table. For the first reference data encountered during the traversal, traverse all the linked data flow tables directly or indirectly linked from the second data flow table, and record the target data flow table encountered into the set of visited tables.
[0130] Step c: When the target data flow table is included in the equivalent indexable expression chain, add the reference data set corresponding to the index value of the first reference data in the data storage table of the target data flow table to the associated calculation table.
[0131] Optionally, the implementation method of selecting N - 1 reference data sets from the other N - 1 data flow tables in the table slots except the first data flow table and adding them to the associated calculation table may include:
[0132] Step 1: Traverse the other N - 1 data flow tables in the table slots except the first data flow table. When the second data flow table encountered during the traversal is included in the dynamic equivalent indexable expression chain, record the second data flow table into the set of visited tables, and add the first data storage table of the second data flow table to the associated calculation table.
[0133] Optionally, when the second data flow table encountered during the traversal is included in the dynamic equivalent indexable expression chain, the data type of the second data flow table is DynamicEqualTable.
[0134] Step 2: Traverse each reference data in the first data storage table. For the first reference data encountered during the traversal, traverse all the linked data flow tables directly or indirectly linked from the second data flow table, and record the target data flow table encountered into the set of visited tables.
[0135] Step 3, when the target data flow table is included in the equivalent indexable expression chain, add the target data in the data storage table of the target data flow table to the association calculation table; the index value corresponding to the flow table number of the second data flow table saved in the target data is the same as the index value of the first reference data.
[0136] Optionally, the implementation manner of performing association calculation on the data in the association calculation table to obtain at least one association result may include: traversing the association calculation table, and each time during traversal, sequentially selecting a reference data from the N - 1 reference data sets to obtain N - 1 reference data, and performing association calculation on the network security data and the N - 1 reference data to obtain the association result.
[0137] Optionally, the implementation manner of performing association calculation on the network security data and the N - 1 reference data to obtain the association result may include:
[0138] Step 1), obtain the association condition in the association analysis expression, where the association condition includes a preset relationship of attribute information of at least two flow table data;
[0139] For example, the association analysis expression is, for example: join stream1 as table1, stream2 as table2, stream3 as table3, stream4 as table4 if table1.sip == table2.sip and table3.dip == table4.dip, and the association condition here is table1.sip == table2.sip and table3.dip == table4.dip.
[0140] Step 2), determine whether the attribute information of the network security data and the N - 1 reference data conforms to the preset relationship;
[0141] Step 3), when the attribute information of the network security data and the N - 1 reference data conforms to the preset relationship, determine that the association result is successful; when the attribute information of the network security data and the N - 1 reference data does not conform to the preset relationship, determine that the association result is failed.
[0142] Optionally, when the association result is successful, use the network security data and the N - 1 reference data as associated data, and determine that there is a network security risk between the network security data and the N - 1 reference data.
[0143] Optionally, when the association result is successful association, risk prompt information is generated; wherein, the risk prompt information is used to indicate that there is a cybersecurity risk between the cybersecurity data and the N-1 reference data.
[0144] Figure 2 is a schematic flowchart of inserting data into a data stream provided by an embodiment of the present invention. As Figure 2 shown, the process of the insertStreamData(data) for inserting data into a data stream includes the following steps:
[0145] Step 201, call insertStreamData(data) and input data stream data <data>;
[0146] Step 202, data flow classifier <streamclassifier>Calculation <data>The corresponding flow table number index;
[0147] Step 203: Obtain the corresponding flow table tableSlot[index] from the table slot using the flow table number index;
[0148] Step 204: Determine whether the type of the flow table tableSlot[index] is an equal value table EqualTable. If it is, execute Step 205; if not, execute Step 206;
[0149] Step 205: Call the process of inserting an equal value table insertEqualTable(tableSlot[index], data). After completion, execute Step 209;
[0150] Step 206: Determine whether the type of the flow table tableSlot[index] is a dynamic equal value table DynamicEqualTable. If it is, execute Step 207; if not, execute Step 208;
[0151] Step 207: Call the process of inserting a dynamic equal value table insertDynamicEqualTable(tableSlot[index], data). After completion, execute Step 209;
[0152] Step 208: Call the process of inserting a general table insertGeneralTable(tableSlot[index], data). After completion, execute Step 209;
[0153] Step 209: Traverse the table slot tableSlot, and set the currently traversed table as tableSlot[n], where 0 <= n < N;
[0154] Step 210: Determine whether there is an untraversed table tableSlot[n] in the table slot tableSlot and the current table tableSlot[n] is not in the visited table set visitedTableSet. If so, execute Step 211; if not, execute Step 216;
[0155] Step 211: Determine whether the type of the flow table tableSlot[n] is an equal value table EqualTable. If it is, execute Step 212; if not, execute Step 213;
[0156] Step 212: Call the process of visiting an equal value table visitEqualTable(tableSlot[n]). After completion, execute Step 210;
[0157] Step 213: Determine whether the type of the flow table tableSlot[n] is the dynamic equal value table DynamicEqualTable; if so, execute Step 214; if not, execute Step 215;
[0158] Step 214: Call the process of accessing the dynamic equal value table visitDynamicEqualTable(tableSlot[n]), and after completion, execute Step 210;
[0159] Step 215: Call the process of accessing the general table visitGeneralTable(tableSlot[n]), and after completion, execute Step 210;
[0160] Step 216: Call joinTableRows(joinTableSlot, joinRowSlot, tableIndex) to perform the calculation of table data association;
[0161] Step 217: To <data>Register a deletion listener above.
