A method and system for real-time analysis of attack sources
By using real-time monitoring and analysis of network attack sources, the problem of misoperation and untimely processing caused by manual maintenance in traditional network security protection has been solved, enabling rapid and accurate handling of attack sources.
Patent Information
- Application Number
- CN202310638181.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-05-31
- Publication Date
- 2025-11-21
- Estimated Expiration
- 2043-05-31
AI Technical Summary
Traditional network information security protection relies on manual maintenance, which is prone to errors and untimely handling, resulting in low efficiency in dealing with attack sources.
The system monitors the network in real time, generates alarm logs and stores them in a structured database, performs real-time logical analysis and judgment, and classifies and processes the attack source IPs based on the results.
The attack source can be classified and processed within 30 seconds, which significantly reduces processing time and eliminates the possibility of human error.
Smart Images

Figure CN116633642B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of real-time analysis and processing of attack sources, in particular to a method and system for real-time analysis and processing of attack sources. BACKGROUND
[0002] In recent years, the situation of network information security is increasingly severe, and more and more malicious attacks have occurred in network information security, so the security and stability of the network are increasingly important, and network information security has attracted more attention from people.
[0003] At present, the traditional network information security protection is generally maintained manually by operation and maintenance personnel, and there are problems of manual maintenance, such as misoperation, time-consuming, and untimely processing. Therefore, how to timely dispose of the attack source and reduce the time and misoperation of the operation and maintenance personnel for analysis and disposal is a problem to be solved by the present application. SUMMARY
[0004] This part aims to summarize some aspects of the embodiments of the present application and briefly introduce some preferred embodiments. Some simplifications or omissions may be made in this part and the abstract and title of the specification to avoid obscuring the purpose of this part, the abstract and the title, and such simplifications or omissions cannot be used to limit the scope of the present application.
[0005] In view of the above-mentioned existing problems, the present application is proposed.
[0006] Therefore, the present application provides a method and system for real-time analysis and processing of attack sources, which can solve the problems mentioned in the background art.
[0007] To solve the above technical problems, the present application provides the following technical scheme, a method for real-time analysis and processing of attack sources, comprising:
[0008] Real-time monitoring of the network, and real-time generation of alarm logs when an attack event occurs;
[0009] Storing the alarm logs in a structured database in real time, and performing real-time logical analysis and judgment on the alarm logs stored in real time;
[0010] According to the results of the real-time logical analysis and judgment, the attack source IP is processed in real time.
[0011] As a preferred scheme of the method for real-time analysis and processing of attack sources, wherein:
[0012] The alarm logs include attack source IP, attack destination IP, attack time and attack mode;
[0013] The real-time storage of the alarm log in the structured database comprises recording the attack target IP, attack time and attack mode of the same attack source IP, sorting the attack source IP in time sequence, and mapping the attack target IP, attack time and attack mode with the same attack source IP for structured storage.
[0014] As a preferred scheme of the method for real-time analysis and processing of attack sources, the logical analysis and judgment comprises attack source IP level judgment, and the level comprises a first serious level, a second medium level and a third light level.
[0015] The first serious level comprises the following:
[0016]
[0017] The second medium level comprises the following:
[0018]
[0019] The third light level comprises the following:
[0020]
[0021] Wherein, M is the number of attack target IPs different from the current attack source IP in the database, and n is the number of days, G(i) is the number of attack target IPs per day, W(i) is the number of attack source IPs per day.
[0022] As a preferred scheme of the method for real-time analysis and processing of attack sources, the logical analysis and judgment further comprises:
[0023] When the level is the first serious level, the corresponding attack source IP is marked as serious, and the attack source IP is immediately blocked on the current firewall, and the analysis operation is continued to determine whether new attack source IP associated information is generated;
[0024] If no new attack source IP associated information is generated for a period, it is determined that the protection is successful, the firewall can cope with the attack of the attack source IP, and the firewall version and model and the attack source IP are sent to the server for storage;
[0025] If other firewalls fail to protect against the attack source IP, the firewall version stored in the server is preferentially called, and the period is the longest attack interval time of the attack source IP twice;
[0026] If new attack source IP associated information is generated in a cycle, it is determined that the protection fails, the firewall cannot cope with the attack of the attack source IP, the attack target IP address of the attack source IP is acquired, and the firewall service corresponding to the attack target IP address is replaced, preferably the firewall version in the server for the attack source IP is replaced;
[0027] If there is no firewall version in the server for the attack source IP, the latest version of the firewall is directly replaced, and if the latest version still cannot cope with the attack of the attack source IP, the network operation is closed, and the operation and maintenance personnel are notified to handle.
