Attack behavior alarm information processing method, device, program, and medium
By deduplicating, filtering, and pattern matching the attack behavior alarm information, the instant messaging client's defense strategy is triggered, which solves the problems of low processing efficiency and omissions in the existing technology, and achieves efficient and accurate attack behavior processing, thus ensuring the security of the target system.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- TENCENT TECHNOLOGY (SHENZHEN) CO LTD
- Filing Date
- 2022-02-22
- Publication Date
- 2026-04-24
AI Technical Summary
In existing technologies, alarm information processing for attack behaviors is inefficient and prone to omission, failing to trigger defense strategies in a timely manner and affecting the secure operation of the target system.
By acquiring attack behavior alarm information from the target system, deduplication and merging are performed, filtering and IP geolocation queries are conducted based on security configurations, and the defense strategies of the instant messaging client are triggered using pattern matching results, thus enabling timely handling of attack behavior.
It improves the efficiency and accuracy of attack behavior alarm information processing, ensuring the secure operation of the target system and the user experience.
Smart Images

Figure CN116668051B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to alarm information processing technology for attack behavior, and more particularly to alarm information processing methods, computer program products, devices, electronic devices, and storage media for attack behavior. Background Technology
[0002] In related technologies, attack behavior detection methods typically employ static and dynamic analysis. With the continuous development of internet technology and software developers constantly updating and iterating their software, a large number of attack behavior families belonging to different categories will continuously appear in application markets and other channels. Traditional attack behavior alarm information processing methods only involve manual login to the device to process the attack behavior. This processing method is inefficient and prone to omissions in attack behavior processing, which is not conducive to timely detection of the target system and triggering defense strategies to handle the attack behavior, and cannot guarantee the operational security of the target system. Summary of the Invention
[0003] In view of this, embodiments of the present invention provide a method, computer program product, device, electronic device, and storage medium for processing alarm information of attack behavior. These methods enable triggering of target system defense strategies via instant messaging clients using pattern matching results, and timely processing of attack behavior through the triggered defense strategies. This not only improves the efficiency of processing alarm information for attack behavior, providing a better user experience for cloud-hosted systems, but also enhances the accuracy of attack behavior processing, ensuring the secure operation of the target system.
[0004] The technical solution of this invention is implemented as follows:
[0005] This invention provides a method for processing alarm information related to attack behavior, including:
[0006] The first attack behavior alarm information of the target system is obtained, and the first attack behavior alarm information is deduplicated and merged to obtain the second attack behavior alarm information.
[0007] Based on the security configuration of the target system, the alarm information for the second attack behavior is filtered to obtain the alarm information for the third attack behavior;
[0008] The IP address location information of the third attack behavior alarm information is queried to obtain the IP address location information;
[0009] Based on the IP address location information, the threat information of the third attack behavior alarm information is marked to obtain the threat information marking result;
[0010] Using the tagging results of the threat information, pattern matching processing is performed on the third attack behavior alarm information to obtain the pattern matching result of the third attack behavior alarm information;
[0011] The attack behavior is processed by the target system's defense strategy triggered by the pattern matching result through an instant messaging client.
[0012] This invention also provides an alarm information processing device for attack behavior, comprising:
[0013] The information transmission module is used to acquire the first attack behavior alarm information of the target system, and to perform deduplication and merging processing on the first attack behavior alarm information to obtain the second attack behavior alarm information.
[0014] The information processing module is used to filter the second attack behavior alarm information according to the security configuration of the target system to obtain the third attack behavior alarm information;
[0015] The information processing module is used to query the IP address information of the third attack behavior alarm information to obtain the IP address information.
[0016] The information processing module is used to mark the threat information of the third attack behavior alarm information based on the IP address location information, and obtain the threat information marking result;
[0017] The information processing module is used to perform pattern matching processing on the third attack behavior alarm information using the tagging result of the threat information, and obtain the pattern matching result of the third attack behavior alarm information.
[0018] The information processing module is used to trigger the target system's defense strategy through the pattern matching result via an instant messaging client, and to process the attack behavior through the triggered defense strategy.
[0019] In the above scheme,
[0020] The information processing module is used to obtain the first attack behavior alarm information of the target system through a multi-threaded polling method, wherein the first attack behavior alarm information includes at least one of the following:
[0021] Honeypot alerts, network layer attack alerts, web attack alerts, DDoS attack alerts, brute-force attack alerts, and remote login alerts;
[0022] The information processing module is used to calculate the hash value corresponding to each attack behavior alarm message in the first attack behavior alarm message;
[0023] The information processing module is used to form an alarm message hash table based on the hash value corresponding to each attack behavior alarm message;
[0024] The information processing module is used to perform deduplication and merging processing on each alarm message obtained by the target system based on the alarm message hash table to obtain the second attack behavior alarm message.
[0025] In the above scheme,
[0026] The information processing module is used to clear the alarm message hash table according to the security configuration of the target system and the time interval threshold; or
[0027] The information processing module is used to query the cloud hosting information corresponding to the target system based on the identifier of the target system;
[0028] The information processing module is used to determine the number of hosts that match the target system based on the cloud hosting information, and to clear the alarm message hash table based on the number of hosts.
[0029] In the above scheme,
[0030] The information processing module is used to acquire filtering events in the security configuration of the target system, wherein the filtering events include at least one of the following:
[0031] Attack source IP, attack target IP, attack source port, attack target port, attack type, and attack behavior details;
[0032] The information processing module is used to determine the regular expression corresponding to the filtering event based on the filtering event;
[0033] The information processing module is used to filter the second attack behavior alarm information using the regular expression to obtain the third attack behavior alarm information.
[0034] In the above scheme,
[0035] The information processing module is used to query the IP address information of the third attack behavior alarm information through an offline query process to obtain the first IP address information of the third attack behavior alarm information.
[0036] The information processing module is used to trigger an online query process when the offline query process fails to find the IP address information of the third attack behavior alarm information;
[0037] The information processing module is used to query the IP address information of the third attack behavior alarm information through the online query process to obtain the second IP address information of the third attack behavior alarm information.
[0038] The information processing module is used to merge the first IP location information and the second IP location information to obtain IP location information.
[0039] In the above scheme,
[0040] The information processing module is used to query the attack history information corresponding to the IP address location information based on the IP address location information.
[0041] The information processing module is used to query the attack type and attack behavior description information corresponding to the IP location information in the attack history information;
[0042] The information processing module is used to mark the threat information of the third attack behavior alarm information by using the attack type and attack behavior description information, and obtain the marking result of the threat information.
[0043] In the above scheme,
[0044] The information processing module is configured to receive a blocking operation instruction through the instant messaging client, wherein the blocking operation instruction includes at least one of the following:
[0045] Network layer blocking, host layer blocking, and application layer blocking;
[0046] The information processing module is used to process the attack behavior based on the blocking operation command; or
[0047] The information processing module is used to receive monitoring information through the instant messaging client and determine the traffic redirection location corresponding to the attack behavior based on the monitoring information.
[0048] The information processing module is used to redirect the attack behavior according to the redirection location corresponding to the attack behavior, so as to achieve high-defense cleaning of the attack behavior through the resources of the redirection location.
[0049] In the above scheme,
[0050] The information processing module is used to capture records of the access services of the attack behavior when different types of target systems obtain corresponding attack behaviors.