[0162] Figure 3 It is a schematic flowchart of the process of inserting an equal value table provided by an embodiment of the present invention. As Figure 3 shown, the process of the insertEqualTable includes the following steps:
[0163] Step 301, call insertEqualTable(equalTable, data), and input parameters <equalTable, data>;
[0164] Step 302, use the index value generator equalTable.keyBuilder to calculate the index value keyValue corresponding to data;
[0165] Step 303, traverse the table link list equalTable.tableLinkList;
[0166] Step 304, determine whether there is an unprocessed tableLink in the table link list equalTable.tableLinkList; if so, execute Step 305; if not, execute Step 309;
[0167] Step 305, use the flow table number tableLink.linkTableID to obtain the corresponding flow table tableSlot[tableLink.linkTableID] from the table slot, and define the parameter toTable = tableSlot[tableLink.linkTableID];
[0168] Step 306, determine whether the type of the flow table toTable is an equal value table EqualTable; if so, execute Step 307; if not, execute Step 308;
[0169] Step 307, call the process of processing the linked equal value table processEqualTableLink(equalTable.tableID, toTable, keyValue), and after completion, execute Step 304;
[0170] Step 308, call the process of processing the linked dynamic equal value table processDynamicEqualTableLink(equalTable.tableID, toTable, keyValue), and after completion, execute Step 304;
[0171] Step 309: Record the current table into the set of visited tables visitedTableSet, save keyValue to data, add data to the join calculation table joinTableSlot[equalTable.tableID], save data to the indexed data storage table equalTable.keyedDataTable with keyValue as the index, and end the process after completion.
[0172] Figure 4 It is a schematic flow diagram of inserting a dynamic equal value table provided by an embodiment of the present invention. As Figure 4 shown, the process of the insert dynamic equal value table insertDynamicEqualTable includes the following steps:
[0173] Step 401: Call insertDynamicEqualTable(dynamicEqualTable, data) with input parameters <dynamicEqualTable, data>;
[0174] Step 402: Traverse the table link list dynamicEqualTable.tableLinkList;
[0175] Step 403: Determine whether there is an unprocessed tableLink in the table link list dynamicEqualTable.tableLinkList; if so, execute Step 404, if not, execute Step 408;
[0176] Step 404: Use the index value generator tableLink.keyBuilder to calculate the index value keyValue corresponding to data, save the value <[tableLink.linkTableID, keyValue> to data, obtain the corresponding flow table tableSlot[tableLink.linkTableID] from the table slot using the flow table number tableLink.linkTableID, and define the parameter toTable = tableSlot[tableLink.linkTableID];
[0177] Step 405: Determine whether the type of the flow table toTable is an equal value table EqualTable; if so, execute Step 406, if not, execute Step 407;
[0178] Step 406: Invoke the process of processing the equal table link, processEqualTableLink(dynamicEqualTable.tableID, toTable, keyValue). After completion, execute Step 403;
[0179] Step 407: Invoke the process of processing the dynamic equal table link, processDynamicEqualTableLink(dynamicEqualTable.tableID, toTable, keyValue). After completion, execute Step 403;
[0180] Step 408: Record the current table in the set of visited tables, visitedTableSet. Add data to the associated calculation table, joinTableSlot[dynamicEqualTable.tableID]. Save data to the data storage table, dynamicEqualTable.dataTable. End the process.
[0181] Figure 5 This is the schematic diagram of the process for inserting a regular table provided by an embodiment of the present invention. As Figure 5 shown, the process for inserting the regular table, insertGeneralTable, includes the following steps:
[0182] Step 501: Invoke insertGeneralTable(generalTable, data) with input parameters <generalTable, data>;
[0183] Step 502: Record the current table in the set of visited tables, visitedTableSet. Add data to the associated calculation table, joinTableSlot[dynamicEqualTable.tableID]. Save data to the data storage table, generalTable.dataTable. End the process.
