Cloud-based collaborative terminal monitoring data intelligent tracking and collecting method and model

By using a cloud-based collaborative intelligent tracking and collection method for terminal monitoring data, combined with process tracking analysis and data fusion, and dynamically adjusting the collection strategy, the problem of network bandwidth overhead and high-value data omission caused by massive terminal data collection is solved, thus achieving efficient terminal data monitoring.

CN116796151BActive Publication Date: 2025-12-30NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310751510.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-25
Publication Date
2025-12-30
Estimated Expiration
2043-06-25

AI Technical Summary

Technical Problem

In existing technologies, the data collection methods for massive computer terminals indiscriminately collect various types of monitoring data from the terminals, resulting in huge network bandwidth consumption, affecting the availability of the network information system, and making it difficult to discover high-value terminal data resources.

Method used

A cloud-based collaborative intelligent tracking and collection method for terminal monitoring data is adopted. The terminal threat intelligent analysis system performs intelligent fusion analysis on terminal data to discover suspicious applications, adjust data collection strategies, implement fine-grained monitoring, and perform dynamic data mining by combining process tracking analysis.

Benefits of technology

It effectively solves the network bandwidth overhead problem caused by the collection of massive terminal data, enables accurate tracking of high-value data, prevents the collection of low-value data resources, and avoids the omission and loss of high-value data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116796151B_ABST
    Figure CN116796151B_ABST
Patent Text Reader

Abstract

The application discloses a kind of based on cloud cooperation's terminal monitoring data intelligent tracking acquisition method and model, including the terminal threat intelligent analysis system, terminal security monitoring system background and a plurality of computer terminals connected in turn, the computer terminal deployment terminal security monitoring system software, the terminal security monitoring system background is provided with security monitoring terminal information base, the terminal threat intelligent analysis system reads and utilizes all information of security monitoring terminal information base to carry out data fusion analysis.Based on the intelligent improvement of the system framework and data resources of terminal security monitoring system, the way of combining "cloud mass data analysis + terminal acquisition mode adjustment" solves the difficulty problem of huge network bandwidth overhead caused by mass terminal data acquisition.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data monitoring technology, specifically to a cloud-based collaborative intelligent tracking and collection method and model for terminal monitoring data. Background Technology

[0002] With the rapid development of network information systems towards "digitalization and intelligence," terminal data resources have gradually become core assets in the construction of network information systems, especially high-value, fine-grained terminal data resources. However, current conventional data collection methods for massive computer terminals indiscriminately collect and transmit various types of terminal monitoring data, resulting in huge overhead on communication network bandwidth and even seriously affecting the availability of network information systems. How to discover high-value terminal data resources and resolve the contradiction between high-value terminal data collection and huge network bandwidth overhead is a key and difficult problem in the development of network information systems. Summary of the Invention

[0003] To address the aforementioned shortcomings in existing technologies, this invention provides a cloud-based collaborative intelligent tracking and acquisition method and model for terminal monitoring data, which solves the problem of efficient terminal data monitoring adaptable to a massive number of computer terminals.

[0004] To achieve the above-mentioned objectives, the technical solution adopted by this invention is: a terminal monitoring data tracking and collection method based on cloud collaboration, comprising the following steps:

[0005] Step 1: Computer terminals x1, x2, x3...x n The white application list List_WProc(M) = (WProc_1, WProc_2, ..., WProc_k) is obtained from the terminal monitoring data, where WProc_k represents the total number of the kth white application that is allowed to be enabled, and the white application list is stored locally.

[0006] Step 2: Computer terminals x1, x2, x3...x n Regularly conduct local security inspections of terminals and generate a snapshot list of terminal applications for the nth period, where terminal x at time n is... i The list of application snapshots is List_RProc(x i RProc_1, RProc_2, ..., RProc_I) = (RProc_1, RProc_2, ..., RProc_I), where RProc_I represents the I-th application currently running on the terminal in the nth cycle. This is compared with the list of white applications to generate the terminal x at time n. i The list of unknown applications is List_Unknown_RProc(x i(n) = (UProc_1, UProc_2, ..., UProc_m), where UProc_m represents the m-th unknown application discovered in the n-th period, and the unknown application b on terminal x2 at time n is obtained. 21 b 22 Unknown application b on terminal x3 31 c 31 ;

[0007] Step 3: In the nth cycle, computer terminals x1, x2, x3...x n Data was collected from computer terminals x1, x2, x3...x using an intelligent data mining and acquisition method based on process tracing analysis. n Basic terminal data, and simultaneously collect data from unknown application b on terminals x2 and x3. 21 b 22 b 31 c 31 The characteristic data is then reported to the backend of the terminal security monitoring system.

