A Remote Data Acquisition Method, Storage Medium and Electronic Device
By establishing a stable communication connection on the target terminal and performing data acquisition processing in cycles, the problem of incomplete data acquisition of APT attacks in the prior art is solved, and continuous network attack evidence collection is realized, which improves the value and comprehensiveness of evidence collection data.
Patent Information
- Application Number
- CN202310674798.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-06-08
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2043-06-08
AI Technical Summary
The existing technology is difficult to effectively obtain the key data of APT attacks during the short-term on-site evidence collection of the defensive party, resulting in incomplete evidence collection data and reduced value.
Establish a stable communication connection with the target terminal through the physical interface, perform data acquisition processing in a loop, and use the data acquisition policy version number comparison and policy library updates to ensure that the latest data acquisition policy is obtained and the target data is continuously obtained to forensic network attacks.
It has achieved long-term and continuous cyber attack evidence collection, overcome the problem of APT attacks avoiding evidence collection through short-term pauses or concealment behaviors, and improves the comprehensiveness and value of evidence collection data.
Smart Images

Figure CN116633652B_ABST
Abstract
Description
Background Art
[0002] The four major threats in cyberspace include interruption threats, interception threats, tampering threats, and forgery threats. The above threats can cause problems such as the destruction of the information systems in use and the theft of important privacy information.
[0003] In recent years, with the continuous development and use of new attack techniques and tactics by cyberspace threat actors at various ability levels, the cyberspace security situation has become increasingly severe. At the same time, due to the improvement of anti-forensics capabilities by some existing APT (Advanced Persistent Threat) attacks, they can pause / suspend or highly conceal their key threat behaviors during the short-term on-site forensics by the defense side. As a result, when conducting on-site forensics manually in a short time currently, more effective data cannot be obtained, leading to problems such as ineffective forensics by the defense side, incomplete forensics data, and reduced value of forensics data. Summary of the Invention
[0004] In view of the above technical problems, the technical solution adopted by the present invention is as follows:
[0005] According to one aspect of the present invention, a remote data acquisition method is provided, and the method includes the following steps:
[0006] Establish a communication connection with the target terminal through a physical interface.
[0007] Repeatedly perform data acquisition processing on the target terminal to obtain target data;
[0008] The data acquisition processing includes:
[0009] Compare the version number of the currently loaded data acquisition policy with the highest version number in the policy library.
[0010] If the version number of the currently loaded data acquisition policy is less than the highest version number in the policy library, then use the data acquisition policy corresponding to the highest version number as the target acquisition policy.
[0011] According to the target acquisition policy, perform data acquisition processing on the target terminal to obtain target data. The target data is used to indicate whether the target terminal has been attacked by unauthorized users.
[0012] Send the target data to the target collection terminal.
[0013] According to a second aspect of the present invention, a non-transitory computer-readable storage medium is provided. The non-transitory computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the above-mentioned remote data acquisition method is implemented.
[0014] According to a third aspect of the present invention, there is provided an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the above-mentioned remote data acquisition method is implemented.
[0015] The present invention has at least the following beneficial effects:
[0016] After establishing a stable communication connection with the target terminal through the physical interface, the present invention will cyclically perform data acquisition processing on the target terminal to obtain target data. Thus, it is possible to continuously collect evidence of network attacks on the target terminal for a long time. Furthermore, it can overcome some existing APT attacks that avoid evidence collection by pausing / aborting for a short time or highly concealing their key threat behaviors. This enables the evidence collection data to be more comprehensive, improves the value of the evidence collection data, and further ensures that more effective data is obtained.
[0017] In addition, the collected target data can be sent to a target collection terminal. The target collection terminal can be a remote terminal with stronger network risk analysis capabilities. Thus, the purpose of remotely and continuously collecting evidence of risks and analyzing the target terminal can be achieved. Since the risk handling capabilities of the target collection terminal can be remotely utilized, it is beneficial to realize the organic integration of automated evidence collection and manual intervention, enabling the network space threat evidence collection operation to obtain the advantages of both efficiency and experience. It is also beneficial to cooperate with other network security defense measures to facilitate the construction of a more comprehensive security defense system. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0019] Figure 1 It is a flowchart of a segmented data acquisition method provided by an embodiment of the present invention;
[0020] Figure 2 It is a flowchart of a remote data acquisition method provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0021] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0022] As an aspect of the present invention, as Figure 2 shown, a method for remotely obtaining data is provided. The method includes the following steps:
[0023] S10: Establish a communication connection with the target terminal through a physical interface.
[0024] Specifically, the target terminal in the present invention can be: mobile terminals such as servers, desktop computers (PCs), laptop computers, tablet computers (Pads), and smart phones, as well as virtual machines in the virtualization dimension, excluding embedded terminal devices, Internet of Things (IoT) terminals (including smart wearable devices), etc.
[0025] The data acquisition terminal can be a device with a storage space and a control chip, such as a USB flash drive or a hard disk.
[0026] This physical connection action can be completed either by the (suspected) victim endpoint asset owner / responsible person (usually the customer himself) or the network security management personnel within the customer organization, or by the security service engineer of a network security enterprise in cooperation with the customer; except for removing the device as needed (i.e., it can also permanently retain the physical connection of the device and never remove it), this physical connection action is the only operation in this implementation process that needs to approach the (suspected) victim endpoint entity device in the cyberspace threat. The remaining operations only need to be remotely operated.
[0027] In this embodiment, a communication connection is established between the data acquisition terminal and the target terminal through a physical interface. It can ensure that the communication connection is more stable, not easily interfered with or stolen, has higher security, and can also have a higher data transmission speed to ensure that the data acquisition terminal can copy data from the target terminal more quickly.
[0028] At the same time, this method can also support long-term continuous remote forensics operations on the target terminal without the need for personnel other than users to enter the site and with zero physical contact with the target terminal. This is beneficial to the (suspected) victim endpoint, that is, the target terminal, and the user to ensure their strict physical proximity protection requirements for the endpoint device. For example, prohibiting all external personnel from physically approaching and contacting the device, and compliance with the control requirements for the entry of external personnel.
[0029] S20: Continuously perform data acquisition processing on the target terminal to obtain target data.
[0030] Performing data acquisition processing on the target terminal in a loop can continuously obtain evidence of network attacks on the target terminal for a long time. Thus, after the target terminal (suspected of) being threatened by the network, timely and effective threat evidence collection support can be obtained immediately after discovery, which can further inhibit the deterioration of the cyber threat situation suffered. The evidence collection speed and immediacy of this method are much higher than those of security engineers going to the scene for evidence collection. This is beneficial for cybersecurity manufacturers to provide their users with longer-duration and better-evidence-collection cyber threat evidence collection operations on the premise of reducing the human resource cost of engineers going to the user site for evidence collection.