[0184] Figure 6 This is the schematic diagram of the process for processing the equal table link provided by an embodiment of the present invention. As Figure 6 shown, the process for processing the equal table link, processEqualTableLink, includes the following steps:
[0185] Step 601: Call processEqualTableLink(fromTableID, equalTable, keyValue) with input parameters <fromTableID, equalTable, keyValue>;
[0186] Step 602: Query the corresponding data set in the indexed data storage table equalTable.keyedDataTable using keyValue as the index value, set the queried data set as keyedRows, and add keyedRows to the association calculation table joinTableSlot[equalTable.tableID];
[0187] Step 603: Traverse the table link list equalTable.tableLinkList;
[0188] Step 604: Determine whether there is an unprocessed tableLink in the table link list equalTable.tableLinkList and tableLink.linkTableID is not equal to fromTableID; if so, execute Step 605, if not, execute Step 609;
[0189] Step 605: Obtain the corresponding flow table tableSlot[tableLink.linkTableID] from the table slot using the flow table number tableLink.linkTableID, and define the parameter toTable = tableSlot[tableLink.linkTableID];
[0190] Step 606: Determine whether the type of the flow table toTable is an equal value table EqualTable; if so, execute Step 607; if not, execute Step 608;
[0191] Step 607: Call the process of processing the linked equal value table processEqualTableLink(equalTable.tableID, toTable, keyValue), and after completion, execute Step 604;
[0192] Step 608: Call the process of processing the linked dynamic equal value table processDynamicEqualTableLink(equalTable.tableID, toTable, keyValue), and after completion, execute Step 604;
[0193] Step 609: Record the current table into the set of visited tables visitedTableSet, and end the process after completion.
[0194] Figure 7 It is a schematic flowchart of the process for processing the dynamic equivalent table of links provided by an embodiment of the present invention. As Figure 7 shown, the process of the processDynamicEqualTableLink for processing the dynamic equivalent table of links includes the following steps:
[0195] Step 701: Call processDynamicEqualTableLink(fromTableID, dynamicEqualTable, keyValue), and input the parameters <fromTableID, dynamicEqualTable, keyValue;
[0196] Step 702: Query the tableLink with linkTableID == fromTableID from the table link list dynamicEqualTable.tableLinkList, and set keyBuilder = tableLink.keyBuilder;
[0197] Step 703: Traverse the data storage table dynamicEqualTable.dataTable;
[0198] Step 704: Determine whether there is any unprocessed data in the traversed data storage table dynamicEqualTable.dataTable; if so, execute Step 705, if not, execute Step 713; record the current table into the set of visited tables visitedTableSet, and end the process after completion;
[0199] Step 705: Determine whether the data is in the associated calculation table joinTableSlot[dynamicEqualTable.tableID]; if so, execute Step 704, if not, execute Step 706;
[0200] Step 706: If the index value fromKeyValue corresponding to fromTableID is saved in the data, directly use it; if not, use the index value generator keyBuilder to calculate the index value fromKeyValue corresponding to the data, and save the value <fromTableID, fromKeyValue> into the data;
[0201] Step 707: Determine whether keyValue is equal to fromKeyValue. If not, execute Step 704. If so, execute Step 708.
[0202] Step 708: Add data to the associated calculation table joinTableSlot[dynamicEqualTable.tableID], and traverse the table link list dynamicEqualTable.tableLinkList.
[0203] Step 709: Determine whether there is an unprocessed tableLink in dynamicEqualTable.tableLinkList and tableLink.linkTalbeID is not equal to fromTableID. If so, execute Step 710. If not, execute Step 704.
[0204] Step 710: Obtain the corresponding flow table tableSlot[tableLink.linkTableID] from the table slot using the flow table number tableLink.linkTableID, and define the parameter toTable = tableSlot[tableLink.linkTableID].
[0205] Step 711: Determine whether the type of the flow table toTable is an equal value table EqualTable. If so, execute Step 712. If not, execute Step 713.
[0206] Step 712: Call the process of processing the linked equal value table processEqualTableLink(equalTable.tableID, toTable, keyValue), and after completion, execute Step 704.
[0207] Step 713: Call the process of processing the linked dynamic equal value table processDynamicEqualTableLink(equalTable.tableID, toTable, keyValue), and after completion, execute Step 704.
[0208] Step 714: Record the current table in the set of visited tables visitedTableSet, and end the process after completion.
[0209] Figure 8 This is a schematic diagram of the process for accessing an equal value table provided by an embodiment of the present invention. As Figure 8 shown, the process of accessing the equal value table visitEqualTable includes the following steps:
[0210] Step 801, call visitEqualTable(equalTable) with the input flow table <equaltable>;
[0211] Step 802, traverse the indexed data storage table equalTable.keyedDataTable;
[0212] Step 803, determine whether there is any unprocessed data in the indexed data storage table equalTable.keyedDataTable; if so, execute Step 804; if not, execute Step 811;
[0213] Step 804, traverse the table link list equalTable.tableLinkList;
[0214] Step 805, determine whether there is any un-traversed tableLink in the table link list equalTable.tableLinkList; if so, execute Step 806; if not, execute Step 803;
[0215] Step 806, obtain the saved index value keyValue from the data;
[0216] Step 807, use the flow table number tableLink.linkTableID to obtain the corresponding flow table tableSlot[tableLink.linkTableID] from the table slot, and define the parameter toTable = tableSlot[tableLink.linkTableID];
[0217] Step 808, determine whether the type of the flow table toTable is an equal value table EqualTable; if so, execute Step 809; if not, execute Step 810;
[0218] Step 809, call the process of processing the linked equal value table processEqualTableLink(equalTable.tableID, toTable, keyValue), and after completion, execute Step 805;
[0219] Step 810, call the process of processing the linked dynamic equal value table processDynamicEqualTableLink(equalTable.tableID, toTable, keyValue), and after completion, execute Step 805;
[0220] Step 811: Record the current table into the set of visited tables visitedTableSet, add the data storage table equalTable.keyedDataTable to the join calculation table joinTableSlot[equalTable.tableID], and end the process after completion.