[0051] The information processing module is used to acquire and parse the network data packets carried by the attack behavior based on the access service records of the attack behavior.
[0052] The information processing module is used to determine and monitor the connection behavior of the target system after the attack behavior intrudes into the target system, based on the network data packets.
[0053] In the above scheme,
[0054] The information processing module is used to determine the corresponding firmware configuration information based on the usage environment of the target system.
[0055] The information processing module is used to obtain a matching target system image from the cloud server of the cloud hosting service process according to the firmware configuration information, wherein the target system image supports target system structures with different organizational structures.
[0056] The information processing module is used to create a container in the target system and create a target system that supports different organizational architectures through the container, so as to capture attack behaviors against the target system through the deployed target system.
[0057] This invention also provides an electronic device, the electronic device comprising:
[0058] Memory, used to store executable instructions;
[0059] A processor, when executing executable instructions stored in the memory, implements an alarm information processing method for a preceding attack behavior, or implements an alarm information processing method for the aforementioned attack behavior.
[0060] This invention also provides a computer-readable storage medium storing executable instructions, wherein the executable instructions, when executed by a processor, implement an alarm information processing method for preceding attack behaviors, or implement an alarm information processing method for preceding attack behaviors.
[0061] The embodiments of the present invention have the following beneficial effects:
[0062] This invention, in its embodiments, acquires a first attack behavior alarm message from a target system, performs deduplication and merging processing on the first attack behavior alarm message to obtain a second attack behavior alarm message; filters the second attack behavior alarm message according to the target system's security configuration to obtain a third attack behavior alarm message; queries the IP address location information of the third attack behavior alarm message to obtain the IP address location information; based on the IP address location information, marks the threat information of the third attack behavior alarm message to obtain the threat information marking result; and uses the threat information marking result to perform pattern matching processing on the third attack behavior alarm message to obtain the pattern matching result of the third attack behavior alarm message. Therefore, it is possible to trigger the target system's defense strategy through an instant messaging client using the pattern matching result, and to promptly handle attack behaviors through the triggered defense strategy. This not only improves the efficiency of attack behavior alarm message processing, providing a better user experience for cloud-hosted systems, but also enhances the accuracy of attack behavior processing, ensuring the secure operation of the target system. Attached Figure Description
[0063] Figure 1 This is a schematic diagram illustrating the usage environment of the alarm information processing method for attack behavior provided in this embodiment of the invention;
[0064] Figure 2 A schematic diagram of the composition structure of the alarm information processing device for attack behavior provided in an embodiment of the present invention;
[0065] Figure 3 A schematic flowchart of an optional method for processing alarm information of attack behavior provided in an embodiment of the present invention;
[0066] Figure 4 A schematic flowchart of an optional method for processing alarm information of attack behavior provided in an embodiment of the present invention;
[0067] Figure 5 A front-end display diagram of the alarm information processing method for attack behaviors provided in this application;
[0068] Figure 6 A schematic flowchart of an optional method for processing alarm information of attack behavior provided in an embodiment of the present invention;
[0069] Figure 7 This is a data storage diagram provided in an embodiment of this application;
[0070] Figure 8 This is a schematic diagram of behavior log storage provided in an embodiment of this application;
[0071] Figure 9This is an optional flowchart illustrating the alarm information processing method for attack behavior provided in an embodiment of the present invention. Detailed Implementation
[0072] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings. The described embodiments should not be regarded as limitations on this invention. All other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this invention.
[0073] In the following description, references are made to “some embodiments,” which describe a subset of all possible embodiments. However, it is understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.
[0074] In the implementation of this application, the collection and processing of relevant data should strictly comply with the requirements of relevant laws and regulations, obtain the informed consent or separate consent of the personal information subject, and carry out subsequent data use and processing within the scope of laws and regulations and the authorization of the personal information subject.
[0075] Before providing a further detailed description of the embodiments of the present invention, the nouns and terms involved in the embodiments of the present invention will be explained, and the nouns and terms involved in the embodiments of the present invention shall be interpreted as follows.
[0076] 1) In response to, used to indicate the conditions or states on which the operation performed depends. When the conditions or states on which it depends are met, one or more operations performed may be performed in real time or with a set delay. Unless otherwise specified, there is no restriction on the order in which the multiple operations are performed.
[0077] 2) Terminals, including but not limited to: ordinary terminals and dedicated cloud servers, wherein the ordinary terminals maintain a long connection and / or a short connection with the transmission channel, and the dedicated cloud servers maintain a long connection with the transmission channel.
[0078] 3) Client: The carrier that implements specific functions in the terminal. For example, a mobile client (APP) is a carrier of specific functions in a mobile terminal, such as performing payment and consumption functions or purchasing financial products.
[0079] 4) Web Application Firewall (WAF): Also known as a website application-level intrusion prevention system, it blocks malicious attack requests by detecting characteristics in Hypertext Transfer Protocol (HTTP) or Hypertext Transfer Protocol over Secure Socket Layer (HTTPS) messages.
[0080] 5) API: Short for Application Programming Interface, it refers to a set of predefined functions or conventions for the interaction between different components of a software system. Its purpose is to provide applications and developers with the ability to access a set of routines based on certain software or hardware, without needing to access the source code or understand the details of the internal workings.
[0081] 6) DDoS (Denial of Service) attack is a network attack method that aims to exhaust the network or system resources of the target computer, causing the service to be temporarily interrupted or stopped, making it inaccessible to normal users. It is also known as distributed denial of service. It refers to the attacker controlling a large number of zombie hosts in the botnet to send large amounts of data to the target, exhausting the target's system resources and causing it to be unable to respond to normal service requests.
[0082] 7) MSS: Managed Security Service, also known as managed security service or managed security service, usually refers to the process by which users outsource the more arduous tasks of enterprise security operations to professional third-party vendors in order to reduce their investment in security monitoring, analysis and operations, thereby focusing on their own business development and achieving cost reduction and efficiency improvement.
[0083] 8) MSSP: Managed Security Service Provider, refers to operators or service providers that provide managed security services.
[0084] 9) SOAR: Security Orchestration, Automation and Response. SOAR technology can collect inputs relevant to security operations, such as alerts from SIEM and other security technologies. Furthermore, SOAR technology enables incident analysis and classification, combining the processing power of human analysts and computers to help define, prioritize, and drive security incident response activities according to standard workflows. Digitally defining incident analysis and response workflows using SOAR tools can accelerate incident response and reduce incident handling response time.
[0085] 10) Cloud security refers to the collective term for security software, hardware, users, organizations, and security cloud platforms based on cloud computing business models. Cloud security integrates emerging technologies and concepts such as parallel processing, grid computing, and unknown virus behavior detection. Through a large network of clients, it monitors abnormal software behavior on the network, obtains the latest information on Trojans and malware on the Internet, sends it to the server for automatic analysis and processing, and then distributes solutions for viruses and Trojans to each client.
[0086] The main research directions in cloud security include: 1. Cloud computing security, which mainly studies how to ensure the security of the cloud itself and various applications on the cloud, including cloud computer system security, secure storage and isolation of user data, user access authentication, information transmission security, network attack protection, and compliance auditing; 2. Cloudification of security infrastructure, which mainly studies how to use cloud computing to build and integrate security infrastructure resources and optimize security protection mechanisms, including building a large-scale security event and information collection and processing platform through cloud computing technology to achieve the collection and correlation analysis of massive amounts of information and improve the ability to control and manage network-wide security events; 3. Cloud security services, which mainly studies various security services provided to users based on cloud computing platforms, such as antivirus services. In this application embodiment, cloud security managed services are provided to users based on a cloud computing platform.