[0008] Step 4: The endpoint threat intelligent analysis system retrieves reported data from the security monitoring endpoint information database in the endpoint security monitoring system's backend, including endpoints x1, x2, x3...x n Terminal basic data and unknown application b 21 b 22 b 31 c 31 Feature data;

[0009] Step 5: The intelligent endpoint threat analysis system integrates endpoints x1, x2, x3...x n The reported data is intelligently fused and analyzed from massive amounts of terminal data to discover unknown applications. 31 The application was flagged as suspicious, and then a suspicious application c was sent to the endpoint security monitoring system backend. 31 Related data information;

[0010] Step 6: The endpoint security monitoring system's backend, based on the suspicious applications provided by the endpoint threat intelligent analysis system, ... 31 Based on the associated data information, adjust the data collection strategy of terminal x3, and add targeting for suspicious applications c 31 The fine-grained monitoring and data collection strategy is then distributed to the terminal x3.

[0011] Step 7: In the (n+1)th cycle, computer terminals x1, x2, x3...x n Data was collected from computer terminals x1, x2, x3...x using an intelligent data mining and acquisition method based on process tracing analysis. nBasic terminal data, and simultaneously collect data from unknown application b on terminals x2 and x3. 21 b 22 b 31 c 31 The characteristic data, and collect suspicious application c 31 The fine-grained monitoring data is then reported to the backend of the endpoint security monitoring system.

[0012] A cloud-based collaborative terminal monitoring data tracking and acquisition model includes a terminal threat intelligent analysis system, a terminal security monitoring system backend, and several computer terminals connected in sequence. The computer terminals are equipped with terminal security monitoring system software. The terminal security monitoring system backend has a security monitoring terminal information database. The terminal threat intelligent analysis system reads and utilizes all information from the security monitoring terminal information database to perform data fusion analysis.

[0013] The beneficial effects of this invention are as follows:

[0014] 1. This invention proposes a cloud-based collaborative intelligent tracking and collection method and model for terminal monitoring data. It intelligently enhances the system framework and data resources of the terminal security monitoring system and effectively solves the problem of huge network bandwidth overhead caused by the collection of massive terminal data by combining cloud-based massive data analysis with terminal collection mode adjustment.

[0015] 2. This invention proposes an intelligent dynamic mining method for terminal monitoring data based on process tracing analysis. It adopts a combination of "intelligent conversion of two lists" and "intelligent adjustment of three modes" to realize dynamic data tracing and mining of suspicious applications based on clues. This method effectively shields the collection of low-value terminal data resources and solves the problem of tracing and restoring historical process data, preventing the omission and loss of high-value terminal data. Attached Figure Description

[0016] Figure 1 A flowchart of a cloud-based collaborative terminal monitoring data intelligent tracking and collection method;

[0017] Figure 2 This is a schematic diagram of the intelligent data mining and collection mechanism for terminal monitoring based on process tracing analysis.

[0018] Figure 3 This is a flowchart of the intelligent data mining and collection process for terminal monitoring based on process tracing analysis. Detailed Implementation

[0019] The specific embodiments of the present invention are described below to enable those skilled in the art to understand the present invention. However, it should be understood that the present invention is not limited to the scope of the specific embodiments. For those skilled in the art, various changes are obvious as long as they are within the spirit and scope of the present invention as defined and determined by the appended claims. All inventions utilizing the concept of the present invention are protected.

[0020] The core idea of ​​the cloud-based collaborative intelligent tracking and collection model for terminal monitoring data proposed in this invention is to intelligently collaborate with the network traffic analysis system and the terminal security monitoring system. By leveraging data fusion and analysis capabilities, the system continuously iterates and inspects the local area network. Once unknown terminal information outside the terminal security monitoring system is detected, the terminal asset detection function integrated into the terminal security monitoring system is used to designate any security monitoring terminal to perform neighbor detection. The system then uses real-time online verification to confirm that the terminal is a hidden terminal in the local area network.