[0221] Figure 9 This is a schematic flow chart of accessing a dynamic equal value table provided by an embodiment of the present invention. As Figure 9 shown, the process of accessing the dynamic equal value table visitDynamicEqualTable includes the following steps:
[0222] Step 901: Call visitDynamicEqualTable(dynamicEqualTable), input the flow table <dynamicequaltable>;
[0223] Step 902: Traverse the data storage table dynamicEqualTable.dataTable;
[0224] Step 903: Determine whether there is still unprocessed data in the data storage table dynamicEqualTable.dataTable; if so, execute Step 904; if not, execute Step 911;
[0225] Step 904: Traverse the table link list dynamicEqualTable.tableLinkList;
[0226] Step 905: Determine whether there is still an untraversed tableLink in dynamicEqualTable.tableLinkList; if so, execute Step 906; if not, execute Step 903;
[0227] Step 906: If the index value keyValue corresponding to tableLink.linkTableID is saved in data, directly use it; if not, use the index value generator tableLink.keyBuilder to calculate the index value keyValue corresponding to data, and save the value <fromTableID, fromKeyValue> into data;
[0228] Step 907: Obtain the corresponding flow table tableSlot[tableLink.linkTableID] from the table slot using the flow table number tableLink.linkTableID, and define the parameter toTable = tableSlot[tableLink.linkTableID];
[0229] Step 908: Determine whether the type of the flow table toTable is an equal value table EqualTable; if so, execute Step 909; if not, execute Step 910;
[0230] Step 909: Call the process of processing the linked equal value table processEqualTableLink(dynamicEqualTable.tableID, toTable, keyValue), and after completion, execute Step 903;
[0231] Step 910: Call the process of processing the dynamic equivalent table link processDynamicEqualTableLink(dynamicEqualTable.tableID, toTable, keyValue). After completion, execute Step 903;
[0232] Step 911: Record the current table into the set of visited tables visitedTableSet, and add the data storage table dynamicEqualTable.dataTable to the associated calculation table joinTableSlot[dynamicEqualTable.tableID]. After completion, end the process.
[0233] Figure 10 It is a schematic diagram of the process for accessing a regular table provided by an embodiment of the present invention. As Figure 10 shown, the process of accessing the regular table visitGeneralTable includes the following steps:
[0234] Step 1001: Call visitGeneralTable(generalTable), and the input stream table <generaltable>;
[0235] Step 1002: Record the current table into the set of visited tables visitedTableSet, add the data storage table generalTable.dataTable to the join calculation table joinTableSlot[generalTable.tableID], and end the process after completion.
[0236] Figure 11 is a schematic flow diagram of the associated table data provided by an embodiment of the present invention. As Figure 11 shown, the process of the associated table data joinTableRows includes the following steps:
[0237] Step 1101: Call joinTableRows(joinTableSlot, joinRowSlot, tableIndex), with input parameters <joinTableSlot, joinRowSlot, tableIndex>;
[0238] Step 1102: Define the current table currentTable and set currentTable = joinTableSlot[tableIndex];
[0239] Step 1103: Traverse the table <currenttable>, for each line of data <row>Perform calculations;
[0240] Step 1104, <currenttable>Is there any data left in the table? <row>; If so, execute step 1105; if not, execute step 1111;
[0241] Step 1105, set joinRowSlot[tableIndex]= <row>;
[0242] Step 1106, determine whether tableIndex + 1 is equal to N; if it is equal to N, then execute Step 1107, if not, then execute Step 1110;
[0243] Step 1107, the associated calculation data slot <joinrowslot>All data in <joinRowSlot[0], joinRowSlot[1], …, joinRowSlot[N-1]> is input to the correlation filter <joinfilter>Perform associated calculations;
[0244] Step 1108, judge <joinfilter>Whether the calculation result is true; if <joinfilter>If the calculation result is true, execute step 1109; if it is false, execute step 1104.
[0245] Step 1109: Insert <joinRowSlot[0], joinRowSlot[1], …, joinRowSlot[N-1]> into the hit table <matchedtable>, after completion, execute step 1104;
[0246] Step 1110, recursively call joinTableRows(joinTableSlot, joinRowSlot, tableIndex + 1), and after the call is completed, execute step 1104;
[0247] Step 1111, return from this function call.