[0031] The data acquisition processing includes:
[0032] S21: Compare the version number of the currently loaded data acquisition policy with the highest version number in the policy library.
[0033] S22: If the version number of the currently loaded data acquisition policy is less than the highest version number in the policy library, then use the data acquisition policy corresponding to the highest version number as the target acquisition policy.
[0034] Specifically, the evidence collection policy set in the built-in storage of the data acquisition terminal covers multiple sets of evidence collection policies, that is, data acquisition policies, including but not limited to:
[0035] The default built-in evidence collection policy Policy_Default, and each evidence collection policy contains multiple default built-in sub-policies, such as target data collection sub-policy, data storage sub-policy, data encryption sub-policy, and data transmission sub-policy. The version number of Policy_Default is Policy_000, which is the policy with the lowest version number.
[0036] The subsequent updated versions of the evidence collection policies Policy_001 to Policy_N (N is a positive integer greater than 1) are all updated evidence collection policies batch-pushed / fixed-point issued by the remote security analysis center, that is, the target collection terminal, and include updated target data collection sub-policies, data storage sub-policies, data encryption sub-policies, and data transmission sub-policies. The version numbers of Policy_001 to Policy_N increase with the increase of the number. For example, Policy_002 > Policy_001 > Policy_Default (Policy_000).
[0037] The selection of the evidence collection policy is mainly based on two-layer judgments, that is, "except for the default built-in policy, is there an updated version of the policy?" and "except for the policy selected last time, is there an updated version of the policy?" After the above judgments, it can be ensured that the currently used evidence collection policy is the latest policy to ensure the evidence collection effect. The specific judgment steps are as follows:
[0038] First - layer judgment: Except for the default built - in policy, is there an updated policy?
[0039] If the judgment result is "no", that is, there is only one set of policies in the evidence - collection policy set, and this policy is the default built - in evidence - collection policy Policy_Default, then continue to execute step S23.
[0040] If the judgment result is "yes", that is, except for the default built - in policy Policy_Default, there are other updated policies, then continue to execute the following second - layer judgment.
[0041] Second - layer judgment: Except for the most recently selected policy, is there an updated policy?
[0042] If the judgment result is "no", that is, there are no other updated policies in the evidence - collection policy set except for the most recently selected policy, then there is no need to repeatedly load the same evidence - collection policy, and directly continue to execute step S23.
[0043] If the judgment result is "yes", that is, there are updated policies in the evidence - collection policy set except for the most recently selected policy, then continue to execute step S22.
[0044] This step is a step that supports periodic and repeated execution, that is, periodically and repeatedly execute the above two - layer judgment to ensure that on the basis of the initial evidence - collection job running completed by the default built - in evidence - collection policy (Policy_Default), the updated version of the evidence - collection policy (Policy_001 to Policy_N) can be adopted in a timely manner; here, parameters such as the time interval of "periodically" and the number of "repeated" times are configured according to customer needs.
[0045] Meanwhile, since the policies and their quantities in the evidence - collection policy set are controlled by the policy management instructions sent by the remote security analysis center and increase or decrease, that is, after the initial connection and the first - round method operation between the evidence - collection device and the connected (suspected) victim endpoint (i.e., the target terminal), there may still be a situation where there is only the default built - in evidence - collection policy (Policy_Default) in the evidence - collection policy set (for example, the evidence - collection device has not yet received the updated policy data pushed / downloaded by the remote security analysis center, or the previously obtained updated policies in the evidence - collection policy set are administratively deleted, etc.). Therefore, in the repeated execution of the judgment process, the first - layer judgment is necessary to be retained for a long time.
[0046] In the "target data collection sub - policy" of the sub - policy, specific regulations are given for the collection of target data, including but not limited to:
[0047] The scope of the target data to be collected. For example, the scope of the target data to be collected is proposed to include basic endpoint information, process information, module information used by processes, subprocess information contained in processes, thread information, file handle information, Dynamic Link Library (DLL) information, loaded drivers, system startup items, scheduled tasks, system services, Service Provider Interface (SPI) information, system registry and its change information, kernel module information, System Services Descriptor Table (SSDT) and Shadow System Services Descriptor Table (Shadow SSDT) information, message hooks, program hooks and kernel hooks, directory objects, Main Boot Record (MBR) information, system shared information, user and their account change information, command line history, open ports, routing table information, current inbound and outbound network connection information, network connection history, Hosts information, browser browsing history, operating system logs, application logs, system security logs, system file installation logs, file operation logs, removable storage transfer logs, optical disc read / write logs, floppy disk read / write logs, scan and print logs, Instant Messaging (IM) transfer data, online video transfer data, email transfer data, downloaded file data, screen image data, (suspected) malicious code sample files, etc.
[0048] The types of the target data to be collected. For example, the types of the target data to be collected are proposed to include, but are not limited to,.dll,.exe,.log, etc.
[0049] The producers (data sources) of the target data to be collected. For example, it is proposed to collect data generated by the network interface card (NIC) of the (suspected) victim endpoint.
[0050] The duration of collection. For example, the proposed duration of collection is 24 hours, 2 days, 3 weeks, 4 months, 1 year, etc.
[0051] The absolute time and relative time intervals for collection start / suspension / termination. For example, it is proposed to start / suspend / terminate collection at 00:00 on January 1, 2023, start / suspend / terminate collection at 22:00 every day, start / suspend / terminate collection every 3 days, etc.
[0052] The conditions for collection suspension / resumption. For example, it is proposed to suspend collection when the average CPU utilization rate of the (suspected) victim endpoint is higher than 95% for 5 consecutive minutes, and resume collection when the average CPU utilization rate is lower than 10% for 5 consecutive minutes, etc.
[0053] S23: According to the target acquisition strategy, perform data acquisition processing on the target terminal to obtain target data. The target data is used to indicate whether the target terminal has been under a network attack by unauthorized users.
[0054] The forensics strategy selection and management module loads the forensics strategy determined through the above S22. Before loading, it is also necessary to determine whether the strategy is already in a state where it has been fully loaded and can be directly used. If there is already a recently selected strategy that has completed a round of method operations or the just-selected strategy is in an available state of being fully loaded, the target terminal directly uses the target acquisition strategy to perform forensic collection of cyberspace threat-related data on the (suspected) victim endpoint.
