An abnormal data evaluation method and device, electronic equipment and storage medium

By generating grouped events and calculating the correlation confidence value between cascading anomaly scores and high-risk grouped events, the problem of inaccurate data anomaly assessment between different applications within an enterprise is solved, enabling efficient assessment and tracing of anomalous data.

CN116992335BActive Publication Date: 2025-10-24CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202311109253.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-08-30
Publication Date
2025-10-24
Estimated Expiration
2043-08-30

AI Technical Summary

Technical Problem

In existing technologies, the accuracy of data anomaly assessment between different applications within an enterprise is not high, especially when managing internal data security. Because different applications are isolated from each other, it is impossible to effectively identify the business relationships between data, resulting in inaccurate assessment of abnormal data.

Method used

By acquiring the correlation information of anomaly information of a specified anomaly type within a specified time range in a specified application, grouped events are generated, and they are classified according to the chronological order of anomaly occurrence. The cascading anomaly score and the correlation confidence value of high-risk grouped events are calculated to evaluate the credibility of the anomaly information.

Benefits of technology

It improves the accuracy of anomaly data analysis, enabling the identification of data security incidents in multiple business-related applications within an enterprise. This reduces the need for refactoring and pre-configuring security policies for each application, thereby increasing the efficiency of anomaly data analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116992335B_ABST
    Figure CN116992335B_ABST
Patent Text Reader

Abstract

The application discloses an abnormal data evaluation method and device, electronic equipment and storage medium. The method comprises the following steps: acquiring the associated information of abnormal information of a specified abnormal type in a specified application within a set time range; generating corresponding queuing events of abnormal information in each time window according to the order of abnormal occurrence time of each abnormal type of abnormal information identified in the same manner according to a preset time window; determining the corresponding cascade abnormal score of each abnormal information according to the preset abnormal score information corresponding to each abnormal type in each queuing event; if it is determined that each queuing event is a high-risk queuing event based on the cascade abnormal score of each queuing event corresponding to the abnormal information and the preset threshold value, determining the associated trust value corresponding to each high-risk queuing event according to the frequency of each high-risk queuing event appearing in each time window and the lower limit of the trust tolerance value; and evaluating the abnormal information based on the associated trust value to obtain an evaluation result.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of communication, and in particular to an abnormal data evaluation method and device, electronic equipment and storage medium. BACKGROUND

[0002] With the development of information technology, a large amount of data assets will be accumulated in the process of enterprise informatization. These data assets hide a lot of important information, and the security of data assets is paid more and more attention. How to find the leakage and attack of important data is an important problem faced by enterprise data security management.

[0003] Various system applications are involved in the enterprise. Different applications have great differences in data classification and grading, desensitization management, permission control, deletion, supervision, etc. Since the open interfaces of these applications do not have unified security design, they often break through the security strategy of data opening and cause abnormalities in data classification and grading, desensitization management, permission control, deletion, supervision, etc. How to find the root cause of data security problems is an important problem to be solved.

[0004] However, the related technology mainly tends to analyze external attacks and focuses on abnormal behaviors. When managing internal data security, the enterprise mainly focuses on data abnormalities within the application due to the mutual isolation between different applications. However, there are business associations between data of different applications, which leads to low accuracy of abnormal data evaluation. SUMMARY

[0005] In order to solve the problem of low accuracy of abnormal data evaluation in the prior art, the embodiments of the present application provide an abnormal data evaluation method, device, electronic equipment and storage medium.

[0006] In a first aspect, the embodiments of the present application provide an abnormal data evaluation method, comprising:

[0007] obtaining association information of abnormal information of a specified abnormal type in a specified application within a specified time range, the association information of the abnormal information comprising identification information of the abnormal information, abnormal occurrence time information, and preset abnormal score information corresponding to the specified abnormal type;

[0008] According to the preset time window, the abnormal information of each different abnormal type with the same identification is generated according to the chronological order of the abnormal occurrence time, and the corresponding queuing event of the abnormal information in each time window is generated;

[0009] For each queuing event corresponding to each abnormal information with the same identification, the preset abnormal score information corresponding to each abnormal type in the queuing event is determined to determine the cascade abnormal score corresponding to the queuing event;

[0010] if it is determined, based on the cascade abnormality score of each platoon event corresponding to the abnormal information and a preset threshold, that each platoon event corresponding to the abnormal information is a high-risk platoon event corresponding to the abnormal information, determining, according to the frequency of each high-risk platoon event corresponding to the abnormal information appearing in each time window and the lower limit of the trust tolerance score, an associated trust value corresponding to each high-risk platoon event of the abnormal information, the associated trust value representing the trust degree of each high-risk platoon event of the abnormal information being an abnormal platoon event with an associated relationship;

[0011] evaluating the abnormal information based on the associated trust value to obtain an evaluation result.

[0012] In an embodiment, for each platoon event corresponding to the same abnormal information, the cascade abnormality score corresponding to the platoon event is determined according to the preset abnormality score information corresponding to each abnormal type in the platoon event, specifically including:

[0013] For each platoon event corresponding to the same abnormal information in each time window, the sub-cascade abnormality score corresponding to the platoon event in each time window is determined according to the preset abnormality score information corresponding to each abnormal type in the platoon event.

[0014] The average of each sub-cascade abnormality score of each platoon event is determined as the cascade abnormality score of each platoon event.

[0015] In an embodiment, for each platoon event corresponding to the same abnormal information in each time window, the sub-cascade abnormality score corresponding to the platoon event in each time window is determined by the following method:

[0016] According to the preset abnormality score information corresponding to the first abnormal type and the preset abnormality score information corresponding to the second abnormal type of the abnormal information in the platoon event in the time window, a two-level abnormality score corresponding to the platoon event is determined.