[0248] Optionally, Table 12 shows two key processes included in deleting data stream data in an embodiment of the present invention, as shown in Table 12:
[0249] Key processes for inserting data stream data in Table 12
[0250]
[0251] Figure 12 is a schematic flowchart of the process for deleting data stream data provided by an embodiment of the present invention. As Figure 12 shown, the process of this deleteStreamData(data) for deleting data stream data includes the following steps:
[0252] Step 1201, call deleteStreamData(data) and input the data stream data to be deleted <data>;
[0253] Step 1202, cancel the transmission to <data>Registered deletion listener;
[0254] Step 1203, from <matchedtable>Query whether there are associated hit rows, and if so, delete the corresponding hit data;
[0255] Step 1204, Use the data flow classifier <streamclassifier>Calculation <data>The corresponding table number index. Use the index value to obtain the corresponding flow table tableSlot[index] from the table slot, and define the parameter toTable = tableSlot[index];
[0256] Step 1205: Determine whether the type of the flow table toTable is an equal value table EqualTable; if so, execute Step 1206; if not, execute Step 1207;
[0257] Step 1206: Obtain the stored keyValue value from data. Use keyValue as the index value to delete the stored data corresponding to data from the indexed data storage table toTable.keyedDataTable. After completion, execute Step 1208;
[0258] Step 1207: Delete the stored data corresponding to data from the data storage table toTable.dataTable. After completion, execute Step 1208;
[0259] Step 1208: If the table slot <tableslot>If the data storage tables of all the tables <tableSlot[0], tableSlot[1], …, tableSlot[N-1]> in it are empty, then delete the current computing unit and end the process after completion.
[0260] Figure 13 It is a schematic flowchart of the process of updating data in the data stream provided by an embodiment of the present invention. As Figure 13 shown, the process of updating the data in the data stream updateStreamData(oldData, newData) includes the following steps:
[0261] Step 1301: Call updateStreamData(oldData, newData) and input the data <oldData, newData> of the data stream to be updated;
[0262] Step 1302: Call the process of deleting data in the data stream deleteStreamData(oldData) to delete <olddata>;
[0263] Step 1303, call the insert data flow of inserting data stream insertStreamData(NewData) to insert <newdata>。
[0264] Figure 14 is a schematic flowchart of the process for notifying data timeout of the notification data stream provided by the embodiments of the present invention. As Figure 14 shown, the process of the onStreamDataExpire(data) for notifying data timeout of the notification data stream includes the following steps:
[0265] Step 1401, call onStreamExpire(data) and input the data stream data with timeout <data>;
[0266] Step 1402, from <matchedtable>Query whether there are associated hit rows, and if so, delete the corresponding hit data;
[0267] Step 1403: Use a data flow classifier <streamclassifier>Calculation <data>The corresponding table number index, use the index value to obtain the corresponding flow table tableSlot[index] from the table slot, and define the parameter toTable = tableSlot[index];
[0268] Step 1404, determine whether the type of the flow table toTable is an equal value table EqualTable; if so, execute Step 1405, if not, execute Step 1406;
[0269] Step 1405, obtain the stored keyValue value from data, use keyValue as the index value, and delete the stored data corresponding to data from the indexed data storage table toTable.keyedDataTable. After completion, execute Step 1407;
[0270] Step 1406, delete the stored data corresponding to data from the data storage table toTable.dataTable. After completion, execute Step 1407;
[0271] Step 1407, if the table slot <tableslot>If the data storage tables of all tables <tableSlot[0], tableSlot[1], …, tableSlot[N - 1]> are empty, delete the current computing unit and end the process after completion.
[0272] The network security data processing device based on an index provided by the present invention will be described below. The network security data processing device based on an index described below can be correspondingly referred to the network security data processing method based on an index described above.
[0273] Figure 15 is a schematic structural diagram of the network security data processing device based on an index provided by an embodiment of the present invention. As Figure 15 shown, the network security data processing device 1500 based on an index includes: a determination module 1501, a processing module 1502, and an association module 1503, where:
[0274] The determination module 1501 is configured to determine a first flow table number corresponding to network security data; the first flow table number is the number of the first data flow table in the table slot; N data flow tables are stored in the table slot, and N is an integer greater than or equal to 3;
[0275] The processing module 1502 is configured to, when the indexable expression chain corresponding to the association analysis expression does not include the first flow table number, select N - 1 reference data sets from the other N - 1 data flow tables in the table slot except the first data flow table and add them to the association calculation table; add the network security data to the association calculation table; where the indexable expression chain includes an expression chain composed of a plurality of indexable expressions, each indexable expression corresponds to two different data flow tables; each reference data set comes from a different data flow table, and each reference data set includes at least one piece of data;
[0276] The association module 1503 is configured to perform an association calculation on the data in the association calculation table to obtain at least one association result; the association result is used to perform network security analysis on the network security data.