[0021] Assume that the monitored computer terminals on a local area network are (x1, x2, x3, ..., x4). n For a specific application scenario and operating system (assuming it's a domestically produced operating system terminal for office applications, denoted by M), computer terminals x1, x2, x3...x n All endpoint security monitoring system software has been installed and deployed, and the endpoint security monitoring system backend has been deployed in the cloud, forming a security monitoring endpoint information database. Based on this, an endpoint threat intelligent analysis system has been deployed in the cloud. This system can read and utilize all information in the security monitoring endpoint information database for data fusion analysis; simultaneously, it can analyze computer endpoints x1, x2, x3…x n The deployed endpoint security monitoring system software has been upgraded and modified to provide dynamic data mining and collection functions for endpoint monitoring with multi-mode switching.

[0022] A cloud-based collaborative method for tracking and collecting terminal monitoring data, such as... Figure 1 As shown, it includes the following steps:

[0023] Step 1: Computer terminals x1, x2, x3...x n The white application list List_WProc(M) = (WProc_1, WProc_2, ..., WProc_k) is obtained from the terminal monitoring data, where WProc_k represents the total number of the kth white application that is allowed to be enabled, and the white application list is stored locally.

[0024] Step 2: Computer terminals x1, x2, x3...x nRegularly conduct local security inspections of terminals and generate a snapshot list of terminal applications for the nth period, where terminal x at time n is... i The list of application snapshots is List_RProc(x i RProc_1, RProc_2, ..., RProc_I) = (RProc_1, RProc_2, ..., RProc_I), where RProc_I represents the I-th application currently running on the terminal in the nth cycle. This is compared with the list of white applications to generate the terminal x at time n. i The list of unknown applications is List_Unknown_RProc(x i (n) = (UProc_1, UProc_2, ..., UProc_m), where UProc_m represents the m-th unknown application discovered in the n-th period, and the unknown application b on terminal x2 at time n is obtained. 21 b 22 Unknown application b on terminal x3 31 c 31 ;

[0025] Step 3: In the nth cycle, computer terminals x1, x2, x3...x n Data was collected from computer terminals x1, x2, x3...x using an intelligent data mining and acquisition method based on process tracing analysis. n Basic terminal data, and simultaneously collect data from unknown application b on terminals x2 and x3. 21 b 22 b 31 c 31 The characteristic data is then reported to the backend of the terminal security monitoring system.

[0026] Step 4: The endpoint threat intelligent analysis system retrieves reported data from the security monitoring endpoint information database in the endpoint security monitoring system's backend, including endpoints x1, x2, x3...x n Terminal basic data and unknown application b 21 b 22 b 31 c 31 Feature data;

[0027] Step 5: The intelligent endpoint threat analysis system integrates endpoints x1, x2, x3...x n The reported data is intelligently fused and analyzed from massive amounts of terminal data to discover unknown applications. 31 The application was flagged as suspicious, and then a suspicious application c was sent to the endpoint security monitoring system backend. 31 Related data information;

[0028] Step 6: The endpoint security monitoring system's backend, based on the suspicious applications provided by the endpoint threat intelligent analysis system, ... 31 Based on the associated data information, adjust the data collection strategy of terminal x3, and add targeting for suspicious applications c 31 The fine-grained monitoring and data collection strategy is then distributed to the terminal x3.

[0029] Step 7: In the (n+1)th cycle, computer terminals x1, x2, x3...x n Data was collected from computer terminals x1, x2, x3...x using an intelligent data mining and acquisition method based on process tracing analysis. n Basic terminal data, and simultaneously collect data from unknown application b on terminals x2 and x3. 21 b 22 b 31 c 31 The characteristic data, and collect suspicious application c 31 The fine-grained monitoring data is then reported to the backend of the endpoint security monitoring system.

[0030] like Figure 2 As shown, this invention can be applied to monitored network areas where endpoint security monitoring system software and the endpoint security monitoring system backend have been deployed. It adds an endpoint threat intelligent analysis system, which can read the security monitoring endpoint information database in the endpoint security monitoring system backend and send it suspicious application-related data information. The endpoint security monitoring system software integrates an endpoint data intelligent mining and collection component and an endpoint threat local intelligent patrol component, and adds an unknown application list and a suspicious application list. These two lists can be dynamically adjusted and mutually converted based on the suspicious application-related data issued by the endpoint threat intelligent analysis system and the unknown application data provided by the endpoint threat local patrol component. This drives the dynamic adjustment and switching of the three data collection mechanisms in the endpoint data intelligent mining and collection component: endpoint basic data, unknown application feature data, and suspicious application tracking data.