[0017] For each level after the two levels, the preset abnormality score information of the current abnormal type of the abnormal information and the previous level abnormality score are used to determine the current level abnormality score.

[0018] According to each level abnormality score, the sub-cascade abnormality score of the platoon event corresponding to the abnormal information in the time window is determined.

[0019] In an embodiment, based on the cascade abnormality score of each platoon event corresponding to the abnormal information and a preset threshold, each platoon event corresponding to the abnormal information is determined to be a high-risk platoon event corresponding to the abnormal information, specifically including:

[0020] If it is determined that the average of the cascade abnormality scores of each platoon event corresponding to the abnormal information is greater than the preset threshold value, it is determined that each platoon event corresponding to the abnormal information is a high-risk platoon event corresponding to the abnormal information.

[0021] In an embodiment, the associated trust value corresponding to each high-risk platoon event of the abnormal information is determined according to the frequency of occurrence of each high-risk platoon event corresponding to the abnormal information in each time window and the lower limit of the trust tolerance score value, and specifically includes:

[0022] For each high-risk platoon event corresponding to the abnormal information, the weight of the high-risk platoon event is determined according to the frequency of occurrence of the high-risk platoon event in each time window.

[0023] The associated trust value corresponding to each high-risk platoon event of the abnormal information is determined according to the weight corresponding to each high-risk platoon event and the lower limit of the trust tolerance score value of each high-risk platoon event.

[0024] In an embodiment, the associated trust value corresponding to each high-risk platoon event of the abnormal information is determined according to the weight corresponding to each high-risk platoon event and the lower limit of the trust tolerance score value of each high-risk platoon event, and specifically includes:

[0025] The trust value corresponding to each high-risk platoon event is determined according to the weight corresponding to each high-risk platoon event and the lower limit of the trust tolerance score value of each high-risk platoon event, respectively, and the trust value corresponding to the high-risk platoon event represents the trustworthiness of the high-risk platoon event as an abnormal platoon event.

[0026] The associated trust value corresponding to each high-risk platoon event is determined according to the trust value corresponding to each high-risk platoon event.

[0027] In a second aspect, an embodiment of the present application provides an abnormal data evaluation device, which includes:

[0028] An acquisition unit is configured to acquire associated information of abnormal information of a specified abnormal type in a specified time range in a specified application, and the associated information of the abnormal information includes identification information of the abnormal information, abnormal occurrence time information, and preset abnormal score information corresponding to the specified abnormal type.

[0029] A generation unit is configured to generate corresponding platoon events of the abnormal information in each time window according to the order of abnormal occurrence time of each different abnormal type of abnormal information with the same identification according to a preset time window.

[0030] The first determining unit is configured to determine, for each queuing event corresponding to each piece of same abnormal information, a cascade abnormal score of the queuing event according to preset abnormal score information corresponding to each abnormal type in the queuing event.

[0031] The second determining unit is configured to determine, if it is determined based on the cascade abnormal scores of the queuing events corresponding to the abnormal information and the preset threshold that the queuing events corresponding to the abnormal information are high-risk queuing events corresponding to the abnormal information, a correlation confidence value corresponding to each high-risk queuing event of the abnormal information according to a frequency of occurrence of each high-risk queuing event of the abnormal information in each time window and a lower limit of a confidence tolerance value, the correlation confidence value representing a confidence degree of each high-risk queuing event of the abnormal information being an abnormal queuing event with a correlation relationship.

[0032] The evaluation unit is configured to evaluate the abnormal information based on the correlation confidence value to obtain an evaluation result.

[0033] In an implementation, the first determining unit is specifically configured to, for each queuing event corresponding to each piece of same abnormal information in each time window, determine a sub-cascade abnormal score of the queuing event in the each time window according to preset abnormal score information corresponding to each abnormal type in the queuing event; and determine a mean value of each sub-cascade abnormal score of each queuing event as a cascade abnormal score of each queuing event.

[0034] In an implementation, the first determining unit is specifically configured to, for each queuing event corresponding to each piece of same abnormal information in each time window, determine a sub-cascade abnormal score of the queuing event in the each time window by the following manner: determining a two-layer abnormal score of the queuing event according to preset abnormal score information corresponding to a first abnormal type of the abnormal information in the queuing event and preset abnormal score information corresponding to a second abnormal type in the time window; for each layer after the two-layer, determining a current layer abnormal score according to preset abnormal score information of a current abnormal type of the abnormal information and a previous layer abnormal score; and determining the sub-cascade abnormal score of the queuing event of the abnormal information in the time window according to each layer abnormal score.

[0035] In an implementation, the second determining unit is specifically configured to determine, if it is determined that a mean value of the cascade abnormal scores of the queuing events corresponding to the abnormal information is greater than the preset threshold, that the queuing events corresponding to the abnormal information are high-risk queuing events corresponding to the abnormal information.

[0036] In an embodiment, the second determining unit is specifically configured to determine a weight of each high-risk platooning event corresponding to the abnormal information according to a frequency of occurrence of the high-risk platooning event in each time window; and determine an associated trust value corresponding to each high-risk platooning event of the abnormal information according to the weight corresponding to each high-risk platooning event and a lower limit of the trust tolerance score of each high-risk platooning event.

[0037] In an embodiment, the second determining unit is specifically configured to determine a trust value corresponding to each high-risk platooning event according to the weight corresponding to each high-risk platooning event and the lower limit of the trust tolerance score of each high-risk platooning event, respectively, wherein the trust value corresponding to each high-risk platooning event represents a trust degree of the high-risk platooning event being an abnormal platooning event; and determine the associated trust value corresponding to each high-risk platooning event according to the trust value corresponding to each high-risk platooning event.

[0038] In a third aspect, an electronic device is provided, which includes a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor executes the program to implement the abnormal data evaluation method.