[0277] The network security data processing device based on indexing provided by the embodiment of the present invention determines the first flow table number corresponding to the network security data. The first flow table number is the number of the first data flow table in the table slot. When the first flow table number is not included in the indexable expression chain corresponding to the association analysis expression, N-1 reference data sets are selected from the other N-1 data flow tables in the table slot except the first data flow table and added to the association calculation table, and the network security data is added to the association calculation table. Each reference data set comes from a different data flow table. Association calculation is performed on the data in the association calculation table to obtain at least one association result. Based on the association result, network security analysis can be performed on the network security data, realizing network security analysis and detection of multiple data flows, being able to discover security risks in a timely manner, and reducing network security risks.
[0278] Based on any of the above embodiments, the indexable expression chain includes: an equivalent indexable expression chain or a dynamic equivalent indexable expression chain;
[0279] In the equivalent indexable expression chain, every two indexable expressions are associated through the same attribute information of the row data of the same flow table; in the dynamic equivalent indexable expression chain, every two indexable expressions are associated through the same flow table;
[0280] The left value and the right value of the indexable expression are equal, and the left value and the right value respectively correspond to the attribute information of the row data of two different flow tables; the indexable expression is a key boolean expression, and the value of the key boolean expression determines the value of the association expression.
[0281] Based on any of the above embodiments, the processing module 1502 is specifically configured to:
[0282] Traverse the other N-1 data flow tables in the table slot except the first data flow table. When the equivalent indexable expression chain includes the traversed second data flow table, record the second data flow table in the accessed table set, and add the first data storage table of the second data flow table to the association calculation table;
[0283] Traverse each reference data in the first data storage table. For the traversed first reference data, traverse all linked data flow tables directly or indirectly linked from the second data flow table, and record the traversed target data flow table in the accessed table set;
[0284] When the equivalent indexable expression chain includes the target data flow table, add the reference data set corresponding to the index value of the first reference data in the data storage table of the target data flow table to the association calculation table.
[0285] Based on any of the above embodiments, the processing module 1502 is specifically configured to:
[0286] Traverse the other N - 1 data flow tables in the table slots except the first data flow table. When the second data flow table traversed is included in the dynamic equivalent indexable expression chain, record the second data flow table into the set of accessed tables, and add the first data storage table of the second data flow table to the association calculation table;
[0287] Traverse each reference data in the first data storage table. For the first reference data traversed, traverse all the linked data flow tables directly or indirectly linked from the second data flow table, and record the traversed target data flow table into the set of accessed tables;
[0288] When the target data flow table is included in the equivalent indexable expression chain, add the target data in the data storage table of the target data flow table to the association calculation table; the index value corresponding to the flow table number of the second data flow table saved in the target data is the same as the index value of the first reference data.
[0289] Based on any of the above embodiments, the association module 1503 is specifically configured to:
[0290] Traverse the association calculation table. Each time when traversing, select one reference data from the N - 1 reference data sets in turn to obtain N - 1 reference data, and perform an association calculation on the network security data and the N - 1 reference data to obtain the association result.
[0291] Based on any of the above embodiments, the association module 1503 is specifically configured to:
[0292] Obtain the association condition in the association analysis expression, where the association condition includes a preset relationship of attribute information of at least two flow table data;
[0293] Judge whether the attribute information of the network security data and the N - 1 reference data conforms to the preset relationship;
[0294] When the attribute information of the network security data and the N - 1 reference data conforms to the preset relationship, determine that the association result is successful;
[0295] When the attribute information of the network security data and the N - 1 reference data does not conform to the preset relationship, determine that the association result is failed.
[0296] Based on any of the above embodiments, the determination module 1501 is further configured to:
[0297] When the association result is successful association, use the network security data and the N - 1 reference data as associated data, and determine that there is a network security risk between the network security data and the N - 1 reference data.
[0298] Based on any of the above embodiments, the processing module 1502 is further configured to:
[0299] Generate a risk prompt message when the association result is successful association;
[0300] Wherein, the risk prompt message is used to indicate that there is a network security risk between the network security data and the N - 1 reference data.
[0301] Based on any of the above embodiments, the determination module 1501 is further configured to: determine a listener for the network security data, where the listener is used to monitor whether the network security data is deleted; add the listener to the listener list associated with the network security data.
[0302] Figure 16 It is a schematic physical structure diagram of an electronic device provided by an embodiment of the present invention. As Figure 16 shown, the electronic device 1600 includes: a processor 1610, a communication interface 1620, a memory 1630, and a communication bus 1640. Among them, the processor 1610, the communication interface 1620, and the memory 1630 complete mutual communication through the communication bus 1640. The processor 1610 can call logic instructions in the memory 1630 to execute the following method:
[0303] Determine a first flow table number corresponding to the network security data; the first flow table number is the number of the first data flow table in the table slot; N data flow tables are stored in the table slot, and N is an integer greater than or equal to 3;
[0304] When the first flow table number is not included in the indexable expression chain corresponding to the association analysis expression, select N - 1 reference data sets from the other N - 1 data flow tables in the table slot except the first data flow table and add them to the association calculation table; add the network security data to the association calculation table; wherein, the indexable expression chain includes an expression chain composed of multiple indexable expressions, and each indexable expression corresponds to two different data flow tables; each reference data set comes from a different data flow table, and each reference data set includes at least one piece of data;
[0305] Perform correlation calculations on the data in the correlation calculation table to obtain at least one correlation result; the correlation result is used to perform network security analysis on the network security data.