[0031] like Figure 3 As shown, in the nth cycle, the specific process of the intelligent mining and collection method for terminal monitoring data based on process tracing analysis is as follows:

[0032] Step 31: For terminal x i Perform periodic collection of basic terminal data to generate terminal x i The terminal basic dataset S_Ter_Basic(x) i ,n)=(Ter_IP(x i ), S_Ter_Port(x i ,n),S_Ter_SysOper(x i,n),S_Ter_RisEvent(x i ,n),S_Ter_DamEvent(x i ,n)), where, Ter_IP(x i ) represents terminal x i IP address, S_Ter_Port(x i (n) represents the nth period terminal x i Open port information, S_Ter_SysOper(x i (n) represents the terminal x in the nth period. i Important system operation behavior that occurred, S_Ter_RisEvent(x i (n) represents the nth period terminal x i The discovered security risk event, S_Ter_DamEvent(x i (n) represents the nth period terminal x i Discovered cyber threat incidents;

[0033] Step 32: Read the terminal x in the (n-1)th cycle i A list of suspicious local applications, List_Local_RisProc(x i , n-1)={lrp1, lrp2, .....lrp u}, lrp u Represents the terminal x in the (n-1)th cycle. i The uth suspicious application existing locally reads the terminal x data issued by the cloud-based intelligent terminal threat analysis system in the nth cycle. i List of suspicious applications List_Cloud_RisProc(x i , n)={crp1, crp2, .....crp v}, crp v This represents the endpoint x discovered by the cloud-based endpoint threat intelligent analysis system in the nth cycle. i For the vth suspicious application, calculate the nth period terminal x. i List_Local_RisProc(x) of local suspicious applications i ,n)=List_Local_RisProc(x i ,n-1)∩List_Cloud_RisProc(x i ,n), that is, List_Local_RisProc(x i , n)={lrp1, lrp2, .....crp w}, crp w Indicates the nth period terminal xi The wth suspicious application existing locally;

[0034] Step 33: If terminal x i List_Local_RisProc(x) of local suspicious applications i If n) is empty, it means that the terminal x in the nth cycle is empty. i If no suspicious application is found, proceed to step 37; otherwise, calculate the terminal x for the nth cycle. i List of newly added suspicious applications List_Local_Add_RisProc(x i ,n)=List_Local_RisProc(x i ,n)-List_Local_RisProc(x i , n-1); if List_Local_Add_RisProc(x i If `List_Local_Add_RisProc(x)` is empty, it means that no new suspicious application was added in the (n-1)th cycle, and proceed to step 34; otherwise, for `List_Local_Add_RisProc(x)`... i If the suspicious application in (n) enables fine-grained data collection and local data caching, proceed to step 34;

[0035] Step 34: For each suspicious application running LRP j Terminal x i Generate a suspicious application tracing dataset S_RisProc_Trace(x) i lrp j ,n)=(Ter_IP(x i ), Proc_ID(lrp j ), S_Proc_Dll(lrp j ,n),S_Proc_Port(lrp j ,n),S_RisProc_Sys_Trace(lrp j ,n),S_RisProc_Net_Trace(lrp j ,n)), where, Ter_IP(x i ) represents terminal x i IP address, Proc_ID(lrp j ) indicates a suspicious application lrp j The name, S_Proc_Dll(lrp j (n) represents the nth cycle and the suspicious application lrp j Related dynamic link library information, S_Proc_Port(lrpj (n) represents the suspicious application lrp in the nth cycle. j Relevant open port information, S_RisProc_Sys_Trace(lrp j (n) represents the nth cycle and the suspicious application lrp j Related operating system behavior data, S_RisProc_Net_Trace(lrp j (n) represents the nth period and the suspicious application lrp j Related communication network behavior data; generate a suspicious application tracing data matrix M_RisProc_Trace(x i ,n)=(S_RisProc_Trace(x i ,lrp1,n),S_RisProc_Trace(x i , lrp2, n), .....S_RisProc_Trace(x i lrp w ,n)),lrp w Indicates the nth period terminal x i The wth suspicious application existing locally;