[0028] As a preferred scheme of the real-time analysis and processing method of the attack source, the logical analysis and judgment further comprises,
[0029] When the level is the second medium level, the corresponding attack source IP is marked as medium, and the attack source IP is immediately marked on the current firewall for the first time, and the analysis work is continued to determine whether new attack source IP associated information is generated;
[0030] If the attack source IP still performs new attack in a cycle, and the attack times are greater than the first preset value, the attack source IP is immediately marked on the current firewall for the second time;
[0031] When the first marking times in three cycles are greater than three times, the attack source IP is immediately blocked on the current firewall, and the first preset value is the ratio of the time of a cycle to the average time interval of the longest attack interval time and the shortest time interval of two times of the attack source IP, and is rounded up.
[0032] As a preferred scheme of the real-time analysis and processing method of the attack source, the logical analysis and judgment further comprises,
[0033] When the level is the third light level, the corresponding attack source IP is marked as light, and the attack source IP is immediately marked on the current firewall for the second time, and the analysis work is continued to determine whether new attack source IP associated information is generated;
[0034] If the attack source IP still performs new attack in a cycle, and the attack times are greater than the second preset value, the attack source IP is immediately marked on the current firewall for the second time;
[0035] When the second marking times in a cycle are greater than five times, the attack source IP is immediately blocked on the current firewall, and the second preset value is the ratio of the time of a cycle to the average time interval of the longest attack interval time and the shortest time interval of two times of the attack source IP, and is rounded down.
[0036] As a preferred solution of the method for analyzing and processing attack source in real time, wherein the logical analysis and judgment further comprises,
[0037] When the second primary marking is performed, the server automatically calls the pre-installed firewall version for the attack source IP;
[0038] If a primary marking operation is further generated within three cycles after the first primary marking, the pre-installed firewall is installed;
[0039] If a third primary marking operation is no longer generated within three cycles after the first primary marking, it is determined that the attack source IP cannot threaten the network, and the attack source IP is not banned on the current firewall;
[0040] When the fourth secondary marking is performed, the server automatically calls the pre-installed firewall version for the attack source IP;
[0041] If a primary marking operation is further generated within the current cycle, the pre-installed firewall is installed;
[0042] If a primary marking operation is no longer generated within the current cycle, it is determined that the attack source IP cannot threaten the network, and the attack source IP is not banned on the current firewall.
[0043] A system for analyzing and processing attack source in real time, characterized by comprising a log generation module, an analysis and judgment module, and a real-time processing module,
[0044] The log generation module is used for real-time monitoring of the network, and real-time generation of an alarm log when an attack event occurs;
[0045] The analysis and judgment module is used for real-time storage of the alarm log in a structured database, and real-time logical analysis and judgment of the alarm log stored in real time;
[0046] The real-time processing module is used for corresponding real-time processing of the attack source IP according to the real-time logical analysis and judgment result.
[0047] A computer device comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the method when executing the computer program.
[0048] A computer-readable storage medium having a computer program stored thereon, wherein the computer program is executed by a processor to implement the steps of the method.
[0049] The present application provides a method and system for real-time analysis and processing of attack sources. The present application discovers attack sources in the first time, analyzes and disposes the attack sources, classifies and processes the attack sources, and performs corresponding processing operations on different types of attack sources. The processing time can be completed within 30 seconds, which is greatly reduced compared with the previous 20-30 minutes. In addition, the present application automatically disposes after analysis, eliminating the possibility of human error. BRIEF DESCRIPTION OF DRAWINGS
[0050] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor. Among them:
[0051] Figure 1 A method flow chart of a method for real-time analysis and processing of attack sources provided by an embodiment of the present application;
[0052] Figure 2 An internal structure diagram of a computer device of a method for real-time analysis and processing of attack sources provided by an embodiment of the present application. DETAILED DESCRIPTION
[0053] In order to make the above-mentioned purposes, features and advantages of the present application more apparent and easy to understand, the specific embodiments of the present application will be described in detail below with reference to the drawings. Obviously, the described embodiments are part of the embodiments of the present application, not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor should be within the scope of protection of the present application.