[0087] Figure 1 This is a schematic diagram illustrating a usage scenario of the alarm information processing method for attack behavior provided in this embodiment of the invention. (See attached diagram.) Figure 1The service cluster (including server 10-1 and server 10-2) is equipped with corresponding clients capable of performing different functions. These clients are terminals (including server 10-1 and server 10-2) that retrieve different information from the corresponding server 200 via network 300 for browsing. The terminals connect to server 200 via network 300, which can be a wide area network, a local area network, or a combination of both, using a wireless link for data transmission. During the information interaction between the terminals and the network, they may be subject to attacks. Therefore, a cloud hosting engine, such as a Web Application Firewall (WAF), can be deployed to handle these attacks.
[0088] As an example, server 200 is used to deploy a cloud hosting engine. Before deploying the cloud hosting engine, it is necessary to accurately and efficiently collect standard task information. In related technologies, taking the pending task as an attack behavior as an example, attack behaviors are generally classified into static analysis and dynamic analysis. Static analysis is a technique for analyzing attacks without running malicious code. This type of method generally involves decompressing and decompiling the APK, which is faster than dynamic analysis. Traditional attack behavior alert processing methods only involve manual login to the device to handle the attack behavior. Timely handling of attacks can ensure the operational security of the target system and guarantee the user's experience with the cloud hosting product.
[0089] Specifically, the attack behavior alarm information processing method provided in this application can be implemented through cloud hosting products on cloud server networks, such as paid anti-DDoS attack software programs offered to all users. These programs support execution of the attack behavior alarm information processing method from any origin server location, and the compatible usage environment has a switching bandwidth of up to 900Gbps, providing 900Gbps BGP line protection. This can easily and effectively cope with DDoS attacks and CC (Challenge Collapsar) attacks, ensuring stable and normal business operations. When a website is located in a cloud server network, the attack behavior alarm information processing method provided in this application can be used to trigger the target system's defense strategy when games, internet, and financial services suffer large-scale DDoS attacks. The triggered defense strategy then processes the attacked event, protecting the normal operation of games, internet, and financial services. Users can configure high-defense IPs to redirect attack traffic for cleaning, ensuring the stability and availability of origin server services. The high-defense IPs using the Border Gateway Protocol (BGP) can access the network via a public proxy and support protocols such as TCP, UDP, HTTP, HTTPS, and HTTP2. This allows the alarm information processing method for attack behaviors provided in this application to cover various business scenarios such as finance, e-commerce, and gaming.
[0090] The structure of the alarm information processing device for attack behavior according to embodiments of the present invention will be described in detail below. The alarm information processing device for attack behavior can be implemented in various forms, such as a dedicated cloud server with alarm information processing function for attack behavior, or a server or server group configured with alarm information processing function for attack behavior, such as a web firewall system deployed in the target system, such as a front-end. Figure 1 Server 200 in the middle. Figure 2 This is a schematic diagram of the composition of the alarm information processing device for attack behavior provided in an embodiment of the present invention. It can be understood that... Figure 2 This only shows an exemplary structure of the alarm information processing device for attack behavior, not the entire structure; it can be implemented as needed. Figure 2 The structure shown may be part or all of the structure.
[0091] The alarm information processing device for attack behavior provided in this embodiment of the invention includes: at least one processor 201, a memory 202, a user interface 203, and at least one network interface 204. The various components in the alarm information processing device for attack behavior are coupled together through a bus system 205. It can be understood that the bus system 205 is used to realize the connection and communication between these components. In addition to a data bus, the bus system 205 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in... Figure 2 The general labeled all buses as Bus System 205.
[0092] The user interface 203 may include a monitor, keyboard, mouse, trackball, click wheel, buttons, touchpad, or touch screen.
[0093] It is understood that memory 202 can be volatile memory or non-volatile memory, or both. In this embodiment of the invention, memory 202 is capable of storing data to support the operation of a terminal (such as 10-1). Examples of this data include any computer programs used to operate on the terminal (such as 10-1), such as operating systems and applications. The operating system includes various system programs, such as the framework layer, core library layer, driver layer, etc., used to implement various basic services and handle hardware-based tasks. Applications can include various applications.
[0094] In some embodiments, the alarm information processing device for attack behavior provided in this invention can be implemented using a combination of hardware and software. For example, the alarm information processing device for attack behavior provided in this invention can be a processor in the form of a hardware decoding processor, programmed to execute the alarm information processing method for attack behavior provided in this invention. For instance, the processor in the form of a hardware decoding processor can employ one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), or other electronic components.
[0095] As an example of the attack behavior alarm information processing device provided in this embodiment of the invention, which is implemented by combining software and hardware, the attack behavior alarm information processing device provided in this embodiment of the invention can be directly embodied as a combination of software modules executed by processor 201. The software modules can be located in a storage medium, which is located in memory 202. Processor 201 reads the executable instructions included in the software modules in memory 202 and combines them with necessary hardware (e.g., including processor 201 and other components connected to bus 205) to complete the attack behavior alarm information processing method provided in this embodiment of the invention.
[0096] As an example, processor 201 can be an integrated circuit chip with signal processing capabilities, such as a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc., wherein the general-purpose processor can be a microprocessor or any conventional processor, etc.
[0097] As an example of the hardware implementation of the alarm information processing device for attack behavior provided in the embodiments of the present invention, the device provided in the embodiments of the present invention can be directly executed by a processor 201 in the form of a hardware decoding processor. For example, it can be executed by one or more application specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), or other electronic components to implement the alarm information processing method for attack behavior provided in the embodiments of the present invention.
[0098] In this embodiment of the invention, the memory 202 is used to store various types of data to support the operation of the alarm information processing device for attack behavior. Examples of such data include: any executable instructions for operation on the alarm information processing device for attack behavior, such as executable instructions, and programs implementing the alarm information processing method for attack behavior according to this embodiment of the invention may be included in the executable instructions.
[0099] In other embodiments, the alarm information processing device for attack behavior provided in this invention can be implemented in software. Figure 2An alarm information processing device for attack behavior stored in memory 202 is shown. This device can be software in the form of programs and plug-ins, and includes a series of modules. As an example of a program stored in memory 202, it may include the alarm information processing device for attack behavior. The alarm information processing device for attack behavior includes the following software modules: an information transmission module 2081 and an information processing module 2082. When the software modules in the alarm information processing device for attack behavior are read into RAM and executed by processor 201, the alarm information processing method for attack behavior provided in this embodiment of the invention will be implemented. The functions of each software module in the alarm information processing device for attack behavior include:
[0100] The information transmission module 2081 is used to acquire the first attack behavior alarm information of the target system, and to perform deduplication and merging processing on the first attack behavior alarm information to obtain the second attack behavior alarm information.
[0101] The information processing module 2082 is used to filter the second attack behavior alarm information according to the security configuration of the target system to obtain the third attack behavior alarm information.
[0102] The information processing module 2082 is used to query the IP address information of the third attack behavior alarm information to obtain the IP address information.