[0055] Preferably, the target acquisition strategy includes a target data collection sub-strategy, a data storage sub-strategy, a data encryption sub-strategy, and a data transmission sub-strategy.
[0056] Specifically, data storage, encryption, and transmission can be carried out according to the data storage sub-strategy, data encryption sub-strategy, and data transmission sub-strategy included in the target acquisition strategy.
[0057] For example, in the sub-strategy "data storage sub-strategy", specific regulations are given for the storage of target data, including but not limited to:
[0058] The storage location of the target data. For example, the storage location of log data is set to the Built-in_Storage\Evidence\Log directory, etc.
[0059] The upper limit of the storage space for the target data. For example, the total storage space occupied by the target data ≤ 512GB, the storage space occupied by the (suspected) malicious code sample file ≤ 20GB, etc.
[0060] The trigger transfer threshold for the storage space occupied by the target data. For example, 75%, that is, when the forensics storage data volume reaches 75% of the total storage space, the trigger transfer condition is met.
[0061] The self-cleaning method of the target data storage space and its trigger threshold. For example, when the storage space is occupied ≥ 95%, the oldest data is overwritten in a rolling manner, etc.
[0062] Whether the target data is stored in a compressed manner; if it is stored in a compressed manner, the settings of parameters such as the compression algorithm and compression format are adopted. For example, for compressed storage, the compression algorithm LZ4 is adopted, and the compression format Zip is adopted, etc.
[0063] Whether the target data is encrypted and stored; if it is encrypted and stored, encryption / decryption algorithms, key security management methods, etc. are adopted. For example, for encrypted storage, the encryption algorithm SM4 (SM4 block cipher algorithm) is adopted, and the key is entrusted by KMS (Key Management Service, key management service), etc.
[0064] Data encryption based on the forensics strategy. The target data encryption and transmission module encrypts the forensics data to be encrypted and transmitted, which is stored in the built-in storage and extended storage, before sending according to the sub-strategy "data encryption sub-strategy" in the selected forensics strategy.
[0065] In the sub-strategy "data encryption sub-strategy", specific regulations are given for the encryption of target data, including but not limited to:
[0066] Encryption methods are adopted. For example, symmetric encryption algorithms are adopted, etc.
[0067] Encryption algorithms are adopted. For example, the encryption algorithm RC4 (Rivest Cipher 4, a stream encryption algorithm) is adopted, etc.
[0068] Key security management methods are adopted. For example, the built-in KMS in the remote security analysis center is used to entrust the key, etc.
[0069] Data transmission based on the forensics strategy. The target data encryption and transmission module transmits the forensics data that has been encrypted before sending to the remote security analysis center as the destination according to the sub-strategy "data transmission sub-strategy" in the selected forensics strategy, and receives the confirmation information feedback from the remote security analysis center to ensure the reliability of data transmission.
[0070] In the sub-strategy "data transmission sub-strategy", specific regulations are given for the transmission of target data, including but not limited to:
[0071] Data transmission methods, such as full amount for the first time and incremental transmission for subsequent times, full amount transmission each time, etc.
[0072] Data transmission time and its interval, such as real-time transmission, transmission every 24 hours, transmission at 22:00 every natural day, etc.
[0073] Data transmission trigger conditions, such as transmission on time according to the configured time, transmission triggered according to the trigger threshold of the occupied storage space of the target data, unconditional transmission, etc.
[0074] S24: Send the target data to the target collection terminal.
[0075] A communication connection is established between the target collection terminal (security analysis center) and the data acquisition terminal (U disk), so that the target collection terminal can initiate corresponding control instructions to the data acquisition terminal to remotely control the evidence collection process, such as whether to continue to execute the data acquisition processing program in a loop.
[0076] After establishing a stable communication connection with the target terminal through a physical interface, the present invention cyclically performs data acquisition processing on the target terminal to obtain target data. As a result, it is possible to continuously collect evidence of network attacks on the target terminal for a long time. In addition, it is possible to overcome some existing APT attacks and avoid the problem of evidence collection by pausing / terminating or highly concealing their key threat behaviors for a short time. This makes the evidence data more comprehensive and improves the value of the evidence data, thereby ensuring that more effective data is obtained.
[0077] As a possible embodiment of the present invention, S10: establishing a communication connection with a target terminal through a physical interface includes:
[0078] S11: After completing the physical connection between the data acquisition terminal and the target terminal through the physical interface, the data acquisition terminal sends a communication request to the target terminal.
[0079] S12: If the data acquisition terminal cannot receive the target response information, the target driver is acquired from the backup driver library for loading. The backup driver library is configured in the data acquisition terminal.
[0080] This embodiment mainly involves the interface adaptation process of the evidence collection device after the physical connection is completed. The evidence collection device of the present invention is physically connected to the (suspected) victim endpoint through the current mainstream and commonly used interface, and the interface driver adaptation module implements the interface adaptation.
[0081] Based on the possibility that the driver of the (suspected) victim endpoint has been damaged by cyber threats and cannot operate normally, the interface driver adaptation module determination device can determine whether the connected endpoint can be driven according to the above steps:
[0082] If a driver is available, the required driver for the forensic device interface adaptation will give priority to the existing driver for the connected endpoint.
[0083] If the driver cannot be provided, the evidence collection device needs to use a backup driver. The driver required for the interface adaptation of the evidence collection device uses the interface driver set (i.e., the backup driver library) in the built-in storage of the evidence collection device itself as the backup driver source to complete the driver installation and realize the control command and data transmission channel between the evidence collection device and the (suspected) victim endpoint to which it is connected.
[0084] The interface driver set in the device's built-in storage covers the current mainstream and commonly used interface drivers, including but not limited to USB Type-A interface driver, USB Type-C interface driver, USB Micro-B interface driver, Lightning interface driver, etc.
[0085] After S12, the present invention also includes a mounting protection method for the target terminal, which is as follows:
[0086] In the "evidence control program" in the evidence collection device, a "evidence collection device mount protection" function module is added to execute the mount protection method for the target terminal. The mount protection is achieved by granting the evidence collection device a high-level management authority of the endpoint operating system. The present invention specifically discloses the mount protection method for the Windows operating system and the Linux operating system as examples.
[0087] 1. Protection method for forensic device mounting in Windows operating system
[0088] After the forensic device is physically plugged into the (suspected) victim endpoint, the "Forensic Control Program" adds the device to the "Administrators" group in the Windows local group as a Windows local user named Administrator_E (taken from the first letters of Evidence), and has the operating system management privileges of the (suspected) victim endpoint.