[0036] Step 35: Read terminal x in the (n-1)th cycle i List_Local_UnkProc(x) is a list of unknown local applications. i , n-1)={lup1, lup2, .....lup r}, lup r Represents the terminal x in the (n-1)th cycle. i The r-th unknown application existing locally calculates the n-th period terminal x. i Transform a list of suspicious applications (List_Trans_UnkProc(x)) i ,n)=List_Local_UnkProc(x i ,n-1)∩List_Local_RisProc(x i ,n), that is, List_Trans_UnkProc(x i , n)={lrp1, lrp2, .....crp s}, crp s Indicates the nth period terminal x i The s-th suspicious application that was transformed from an unknown application;

[0037] Step 36: If terminal x iTransform a list of suspicious applications (List_Trans_UnkProc(x)) i If n) is empty, it means that the terminal x in the nth cycle is empty. i If no unknown application is converted into a suspicious application, proceed to step 37; otherwise, read the generated application conversion trace data matrix set {M_Trans_RisProc_Trace(x i ,lrp1,n),M_Trans_RisProc_Trace(x i , lrp2, n), .....M_Trans_RisProc_Trace(x i lrp s ,n)},lrp s Indicates the nth period terminal x i The s-th suspicious application transformed from an unknown application, M_Trans_RisProc_Trace(x i lrp j ,n)={S_RisProc_Trace(x i lrp j ,n-1),S_RisProc_Trace(x i lrp j ,n-2).....S_RisProc_Trace(x i lrp j , np)}, where p represents the number of cycles from the discovery of an unknown application to its transformation into a suspicious application, with an upper limit of 10;

[0038] Step 37: Read the data for terminal x i The list of white applications is List_WProc(M) = (wp1, wp2, ..., wp... k ), wp k This indicates that the kth white application is allowed to be enabled, and the nth period terminal x is obtained. i The list of application snapshots is List_Local_RProc(x i (lp1, lp2, ..., lpn) = (lp1, lp2, ..., lpn) I )lp I This represents the i-th running application. The application snapshot list is compared and analyzed with the white application list to generate the terminal x for the n-th cycle. i List_Local_UnkRProc(x) i ,n)=(List_Local_RProc(x i,n)-List_WPrc(M))∪List_Local_UnkRProc(x i (n-1); calculate List_Unknown_RProc(x i , n) = (lup1, lup2, .....lup m ), lup m This represents the m-th unknown application discovered in the n-th cycle;

[0039] Step 38: If terminal x i List_Local_UnkRProc(x) i If (x, n) is empty, then the execution step of the nth cycle ends; otherwise, the list of newly added unknown applications, List_Local_Add_UnkRProc(x), is calculated. i ,n)=List_Local_UnkRProc(x i ,n)-List_Local_UnkRProc(x i (n-1); calculate List_Local_Add_UnkRProc(x i , n) = (lup1, lup2, .....lup h ), lup h This represents the h-th unknown application discovered in the nth cycle. If a new unknown application is added to the list, List_Local_Add_UnkRProc(x) i If n is not empty, then for (lup1, lup2, ..., lup... h Enable fine-grained data acquisition and local caching; fine-grained data acquisition includes dynamic link library information related to the unknown application lup_i, related open port information, related operating system behavior data, and related communication network behavior data.

[0040] Step 39: For each LUP application that ran an unknown application j Terminal x i Generate an unknown application feature dataset S_UnkProc_Charac(x) i ,lup j ,n)=(Ter_IP(x i ), Proc_ID(lup j ), S_Proc_Dll(lup j ,n),S_Proc_Port(lup j ,n)), where Ter_IP(x i ) represents terminal xi IP address, Proc_ID(lup j ) indicates an unknown application lup j The name, S_Proc_Dll(lup j (n) represents the unknown application in the nth period, lup j Related dynamic link library information, S_Proc_Port(lup j (n) represents the unknown application in the nth period, lup j Relevant open port information, until LUP j Once an unknown application is identified as a suspicious application, complete data information is extracted and reported.