[0103] The information processing module 2082 is used to mark the threat information of the third attack behavior alarm information based on the IP address information, and obtain the marking result of the threat information.
[0104] The information processing module 2082 is used to perform pattern matching processing on the third attack behavior alarm information using the tagging result of the threat information, and obtain the pattern matching result of the third attack behavior alarm information.
[0105] The information processing module 2082 is used to trigger the target system's defense strategy through the pattern matching result via an instant messaging client, and to process the attack behavior through the triggered defense strategy.
[0106] according to Figure 2 The electronic device shown, in one aspect of this application, also provides a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, executes the computer instructions, and causes the computer device to perform the method provided in various optional implementations of the alarm information processing method for the aforementioned attack behavior.
[0107] The alarm information processing method for attack behavior provided in this application embodiment can be based on artificial intelligence (AI). AI is the theory, method, technology, and application system that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to obtain optimal results. In other words, AI is a comprehensive technology within computer science that attempts to understand the essence of intelligence and produce a new type of intelligent machine that can react in a way similar to human intelligence. AI studies the design principles and implementation methods of various intelligent machines, enabling them to possess perception, reasoning, and decision-making capabilities.
[0108] Artificial intelligence (AI) is a comprehensive discipline encompassing a wide range of fields, including both hardware and software technologies. Fundamental AI technologies generally include sensors, dedicated AI chips, cloud computing, distributed storage, big data processing, operating / interactive systems, and mechatronics. AI software technologies primarily include computer vision, speech processing, natural language processing, and machine learning / deep learning.
[0109] In the embodiments of this application, the main artificial intelligence software technologies involved include the aforementioned speech processing technologies and machine learning. For example, it may involve automatic speech recognition (ASR) technology for alarm information processing of attack behaviors in speech technology, including speech signal preprocessing, speech signal frequency analyzing, speech signal feature extraction, speech signal feature matching / recognition, and speech training.
[0110] For example, this could involve machine learning (ML), a multidisciplinary field encompassing probability theory, statistics, approximation theory, convex analysis, and algorithm complexity theory. It specifically studies how computers can simulate or implement human learning behavior to acquire new knowledge or skills and reorganize existing knowledge structures to continuously improve their performance. Machine learning is the core of artificial intelligence and the fundamental way to endow computers with intelligence; its applications span all areas of artificial intelligence. Machine learning typically includes techniques such as deep learning, which includes artificial neural networks, such as convolutional neural networks (CNNs), recurrent neural networks (RNNs), and deep neural networks (DNNs).
[0111] Before introducing the alarm information processing method for attack behavior provided in this application, we will first introduce the alarm information processing methods in related technologies. In related technologies, the alarm information processing method for attack behavior only involves manually logging into the device to process the attack behavior. The drawback of this method is that it requires manual login to different devices of the target system for processing, which is a cumbersome operation. At the same time, the blocking policy also requires manual login to different devices of the target system to send, which makes it impossible to process the attack behavior in a timely manner and affects the security of the target system.
[0112] Combination Figure 2 The illustrated alarm information processing device for attack behavior describes the alarm information processing method for attack behavior provided in this embodiment of the invention. See also: Figure 3 , Figure 3 This is an optional flowchart illustrating the alarm information processing method for attack behavior provided in an embodiment of the present invention. It can be understood that... Figure 3 The steps shown can be performed by various electronic devices that run alarm information processing devices for attack behavior, such as dedicated cloud servers with alarm information processing capabilities for attack behavior, antivirus engine servers with alarm information processing capabilities for attack behavior, or server clusters of cloud-hosted software programs. The following addresses... Figure 3 The steps shown are explained.
[0113] Step 301: The alarm information processing device for attack behavior obtains the first attack behavior alarm information of the target system, and performs deduplication and merging processing on the first attack behavior alarm information to obtain the second attack behavior alarm information.
[0114] In some embodiments of the present invention, obtaining the first attack behavior alarm information of the target system, and performing deduplication and merging processing on the first attack behavior alarm information to obtain the second attack behavior alarm information, can be achieved in the following ways:
[0115] The first attack behavior alarm information of the target system is obtained through multi-threaded polling. The first attack behavior alarm information includes at least one of the following: honeypot alarm information, network layer attack alarm information, web attack alarm information, DDoS attack alarm information, brute-force attack alarm information, and remote login alarm information. The hash value corresponding to each attack behavior alarm information in the first attack behavior alarm information is calculated. An alarm message hash table is formed based on the hash value corresponding to each attack behavior alarm information. Based on the alarm message hash table, each alarm information obtained from the target system is deduplicated and merged to obtain the second attack behavior alarm information. Among these methods, the multi-threaded polling approach can simultaneously call all API interfaces of the target system, ensuring the timeliness of alarm information for attack behavior. For target systems using cloud-hosted security, the multi-threaded polling approach can make full use of CPU idle time slices, responding to alarm information for attack behavior in as little time as possible, thereby improving the operating efficiency of the target system. At the same time, since all threads of the same target system share the same memory space, there is no need to design special data transfer mechanisms or establish shared storage areas or shared files. Therefore, it is very convenient to coordinate and run different tasks, interact with data, and allocate resources, saving the resource consumption cost of the target system.
[0116] In some embodiments of the present invention, the first attack behavior alarm information can be obtained according to different usage environments of the target system. Specifically, it may include:
[0117] (1) Honeypot alarm information: In order to avoid network attacks on the target system during the use of the target system, a honeypot system can be deployed in the server or server group. Specifically, the corresponding firmware configuration information can be determined according to the usage environment of the target system. According to the firmware configuration information, a matching honeypot image can be obtained from the honeypot image cloud server. The honeypot image supports honeypot structures with different organizational structures. The cloud server stores different types of honeypot images. Furthermore, a container is created in the target system, and a honeypot system supporting different organizational structures is created through the container. It is possible to capture the attack traffic to the target system through the deployed honeypot system. The attack traffic refers to the attack behavior initiated by the attacker through the Internet. One attack behavior corresponds to one attack traffic. The specific fields of the honeypot alarm information are: time, attack target IP, attack target port, attack source IP address, attack source port, honeypot node, username, user password, protocol type and event additional information.
[0118] (2) Network layer attack alarm information: Network layer attack data comes from the enterprise's network intrusion prevention system or network intrusion detection system, and mainly detects network layer-based attack behaviors. Specific fields include: time, attack source IP, attack source port, attack destination IP, attack destination port, risk stage, number of attacks, transmitted data, protocol type, attack type and attack payload, etc.
[0119] (3) Web attack alarm information: Web attack data mainly comes from the WAF device in the target system. It mainly reflects the event information of the web system in the target system being attacked. The specific fields include time, attack source IP address, attack source port, attack destination IP address, attack destination port, attack domain name, protocol type, HTTP method, HTTP UA, attack address, attack message, attack type and attack payload.
[0120] (4) DDoS attack alarm information: DDoS data mainly comes from the anti-DDoS device in the target system. It describes denial-of-service attack events from external attackers. Specific data fields include: attack start time, attack end time, attack type, attack source IP distribution list, attack packet capture and the maximum peak value of attack traffic, etc.
[0121] (5) Brute-force attack event alarm information: The brute-force attack event data records the events in which the business server in the target system is attacked by attackers from the Internet to brute-force passwords. The specific fields include: time, target IP address, target port, source IP address, source port, protocol type, username, password and number of times it was attacked.