[0054] In the following description, many specific details are set forth in order to provide a thorough understanding of the present application, but the present application can also be implemented in other ways different from those described herein, and those skilled in the art can make similar generalizations without departing from the scope of the present application. Therefore, the present application is not limited to the specific embodiments disclosed below.
[0055] Secondly, the "one embodiment" or "embodiment" referred to herein means that the specific features, structures or characteristics can be included in at least one implementation of the present application. In this specification, "in one embodiment" does not mean the same embodiment, nor is it an independent or alternative embodiment that excludes other embodiments.
[0056] The application is described in detail in combination with the schematic diagram. In the detailed description of the embodiments of the application, the sectional view of the device structure is partially enlarged without the general proportion for the convenience of illustration, and the schematic diagram is only an example which should not limit the scope of protection of the application herein. In addition, the three-dimensional spatial dimensions of length, width and depth should be included in the actual manufacture.
[0057] Meanwhile, in the description of the application, it should be noted that the orientation or positional relationship indicated by the terms "upper, lower, inner and outer" is based on the orientation or positional relationship shown in the drawings, and is only for the convenience of describing the application and simplifying the description, and does not indicate or imply that the device or element referred to must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as a limitation of the application. In addition, the terms "first, second or third" are only for the purpose of description and cannot be understood as indicating or implying relative importance.
[0058] Unless otherwise explicitly specified and limited in the application, the terms "mounting, connection, connection" should be understood broadly, for example: it can be fixed connection, detachable connection or integral connection; it can also be mechanical connection, electrical connection or direct connection, it can also be indirectly connected through an intermediate medium, or it can be the communication between two elements inside. For those skilled in the art, the specific meaning of the above terms in the application can be understood according to the specific circumstances.
[0059] Embodiment 1
[0060] Reference Figures 1-2 For the first embodiment of the application, the embodiment provides a method and system for real-time analysis and processing of attack source, comprising:
[0061] Real-time monitoring of the network, when an attack event occurs, real-time generation of alarm log;
[0062] Among them, the alarm log includes attack source IP, attack destination IP, attack time and attack mode;
[0063] It should be noted that the alarm log is stored in the structured database in real time, including recording the attack destination IP, attack time and attack mode of the same attack source IP, sorting the attack source IP in time sequence, and mapping the attack destination IP, attack time and attack mode with the same attack source IP, and saving in structure. When logical analysis and judgment are performed, the structured data is directly called.
[0064] Further, the alarm log is stored in the structured database in real time, and the alarm log stored in real time is subjected to real-time logical analysis and judgment;
[0065] It should be noted that the logical analysis and judgment includes judgment including the judgment of the attack source IP level, the level including the first serious level, the second medium level and the third light level,
[0066] Further, the first serious level includes the following:
[0067]
[0068] Further, the second medium level includes the following:
[0069]
[0070] Further, the third light level includes the following:
[0071]
[0072] Wherein, M is the number of the same attack source IP in the database, but different attack destination IP, n is the number of days, G(i) The number of attack destination IP per day, W(i) The number of attack source IP per day.
[0073] Further, the logical analysis and judgment also includes when the level is the first serious level, the corresponding attack source IP is marked as serious, and the attack source IP is immediately blocked on the current firewall, and the analysis job is continued to determine whether new attack source IP associated information is generated;
[0074] Further, if no new attack source IP associated information is generated for a period of time, it is determined that the protection is successful, the firewall can cope with the attack of the attack source IP, and the firewall version and model of this time and the attack source IP are sent to the server for saving;
[0075] Further, if other firewalls fail to protect against the attack source IP, the firewall version saved in the server is preferentially called, and the period is twice the longest attack interval time of the attack source IP;
[0076] Further, if new attack source IP associated information is generated within a period of time, it is determined that the protection fails, the firewall cannot cope with the attack of the attack source IP, the attack destination IP address of the attack source IP is obtained at this time, and the corresponding firewall service at the attack destination IP address is replaced, and the firewall version against the attack source IP in the server is preferentially replaced;
[0077] It should be noted that if the server does not exist for the attack source IP firewall version, directly replace the latest version of the firewall, if the latest version still cannot cope with the attack of this attack source IP, turn off the network operation, and inform the operation and maintenance personnel to handle.