[0039] In a fourth aspect, a computer readable storage medium is provided, which stores a computer program executable by a processor to implement the steps of the abnormal data evaluation method.

[0040] The beneficial effects of the present application are as follows:

[0041] The abnormal data evaluation method and device provided in the embodiments of the present application, the electronic device and the storage medium, obtain the association information of abnormal information of a specified abnormal type in a specified time range in a specified application, the association information of the abnormal information includes identification information of the abnormal information, abnormal occurrence time information, and preset abnormal score information corresponding to the specified abnormal type; according to a preset time window, abnormal information of each different abnormal type with the same identification is generated into corresponding platoon events of the abnormal information in each time window according to the chronological order of the abnormal occurrence time; for each platoon event corresponding to each abnormal information with the same identification, a cascading abnormal score corresponding to the platoon event is determined according to the preset abnormal score information corresponding to each abnormal type in the platoon event; if it is determined that each platoon event corresponding to the abnormal information is a high-risk platoon event of the abnormal information based on the cascading abnormal score of each platoon event corresponding to the abnormal information and a preset threshold, then an association confidence value corresponding to each high-risk platoon event of the abnormal information is determined according to the frequency of occurrence of each high-risk platoon event of the abnormal information in each time window and a lower limit of a confidence tolerance value, and the association confidence value represents the confidence of each high-risk platoon event of the abnormal information as an abnormal platoon event with an association relationship; and the abnormal information is evaluated based on the association confidence value to obtain an evaluation result. In the embodiments of the present application, the corresponding preset abnormal score is set according to different abnormal types of information in advance, for each abnormal information with the same identification obtained from the specified application, abnormal information of each different abnormal type of the abnormal information is generated into platoon events of the abnormal information in each time window according to the chronological order of the abnormal occurrence time according to a preset time window, and then whether each platoon event is a high-risk platoon event corresponding to the abnormal information is judged according to the determined cascading abnormal score corresponding to each platoon event and the preset threshold, if yes, then the association confidence value corresponding to each high-risk platoon event of the abnormal information is further determined, that is, the confidence of each high-risk platoon event as an abnormal platoon event with an association relationship. Since the user can specify the association information of the abnormal information obtained from multiple applications in advance, for each abnormal information with the same identification, the platoon events are generated by associating abnormal information of different specified abnormal types, the cascading abnormal score of the platoon events is calculated to determine whether it is a high-risk platoon event, and the confidence of the high-risk platoon event of the abnormal information is evaluated, so that the root cause of the abnormal information can be more accurately evaluated, which is suitable for data security event analysis and tracing of multiple business-associated applications in an enterprise, without the need to reconstruct and preset different security strategies for each application, and the efficiency of abnormal data analysis is improved.

[0042] Other features and advantages of the present application will be set forth in the following description, and in part will be apparent from the description, or can be learned by practice of the present application. The objects and other advantages of the present application will be realized and attained by the structure particularly pointed out in the written description and claims hereof as well as the appended drawings. BRIEF DESCRIPTION OF DRAWINGS

[0043] The accompanying drawings, which are included to provide a further understanding of the application and are incorporated in and constitute a part of this application, illustrate embodiments of the application and serve to explain the principles of the application. In the drawings:

[0044] Figure 1 An implementation flowchart of the abnormal data evaluation method provided by the embodiments of the application is shown in the figure;

[0045] Figure 2 An implementation flowchart of determining the cascade abnormal score corresponding to the platoon event is shown in the figure;

[0046] Figure 3 An implementation flowchart of determining the sub-cascade abnormal score corresponding to the platoon event in each time window is shown in the figure;

[0047] Figure 4 An implementation flowchart of determining the associated trust value corresponding to each high-risk platoon event of the abnormal information is shown in the figure;

[0048] Figure 5 An implementation flowchart of the abnormal data evaluation device provided by the embodiments of the application is shown in the figure;

[0049] Figure 6 An implementation flowchart of the electronic device provided by the embodiments of the application is shown in the figure. DETAILED DESCRIPTION

[0050] In order to solve the problem of low accuracy of abnormal data evaluation in the prior art, the embodiments of the application provide an abnormal data evaluation method, device, electronic device and storage medium.

[0051] The preferred embodiments of the application will be described below with reference to the accompanying drawings of the specification. It should be understood that the preferred embodiments described herein are only used to explain and illustrate the application, and are not used to limit the application, and the embodiments in the application and the features in the embodiments can be combined with each other without conflict.

[0052] The abnormal data evaluation method provided by the embodiments of the application is applied to a data detection device, which can be but is not limited to a server or a terminal and the like. The embodiments of the application do not limit this.

[0053] The server can be a stand-alone physical server, or a cloud server providing basic cloud computing services such as cloud server, cloud database, cloud storage, etc. The terminal can be but is not limited to a smart phone, a tablet computer, a notebook computer, a desktop computer and the like. The embodiments of the application do not limit this.

[0054] AsFigure 1 As shown in the figure, it is an implementation flow diagram of the abnormal data evaluation method provided by the embodiment of the application, which is taken as an example to be applied to a server. The abnormal data evaluation method can include the following steps:

[0055] S11, acquiring associated information of abnormal information of a specified abnormal type in a specified time range in a specified application.