Claims

1. A method for tracking and collecting terminal monitoring data based on cloud collaboration, characterized in that, The method comprises the following steps: Step 1: computer terminal x1, x2, x3... x n Obtain the white application program list List_WProc(M) = (WProc_1, WProc_2,... WProc_k) of terminal monitoring data, WProc_k represents the total number of the kth white application program allowed to be enabled, and store the white application program list locally. Step 2: computer terminal x1, x2, x3 … x n Periodically carry out terminal local security patrol, and form the terminal application snapshot list of the nth period, where the time n terminal x i The application snapshot list is List_RProc(x i , n) = (RProc_1, RProc_2, … … RProc_I), RProc_I represents the Ith application running in the nth period, and the white application list is compared and analyzed to generate the unknown application list of terminal x i At time n, List_Unknown_RProc(x i , n) = (UProc_1, UProc_2, … … UProc_m), UProc_m represents the mth unknown application discovered in the nth period, and the unknown application b 21 , b 22 , the unknown application b 31 , c 31 on terminal x3 is obtained; Step 3: At the nth cycle, computer terminals x1, x2, x3……x n Collect the terminal basic data of computer terminals x1, x2, x3……x n through the intelligent mining collection method of terminal monitoring data based on process tracking analysis, and collect the feature data of unknown application programs b 21 , b 22 , b 31 , c 31 on terminals x2, x3, and then report to the terminal security monitoring system background; Step 4: The terminal threat intelligent analysis system obtains the reported data information from the security monitoring terminal information base in the background of the terminal security monitoring system, including the terminal basic data of terminal x1, x2, x3...x n and the feature data of unknown application program b 21 , b 22 , b 31 , c 31 ; Step 5: the terminal threat intelligent analysis system fuses terminals x1, x2, x3...x n The reported data information, intelligently fusing massive terminal data, discovers unknown application programs c 31 Suspicious application programs, and then sends the suspicious application programs c 31 Association data information to the terminal security monitoring system background; Step 6: The terminal security monitoring system background adjusts the data collection strategy of terminal x3 according to the association data information of suspicious application c provided by the terminal threat intelligent analysis system, increases the fine-grained monitoring collection strategy for suspicious application c and issues it to terminal x3. 31 31 Step 6: The terminal security monitoring system background adjusts the data collection strategy of terminal x3 according to the association data information of suspicious application c provided by the terminal threat intelligent analysis system, increases the fine-grained monitoring collection strategy for suspicious application c and issues it to terminal x3.​ Step 7: In the nth+1 cycle, computer terminals x1, x2, x3……x n Collect the terminal basic data of computer terminals x1, x2, x3……x n through the intelligent mining collection method of terminal monitoring data based on process tracking analysis, collect the feature data of unknown application programs b 21 , b 22 , b 31 , c 31 on terminals x2, x3, and collect the fine-grained monitoring data of suspicious application program c 31 , and then report to the terminal security monitoring system background. 2.The cloud-based collaborative terminal monitoring data tracking and collecting method according to claim 1, characterized in that, In the nth cycle, the terminal monitoring data intelligent mining collection method based on process tracking analysis has the following specific process: Step 31: Collecting terminal x's periodic terminal-based data i Step 32: Generating terminal x's periodic terminal-based data set S_Ter_Basic(x i , n) = (Ter_IP(x i ), S_Ter_Port(x i , n), S_Ter_SysOper(x i , n), S_Ter_RisEvent(x i , n), S_Ter_DamEvent(x i , n)), where Ter_IP(x i ) represents terminal x i 's IP address, S_Ter_Port(x i , n) represents the open port information of terminal x i in the nth period, S_Ter_SysOper(x i , n) represents the important system operation behavior of terminal x i in the nth period, S_Ter_RisEvent(x i , n) represents the security risk event discovered by terminal x i in the nth period, and S_Ter_DamEvent(x i , n) represents the network threat event discovered by terminal x i in the nth period i ​ Step 32: Read the terminal x in the (n-1)th cycle i A list of suspicious local applications, List_Local_RisProc(x i , n-1)={lrp1, lrp2, ..... lrp u }, lrp u Represents the terminal x in the (n-1)th cycle. i The uth suspicious application existing locally reads the terminal x data issued by the cloud-based intelligent terminal threat analysis system in the nth cycle. i List of suspicious applications List_Cloud_RisProc (x i , n) = {crp1, crp2, ..... crp v }, crp v This represents the endpoint x discovered by the cloud-based endpoint threat intelligent analysis system in the nth cycle. i For the vth suspicious application, calculate the nth period terminal x. i List_Local_RisProc(x) is a local list of suspicious applications. i ,n) = List_Local_RisProc(x i ,n-1)∩List_Cloud_RisProc(x i (n), that is, List_Local_RisProc(x i , n) = { lrp1, lrp2, ..... crp w }, crp w Indicates the nth period terminal x i The wth suspicious application existing locally; Step 33: If terminal x i List_Local_RisProc(x) is a local list of suspicious applications. i If n is empty, it means that the terminal x in the nth cycle is empty. i If no suspicious application is found, proceed to step 37; otherwise, calculate the terminal x for the nth cycle. i List of newly added suspicious applications List_Local_Add_RisProc(x i ,n) = List_Local_RisProc(x