[0078] Further, the logical analysis and judgment also includes, when the level is two medium level, the corresponding attack source IP is marked as medium, and the attack source IP is immediately marked on the current firewall, and the analysis work is continued, and it is judged whether new attack source IP associated information is generated;
[0079] Further, if the attack source IP still performs new attack in a period, and the attack times are greater than the first preset value, the attack source IP is immediately marked on the current firewall for the second time;
[0080] It should be noted that when the first marking times in three periods are greater than three times, the attack source IP is immediately blocked on the current firewall, the first preset value is the ratio of the time of a period to the average time interval of the two longest attack interval times and the two shortest time interval of the attack source IP, and the ratio is rounded up.
[0081] Further, the logical analysis and judgment also includes, when the level is three light level, the corresponding attack source IP is marked as light, and the attack source IP is immediately marked on the current firewall for the second time, and the analysis work is continued, and it is judged whether new attack source IP associated information is generated;
[0082] It should be noted that if the attack source IP still performs new attack in a period, and the attack times are greater than the second preset value, the attack source IP is immediately marked on the current firewall for the second time;
[0083] It should be noted that when the second marking times in a period are greater than five times, the attack source IP is immediately blocked on the current firewall, the second preset value is the ratio of the time of a period to the average time interval of the two longest attack interval times and the two shortest time interval of the attack source IP, and the ratio is rounded down.
[0084] Further, the logical analysis and judgment also includes, when the first marking is performed for the second time, the server automatically calls the firewall version for the attack source IP for pre-installation;
[0085] It should be noted that if a first marking operation is further generated in three periods after the first marking, the pre-installed firewall is installed;
[0086] Further, if a third primary marking operation is not generated within three cycles from the first primary marking, it is determined that the attack source IP cannot pose a threat to the network, and the attack source IP is not blocked on the current firewall;
[0087] Further, when the fourth secondary marking is performed, the server automatically calls the pre-installed firewall version for the attack source IP;
[0088] Further, if a primary marking operation is further generated within the cycle, the pre-installed firewall is installed;
[0089] Further, if a primary marking operation is not generated within the cycle, it is determined that the attack source IP cannot pose a threat to the network, and the attack source IP is not blocked on the current firewall.
[0090] Further, according to the real-time logical analysis and judgment result, the attack source IP is processed in real time.
[0091] In one embodiment, a system for real-time analysis and processing of attack sources includes a log generation module, an analysis and judgment module, and a real-time processing module,
[0092] The log generation module is used to monitor the network in real time, and when an attack event occurs, an alarm log is generated in real time;
[0093] The analysis and judgment module is used to store the alarm log in a structured database in real time, and perform real-time logical analysis and judgment on the alarm log stored in real time;
[0094] The real-time processing module is used to process the attack source IP in real time according to the real-time logical analysis and judgment result.
[0095] The above modules can be embedded in or independent of the processor in the computer device in hardware form, or stored in the memory in the computer device in software form, so that the processor can call and execute the operations of the above modules.
[0096] In one embodiment, a computer device is provided, which can be a terminal, and its internal structure diagram can be as shown in Figure 2As shown. The computer device includes a processor, a memory, a communication interface, a display screen and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used for wired or wireless communication with external terminals. Wireless mode can be achieved through WIFI, operator network, NFC (near field communication) or other technologies. The computer program is executed by the processor to implement a method for real-time analysis and processing of attack sources. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer overlaid on the display screen, or a key, trackball or touchpad provided on the shell of the computer device. It can also be an external keyboard, touchpad or mouse, etc.