[0056] In a specific implementation, different applications with business association in an enterprise will respectively perform classification, grading, desensitization, deletion, supervision and other operations on data in their respective application platforms. In different applications, the same information has a unique identifier, which can be represented by infoID. In the process of classification, grading, desensitization, deletion, supervision and other operations on information by different application platforms, different types of abnormalities will inevitably occur for some information. The server sets an identifier for each abnormal type in advance, which can be represented by infoType. The abnormal types contained in classification, grading, desensitization, deletion and supervision are shown in Table 1:

[0057] Table 1

[0058]

[0059]

[0060]

[0061] The abnormal types contained in the classification grading include, but are not limited to, the following types: a classification grading algorithm and parameters do not meet the classification grading requirement exception, an information classification grading operation subject does not meet the classification grading requirement exception, an information classification grading result does not match the scene exception, a classification grading process does not meet the classification grading requirement exception, information over-classification grading exception, personal sensitive information identification result return exception, and classification grading tool set parameters do not meet the requirement exception. Through the analysis of the information by the classification grading effect evaluation system, it can be determined whether the information is abnormal information of the following abnormal types: a classification grading algorithm and parameters do not meet the classification grading requirement exception, an information classification grading operation subject does not meet the classification grading requirement exception, an information classification grading result does not match the scene exception, a classification grading process does not meet the classification grading requirement exception, and information over-classification grading exception. Through the analysis of the information by the sensitive personal information identification system, it can be determined whether the information is abnormal information of the following abnormal types: a personal sensitive information identification result return exception and a classification grading tool set parameters do not meet the requirement exception. A first classification identifier can be set in advance for the classification grading: 0x0. A second classification identifier can be set for the classification grading exceptions analyzed by the classification grading effect evaluation system: 0x01. A second classification identifier can be set for the classification grading exceptions analyzed by the sensitive personal information identification system: 0x02. A third classification identifier can be set for specific classification grading exception types. The third classification identifier of the exception type "classification grading algorithm and parameters do not meet the classification grading requirement exception" can be set as: 0x0101. The third classification identifier of the exception type "information classification grading operation subject does not meet the classification grading requirement exception" can be set as: 0x0102. The third classification identifier of the exception type "information classification grading result does not match the scene exception" can be set as: 0x0103. The third classification identifier of the exception type "classification grading process does not meet the classification grading requirement exception" can be set as: 0x0104. The third classification identifier of the exception type "information over-classification grading exception" can be set as: 0x0105. The third classification identifier of the exception type "personal sensitive information identification result return exception" can be set as: 0x0201. The third classification identifier of the exception type "classification grading tool set parameters do not meet the requirement exception" can be set as: 0x0202.

[0062] The desensitization includes the following types of abnormalities, but not limited to: desensitization algorithm, algorithm parameter selection abnormality, post-desensitization information does not meet desensitization requirements abnormality, desensitization effect evaluation result invalidity abnormality, anti-big data analysis desensitization effect evaluation result invalidity abnormality, desensitization effect evaluation result evaluation process irregularity abnormality, desensitization time does not meet desensitization requirements abnormality, etc. Through the desensitization effect evaluation system, it can be concluded whether the information is abnormal information of the following abnormal types: desensitization algorithm, algorithm parameter selection abnormality, post-desensitization information does not meet desensitization requirements abnormality, desensitization effect evaluation result invalidity abnormality, anti-big data analysis desensitization effect evaluation result invalidity abnormality, through the desensitization technology requirement compliance inspection system, it can be concluded whether the information is abnormal information of the following abnormal types: desensitization effect evaluation result evaluation process irregularity abnormality, desensitization time does not meet desensitization requirements abnormality. The first-level classification identifier for desensitization can be set in advance: 0x1, the second-level classification identifier for the desensitization effect evaluation system analyzed desensitization abnormality is set further: 0x11, the second-level classification identifier for the desensitization technology requirement compliance inspection system analyzed desensitization abnormality is set: 0x12, the third-level classification identifier for the specific desensitization abnormality type is set further, the third-level classification identifier for the abnormal type of "desensitization algorithm, algorithm parameter selection abnormality" is set: 0x1101, the third-level classification identifier for the abnormal type of "post-desensitization information does not meet desensitization requirements abnormality" is set: 0x1102, the third-level classification identifier for the abnormal type of "desensitization effect evaluation result invalidity abnormality" is set: 0x1103, the third-level classification identifier for the abnormal type of "anti-big data analysis desensitization effect evaluation result invalidity abnormality" is set: 0x1104, the third-level classification identifier for the abnormal type of "desensitization effect evaluation result evaluation process irregularity abnormality" is set: 0x1201, the third-level classification identifier for the abnormal type of "desensitization time does not meet desensitization requirements abnormality" is set: 0x1202.

[0063] The deletion-included exception type can be, but is not limited to, the following types: information is not deleted according to the deletion intention, information is not deleted according to the deletion trigger condition, deletion algorithm failure exception, deletion consistency invalid exception, overall deletion invalid exception, deletion notification sending failure exception, deletion confirmation notification sending failure exception, deletion notification sending failure exception, deletion confirmation notification sending failure exception, etc. By analyzing the information through the deletion effect evaluation system, it can be determined whether the information is abnormal information of the following exception types: information is not deleted according to the deletion intention, information is not deleted according to the deletion trigger condition, deletion algorithm failure exception, deletion consistency invalid exception, overall deletion invalid exception. By analyzing the information through the deletion instruction notification and confirmation system, it can be determined whether the information is abnormal information of the following exception types: deletion consistency invalid exception, overall deletion invalid exception. By analyzing the information through the deterministic deletion system, it can be determined whether the information is abnormal information of the following exception types: deletion notification sending failure exception, deletion confirmation notification sending failure exception. The first classification identifier for deletion can be set in advance as 0x2. The second classification identifier for the deletion exception analyzed by the deletion effect evaluation system is set as 0x21. The second classification identifier for the deletion exception analyzed by the deletion instruction notification and confirmation system is set as 0x22. The second classification identifier for the deletion exception analyzed by the deterministic deletion system is set as 0x23. Further, the third classification identifier for the specific deletion exception type can be set. The third classification identifier for the exception type of "information is not deleted according to the deletion intention" is set as 0x2101. The third classification identifier for the exception type of "information is not deleted according to the deletion trigger condition" is set as 0x2102. The third classification identifier for the exception type of "deletion algorithm failure exception" is set as 0x2103. The third classification identifier for the exception type of "deletion consistency invalid exception" is set as 0x2104. The third classification identifier for the exception type of "overall deletion invalid exception" is set as 0x2105. The third classification identifier for the exception type of "deletion notification sending failure exception" is set as 0x2201. The third classification identifier for the exception type of "deletion confirmation notification sending failure exception" is set as 0x2202. The third classification identifier for the exception type of "deletion notification sending failure exception" is set as 0x2301. The third classification identifier for the exception type of "deletion confirmation notification sending failure exception" is set as 0x2302.