i ,n)-List_Local_RisProc(x i , n-1); if List_Local_Add_RisProc (x i If List_Local_Add_RisProc(x, n) is empty, it means that no new suspicious application was added in the (n-1)th cycle, proceed to step 34; otherwise, for List_Local_Add_RisProc(x i If the suspicious application in (n) enables fine-grained data collection and local data caching, proceed to step 34; Step 34: For each terminal x j running a suspicious application lrp i , generate a suspicious application trace dataset S_RisProc_Trace(x i , lrp j , n) = (Ter_IP(x i ), Proc_ID(lrp j ), S_Proc_Dll(lrp j , n), S_Proc_Port(lrp j , n), S_RisProc_Sys_Trace(lrp j , n), S_RisProc_Net_Trace(lrp j , n)), where Ter_IP(x i ) denotes the IP address of terminal x i , Proc_ID(lrp j ) denotes the name of suspicious application lrp j , S_Proc_Dll(lrp j , n) denotes the dynamic link library information related to suspicious application lrp j in the nth period, S_Proc_Port(lrp j , n) denotes the open port information related to suspicious application lrp j in the nth period, S_RisProc_Sys_Trace(lrp j , n) denotes the operating system behavior data related to suspicious application lrp j in the nth period, and S_RisProc_Net_Trace(lrp j , n) denotes the communication network behavior data related to suspicious application lrp j in the nth period; and generate a suspicious application trace matrix M_RisProc_Trace(x i , n) = (S_RisProc_Trace(x i , lrp1, n), S_RisProc_Trace(x i , lrp2, n),..., S_RisProc_Trace(x i , lrp w , n)), where lrp w denotes the wth suspicious application existing in terminal x i in the nth period. Step 35: Read terminal x in the (n-1)th cycle i List_Local_UnkProc(x) of unknown local applications i , n-1)={lup1, lup2, ..... lup r }, lup r Represents the terminal x in the (n-1)th cycle. i The r-th unknown application existing locally calculates the n-th period terminal x. i Transform a list of suspicious applications (List_Trans_UnkProc(x)) i ,n) = List_Local_UnkProc(x i ,n-1)∩List_Local_RisProc(x i (n), that is, List_Trans_UnkProc(x i , n) = {lrp1, lrp2, ..... crp s }, crp s Indicates the nth period terminal x i The s-th suspicious application that was transformed from an unknown application; Step 36: If terminal x i is not in the suspicious application list List_SusApp(x i , n) in the n-th cycle, it means that terminal x i has not been transformed into a suspicious application by an unknown application in the n-th cycle, and step 37 is entered; otherwise, the transformed application trace data matrix set {M_Trans_RisProc_Trace(x i , lrp1, n), M_Trans_RisProc_Trace(x i , lrp2, n),... M_Trans_RisProc_Trace(x i , lrp s , n)} is read, where lrp s represents the s-th suspicious application to which terminal x i has been transformed by an unknown application in the n-th cycle, and M_Trans_RisProc_Trace(x i , lrp j , n) = {S_RisProc_Trace(x i , lrp j , n-1), S_RisProc_Trace(x i , lrp j , n-2),... S_RisProc_Trace(x i , lrp j , n-p)}, where p represents the number of cycles experienced from the discovery of the unknown application to the transformation into a suspicious application. Step 37: Read the white application list for terminal x i List_WProc(M) = (wp1, wp2,.... wp k ), wp k represents the kth white application allowed to be enabled, obtain the application snapshot list of terminal x i in the nth period List_Local_RProc(x i , n) = (lp1, lp2,.... lp I ), lp I represents the Ith application running, the application snapshot list is compared and analyzed with the white application list, and the unknown application list of terminal x i in the nth period List_Local_UnkRProc(x i , n) = (List_Local_RProc(x i , n) - List_WProc(M)) ∪List_Local_UnkRProc(x i , n-1); calculation List_Unknown_RProc(x i , n) = (lup1, lup2,.... lup m ), lup m represents the mth unknown application found in the nth period; Step 38: If terminal x i List_Local_UnkRProc(x) i If (x, n) is empty, then the execution step of the nth cycle ends; otherwise, the list of newly added unknown applications, List_Local_Add_UnkRProc(x), is calculated. i ,n) = List_Local_UnkRProc(x i ,n)-List_Local_UnkRProc(x i (n-1); calculate List_Local_Add_UnkRProc(x i , n) = (lup1, lup2, ..... lup h ), lup h This represents the h-th unknown application discovered in the nth cycle. If a new unknown application is added, the list of unknown applications is defined as List_Local_Add_UnkRProc(x). i If (lup1, lup2, ..., lup) is not empty, then for (lup1, lup2, ..., lup) h Enable fine-grained data acquisition and local caching; Step 39: For each terminal x j running an unknown application lup i , generate the unknown application characteristic data set S_UnkProc_Charac(x i , lup j , n) = (Ter_IP(x i ), Proc_ID(lup j ), S_Proc_Dll(lup j , n), S_Proc_Port(lup j , n)), where Ter_IP(x i ) represents the IP address of terminal x i , Proc_ID(lup j ) represents the name of unknown application lup j , S_Proc_Dll(lup j , n) represents the dynamic link library information related to unknown application lup j in the nth period, and S_Proc_Port(lup j , n) represents the open port information related to unknown application lup j in the nth period. After lup j is converted into a suspicious application by an unknown application, the complete data information is extracted and reported. 3.The cloud-based collaborative terminal monitoring data tracking and collecting method according to claim 2, characterized in that, The fine-grained data collection includes collecting suspicious application program or unknown application program related dynamic link library information, related open port information, related operating system behavior data, and related communication network behavior data. 4.The cloud-based collaborative terminal monitoring data tracking and collecting method according to claim 2, characterized in that, The threshold of the number of cycles experienced from discovering unknown application programs to converting into suspicious application programs is 10.