[0097] In one embodiment, a computer readable storage medium is provided, which stores a computer program, and the computer program is executed by a processor to implement the following steps:
[0098] Real-time monitoring of the network, real-time generation of alarm logs when an attack event occurs;
[0099] Real-time storage of the alarm log in the structured database, real-time logical analysis and judgment of the alarm log stored in real time;
[0100] According to the real-time logical analysis and judgment result, the attack source IP is processed in real time.
[0101] Embodiment 2
[0102] Reference Figures 1-2 For an embodiment of the present application, a method and system for real-time analysis and processing of attack sources are provided. In order to verify the beneficial effects of the present application, scientific demonstration is carried out through comparative experiments.
[0103] Table 1 Different attack source data obtained by the method for real-time analysis and processing of attack sources in a certain short time
[0104]
[0105]
[0106] The judgment of different attack source IPs is realized according to a first-class serious level, a second-class medium level and a third-class light level calculation formula, the attack source is classified and processed after the attack source is found at the first time, corresponding processing operations are performed on different types of attack sources, and the processing time can be completed within 30s, which is greatly reduced compared with the previous 20-30 minutes, and in addition, the application is analyzed and disposed automatically, and the possibility of misoperation during manual operation is eliminated.
[0107] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present application but not limit the present application. Although the present application is described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present application can be modified or replaced equivalently without departing from the spirit and scope of the technical solutions of the present application, and all of them should be covered in the scope of the claims of the present application.
[0108] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system or a computer program product. Therefore, the present application can adopt a completely hardware embodiment, a completely software embodiment or an embodiment combining software and hardware aspects. Moreover, the present application can adopt a computer program product in the form of being implemented on one or more computer usable storage media containing computer usable program codes (including but not limited to disk storage, CD-ROM, optical storage, etc.). The solutions in the embodiments of the present application can be implemented in various computer languages, such as object-oriented programming language Java and interpreted scripting language JavaScript, etc.
[0109] The present application is described with reference to flowcharts and / or block diagrams according to the methods, devices (systems) and computer program products of the embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of the flows and / or blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device implemented in the flowcharts and / or block diagrams. Figure 1 The device that implements the functions specified in one flow or multiple flows and / or blocks. Figure 1 The device that implements the functions specified in one flow or multiple flows and / or blocks.
[0110] These computer program instructions can also be stored in a computer readable storage medium which can guide the computer or other programmable data processing device to work in a specific way, so that the instructions stored in the computer readable storage medium produce a manufactured product including instruction devices which implement the flowcharts and / or block diagrams. Figure 1 The device that implements the functions specified in one flow or multiple flows and / or blocks.Figure 1 the function specified in the one or more blocks.
[0111] These computer program instructions can also be loaded into computer or other programmable data processing devices, so that a series of operations steps are performed on the computer or other programmable data processing devices to generate computer-implemented processes, thus the instructions executed on the computer or other programmable data processing devices provide processes for implementing the flow Figure 1 the flow or flows and / or blocks Figure 1 the steps of the function specified in the one or more blocks.
[0112] Although preferred embodiments of the application have been described, those skilled in the art will recognize that additional modifications and variations may be possible in light of the above disclosure. It is therefore intended that the appended claims cover all such modifications and variations as fall within the scope of the application.
[0113] Obviously, numerous modifications and variations of the present application are possible in light of the above teachings. It is therefore intended that the application be covered within the scope of the claims, and that the scope of the claims be interpreted not to be limited by the embodiments set forth in the specification.