[0064] The supervision-included abnormal types can include, but are not limited to, the following types: information flow transfer range non-compliance abnormality, information flow transfer mode non-compliance abnormality, information flow transfer hop count non-compliance abnormality, storage control information non-compliance abnormality, information retention time non-compliance abnormality, information storage mode non-compliance abnormality, information storage format non-compliance abnormality, information storage address non-compliance abnormality, information encryption mode non-compliance abnormality, linkage basis non-compliance abnormality, linkage time non-compliance abnormality, linkage type non-compliance abnormality, linkage result invalidity abnormality, evidence storage information format non-compliance abnormality, incomplete evidence storage according to evidence storage requirements abnormality, evidence storage information storage format non-compliance abnormality, evidence storage information storage mode non-compliance abnormality, evidence storage information storage address non-compliance abnormality, supervision subject not meeting supervision requirements abnormality, fusion analysis method not meeting requirements abnormality, infringement event judgment result not meeting supervision requirements abnormality, infringement event evidence not meeting requirements abnormality, infringement event traceability method and parameters meeting supervision requirements abnormality, infringement event traceability result incorrect abnormality, infringement event disposal effect evaluation result not meeting supervision requirements abnormality, infringement event disposal method and parameters not meeting supervision requirements abnormality, infringement event disposal instruction not correctly executed abnormality, and infringement event disposal instruction not meeting supervision requirements abnormality. A first classification identifier 0x3 can be set for supervision in advance, a second classification identifier 0x31 can be set for information flow transfer abnormality, a second classification identifier 0x32 can be set for information storage abnormality, a second classification identifier 0x33 can be set for abnormal operation fusion analysis system analyzed linkage abnormality, a second classification identifier 0x34 can be set for evidence storage abnormality, a second classification identifier 0x35 can be set for right protection supervision and disposal system analyzed supervision and infringement abnormality, and a third classification identifier can be further set for specific supervision abnormality types. The third classification identifier of the abnormality type “information flow transfer range non-compliance abnormality” can be set as 0x3101, the third classification identifier of the abnormality type “information flow transfer mode non-compliance abnormality” can be set as 0x3102, the third classification identifier of the abnormality type “information flow transfer hop count non-compliance abnormality” can be set as 0x3103, the third classification identifier of the abnormality type “storage control information non-compliance abnormality” can be set as 0x3201, the third classification identifier of the abnormality type “information retention time non-compliance abnormality” can be set as 0x3202, the third classification identifier of the abnormality type “information storage mode non-compliance abnormality” can be set as 0x3203, the third classification identifier of the abnormality type “information storage format non-compliance abnormality” can be set as 0x3204, the third classification identifier of the abnormality type “information storage address non-compliance abnormality” can be set as 0x3205, the third classification identifier of the abnormality type “information encryption mode non-compliance abnormality” can be set as 0x3206, the third classification identifier of the abnormality type “linkage basis non-compliance abnormality” can be set as 0x3301, the third classification identifier of the abnormality type “linkage time non-compliance abnormality” can be set as 0x3302, and so on.The three-level classification identifier of the abnormal type of "linkage type non-compliance abnormality" is set to 0x3303, the three-level classification identifier of the abnormal type of "linkage result invalidity abnormality" is set to 0x3304, the three-level classification identifier of the abnormal type of "storage evidence information format non-compliance abnormality" is set to 0x3401, the three-level classification identifier of the abnormal type of "incomplete storage evidence abnormality not in accordance with storage requirements" is set to 0x3402, the three-level classification identifier of the abnormal type of "storage format of storage evidence information non-compliance abnormality" is set to 0x3403, the three-level classification identifier of the abnormal type of "storage method of storage evidence information non-compliance abnormality" is set to 0x3404, the three-level classification identifier of the abnormal type of "storage address of storage evidence information non-compliance abnormality" is set to 0x3405, the three-level classification identifier of the abnormal type of "supervision subject not in accordance with supervision requirements abnormality" is set to 0x3501, the three-level classification identifier of the abnormal type of "fusion analysis method not in accordance with requirements abnormality" is set to 0x3502, the three-level classification identifier of the abnormal type of "infringement event judgment result not in accordance with supervision requirements abnormality" is set to 0x3503, the three-level classification identifier of the abnormal type of "infringement event evidence not in accordance with requirements abnormality" is set to 0x3504, the three-level classification identifier of the abnormal type of "infringement event traceability method and parameters in accordance with supervision requirements abnormality" is set to 0x3505, the three-level classification identifier of the abnormal type of "infringement event traceability result incorrect abnormality" is set to 0x3506, the three-level classification identifier of the abnormal type of "infringement event disposal effect evaluation result not in accordance with supervision requirements abnormality" is set to 0x3507, the three-level classification identifier of the abnormal type of "infringement event disposal method and parameters not in accordance with supervision requirements abnormality" is set to 0x3508, the three-level classification identifier of the abnormal type of "infringement event disposal instruction not correctly executed abnormality" is set to 0x3509, and the three-level classification identifier of the abnormal type of "infringement event disposal instruction not in accordance with supervision requirements abnormality" is set to 0x350a.