[0089] In the case where the (suspected) victim endpoint "Universal Serial Bus Controller - Driver - Disable Device" has been set by the attacker, the "Enable Device" operation is given.
[0090] In case the "uninstall device" of the (suspected) victim endpoint has been set by the attacker, a "scan for hardware changes" operation is given and the interface driver set (backup) inside the device is used to remount it.
[0091] For the local users and groups of the (suspected) victim endpoint, this forensic device supports the following operations:
[0092] Disable or lock out the Administrator user that could have been exploited by an attacker, or remove the user from the Administrators group to which the user belongs.
[0093] Disable or lock the "DefaultAccount" user, or remove it from the "System ManagedAccounts Group" group to which it belongs.
[0094] Disable or lock the "Guest" user, or remove it from the "Guests" group to which it belongs.
[0095] Except for the "WDAGUtilityAccount" user (a user account used by the system for managing and using the Windows Defender Application Guard solution) and the "Administrator_E" user, disable or lock all other suspicious users.
[0096] Except for the "Administrator_E" user, remove all other suspicious users from the "Administrators" group.
[0097] Remove all suspicious users from the "System Managed Accounts Group" group.
[0098] Remove all suspicious users from the "Guests" group.
[0099] Support the downgrading of users suspected of being attackers, for example, downgrading the users they exploited from the "Administrators" group to the "Guests" group.
[0100] Support the mandatory logout operation for users suspected of being attackers who have logged in to the operating system.
[0101] At the same time, based on establishing a trust relationship with domestic mainstream endpoint protection systems / software products, by adding a trusted list, etc., when the relevant endpoint protection systems / software in the (suspected) victimized endpoint system are still running, to avoid, to the greatest extent, misinterception or damage to the operation of this forensic device.
[0102] II. Mounting Protection Method for Forensic Devices for Linux Operating Systems
[0103] After this forensic device is physically plugged into the (suspected) victimized endpoint, the "Forensic Control Program" sets the UID of this device to 0 with the user identity named root_E (derived from the first letter of Evidence), which is equivalent to the superuser root or super administrator, enabling it to have the management authority of the (suspected) victimized endpoint operating system.
[0104] After S12, the present invention further includes a method for protecting the concealment of the target terminal, specifically as follows:
[0105] In the "Forensics Control Program" within the forensics device, add a "Device Concealment Protection" function module to execute the method for concealing and protecting the target terminal. By hiding the device of this device in the Device Manager of the (suspected) victim endpoint Windows operating system, the time for the attacker to discover this forensics device and its operations is delayed, providing protection for the forensics device and its operations from the dimension of concealment.
[0106] Under normal circumstances (that is, when the attacker has not set "Show All Devices" in the Device Manager of the (suspected) victim endpoint Windows operating system), the Device Manager does not display hidden devices. The "Device Concealment Protection" function module marks the device itself as a "hidden device" based on two methods of hiding devices in the Device Manager of the Windows operating system, thereby achieving hiding in the Device Manager. The specific methods are as follows:
[0107] I. Method for hiding this forensics device from the driver
[0108] The driver of this device can be marked as hidden through the following two methods:
[0109] 1.1 The function driver or function filter driver can request the operating system to hide the successfully started device by responding to the IRP_MN_QUERY_PNP_DEVICE_STATE IRP. When the IRP arrives, the driver must set the PNP_DEVICE_DONT_DISPLAY_UI bit in IoStatus.Information to TRUE in the driver dispatch routine.
[0110] 1.2 On Windows XP and later Windows operating systems, the bus driver or bus filter driver can hide any device (started or other devices) by responding to the IRP_MN_QUERY_CAPABILITIES IRP. When the IRP arrives, the driver must set the Parameters.DeviceCapabilities.NoDisplayInUI member to TRUE in the driver's dispatch routine. In some cases, the bus filter driver may need to set this bit in the completion routine. This additional step is required when the underlying bus driver dispatch routine erroneously clears all function fields set by other drivers.
[0111] II. Method for hiding the forensics device using ACPI BIOS
[0112] It includes the following two specific implementation methods:
[0113] 2.1 The device can be marked as hidden in the ACPI BIOS. The BIOS can expose the _STA method of the device. The _STA method returns a bitmask. Bit 2 (mask 0x4) specifies whether the device manager should make the device visible by default. If the device should be visible, this bit should be 1; otherwise, it is 0.
[0114] 2.2 In Microsoft Windows 2000, only started and working devices can be hidden. In Windows XP and later versions of Windows, damaged devices can also be hidden. Bit 3 (mask 0x8) returned by the _STA method indicates whether the device is working properly. If the device is working properly, this bit is 1; otherwise, it is 0.
[0115] Thus, through the mounting protection method and / or device hiding method in this embodiment, it can be ensured that the data acquisition terminal can collect data on the target terminal more smoothly.
[0116] As a possible embodiment of the present invention, the method further includes:
[0117] S30: Obtain an updated acquisition policy and add it to the policy library. The updated acquisition policy is generated based on the obtained target data. The version number of the updated acquisition policy is the timestamp when the updated acquisition policy is generated.
[0118] In this method, the measurement criteria for the "updated version policy" mainly include factors such as the number of existing policies in the forensics policy set, the level of the policy version number, and the newness of the policy generation timestamp, that is, there is more than just the default built-in policy (Policy_Default) in the forensics policy set. Policies with a higher version number and policies with a newer generation timestamp are all included in the measurement and determination of the "updated version policy".
[0119] The generation and distribution of the above-mentioned updated acquisition policy can be completed by the remote security analysis center.
[0120] As a possible embodiment of the present invention, after S20, the method further includes:
[0121] S40: Store the target data in the specified path of the data acquisition terminal. The specified path enables the execution permission prohibition function.
[0122] S41: When any program performs a write operation on the specified path, verify the digital signature of the program.
[0123] S42: If the verification passes, allow the write operation on the specified path.
[0124] In the implementation process of the above method, only the forensics control program (with a dedicated digital signature) in the corresponding device and computer-readable medium of the method has the write data permission for the storage of the forensics device (including built-in storage and extended storage). The execution permission of all other portable executable (PE) files is prohibited within this storage space. In this way, "write protection" and "execution permission prohibition" are used to prevent malicious tampering / destruction / deletion, forgery / counterfeiting, etc. of the collected forensics data by malicious code and its related cyberspace threats that may come from (suspected) victim malicious endpoints.