5. A terminal monitoring data tracking and collecting model based on cloud collaboration, characterized in that, The terminal monitoring data tracking collection method based on cloud cooperation for realizing any one of claims 1-4 comprises a terminal threat intelligent analysis system, a terminal security monitoring system background, and a plurality of computer terminals connected in sequence, the computer terminals deploy terminal security monitoring system software, the terminal security monitoring system background is provided with a security monitoring terminal information library, and the terminal threat intelligent analysis system reads and utilizes all information of the security monitoring terminal information library for data fusion analysis. 6.The cloud-based collaborative terminal monitoring data tracking acquisition model of claim 5, wherein, The terminal threat intelligent analysis system can read the security monitoring terminal information library of the terminal security monitoring system background and send suspicious application program associated data information found to the terminal security monitoring system background. 7.The cloud-based collaborative terminal monitoring data tracking and collecting model according to claim 5, characterized in that, The terminal security monitoring system software is integrated with a terminal data intelligent mining collection component, a terminal threat local intelligent patrol component, an unknown application program list, and a suspicious application program list. 8.The cloud-based collaborative terminal monitoring data tracking and collecting model according to claim 7, characterized in that, The unknown application program list and the suspicious application program list can be dynamically adjusted and mutually converted according to suspicious application program associated data issued by the terminal threat intelligent analysis system and unknown application program data provided by the terminal threat local patrol component, and drive the dynamic adjustment and switching of three data collection mechanisms of terminal basic data, unknown application program feature data, and suspicious application program tracking data in the terminal data intelligent mining collection component.

Citation Information

Patent Citations

  • Mobile intelligent terminal abnormal code cloud detection method based on behavioral characteristics

    CN105897807A

  • Intelligent security policy configuration method based on target perception

    CN113328996A