[0065] The server can configure preset abnormality scores for different abnormality types according to the influence degree of the information in advance, for example, but not limited to, setting 1, 2, 3, 4, 5 points according to the importance, the higher the score, the higher the influence degree of the information, and the preset abnormality score can be represented by abValue.

[0066] In a specific implementation, the specified application can include a plurality of applications with business association, the time range can be set as required, for example, 1 week, half a month, etc., and the application embodiments are not limited to this. The specified abnormal type can be specified by the user through the server, and can include but is not limited to the abnormal types shown in Table 1: classification grading, desensitization, deletion, supervision, and any of the above abnormal types. The application embodiments are not limited to this. The information related to an abnormal information, i.e., the associated information of the abnormal information, can include but is not limited to the following contents: identification information of the abnormal information: infoID, abnormal occurrence time information: abnormalTime, content signature information of the abnormal information: hashSign, identification information of different abnormal types of the abnormal information: infoType, preset abnormal value information corresponding to different abnormal types of the abnormal information: abValue, and can also include content information of the abnormal information: infoContent, etc.

[0067] Specifically, the server can use the Filter method of the Flink platform to filter out the identification information of the abnormal information of the specified abnormal type in the specified time range (such as one week) of each specified application, the abnormal occurrence time information of each specified type, the content signature information of the abnormal information, the identification information of each abnormal type of the abnormal information, and the preset abnormal value information corresponding to each specified abnormal type of the abnormal information. Assuming that the specified abnormal type includes four types of abnormal information in Table 1, the filtered associated information of the abnormal information can be as shown in Table 2:

[0068] Table 2

[0069]

[0070]

[0071]

[0072] As can be seen from Table 2, the identification infoID of the abnormal information in rows 1-8 is: "37ffb8ac-4f79-4774-bb78-237694fc09ec", and the identification infoType of the abnormal type is respectively: 0x0101, 0x1101, 0x2101, 0x3101, 0x3201, 0x3301, 0x3401, 0x3501, indicating that the abnormal information has the following type of abnormality: classification and grading algorithm and its parameters in classification and grading abnormality do not meet the classification and grading requirements (0x0101), desensitization algorithm, algorithm parameter selection abnormality in desensitization abnormality (0x1101), information is not deleted according to the deletion intention in the deletion abnormality (0x2101), the information flow range is not in line with the regulation abnormality in the supervision abnormality (0x3101), the storage control information is not in line with the regulation abnormality in the supervision abnormality (0x3201), the linkage basis is not in line with the regulation abnormality in the supervision abnormality (0x3301), the evidence storage information format is not in line with the regulation abnormality in the supervision abnormality (0x3401), and the supervision subject does not meet the supervision requirements in the supervision abnormality (0x3501). The abnormality scores abValue corresponding to each type of abnormality are respectively: 2, 1, 5, 3, 1, 2, 3, and 2.

[0073] Further, the server performs data cleaning on the associated information of all the abnormal information obtained, and deletes repeated data, data with incorrect format, and the like.

[0074] S12, according to the preset time window, the abnormal information of each different abnormal type with the same identification is generated according to the chronological order of the abnormal occurrence time, and the corresponding queuing event of the abnormal information in each time window is generated.

[0075] In specific implementation, the preset time window (windowsize) can be set according to requirements, for example, but not limited to, 5 seconds, and the embodiments of the present application do not limit this.

[0076] In an implementation, before generating the collector event, the abnormal type of the collector event can also be specified, for example, the associated information of the abnormal information with the abnormal type of classification grading, desensitization, and deletion can be specified to generate the collector event, then in implementation, the server can generate the corresponding collector event of the abnormal information in each time window according to the order of abnormal occurrence time according to the associated information of the abnormal information with the abnormal type of classification grading abnormality, the associated information of the abnormal information with the desensitization abnormality, and the associated information of the abnormal information with the deletion abnormality, if in a certain time window, the abnormal type of a certain abnormal information only contains two types of the specified abnormal type of the collector event, then the associated information of the abnormal information with the two types is generated to generate the corresponding collector event of the abnormal information in the time window. It should be noted that if the abnormal types in the collector events generated in different time windows for the same abnormal information are the same, but the arrangement order is different, it is considered that the two collector events are the same collector event corresponding to the abnormal information.

[0077] That is, the collector event (Collector Event) is generated <abnormalevents>The trigger condition of the abnormal information includes: the same identification of the abnormal information, the same time window, and the different abnormal types of the abnormal type of the abnormal information and the specified abnormal type of the platoon event.

[0078] S13, for each platoon event corresponding to each abnormal information with the same identification, determining a cascade abnormal score corresponding to the platoon event according to preset abnormal score information corresponding to each abnormal type in the platoon event.

[0079] In specific implementation, for each platoon event corresponding to each abnormal information with the same identification, the cascade abnormal score corresponding to the platoon event can be determined according to the flow as shown in Figure 2 , including the following steps:

[0080] S21, for each platoon event corresponding to each abnormal information with the same identification in each time window, determining a sub-cascade abnormal score corresponding to the platoon event in each time window according to preset abnormal score information corresponding to each abnormal type in the platoon event.

[0081] In specific implementation, for each platoon event corresponding to each abnormal information with the same identification in each time window, the sub-cascade abnormal score corresponding to the platoon event in each time window can be determined according to the flow as shown in Figure 3 , including the following steps:

[0082] S31, determining a two-layer abnormal score corresponding to the platoon event according to preset abnormal score information corresponding to a first abnormal type and preset abnormal score information corresponding to a second abnormal type of the abnormal information in the platoon event in the time window.