[0306] In addition, when the logical instructions in the above-mentioned memory 1630 can be implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.
[0307] On the other hand, the present invention also provides a computer program product. The computer program product includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the index-based network security data processing method provided by the above-mentioned various methods. The method includes:
[0308] Determine the first flow table number corresponding to the network security data; the first flow table number is the number of the first data flow table in the table slot; N data flow tables are stored in the table slot, and N is an integer greater than or equal to 3;
[0309] In the case where the first flow table number is not included in the indexable expression chain corresponding to the correlation analysis expression, select N - 1 reference data sets from the other N - 1 data flow tables in the table slot except the first data flow table and add them to the correlation calculation table; add the network security data to the correlation calculation table; wherein, the indexable expression chain includes an expression chain composed of multiple indexable expressions, and each indexable expression corresponds to two different data flow tables; each reference data set comes from a different data flow table, and each reference data set includes at least one piece of data;
[0310] Perform correlation calculations on the data in the correlation calculation table to obtain at least one correlation result; the correlation result is used to perform network security analysis on the network security data.
[0311] In another aspect, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the index-based network security data processing method provided by the above various methods. The method includes:
[0312] Determine a first flow table number corresponding to the network security data; the first flow table number is the number of the first data flow table in the table slot; N data flow tables are stored in the table slot, and N is an integer greater than or equal to 3;
[0313] In the case that the first flow table number is not included in the indexable expression chain corresponding to the association analysis expression, select N-1 reference data sets from the other N-1 data flow tables in the table slot except the first data flow table and add them to the association calculation table; add the network security data to the association calculation table; wherein, the indexable expression chain includes an expression chain composed of multiple indexable expressions, each indexable expression corresponds to two different data flow tables; each reference data set comes from a different data flow table, and each reference data set includes at least one piece of data;
[0314] Perform association calculation on the data in the association calculation table to obtain at least one association result; the association result is used for network security analysis of the network security data.
[0315] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative labor.
[0316] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solution, in essence, or the part that contributes to the prior art can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0317] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention.< / tableslot> < / data> < / streamclassifier> < / matchedtable> < / data> < / newdata> < / olddata> < / tableslot> < / data> < / streamclassifier> < / matchedtable> < / data> < / data> < / matchedtable> < / joinfilter> < / joinfilter> < / joinfilter> < / joinrowslot> < / row> < / row> < / currenttable> < / row> < / currenttable> < / generaltable> < / dynamicequaltable> < / equaltable> < / data> < / data> < / streamclassifier> < / data>
Claims
1. An index-based network security data processing method, characterized in that Including: Determine a first flow table number corresponding to network security data; the first flow table number is the number of the first data flow table in the table slot; N data flow tables are stored in the table slot, and N is an integer greater than or equal to 3; When the first flow table number is not included in the indexable expression chain corresponding to the association analysis expression, select N - 1 reference data sets from the other N - 1 data flow tables in the table slot except the first data flow table and add them to the association calculation table; add the network security data to the association calculation table; wherein, the indexable expression chain includes an expression chain composed of multiple indexable expressions, and each indexable expression corresponds to two different data flow tables; each reference data set comes from a different data flow table, and each reference data set includes at least one piece of data; Perform association calculation on the data in the association calculation table to obtain at least one association result; the association result is used to perform network security analysis on the network security data; The indexable expression chain includes: an equal - value indexable expression chain or a dynamic equal - value indexable expression chain; In the equal - value indexable expression chain, every two indexable expressions are associated by the same attribute information of the row data of the same flow table; In the dynamic equal - value indexable expression chain, every two indexable expressions are associated by the same flow table; The left value and the right value of the indexable expression are equal, and the left value and the right value respectively correspond to the attribute information of the row data of two different flow tables; the indexable expression is a key Boolean expression, and the value of the key Boolean expression determines the value of the association expression; The step of selecting N - 1 reference data sets from the other N - 1 data flow tables in the table slot except the first data flow table and adding them to the association calculation table includes: Traverse the other N - 1 data flow tables in the table slot except the first data flow table; When the second data flow table traversed is included in the equal - value indexable expression chain, record the second data flow table in the accessed table set, and add the first data storage table of the second data flow table to the association calculation table; traverse each reference data in the first data storage table, for the traversed first reference data, traverse all linked data flow tables directly or indirectly linked from the second data flow table, and record the traversed target data flow table in the accessed table set; when the target data flow table is included in the equal - value indexable expression chain, add the reference data set corresponding to the index value of the first reference data in the data storage table of the target data flow table to the association calculation table; When the traversed second data flow table is included in the dynamic equivalent indexable expression chain, record the second data flow table into the set of accessed tables, and add the first data storage table of the second data flow table to the associated calculation table; traverse each reference data in the first data storage table, for the traversed first reference data, traverse all linked data flow tables directly or indirectly linked from the second data flow table, and record the traversed target data flow table into the set of accessed tables; when the target data flow table is included in the equivalent indexable expression chain, add the target data in the data storage table of the target data flow table to the associated calculation table; the index value corresponding to the flow table number of the second data flow table saved in the target data is the same as the index value of the first reference data.