Claims
1. A method for real-time analysis and processing of attack sources, characterized in that: include, Real-time network monitoring; when an attack occurs, alarm logs are generated immediately. Alarm logs are stored in a structured database in real time, and real-time logical analysis and judgment are performed on the stored alarm logs. Based on the real-time logic analysis and judgment results, the attack source IP is processed accordingly in real time. The alarm log includes the attack source IP, attack destination IP, attack time, and attack method; The real-time storage of alarm logs in a structured database includes recording the target IP, attack time, and attack method of the same attack source IP, sorting the attack source IPs in chronological order, mapping the target IP, attack time, and attack method to the same attack source IP, and storing them in a structured manner. When performing logical analysis and judgment, the structured data can be directly retrieved. The logical analysis and judgment include, among other things, judging the attack source IP level, which includes Level 1 (Severe), Level 2 (Medium), and Level 3 (Mild). The Level 1 severity level includes the following: The second-class intermediate level includes the following: The third-level light-duty category includes the following: Where M is the number of IPs in the database that are the same as the current attack source IP but different from the attack destination IP, n is the number of days, G(i) is the number of attack destination IPs per day, and W(i) is the number of attack source IPs per day. The logical analysis and judgment also include, When the level is Level 1 Severe, the corresponding attack source IP is marked as severe, and the attack source IP is immediately blocked on the current firewall. The analysis continues to determine whether new information related to the attack source IP is generated. If no new information related to the attack source IP is generated for a continuous period, the protection is considered successful and the firewall can deal with the attack source IP. The firewall version and model, as well as the attack source IP, are sent to the server for storage. If other firewalls fail to protect against the attack source IP, the firewall version stored in the server will be retrieved first, and the period is the longest interval between two attacks by the attack source IP. If new information associated with the attack source IP is generated within a cycle, the protection is considered to have failed and the firewall is unable to deal with the attack from this attack source IP. At this time, the attack destination IP address of the attack source IP is obtained, and the firewall service corresponding to the attack destination IP address is replaced. Priority is given to replacing the firewall version in the server that is designed for the attack source IP. If the server does not have a firewall version that targets the attacking source IP, replace it with the latest version. If the latest version still cannot handle the attack from this source IP, shut down the network and notify the operations and maintenance personnel for handling.
2. The method for real-time analysis and processing of attack sources as described in claim 1, characterized in that: The logical analysis and judgment also include, When the level is Level 2, Medium, the corresponding attack source IP is marked as Medium, and the attack source IP is immediately marked as Level 1 on the current firewall. The analysis continues to determine whether new information related to the attack source IP is generated. If the attack source IP continues to launch new attacks within a period of time, and the number of attacks exceeds the first preset value, then the attack source IP will be immediately marked with a second level 1 label on the current firewall. If the number of first-level markers exceeds three within three cycles, the attack source IP will be immediately blocked on the current firewall. The first preset value is the ratio of the time of one cycle to the average time interval between the two longest attack intervals and the two shortest attack intervals of the attack source IP, rounded up.
3. The method for real-time analysis and processing of attack sources as described in claim 2, characterized in that: The logical analysis and judgment also include, When the level is Level 3 Light, the corresponding attack source IP is marked as Light, and the attack source IP is immediately marked as Level 2 on the current firewall. The analysis continues to determine whether new information related to the attack source IP is generated. If the attack source IP continues to launch new attacks within a period of time, and the number of attacks exceeds the second preset value, then the attack source IP will be immediately marked with a second level two label on the current firewall. If the number of secondary markers exceeds five within a period, the attack source IP will be immediately blocked on the current firewall. The second preset value is the ratio of the time of one period to the average time interval between the two longest attack intervals and the two shortest attack intervals of the attack source IP, rounded down.
4. The method for real-time analysis and processing of attack sources as described in claim 3, characterized in that: The logical analysis and judgment also include, When the first-level labeling is performed for the second time, the server automatically retrieves the firewall version for the attack source IP and pre-installs it; If no third level-one marking operation is generated within three cycles after the first level-one marking, the attack source IP is deemed not to pose a threat to the network, and the attack source IP will not be blocked on the current firewall. When the fourth secondary labeling is performed, the server automatically retrieves the firewall version for the attack source IP and pre-installs it; If another Level 1 labeling operation occurs within this cycle, the pre-installed firewall will be installed. If no Level 1 marking operation is generated within this cycle, the attack source IP is deemed not to pose a threat to the network, and the attack source IP will not be blocked on the current firewall.
5. A system for real-time analysis and processing of attack sources using the method described in claim 1, characterized in that: It includes a log generation module, an analysis and judgment module, and a real-time processing module. A log generation module is used to monitor the network in real time and generate alarm logs in real time when an attack event occurs. The analysis and judgment module is used to store alarm logs in a structured database in real time and perform real-time logical analysis and judgment on the alarm logs after they are stored in real time. A real-time processing module is used to perform corresponding real-time processing on the attack source IP based on the real-time logic analysis and judgment results.
6. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 4.
7. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Risk control method and device and storage medium
CN113542200A