[0083] In specific implementation, the server can calculate the abnormal score according to the preset abnormal score corresponding to the first abnormal type and the preset abnormal score corresponding to the second abnormal type of the abnormal information as the two-layer abnormal score corresponding to the platoon event for each platoon event corresponding to each abnormal information with the same identification in each time window.

[0084] Specifically, the two-layer abnormal score corresponding to the platoon event can be calculated by the following formula:

[0085] A2=0.8*(a1*1.1+a2)+0.2*(a1+a2)

[0086] Wherein, A2 represents the two-layer abnormal score corresponding to the platoon event;

[0087] a1 represents the preset abnormal score corresponding to the first abnormal type in the platoon event;

[0088] a2 represents the preset abnormal score corresponding to the second abnormal type in the platoon event.

[0089] S32, for each level after the second level, determining a current level anomaly score according to preset score information of a current anomaly type of the anomaly information and a previous level anomaly score.

[0090] In particular implementation, the server can calculate the current level anomaly score for each level after the second level by the following formula:

[0091] A n =0.8*(A n-1 *1.1+a n )+0.2*(A n-1 +a n )

[0092] Wherein, A n represents the n-level anomaly score corresponding to the platooning event;

[0093] A n-1 represents the n-1-level anomaly score corresponding to the platooning event;

[0094] a n represents the preset anomaly score corresponding to the nth anomaly type in the platooning event.

[0095] For example, when n = 3, the three-level anomaly score corresponding to the platooning event is:

[0096] A3=0.8*(A2*1.1+a3)+0.2*(A2+a3)

[0097] Wherein, A2 is the two-level anomaly score corresponding to the platooning event calculated in step S31, and a3 is the preset anomaly score corresponding to the third anomaly type in the platooning event.

[0098] S33, determining the sub-cascading anomaly score corresponding to the platooning event of the anomaly information in the time window according to the anomaly scores of each level.

[0099] In particular implementation, the server can, but not limited to, determine the average of the anomaly scores of each level as the sub-cascading anomaly score corresponding to the platooning event of the anomaly information in the time window.

[0100] Specifically, the sub-cascading anomaly score corresponding to the platooning event of the anomaly information in the time window can be calculated by the following formula:

[0101] A=(A2+......+A n ) / (n-1)

[0102] A represents the corresponding sub cascade abnormal score of the platoon event of the abnormal information in the time window.

[0103] For example, when n=3, A=(A2+A3) / 2.

[0104] S22, determine the mean value of each sub cascade abnormal score of each platoon event as the cascade abnormal score of each platoon event.

[0105] In specific implementation, for each abnormal information with the same identifier, the mean value of each sub cascade abnormal score of each platoon event can be determined as the cascade abnormal score of each platoon event.

[0106] S14, if it is determined that each platoon event corresponding to the abnormal information is a high-risk platoon event corresponding to the abnormal information based on the cascade abnormal score of each platoon event corresponding to the abnormal information and the preset threshold value, determine the associated trust value corresponding to each high-risk platoon event of the abnormal information according to the frequency of each high-risk platoon event of the abnormal information appearing in each time window and the lower limit of the trust tolerance score.

[0107] In specific implementation, the server determines, for each abnormal information with the same identifier, that each platoon event corresponding to the abnormal information is a high-risk platoon event corresponding to the abnormal information if the mean value of the cascade abnormal score of each platoon event corresponding to the abnormal information is greater than a preset threshold value, which can also be referred to as an infringement event, wherein the preset threshold value can be set according to requirements, for example, can be set to 10 points, and the present embodiment does not limit this.

[0108] As shown in Table 3, assuming that the abnormal information identified as "1ec36468-8989-4e2a-928b-6f134ed4794f" contains two platooning events, the events in the first platooning event include: E1: 0x0101 and E2: 0x3501, and the concatenated abnormal score TotalValue of the platooning event is: 2.080, the events in the second platooning event include: E1: 0x1101, E2: 0x3101, E3: 0x3201, and the concatenated abnormal score TotalValue of the platooning event is: 12.362, then the average of the two platooning events of the abnormal information identified as "1ec36468-8989-4e2a-928b-6f134ed4794f" is (2.080+12.362) / 2=7.221 points, assuming that the preset threshold is 10 points, since the average of the concatenated abnormal scores of the two platooning events of the abnormal information identified as "1ec36468-8989-4e2a-928b-6f134ed4794f" is less than 10 points, the two platooning events of the abnormal information identified as "1ec36468-8989-4e2a-928b-6f134ed4794f" are not high-risk platooning events.

[0109] In the two platooning events of the abnormal information identified as "44d22eac-5591-49d4-b8d5-df9ab0e18952", the events in the first platooning event include: E1: 0x0101, E2: 0x1101, and E3: 0x3101, and the concatenated abnormal score TotalValue of the platooning event is: 10.475, the events in the second platooning event include: E1: 0x3201, E2: 0x3401, E3: 0x3501, and the concatenated abnormal score TotalValue of the platooning event is: 6.496, then the average of the two platooning events of the abnormal information identified as "44d22eac-5591-49d4-b8d5-df9ab0e18952" is (10.475+6.496) / 2=8.486 points<10 points, then the two platooning events of the abnormal information identified as "44d22eac-5591-49d4-b8d5-df9ab0e18952" are also not high-risk platooning events.

[0110] In the two platooning events of the abnormal information identified as "67f556c7-6967-4eac-ba70-6c13fa6f2b3f", the events in the first platooning event include: E1: 0x1101, E2: 0x3101 and E3: 0x3201, and the concatenated abnormal score TotalValue of the platooning event is: 16.618, the events in the second platooning event include: E1: 0x3301, E2: 0x3401 and E3: 0x3501, and the concatenated abnormal score TotalValue of the platooning event is: 12.080, then the average of the two platooning events of the abnormal information identified as "44d22eac-5591-49d4-b8d5-df9ab0e18952" is (16.618+12.080) / 2=14.349 points>10 points, then the two platooning events of the abnormal information identified as "67f556c7-6967-4eac-ba70-6c13fa6f2b3f" are high-risk platooning events, that is, infringement events. By analogy, it can be determined whether the platooning events of all abnormal information are high-risk platooning events.