[0122] (6) Remote Login Event Alarm Information: Remote login event data records login behavior events on the enterprise business server. If the login source IP is an IP address that is not commonly used by the operator in the target system, it is very likely an illegal login behavior. The specific fields of the data are: time, target IP address, target port, source IP address, source port, protocol type, username, password, and login command.
[0123] In some embodiments of the present invention, the corresponding firmware configuration information can be determined according to the usage environment of the target system; based on the firmware configuration information, a matching target system image can be obtained from the cloud server of the cloud hosting service process, wherein the target system image supports target system structures of different organizational architectures; a container is created in the target system, and a target system supporting different organizational architectures is created through the container, so as to capture attack behaviors against the target system through the deployed target system. To avoid the server from being attacked by the network, the target system can be deployed in the server or server group. Specifically, the corresponding firmware configuration information can be determined according to the usage environment of the target system; based on the firmware configuration information, a matching target system image can be obtained from the target system image cloud server, wherein the target system image supports target system structures of different organizational architectures; and the cloud server stores different types of target system images. Further, a container is created in the target system, and a target system supporting different organizational architectures is created through the container, so as to capture attack events against the target system through the deployed target system, wherein an attack event refers to an attack behavior launched by an attacker through the Internet, and one attack behavior corresponds to one attack event.
[0124] In some embodiments of the present invention, in order to perform deduplication and merging processing on the alarm information of the first attack behavior, see [reference needed]. Figure 4 , Figure 4 This is an optional flowchart illustrating the alarm information processing method for attack behavior provided in an embodiment of the present invention. It can be understood that... Figure 4 The steps shown can be performed by various electronic devices that run alarm information processing devices for attack behavior, such as dedicated cloud servers with alarm information processing capabilities for attack behavior, antivirus engine servers with alarm information processing capabilities for attack behavior, or server clusters of cloud-hosted software programs. The following addresses... Figure 4 The steps shown are explained.
[0125] Step 401: Calculate the hash value corresponding to each attack behavior alarm message in the first attack behavior alarm message.
[0126] Step 402: Form an alarm message hash table based on the hash value corresponding to each attack behavior alarm message.
[0127] Step 403: Based on the alarm message hash table, perform deduplication and merging processing on each alarm message obtained by the target system to obtain the second attack behavior alarm message.
[0128] Specifically, attacks on a target system are not usually one-step attacks (they can be multi-step or a single, direct attack), but rather dispersed across many steps, with each step generating multiple alerts. Therefore, it's necessary to deduplicate alert information to prevent operators of the target system from receiving a large number of repetitive notifications simultaneously via instant messaging clients, potentially causing system crashes. This can be achieved by grouping events of the same attack type from the same source IP within a minute into a single record. A new alert message hash table can be created to store the hash values of different alert messages. Each time an alert message is read, it is hashed to obtain a hash value, which is then matched against the alert message hash table. If a match is found, it's a duplicate message and is discarded. If no match is found, the hash value is stored in the alert message hash table for matching other alert message hash values. The alert message is then retained for further processing. In this way, the hash values of non-duplicate messages are stored in the alert message hash table for comparison to ensure that received attack alert messages are not duplicates.
[0129] Step 404: According to the security configuration of the target system, the alarm message hash table is cleared based on the time interval threshold.
[0130] In some embodiments of the present invention, the cloud hosting information corresponding to the target system can be queried based on the identifier of the target system; the number of hosts matching the target system can be determined based on the cloud hosting information; and the alarm message hash table can be cleared based on the number of hosts. The cloud server can store cloud security service content for various cloud security hosting services. This cloud security service content records various cloud security service operations and the execution tools used to perform these operations. Cloud security service operations refer to various execution actions that implement cloud security hosting services; the execution tools can be specific devices or applications. Optionally, the cloud security service content can also record the execution order of various cloud security service operations. Furthermore, the cloud security service content for various cloud security hosting services can also be stored in a blockchain.
[0131] The cloud security service content of managed security services can be recorded in the form of scripts. In practice, event sources and event handling procedures are obtained from a data platform. Event sources can be historical security events collected from the cloud platform or other external security systems. Event handling procedures can be manually entered or obtained from external security systems. An orchestration engine is used to orchestrate the event sources and event handling procedures to obtain the corresponding managed cloud security services and their scripts.
[0132] Step 302: The alarm information processing device for attack behavior filters the second attack behavior alarm information according to the security configuration of the target system to obtain the third attack behavior alarm information.
[0133] In some embodiments of the present invention, the second attack behavior alarm information is filtered according to the security configuration of the target system to obtain the third attack behavior alarm information, which can be achieved in the following ways:
[0134] The system retrieves filtering events from the security configuration of the target system, wherein the filtering events include at least one of the following: attack source IP, attack target IP, attack source port, attack target port, attack type, and attack behavior details; based on the filtering events, it determines a regular expression corresponding to the filtering events; and uses the regular expression to filter the second attack behavior alarm information to obtain the third attack behavior alarm information. Since different target systems have different usage requirements, to ensure that diverse filtering needs are met, the alarm message filtering logic needs to guarantee the openness of the filtering conditions. Filtering events that can generate regular expressions include:
[0135] (1) Attack source IP address: Match the attack source IP address described in the alarm information of the attack behavior. The matching method supports two matching logics: equal to and contain. It also supports matching IP address mask.
[0136] (2) Attack target IP: Match the attack target IP of the attack event described in the alarm information of the attack behavior. The matching method supports two matching logics: equal to and contain. It also supports matching of IP address mask.
[0137] (3) Attack source port: Match the attack source port number of the attack event described in the alarm information of the attack behavior. The matching method supports two matching logics: equal to and contain.
[0138] (4) Attack target port: Match the attack target port number of the attack event described in the alarm information of the attack behavior. The matching method supports two matching logics: equal to and contain.
[0139] (5) Attack type: Matches the attack type of the alarm message, supporting matching logic for one or more types.
[0140] (6) Attack event details: Feature matching is performed on the details of alarm messages, and string regular expression matching logic is supported.
[0141] In some embodiments of the present invention, when multiple filtering events exist simultaneously, they can be matched in descending order according to their priority, or different filtering events can be combined to ensure the accuracy of the filtering process.
[0142] Step 303: The alarm information processing device for attack behavior queries the IP location information of the third attack behavior alarm information to obtain the IP location information.
[0143] In some embodiments of the present invention, the IP address attribution information of the third attack behavior alarm information can be queried through an offline query process to obtain the first IP address attribution information of the third attack behavior alarm information; when the offline query process does not find the IP address attribution information of the third attack behavior alarm information, an online query process is triggered; the IP address attribution information of the third attack behavior alarm information is queried through the online query process to obtain the second IP address attribution information of the third attack behavior alarm information; the first IP address attribution information and the second IP address attribution information are merged to obtain the IP address attribution information. Offline querying involves storing the address and its corresponding address information locally on the server as offline text. When a query is needed, the attribution information is obtained directly from the offline text. Online querying involves querying the IP address attribution information through a public interface on the Internet. Online querying can obtain the latest attribution information. The combination of online and offline querying can ensure the completeness and accuracy of the IP address attribution information. One optional method for obtaining the IP address attribution information is shown in Table 1.