[0125] As another aspect of the present invention, as Figure 1 shown, a segmented data acquisition method is provided, and this method includes the following steps:
[0126] S100: Establish a communication connection with the target terminal. This step can be the same as S10.
[0127] S23 can also be a method of implementing data forensics in stages and categories. Specifically, the process of data acquisition is set to two stages, namely the first acquisition process and the second acquisition process. The first acquisition process is the silent forensics stage, and the second acquisition process is the public forensics stage. Specifically, S500 in this embodiment is used to control which stage to switch to specifically. Correspondingly, the silent forensics stage can cooperate with the above-mentioned method of hiding the forensics device to reduce the probability of being discovered by the attacker.
[0128] The target acquisition strategy includes the first data acquisition strategy and the second data acquisition strategy; the target data includes the first target data and the second target data.
[0129] S200: According to the first data acquisition strategy, perform the first acquisition process on the target terminal. The first acquisition process is used to acquire the target data belonging to several first preset categories in the target terminal, that is, the first target data. The target data is used to indicate whether the target terminal has been attacked by unauthorized users through the network.
[0130] The first target data can be some information that occupies less system resources during the collection process, such as some information with a lower change frequency. Specifically, it can be a part of the information in the range and types of the target data to be collected determined in the above-mentioned target data collection sub-strategy. For example, the range selects basic endpoint information, system self-start items, scheduled tasks, system services, system registry information, open ports, ARP table information, routing table information, various logs, etc., and the type selects.log, etc., as the first target data to be collected in the first stage (silent forensics stage).
[0131] During the process of collecting this part of information, it occupies less system resources, causes less interference to the processes ongoing in the system, and is less likely to be detected by attackers.
[0132] In the above-mentioned target data collection sub-strategy, the entire range of the target data to be collected and the entire types of the target data to be collected determined are used as the second target data to be collected in the second stage (public forensics stage).
[0133] S300: During the first acquisition and processing, based on the acquired target data, obtain the target switching parameter.
[0134] Furthermore, S300 includes:
[0135] S301: Based on the preset assignment weight and the currently acquired target data, obtain the target switching parameter A1 corresponding to each preset parameter at the current moment t , A2 t , …, A i t , …, A z t . A i t is the i-th target switching parameter at the current moment. A i t =K i *B i t ; K i is the preset assignment weight corresponding to the i-th preset parameter. B i t is the number of times the preset parameter belonging to the i-th category in the first preset category has appeared at the current moment. z is the total number of preset parameters, i = 1, 2, …, z. t is the identifier of the current moment.
[0136] S302: Based on the target switching parameter, obtain the switching degree of the first acquisition and processing, including:
[0137] Based on A1 t , A2 t , …, A i t , …, A z t , obtain the switching degree C of the first acquisition and processing at the current moment t . C t satisfies the following conditions: .
[0138] The switching degree is the decision parameter for determining whether to switch from the first acquisition and processing to the second acquisition and processing.
[0139] The preset parameters and their corresponding preset assignment weights can be set according to the actual usage scenario. During the setting process, the preset parameters need to meet the requirement of indicating the degree of discovery by the attacker, that is, the exposure degree of the forensics processing, which is proportional to the corresponding preset assignment weight. For example:
[0140] I. For the Windows operating system, the preset parameters for the sudden malicious change of the identity and permissions of the Windows local user named "Administrator_E" of this device include the following 3 types:
[0141] 1. The preset parameter indicating that the user "Administrator_E" is suddenly or repeatedly deleted from the "Administrators" group in the Windows local group within a short period of time. The corresponding preset assignment weight can be 1.5.
[0142] 2. The preset parameter indicating that the user "Administrator_E" is suddenly or repeatedly disabled or locked within a short period of time. The corresponding preset assignment weight can be 1.4.
[0143] 3. The preset parameter indicating that the user "Administrator_E" is suddenly or repeatedly downgraded to the "Guests" group in the Windows local group within a short period of time. The corresponding preset assignment weight can be 1.4.
[0144] II. For the Linux operating system, the preset parameter indicating that the UID of the user identity named root_E of this device is suddenly or repeatedly set to a non-zero value within a short period of time. The corresponding preset assignment weight can be 1.5.
[0145] III. The preset parameter indicating that during the operation of the silent forensics stage of this device, the (suspected) victim endpoint is suddenly set or repeatedly set within a short period of time through "Universal Serial Bus Controller - Driver - Disable Device". The corresponding preset assignment weight can be 1.2.
[0146] IV. The preset parameter indicating that during the operation of the silent forensics stage of this device, "Uninstall Device" is suddenly set or repeatedly set within a short period of time. The corresponding preset assignment weight can be 1.2.
[0147] V. The preset parameter indicating that the hidden state of this device is suddenly lifted and the hidden settings are suddenly tampered with. The corresponding preset assignment weight can be 1.7.
[0148] Therefore, according to the calculation of various parameters indicating the degree of discovery by the attacker in S300, the switching degree of the first acquisition process can be generated. The higher the switching degree, the higher the risk of discovery of the first acquisition process.
[0149] Furthermore, the first acquisition process includes the following steps:
[0150] S201: Whenever the update time is reached, generate the data acquisition speed for the current acquisition cycle according to the switching degree of the first acquisition process obtained in the previous adjacent acquisition cycle. Among them, V1 d satisfies the following condition: V1 d =V0*e avg(Cd-1) . V1 d is the data acquisition speed for the d-th acquisition cycle. V0 is the initial data acquisition speed. avg(C d-1 ) is the average value of the switching degrees of the first acquisition process obtained in the (d - 1)-th acquisition cycle. avg() is the average value function. C d-1 is all the switching degrees of the first acquisition process obtained in the (d - 1)-th acquisition cycle.
[0151] S202: Acquire target data belonging to several first preset categories according to the data acquisition speed of the current acquisition cycle.
[0152] The acquisition cycle and the update time are the same concept. That is, if one acquisition cycle is 1 min, then starting from the starting time, every subsequent time point one minute apart is an update time. And in a cycle of the first acquisition process, multiple update times will be set to adjust the data acquisition speed. For example, if a cycle of the first acquisition process is 3 min, the starting time is 00:00:00, and the acquisition cycle is 30 s, then 00:00:30, 00:01:00, 00:01:30, 00:02:00, 00:02:30, 00:03:00 are the corresponding update times.