2. The index-based network security data processing method according to claim 1, characterized in that The performing an association calculation on the data in the associated calculation table to obtain at least one association result includes: Traverse the associated calculation table, and each time during traversal, select one reference data from the N - 1 reference data sets in sequence to obtain N - 1 reference data, and perform an association calculation on the network security data and the N - 1 reference data to obtain the association result.
3. The method for processing network security data based on indexing according to claim 2, wherein, The performing an association calculation on the network security data and the N - 1 reference data to obtain the association result includes: Obtain the association condition in the association analysis expression, where the association condition includes a preset relationship of attribute information of at least two flow table data; Judge whether the attribute information of the network security data and the N - 1 reference data conforms to the preset relationship; When the attribute information of the network security data and the N - 1 reference data conforms to the preset relationship, determine that the association result is an association success; When the attribute information of the network security data and the N - 1 reference data does not conform to the preset relationship, determine that the association result is an association failure.
4. The index-based network security data processing method according to claim 2, wherein The method further includes: When the association result is an association success, use the network security data and the N - 1 reference data as associated data, and determine that there is a network security risk between the network security data and the N - 1 reference data.
5. The index-based network security data processing method according to claim 2, wherein The method further includes: When the association result is an association success, generate a risk prompt message; Wherein, the risk prompt message is used to indicate that there is a network security risk between the network security data and the N - 1 reference data.
6. The index-based network security data processing method according to claim 1, characterized in that The method further includes: Determine a listener for the network security data, where the listener is used to monitor whether the network security data is deleted; add the listener to the listener list associated with the network security data.
7. An index-based network security data processing device, characterized in that, Includes: A determination module, configured to determine a first flow table number corresponding to network security data; the first flow table number is the number of the first data flow table in the table slot; N data flow tables are stored in the table slot, and N is an integer greater than or equal to 3; A processing module, configured to, when the indexable expression chain corresponding to the association analysis expression does not include the first flow table number, select N-1 reference data sets from the other N-1 data flow tables in the table slots except the first data flow table and add them to the association calculation table; add the network security data to the association calculation table; wherein, the indexable expression chain includes an expression chain composed of a plurality of indexable expressions, and each indexable expression corresponds to two different data flow tables; each reference data set comes from a different data flow table, and each reference data set includes at least one piece of data. An association module, configured to perform association calculation on the data in the association calculation table to obtain at least one association result; the association result is used to perform network security analysis on the network security data. The indexable expression chain includes: an equal-value indexable expression chain or a dynamic equal-value indexable expression chain; in the equal-value indexable expression chain, every two indexable expressions are associated by the same attribute information of the row data of the same flow table; in the dynamic equal-value indexable expression chain, every two indexable expressions are associated by the same flow table; the left value and the right value of the indexable expression are equal, and the left value and the right value respectively correspond to the attribute information of the row data of two different flow tables; the indexable expression is a key Boolean expression, and the value of the key Boolean expression determines the value of the association expression; specifically, the processing module is configured to: Traverse the other N-1 data flow tables in the table slots except the first data flow table. When the equal-value indexable expression chain includes the second data flow table traversed, record the second data flow table in the accessed table set, and add the first data storage table of the second data flow table to the association calculation table; traverse each reference data in the first data storage table, for the first reference data traversed, traverse all linked data flow tables directly or indirectly linked from the second data flow table, and record the traversed target data flow table in the accessed table set; when the equal-value indexable expression chain includes the target data flow table, add the reference data set corresponding to the index value of the first reference data in the data storage table of the target data flow table to the association calculation table. When the second data flow table traversed is included in the dynamic equivalent indexable expression chain, record the second data flow table into the set of accessed tables, and add the first data storage table of the second data flow table to the associated calculation table; traverse each reference data in the first data storage table, for the traversed first reference data, traverse all linked data flow tables directly or indirectly linked from the second data flow table, and record the traversed target data flow table into the set of accessed tables; when the target data flow table is included in the equivalent indexable expression chain, add the target data in the data storage table of the target data flow table to the associated calculation table; the index value corresponding to the flow table number of the second data flow table saved in the target data is the same as the index value of the first reference data.
8. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the index-based network security data processing method according to any one of claims 1 to 6.
9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the index-based network security data processing method according to any one of claims 1 to 6.
10. A computer program product having executable instructions stored thereon, characterized in that, When the instruction is executed by a processor, it causes the processor to implement the index-based network security data processing method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Openflow flow table storage and optimization method based on resource reuse
CN103368851A
Enhanced real-time calculation method for dynamic real-time synchronization of multi-source large table data
CN113407600A