[0144]
[0145] Table 1
[0146] Step 304: The alarm information processing device for attack behavior marks the threat information of the third attack behavior alarm information based on the IP home location information, and obtains the marking result of the threat information.
[0147] In some embodiments of the present invention, the threat information of the third attack behavior alarm information is marked in the following ways:
[0148] Based on the IP address location information, query the attack history information corresponding to the IP address location information; query the attack type and attack behavior description information corresponding to the IP address location information in the attack history information; mark the threat information of the third attack behavior alarm information using the attack type and attack behavior description information to obtain the threat information marking result. The threat information marking result of the third attack behavior alarm information is shown in Table 2:
[0149]
[0150] Table 2
[0151] Step 305: The alarm information processing device for attack behavior uses the tagging result of the threat information to perform pattern matching processing on the alarm information of the third attack behavior, and obtains the pattern matching result of the alarm information of the third attack behavior.
[0152] The pattern matching results of the third attack behavior alarm information include:
[0153] (1) High-frequency regions: After obtaining the region information of the attack source IP of each attack behavior alarm message, it is necessary to count the regions of all alarm messages and filter out the top ten regions that appear most frequently. If the region of the attack source IP in the new alarm message is among the top ten regions that appear most frequently, then this alarm message is marked as "high-frequency region".
[0154] (2) Dense network segments: The network segments of the IP address to which the attack source IP belongs in each alarm message need to be counted, and the top ten network segments that appear most frequently are filtered out. If the network segment to which the attack source IP belongs in a new alarm message is among the top ten most frequently appearing network segments, then this alarm message is marked as "dense network segment".
[0155] (3) Composite attack: The number of attack types associated with the attack source IP of each alarm message is counted. If the attack behavior associated with the attack source IP in the alarm message is greater than or equal to 2, the alarm message is marked as "composite attack".
[0156] Step 306: The alarm information processing device for attack behavior triggers the target system's defense strategy through the instant messaging client using the pattern matching result, and processes the attack behavior through the triggered defense strategy.
[0157] In some embodiments of the present invention, see Figure 6 , Figure 6 This is an optional flowchart illustrating the alarm information processing method for attack behavior provided in an embodiment of the present invention. It can be understood that... Figure 6The steps shown can be performed by various electronic devices that run alarm information processing devices for attack behavior, such as dedicated cloud servers with alarm information processing capabilities for attack behavior, antivirus engine servers with alarm information processing capabilities for attack behavior, or server clusters of cloud-hosted software programs. The following addresses... Figure 6 The steps shown are explained.
[0158] Step 601: Receive a blocking operation instruction through the instant messaging client, wherein the blocking operation instruction includes at least one of the following: network layer blocking, host layer blocking, and application layer blocking.
[0159] Since operators of the target system can monitor its operational status via the cloud server network after binding their instant messaging clients to the target system, the attack alert information is sufficiently comprehensive and rich after deduplication, message filtering, regional information tagging, threat intelligence tagging, and pattern matching tagging. Operators can then accurately assess the attack alert information. The cloud security managed process can format the alert information, add regional information tags, threat intelligence tags, and pattern matching tags to generate the final message text, and send it to the operators via the instant messaging client interface. Operators can then review the message through the instant messaging client to confirm whether to block the attack source IP address.
[0160] Step 602: Process the attack behavior based on the blocking operation command.
[0161] The processing results of the blocking operation instructions include: (1) Network layer blocking: Blocking the attack source IP using network access control devices, such as network intrusion prevention systems, network firewalls, and cloud firewalls. (2) Host layer blocking: Blocking the attack source IP at the host level, mainly using server security groups, system iptables, and system host intrusion prevention systems. (3) Application layer blocking: Blocking the attack source IP at the application layer, mainly using WAF (web application firewall).
[0162] Step 603: Receive monitoring information through the instant messaging client, and determine the traffic redirection location corresponding to the attack behavior based on the monitoring information.
[0163] Step 604: Based on the traffic redirection location corresponding to the attack behavior, redirect the attack behavior to achieve high-defense cleaning of the attack behavior through the resources of the traffic redirection location.
[0164] In some embodiments of this invention, taking the processing of network attack information in cloud gaming as an example, a new cloud game may be frequently attacked in its initial launch phase. Because during the initial launch phase of a new game, if it is continuously and frequently attacked, the retention rate of game users will be very low, causing significant economic losses to the game operator. Therefore, by configuring a large number of high-defense resources, for example, a new game can use BGP high-defense IPs or BGP high-defense packages to cover all public network services. When an attack occurs, the black hole state can be quickly lifted by increasing the number of protection resources, restoring business access. After the new game has been in operation for a period of time, the binding of high-defense resources can be removed to reduce the usage cost of high-defense resources, making the processing of network attack information more flexible. During the high-defense cleaning process, users can flexibly adjust the start time of high-defense cleaning according to the attack situation, quickly responding to different types of DDoS attacks, fully matching different users and different business types, so that the attack behavior alarm method provided in this application can be applied to more business scenarios.
[0165] Furthermore, when using a honeypot system, when different types of target systems acquire corresponding attack behaviors, the system captures records of the access services associated with those attack behaviors; based on these access service records, it acquires and parses the network data packets carried by the attack behaviors; and based on these network data packets, it determines and monitors the connection behavior of the target system after the attack behaviors have infiltrated it. For example, it records the source Internet Protocol address (IP address), the time and frequency of the attack behaviors, the type of attack behaviors, and the origin of the attack traffic. In addition, when a computer device captures a network attack behavior, it can respond to it by returning a reply message to the attacker, thereby preventing the victim from recognizing that they have infiltrated the honeypot environment through interaction with the attacker. Furthermore, the computer device can hide its own IP address to prevent the leakage of its real IP address and protect the secure operation of the target system.
[0166] In some embodiments of the present invention, the alarm information processing device for attack behavior can be encapsulated in a cloud-hosted software program. It performs suspicious risk assessment on newly created Web application files on the cloud server. For a small number of suspected Webshell files, they need to be reported to the cloud for further detection by the cloud's machine learning detection engine module. After detection, the sample file is deleted in real time. Tasks to be processed are continuously acquired through a full scan at fixed time intervals. The types of tasks to be processed are shown in Table 3.
[0167] Table 3
[0168]
[0169] Figure 7This is a schematic diagram of data storage provided in an embodiment of this application. For example... Figure 7 As shown, under normal operating conditions, database A is the primary database providing read and write services, and database B is the backup database for data backup. Database A, as the primary, can handle all data read and write operations, while database B, as the backup, can synchronize data from database A, backing up the data stored in database A to database B. When database A fails as the primary, it can no longer provide data read and write services, which are then taken over by database B. Simultaneously, data synchronization and backup between databases A and B are interrupted. When database A is repaired, the roles of databases A and B are reversed. Database B becomes the primary database providing read and write services, and database A becomes the backup database for data backup, enabling database A to synchronize data from database B.
[0170] In addition, during the operation of the server, behavior logs are generated, which record the actions that occur on the server. Therefore, these behavior logs also need to be stored.
[0171] Optionally, the server stores the behavior log in a log server, and also stores a copy of the behavior log locally on the server in text format. Figure 8 This is a schematic diagram of behavior log storage provided in an embodiment of this application. For example... Figure 8 As shown, after the server obtains the behavior log, it stores the behavior log on the log server and also stores a copy locally as a text file.