[0153] By setting multiple update times, the data acquisition speed in a cycle of the first acquisition process can be adjusted in real time. Specifically, from V1 d =V0*e avg(Cd-1) it can be seen that it is equivalent to an adjustment coefficient for V0. When d = 1, since there is no data in C0, it will be assigned a value of 0. At this time, e avg(C1-1) =1, V1 d =V0, that is, in the first acquisition cycle, data will be acquired at a relatively low and stable speed all the time to be more concealed. And the exponential function of e has the characteristic that the rising amplitude is smaller in the early stage and larger in the later stage. Therefore, during the initial stage of silent evidence collection, since the evidence collection actions are small, the possibility of being discovered by the attacker is also small, that is, the switching degree is also small, and the corresponding data acquisition speed increases, but the amplitude is small. Thus, it is still not easy for the attacker to discover the evidence collection activity. However, when the switching degree is large, that is, in the later stage of the exponential function of e, at this time, as the switching degree increases, eavg(C1-1) It will increase more rapidly, and the corresponding data acquisition speed will also increase significantly. Usually, when the switching degree is relatively large, it means that the attacker has basically discovered the forensic activities. Therefore, at this time, a significant increase in the data acquisition speed is also required to quickly extract effective data.
[0154] At the same time, rapidly increasing the data acquisition speed in the later stage of the first acquisition process is also beneficial for a smooth transition of the data acquisition speed when switching to the second acquisition process, which is conducive to extending the lifespan of the data acquisition terminal.
[0155] S400: Obtain the switching degree of the first acquisition process according to the target switching parameter. The switching degree is a determination parameter used to determine whether to switch from the first acquisition process to the second acquisition process.
[0156] S500: If the switching degree is greater than the first switching threshold, perform a second acquisition process on the target terminal according to the second data acquisition strategy. The second acquisition process is used to obtain target data of several second preset categories, that is, second target data. The data acquisition speed of the second acquisition process is greater than that of the first acquisition process. The several second preset categories include several first preset categories.
[0157] When the switching degree is greater than the first switching threshold, it means that the attacker has discovered the current forensic activities. At the same time, the attacker will also quickly launch a counterattack, such as quickly deleting the trace data left by the attack. At this time, the data acquisition terminal needs to collect the second target data at the fastest speed to ensure obtaining more effective evidence. Therefore, the data acquisition speed of the second acquisition process needs to be greater than that of the first acquisition process. At the same time, the second acquisition process stage can also be used in conjunction with the above-mentioned mounting protection to provide a higher system priority for the data acquisition terminal in this stage to ensure that more system resources can be tilted towards the forensic process.
[0158] As a possible embodiment of the present invention, after obtaining the switching degree of the first acquisition process according to the target switching parameter, the method further includes:
[0159] S600: When the switching degree is greater than the second switching threshold, perform an attack feature analysis process on the obtained first target data to generate an attack level sequence. The second switching threshold is less than the first switching threshold.
[0160] The attack feature analysis process includes:
[0161] S601: Encode the feature information included in each obtained first target data according to the feature coding mapping table. The feature coding mapping table includes multiple feature codings, and each feature coding corresponds to at least one feature information.
[0162] S602: Generate an attack vector for each first target data according to the feature code corresponding to each feature information and the occurrence order.
[0163] S603: Use the attack identifier corresponding to the preset attack reference vector with the highest similarity to the attack vector of the first target data as the attack identifier of the first target data.
[0164] Specifically, in the same usage scenario, the target resources targeted by network attacks and the common attack methods have certain similarities. That is, there will be certain identical or similar aspects in each attack activity, so corresponding feature data will also be generated. Thus, according to this feature, a feature code mapping table can be obtained. According to this table, the same code can be assigned to feature data with the same or similar features. In the process of an attack, the occurrence order of each feature data can form the attack vector of each first target data. Similarly, according to the above method, multiple corresponding preset attack reference vectors can be generated based on the feature vectors generated by complete network attacks discovered in history.
[0165] The above steps are illustrated by the following example. For example, a certain network attack includes the following process:
[0166] 1. There is a spear-phishing email delivered by an attacker / organization on the (suspected) victim endpoint. The email contains malicious code and an ISO image of a bait file. Among them, the bait file is mostly related to the department and industry to which the (suspected) victim endpoint user belongs. For example, it contains common words of the department and industry to which the (suspected) victim endpoint user belongs.
[0167] 2. After the (suspected) victim endpoint user is induced to open the exe file disguised as a document in the image, the malicious code loads a malicious module in the form of DLL side loading.
[0168] 3. After the malicious module runs, it reads the data at the end of the bait document, decrypts the XML format file (i.e., releases the malicious XML file payload), and establishes a persistence mechanism (for example, modifying the registry), creates a scheduled task (for example, the infected machine is forced to log off at 13:15 on Wednesdays and Fridays every week, forcing the user to log in again). Whenever the (suspected) victim endpoint user logs in, it calls PowerShell to open the MSBuild.exe file (Microsoft Build Engine) to execute the malicious XML file, decrypts the data stored in the XML file, and loads it into memory for execution.
[0169] 4. The decrypted data is malicious payload, and it communicates with other devices and steals browser data, executes remote control commands and other functions.
[0170] According to the characteristic data generated in the above four attack processes, the obtained vector can be (11, 21, 32, 43). Among them, when there is a phishing email and there are preset common words in certain departments and industries, the corresponding code in the feature encoding mapping table is 11; there is an exe file opened, and the exe file is loaded in the form of DLL side loading, then the corresponding code in the feature encoding mapping table is 21; there is a decrypted XML format file and there is an act of modifying the registry, then the corresponding code in the feature encoding mapping table is 32; the malicious payload communicates with other devices, then the corresponding code in the feature encoding mapping table is 43.
[0171] Thus, through the similarity calculation between vectors, it is possible to evaluate which network attack corresponding to the preset attack reference vector the network attack represented by the currently obtained first target data is most likely to be.
[0172] Further, before S603, the attack feature analysis and processing further includes:
[0173] S613: Calculate the similarity for each attack vector to obtain the preset attack reference vector with the highest similarity to each attack vector.
[0174] The similarity calculation includes:
[0175] S623: Generate a sliding window with the same length as the attack vector.
[0176] S633: Use the sliding window to slide successively on each preset attack reference vector to generate a set of reference sub-vectors E1, E2,..., E g 、…、E p . Among them, E g is the set of reference sub-vectors of the g-th preset attack reference vector. E g = (E g 1 、E g 2 、…、E g h 、…、E g f(g) ), E g h is the h-th reference sub-vector in E g . f(g) is the total number of reference sub-vectors in E g . h = 1, 2,..., f(g). p is the total number of sets of reference sub-vectors of the preset attack reference vector, g = 1, 2,..., p.
[0177] Since the first acquisition process is a silent forensics stage, its data acquisition speed is low, and the amount of acquired data is small and the types of data are limited. Therefore, the first target data obtained is also very likely to be part of the data of a complete attack process. Therefore, the length of the finally determined attack vector will also be less than the length of the preset attack reference vector. For example, if the first target data is only the data of the second and third steps of the above network attack example, the corresponding attack vector generated at this time is also (21, 32).
[0178] Therefore, to solve the above problems, first use a sliding window to slide on each preset attack reference vector in turn to divide the reference sub-vectors corresponding to the response length of the attack vector, so as to perform more accurate subsequent similarity calculations. For example, the above preset attack reference vector will be divided into three reference sub-vectors: (11, 21), (21, 32), and (32, 43). Among them, the similarity between the attack vector (21, 32) and the second reference sub-vector (21, 32) is the highest.
[0179] S643: Calculate the vector similarity between the attack vector and each reference sub-vector, and use the preset attack reference vector to which the reference sub-vector with the highest similarity belongs as the preset attack reference vector with the highest similarity to the attack vector.
[0180] S604: Generate an attack level sequence according to the total number of each type of attack identifier. Among them, the more the number of attack identifiers, the higher the attack level of the attack identifier.
[0181] S700: Adjust the priority of the corresponding acquisition sub-strategies in the second data acquisition strategy according to the attack level sequence.
[0182] Preferably, each acquisition sub-strategy in the second data acquisition strategy uniquely corresponds to an attack identifier. S700 includes:
[0183] S701: Use the attack level of the attack identifier corresponding to each acquisition sub-strategy in the attack level sequence as the priority of each acquisition sub-strategy.
[0184] According to the above steps, a corresponding attack identifier can be matched for each first target data obtained. Then, through statistics, the number of occurrences of each type of attack identifier can be determined. The more the number of occurrences, the higher the attack level of the corresponding attack identifier. Therefore, the forensics strategy for the network attack represented by this attack identifier also requires a higher priority to facilitate more effective forensics. In this embodiment, a small amount of data obtained through the silent forensics stage can be used to quickly predict the types and attack levels of network attacks currently suffered by the target terminal, and then, based on this feature, the forensics sub-strategies in the public forensics stage can be adjusted in a timely manner so that more effective data can be obtained more efficiently during public forensics.
[0185] As a possible embodiment of the present invention, the method further includes:
[0186] S800: Whenever a new update cycle arrives, adjust the existing preset attack reference vector and the existing acquisition sub-strategy according to the first target data and the second target data obtained in the previous update cycle.
[0187] In this embodiment, the length of the update cycle can be set by itself according to the usage scenario, such as 1 week or 1 month, etc. In this embodiment, a new preset attack reference vector and a new corresponding evidence collection sub-strategy can be formed according to the characteristic data of network attacks reflected by the first target data and the second target data obtained in the historical cycle. And update and supplement the existing preset attack reference vector and the existing acquisition sub-strategy with this to ensure the effectiveness of subsequent data acquisition.
[0188] An embodiment of the present invention also provides a non-transitory computer-readable storage medium, which can be set in an electronic device to store at least one instruction or at least one segment of program related to a method in the method embodiment. The at least one instruction or the at least one segment of program is loaded and executed by the processor to implement the method provided in the above embodiment.
[0189] An embodiment of the present invention also provides an electronic device, including a processor and the aforementioned non-transitory computer-readable storage medium.
[0190] An embodiment of the present invention also provides a computer program product, which includes program code. When the program product runs on an electronic device, the program code is used to cause the electronic device to execute the steps in the method according to various exemplary embodiments of the present invention described above in this specification.
[0191] In addition, although the steps of the method in the present disclosure are described in a specific order in the drawings, this does not require or imply that these steps must be executed in this specific order, or that all the steps shown must be executed to achieve the desired result. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step for execution, and / or one step may be decomposed into multiple steps for execution, etc.
[0192] Those skilled in the art can easily understand from the description of the above embodiments that the exemplary embodiments described herein can be implemented by software or by a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (such as a personal computer, a server, a mobile terminal, or a network device, etc.) to execute the method according to the embodiments of the present disclosure.
[0193] In an exemplary embodiment of the present disclosure, there is also provided an electronic device capable of implementing the above method.
[0194] Those skilled in the art to which the present invention pertains can understand that various aspects of the present invention can be implemented as a system, a method, or a program product. Therefore, various aspects of the present invention can be specifically implemented in the following forms, namely: a complete hardware implementation, a complete software implementation (including firmware, microcode, etc.), or an implementation combining hardware and software aspects, which can be collectively referred to herein as "circuitry", "module", or "system".
[0195] The electronic device according to this embodiment of the present invention. The electronic device is merely an example and should not impose any limitation on the functions and usage scope of the embodiments of the present invention.
[0196] The electronic device is presented in the form of a general-purpose computing device. The components of the electronic device may include, but are not limited to: the above-mentioned at least one processor, the above-mentioned at least one storage, and a bus connecting different system components (including the storage and the processor).
[0197] Among them, the storage stores program codes, and the program codes can be executed by the processor, so that the processor executes the steps according to various exemplary embodiments of the present invention described in the above "Exemplary Method" section of this specification.
[0198] The storage may include a readable medium in the form of a volatile storage, such as a random access memory (RAM) and / or a cache memory, and may further include a read-only memory (ROM).
[0199] The storage may further include a program / utility having a set (at least one) of program modules, and such program modules include, but are not limited to: an operating system, one or more application programs, other program modules, and program data. The implementation of a network environment may be included in each or some combination of these examples.
[0200] The bus can represent one or more of several bus architectures, including a memory bus or a memory controller, a peripheral bus, an accelerated graphics port, a processor, or a local bus using any of the various bus architectures.
[0201] The electronic device can also communicate with one or more external devices (such as a keyboard, a pointing device, a Bluetooth device, etc.), and can also communicate with one or more devices that enable a user to interact with the electronic device, and / or communicate with any device that enables the electronic device to communicate with one or more other computing devices (such as a router, a modem, etc.). Such communication can be carried out through an input / output (I / O) interface. Moreover, the electronic device can also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through a network adapter. The network adapter communicates with other modules of the electronic device through the bus. It should be understood that, although not shown in the figure, other hardware and / or software modules can be used in combination with the electronic device, including but not limited to: microcode, device drivers, redundant processors, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.