[0172] The aforementioned behavior logs can be categorized into different levels, such as ERROR, WARN, INFO, and DEBUG. Details of these log levels are shown in Table 5 below.
[0173] Table 5
[0174]
[0175] Optionally, the above behavior logs are used for daily troubleshooting and status recording of the system. The behavior logs are classified according to their content, as shown in Table 6 below, into configuration logs, monitoring logs, alarm logs, and operation log information.
[0176] Table 6
[0177]
[0178] The following example, using the prediction of target users who need to receive financial payments in a payment (or receipt) financial payment scenario, illustrates the alarm information processing method for attack behaviors provided in this application. See also... Figure 5 , Figure 5A front-end display diagram of the alarm information processing method for attack behavior provided in this application, wherein the terminal (e.g. Figure 1 Servers 10-1 and 10-2 are equipped with clients for financial payment software, such as clients or plugins for financial activities using virtual or physical resources, or for financial payments through virtual resource games. Users can receive payments from financial institutions or platforms through these clients (e.g., receiving financial payment red envelopes of varying amounts via payment mini-programs in instant messaging clients). Terminals connect to server 200 via network 300, which can be a wide area network (WAN), a local area network (LAN), or a combination of both, using a wireless link for data transmission. The server (e.g., Figure 1 This refers to servers belonging to companies providing payment, game payment, and wealth management services, such as banks, securities firms, internet finance companies, and P2P platforms. When distributing red envelopes (digital cash gifts), the attack behavior alert processing method provided in this application can promptly identify users exhibiting abnormal behavior, thereby blocking cheating users. Therefore, utilizing a cloud-hosted system assists financial platforms or payment providers in determining whether to provide payment services to users, ensuring the secure operation of the financial platform.
[0179] refer to Figure 9 , Figure 9 The diagram illustrates the process of using the alarm information processing method for attack behaviors provided in this application, which includes the following steps:
[0180] Step 901: Unified collection of alarm information on intrusion behavior of financial server systems.
[0181] Step 902: Deduplicate and merge alarm messages based on the principle of merging events of the same attack source IP with the same attack type into one record per minute.
[0182] Step 903: Determine if the message is a duplicate. If so, proceed to step 904; otherwise, ignore.
[0183] Step 904: Filter messages according to the filtering policy issued by the system control.
[0184] Step 905: Determine if the filtering strategy matches. If it does, proceed to step 906; otherwise, ignore this step.
[0185] Step 906: Query the geographical region of attack source I for the alarm event, using a combination of offline and online queries to ensure accuracy.
[0186] Step 907: Mark the attack source IP with threat intelligence;
[0187] Step 908: Perform pattern matching and tagging on alarm messages.
[0188] Step 909: Does it match the high-frequency regional pattern? If not, proceed to step 904; otherwise, record it as a high-frequency regional pattern.
[0189] Step 910: Does it match the dense network segment pattern? If not, proceed to step 904; otherwise, record it as a dense network segment pattern.
[0190] Step 911: Does it match the composite attack pattern? If not, proceed to step 912; otherwise, record it as a composite attack pattern.
[0191] Step 912: Do not perform pattern matching marking
[0192] Step 913: The instant messaging client displays messages and approves account bans.
[0193] Step 914: Should the attack source IP be blocked? If yes, proceed to step 915; otherwise, ignore this step.
[0194] Step 915: Call the API interface to send in blocking mode
[0195] Step 916: Manage and control the financial server system, view alarm information and send messages under filtering modes.
[0196] Step 917: Store all process data and record a detailed log of the entire process.
[0197] The specific handling methods after identifying pending tasks on the financial platform as attack behavior include: disabling payment or receiving functions for high-risk users, and issuing payment red envelopes to medium- and low-risk users, thereby preventing high-risk users from receiving the payment red envelopes.
[0198] The present invention has the following beneficial technical effects:
[0199] This invention, in its embodiments, acquires a first attack behavior alarm message from a target system, performs deduplication and merging processing on the first attack behavior alarm message to obtain a second attack behavior alarm message; filters the second attack behavior alarm message according to the target system's security configuration to obtain a third attack behavior alarm message; queries the IP address location information of the third attack behavior alarm message to obtain the IP address location information; based on the IP address location information, marks the threat information of the third attack behavior alarm message to obtain the threat information marking result; and uses the threat information marking result to perform pattern matching processing on the third attack behavior alarm message to obtain the pattern matching result of the third attack behavior alarm message. Therefore, it is possible to trigger the target system's defense mode through an instant messaging client using the pattern matching result, and to promptly handle attack behaviors through the triggered defense mode. This not only improves the efficiency of attack behavior alarm message processing, providing a better user experience for cloud-hosted systems, but also enhances the accuracy of attack behavior processing, ensuring the secure operation of the target system.
[0200] The above description is merely an embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A method for processing alarm information of attack behavior, characterized in that, The method includes: Obtain the first attack behavior alarm information of the target system, and form an alarm message hash table based on the hash value corresponding to each first attack behavior alarm information; Based on the alarm message hash table, the first attack behavior alarm information is deduplicated and merged to obtain the second attack behavior alarm information; Based on the cloud hosting information of the target system, determine the number of hosts that match the target system, and clear the alarm message hash table according to the number of hosts. The second attack behavior alarm information is filtered by the regular expression corresponding to the filtering event in the security configuration of the target system to obtain the third attack behavior alarm information. By combining online and offline queries, the first IP address location information and the second IP address location information of the third attack behavior alarm information are obtained. When the offline query process fails to find the IP address location information of the third attack behavior alarm information, the online query process is triggered. The first IP address location information and the second IP address location information are merged to obtain the IP address location information; Based on the IP address location information, the threat information of the third attack behavior alarm information is marked to obtain the threat information marking result; Using the tagging results of the threat information, pattern matching processing is performed on the third attack behavior alarm information to obtain the pattern matching result; The attack behavior is processed by the target system's defense strategy triggered by the pattern matching result through an instant messaging client.
2. The method according to claim 1, characterized in that, The acquisition of first attack behavior alarm information of the target system, based on the hash value corresponding to each first attack behavior alarm information, forms an alarm message hash table, including: The first attack behavior alarm information of the target system is obtained by a multi-threaded polling method, wherein the first attack behavior alarm information includes at least one of the following: Honeypot alerts, network layer attack alerts, web attack alerts, DDoS attack alerts, brute-force attack alerts, and remote login alerts; Calculate the hash value corresponding to each attack behavior alarm message in the first attack behavior alarm message; An alarm message hash table is formed based on the hash value corresponding to each attack behavior alarm message.
3. The method according to claim 2, characterized in that, The method further includes: According to the security configuration of the target system, the alarm message hash table is cleared when the time interval threshold is reached.
4. The method according to claim 1, characterized in that, The second attack behavior alarm information is filtered using a regular expression corresponding to the filtering event in the security configuration of the target system to obtain the third attack behavior alarm information, including: Obtain filtering events from the security configuration of the target system, wherein the filtering events include at least one of the following: Attack source IP, attack target IP, attack source port, attack target port, attack type, and attack behavior details; Based on the filtering event, determine the regular expression corresponding to the filtering event; The second attack behavior alarm information is filtered using the regular expression to obtain the third attack behavior alarm information.