[0202] Through the description of the above embodiments, those skilled in the art can easily understand that the exemplary embodiments described herein can be implemented by software, or can be implemented by the way of software combined with necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, and the software product can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to execute the method according to the embodiments of the present disclosure.
[0203] In an exemplary embodiment of the present disclosure, there is also provided a computer-readable storage medium, on which a program product capable of implementing the above method of this specification is stored. In some possible implementation manners, various aspects of the present invention can also be implemented in the form of a program product, which includes program code. When the program product runs on a terminal device, the program code is used to enable the terminal device to execute the steps according to various exemplary embodiments of the present invention described in the above "Exemplary Method" section of this specification.
[0204] The program product may employ any combination of one or more readable media. The readable media may be a readable signal medium or a readable storage medium. The readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the foregoing. More specific examples (a non-exhaustive list) of the readable storage medium include: an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0205] The computer readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries the readable program code. Such a propagated data signal may take many forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the foregoing. The readable signal medium may also be any readable medium other than the readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device.
[0206] The program code contained on the readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber cable, RF, etc., or any suitable combination of the foregoing.
[0207] The program code for performing the operations of the present invention may be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and also including conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computing device, partially on the user's device, executed as a stand-alone software package, partially on the user's computing device and partially on a remote computing device, or entirely on the remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., through the Internet using an Internet service provider).
[0208] In addition, the above-mentioned drawings are only schematic illustrations of the processes included in the method according to the exemplary embodiments of the present invention, rather than for limiting purposes. It is easy to understand that the processes shown in the above-mentioned drawings do not indicate or limit the chronological order of these processes. Additionally, it is also easy to understand that these processes may be executed synchronously or asynchronously, for example, in multiple modules.
[0209] It should be noted that although several modules or units of the device for action execution are mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of the two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.
[0210] The above are only the specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present invention should be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.
Claims
1. A method for remotely obtaining data, characterized in that, The method includes the following steps: Establish a communication connection with the target terminal through a physical interface; Loop to perform data acquisition processing on the target terminal to obtain target data; The data acquisition processing includes: Compare the version number of the currently loaded data acquisition policy with the highest version number of the data acquisition policies in the policy library; If the version number of the currently loaded data acquisition policy is less than the highest version number of the data acquisition policies in the policy library, then use the data acquisition policy corresponding to the highest version number as the target acquisition policy; According to the target acquisition policy, perform data acquisition processing on the target terminal to obtain target data; the target data is used to indicate whether the target terminal has been subjected to a network attack by unauthorized users; Send the target data to the target collection terminal; The target acquisition policy includes a first data acquisition policy and a second data acquisition policy; the target data includes first target data and second target data; According to the target acquisition policy, performing data acquisition processing on the target terminal to obtain target data includes: Perform a first acquisition process on the target terminal according to the first data acquisition policy; the first acquisition process is used to acquire first target data, and the first target data is target data in the target terminal belonging to several first preset categories; during the first acquisition process, obtain a target switching parameter according to the acquired target data; Obtain the switching degree of the first acquisition process according to the target switching parameter; the switching degree is a determination parameter used to determine whether to switch from the first acquisition process to the second acquisition process; If the switching degree is greater than a first switching threshold, then perform a second acquisition process on the target terminal according to the second data acquisition policy; the second acquisition process is used to acquire second target data; the second target data is target data in the target terminal belonging to several second preset categories; the data acquisition speed of the second acquisition process is greater than the data acquisition speed of the first acquisition process; several second preset categories include several of the first preset categories.
2. The method according to claim 1, characterized in that, Establishing a communication connection with the target terminal through a physical interface includes: After the physical connection between the data acquisition terminal and the target terminal is completed through the physical interface, the data acquisition terminal sends a communication request to the target terminal; If the data acquisition terminal cannot receive the target response information, then obtain a target driver program from the backup driver library for loading; the backup driver library is configured in the data acquisition terminal.
3. The method according to claim 1, characterized in that, The method further includes: Obtain an updated acquisition policy and add it to the policy library; the updated acquisition policy is generated according to the obtained target data; the version number of the updated acquisition policy is the timestamp when the updated acquisition policy is generated.
4. The method according to claim 1, characterized in that, The target acquisition policy includes a target data collection sub-policy, a data storage sub-policy, a data encryption sub-policy, and a data transmission sub-policy.
5. The method according to claim 1, characterized in that, After obtaining the target data, the method further includes: Store the target data in a specified path of the data acquisition terminal; the specified path enables the execution permission prohibition function; When any program performs a write operation on the specified path, verify the digital signature of the program; If the verification passes, writing operations on the specified path are allowed.
6. The method according to claim 1, characterized in that, During the first acquisition process, based on the acquired target data, obtain target switching parameters, including: Based on the preset assignment weights and the currently obtained target data, the target switching parameters A1 corresponding to each preset parameter at the current moment are obtained t , A2 t , …, A i t , …, A z t ; A i t is the i-th target switching parameter at the current moment; A i t = K i × B i t ; K i is the preset assignment weight corresponding to the i-th preset parameter; B i t is the number of times the preset parameter belonging to the i-th category in the first preset category has appeared at the current moment; z is the total number of preset parameters, i = 1, 2, …, z; Based on the target switching parameters, obtain the switching degree of the first acquisition process, including: According to A1 t , A2 t , …, A i t , …, A z t , the switching degree C of the first acquisition process at the current moment is obtained t ; C t satisfies the following conditions: .
7. The method according to claim 6, characterized in that, The first acquisition process includes the following steps: Whenever the update time arrives, generate the data acquisition speed for the current acquisition period according to the switching degree of the first acquisition process obtained in the previous adjacent acquisition period; Among them, V1 d satisfies the following conditions: V1 d = V0 × e avg(Cd-1) ; V1 d is the data acquisition speed in the d-th acquisition cycle; V0 is the initial data acquisition speed; avg() is the mean function; C d-1 is the switching degree of all the first acquisition processes obtained in the (d - 1)-th acquisition cycle; According to the data acquisition speed for the current acquisition period, acquire target data belonging to several first preset categories.
8. A non-transitory computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements a remote data acquisition method according to any one of claims 1 to 7.
9. An electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements a remote data acquisition method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Method for deploying and upgrading a wind control strategy
CN109522031A
Flow data monitoring method and device, electronic equipment and computer readable medium
CN110198297A