5. The method according to claim 1, characterized in that, The method of obtaining the first IP address location information and the second IP address location information of the third attack behavior alarm information through a combination of online and offline queries includes: By querying the IP address information of the third attack behavior alarm information through an offline query process, the first IP address information of the third attack behavior alarm information is obtained. When the offline query process fails to find the IP address of the third attack behavior alarm information, the online query process is triggered. The online query process is used to query the IP address information of the third attack behavior alarm information to obtain the second IP address information of the third attack behavior alarm information. The first IP location information and the second IP location information are merged to obtain the IP location information.
6. The method according to claim 1, characterized in that, The step of marking the threat information of the third attack behavior alarm information based on the IP address location information to obtain the threat information marking result includes: Based on the IP address location information, query the attack history information corresponding to the IP address location information; Query the attack history information for the attack type and attack behavior description corresponding to the IP address location information; The threat information of the third attack behavior alarm information is marked by the attack type and attack behavior description information to obtain the threat information marking result.
7. The method according to claim 1, characterized in that, The step of triggering the target system's defense strategy using the pattern matching result via an instant messaging client, and processing the attack behavior according to the triggered defense strategy, includes: The instant messaging client receives a blocking operation command, wherein the blocking operation command includes at least one of the following: Network layer blocking, host layer blocking, and application layer blocking; Based on the blocking operation command, the attack behavior is processed; or The monitoring information is received through the instant messaging client, and the traffic redirection location corresponding to the attack behavior is determined based on the monitoring information. Based on the referral location corresponding to the attack behavior, the attack behavior is redirected to achieve high-defense cleaning of the attack behavior through the resources of the referral location.
8. The method according to claim 1, characterized in that, The method further includes: When different types of target systems acquire corresponding attack behaviors, the access records of the attack behaviors are captured based on the attack behaviors. Based on the access service records of the attack behavior, obtain and parse the network data packets carried by the attack behavior; Based on the network data packets, the connection behavior of the target system after the attack behavior intrudes into the target system is determined and monitored.
9. The method according to claim 1, characterized in that, The method further includes: Based on the usage environment of the target system, determine the corresponding firmware configuration information; Based on the firmware configuration information, a matching target system image is obtained from the cloud server of the cloud hosting service process. The target system image supports target system structures with different organizational structures. A container is created in the target system, and a target system supporting different organizational architectures is created through the container, so as to capture attack behaviors against the target system through the deployed target system.
10. An alarm information processing device for attack behavior, characterized in that, The device includes: The information transmission module is used to acquire the first attack behavior alarm information of the target system, form an alarm message hash table based on the hash value corresponding to each first attack behavior alarm information, and perform deduplication and merging processing on the first attack behavior alarm information based on the alarm message hash table to obtain the second attack behavior alarm information. The information processing module is used to determine the number of hosts matching the target system based on the cloud hosting information of the target system, clear the alarm message hash table according to the number of hosts, and filter the second attack behavior alarm information through the regular expression corresponding to the filtering event in the security configuration of the target system to obtain the third attack behavior alarm information. The information processing module is used to query the first IP address location information and the second IP address location information of the third attack behavior alarm information through a combination of online and offline queries. When the offline query process fails to find the IP address location information of the third attack behavior alarm information, the online query process is triggered to merge the first IP address location information and the second IP address location information to obtain the IP address location information. The information processing module is used to mark the threat information of the third attack behavior alarm information based on the IP address location information, and obtain the threat information marking result; The information processing module is used to perform pattern matching processing on the third attack behavior alarm information using the tagging result of the threat information, and obtain the pattern matching result of the third attack behavior alarm information. The information processing module is used to trigger the target system's defense strategy through the pattern matching result via an instant messaging client, and to process the attack behavior through the triggered defense strategy.
11. The apparatus as claimed in claim 10, characterized in that, The information processing module is also used for: The first attack behavior alarm information of the target system is obtained through multi-threaded polling. The first attack behavior alarm information includes at least one of the following: honeypot alarm information, network layer attack alarm information, WEB attack alarm information, DDoS attack alarm information, brute-force attack event alarm information, and remote login event alarm information. The hash value corresponding to each attack behavior alarm information in the first attack behavior alarm information is calculated. An alarm message hash table is formed based on the hash value corresponding to each attack behavior alarm information.
12. The apparatus as claimed in claim 11, characterized in that, The information processing module is also used for: According to the security configuration of the target system, the alarm message hash table is cleared when the time interval threshold is reached.
13. The apparatus as claimed in claim 10, characterized in that, The information processing module is also used for: Obtain filtering events from the security configuration of the target system, wherein the filtering events include at least one of the following: attack source IP, attack target IP, attack source port, attack target port, attack type, and attack behavior details; determine a regular expression corresponding to the filtering events based on the filtering events; filter the second attack behavior alarm information using the regular expression to obtain the third attack behavior alarm information.
14. The apparatus as claimed in claim 10, characterized in that, The information processing module is also used for: By querying the IP address information of the third attack behavior alarm information through an offline query process, the first IP address information of the third attack behavior alarm information is obtained. When the offline query process fails to find the IP address of the third attack behavior alarm information, the online query process is triggered. The online query process queries the IP address information of the third attack behavior alarm information to obtain the second IP address information of the third attack behavior alarm information; the first IP address information and the second IP address information are then merged to obtain the IP address information.
15. The apparatus as claimed in claim 10, characterized in that, The information processing module is also used for: Based on the IP address location information, query the attack history information corresponding to the IP address location information; query the attack type and attack behavior description information corresponding to the IP address location information in the attack history information; mark the threat information of the third attack behavior alarm information through the attack type and attack behavior description information to obtain the threat information marking result.
16. The apparatus as claimed in claim 10, characterized in that, The information processing module is also used for: The instant messaging client receives blocking operation instructions, wherein the blocking operation instructions include at least one of the following: network layer blocking, host layer blocking, and application layer blocking; the attack behavior is processed based on the blocking operation instructions; or the instant messaging client receives monitoring information, and the corresponding traffic redirection location is determined based on the monitoring information; the attack behavior is redirected according to the traffic redirection location, so as to achieve high-defense cleaning of the attack behavior through the resources of the traffic redirection location.
17. The apparatus as claimed in claim 10, characterized in that, The information processing module is also used for: When different types of target systems acquire corresponding attack behaviors, the system captures records of the access services of the attack behaviors; based on the records of the access services of the attack behaviors, it acquires and parses the network data packets carried by the attack behaviors. Based on the network data packets, the connection behavior of the target system after the attack behavior intrudes into the target system is determined and monitored.
18. A computer program product comprising a computer program or instructions, characterized in that, When the computer program or instructions are executed by the processor, they implement the alarm information processing method for attack behavior as described in any one of claims 1 to 9.
19. An electronic device, characterized in that, The electronic device includes: Memory, used to store executable instructions; A processor, when executing executable instructions stored in the memory, implements the alarm information processing method for attack behavior as described in any one of claims 1 to 9.
20. A computer-readable storage medium storing executable instructions, characterized in that, When the executable instructions are executed by the processor, they implement the alarm information processing method for the attack behavior described in any one of claims 1 to 9.
Citation Information
Patent Citations
Network attack source positioning and protecting method, electronic equipment and computer storage medium
CN110445770A