[0111] Table 3

[0112]

[0113]

[0114] Further, the server determines, for each abnormal information whose platooning event is a high-risk platooning event, an associated trust value corresponding to each high-risk platooning event of the abnormal information according to the frequency of occurrence of each high-risk platooning event of the abnormal information in each time window and the lower limit of the trust tolerance score of each high-risk platooning event, wherein the associated trust value represents the trust degree of each high-risk platooning event of the abnormal information as an abnormal platooning event with an associated relationship, and the higher the associated trust value, the higher the trust degree of each high-risk platooning event of the abnormal information as an abnormal platooning event with an associated relationship. In implementation, the lower limit of the trust tolerance score of different platooning events can be set in advance according to the importance of the influence of the platooning events of different abnormal type combinations on information abnormality.

[0115] In specific implementation, the associated trust value corresponding to each high-risk platooning event of the abnormal information can be determined according to the flow as shown in Figure 4 , which includes the following steps:

[0116] S41, for each high-risk platooning event corresponding to the abnormal information, determining a weight of the high-risk platooning event according to the frequency of occurrence of the high-risk platooning event in each time window.

[0117] In implementation, for each abnormal information corresponding to a high-risk platoon event, the weight of each high-risk platoon event corresponding to the abnormal information can be determined in the following manner:

[0118] The ratio of the frequency of each high-risk platoon event in each time window to the total frequency of all high-risk platoon events of the abnormal information in each time window is determined as the weight of each high-risk platoon event. Taking the abnormal information with the identifier "67f556c7-6967-4eac-ba70-6c13fa6f2b3f" in Table 3 as an example, assuming that the frequencies of the platoon events {E1: 0x1101, E2: 0x3101, E3: 0x3201} and {E1: 0x3301, E2: 0x3401, E3: 0x3501} in all time windows are 4 and 6 respectively, the weight of the platoon event {E1: 0x1101, E2: 0x3101, E3: 0x3201} is 4 / (4+6)=0.4, and the weight of the platoon event {E1: 0x3301, E2: 0x3401, E3: 0x3501} is 6 / (4+6)=0.6.

[0119] S42, determining the associated confidence value of each high-risk platoon event corresponding to the abnormal information according to the weight corresponding to each high-risk platoon event and the lower limit of the confidence tolerance score of each high-risk platoon event.

[0120] In implementation, the associated confidence value of each high-risk platoon event corresponding to the abnormal information can be determined in the following steps:

[0121] Step one, determining the confidence value corresponding to each high-risk platoon event according to the weight corresponding to each high-risk platoon event and the lower limit of the confidence tolerance score of each high-risk platoon event, wherein the confidence value corresponding to the high-risk platoon event represents the confidence of the high-risk platoon event being an abnormal platoon event.

[0122] In implementation, for each high-risk platoon event of the abnormal information, the confidence value corresponding to the high-risk platoon event can be calculated by the following confidence model:

[0123]

[0124] wherein T i represents the confidence value of the i-th high-risk platoon event of the abnormal information;

[0125] ω i represents the weight of the i-th high-risk platoon event of the abnormal information;

[0126] x i a cascade abnormal score of an i-th high-risk platoon event representing abnormal information;

[0127] u i a lower limit of a trust tolerance score of the i-th high-risk platoon event representing abnormal information;

[0128] α and β are adjustment coefficients, and values of α and β can be set according to empirical values in advance.

[0129] The trust evaluation value of a single cascade event of abnormal information can be calculated through the trust model.

[0130] Step two, determining the corresponding correlation trust value of each high-risk platoon event according to the corresponding trust value of each high-risk platoon event.

[0131] In specific implementation, the weighted average value of the trust values of the high-risk platoon events of abnormal information can be determined as the corresponding correlation trust value of each high-risk platoon event of the abnormal information.

[0132] Specifically, the corresponding correlation trust value of each high-risk platoon event of abnormal information can be calculated through the following correlation trust model:

[0133]

[0134] wherein, T represents the corresponding correlation trust value of each high-risk platoon event of abnormal information, and N is the number of high-risk platoon events of abnormal information.

[0135] The overall trust evaluation value of abnormal information can be calculated through the correlation trust model.

[0136] S15, evaluating abnormal information based on the correlation trust value to obtain an evaluation result.

[0137] In specific implementation, if the corresponding correlation trust value of each high-risk platoon event of abnormal information is greater than a set threshold value, it is determined that multiple high-risk platoon events of abnormal information are triggered in parallel, and the multiple high-risk platoon events of abnormal information can be considered as possible cascading abnormal events, wherein the set threshold value can be set according to empirical values, for example, it can be set as 15, and the present embodiment is not limited in this regard.

[0138] In the present embodiment, the trust evaluation value of a single cascade event of abnormal information can be calculated according to the trust model, and the overall trust evaluation value of abnormal information can be calculated according to the correlation trust model, assuming that event A is an important influential event, according to the sensitivity influence degree and correlation of the corresponding cascade events of event A on the overall risk, a closely related interval can be obtained, which provides a basis for security management of data security problems, and if an abnormality occurs in an upstream event in the security management link, the data can be timely alarmed and prevented from continuing to be leaked.

[0139] The abnormal data evaluation method, device, electronic equipment and storage medium provided by the embodiments of the present application, the server obtains the association information of the abnormal information of the specified abnormal type in the specified time range in the specified application, the association information of the abnormal information includes the identification information of the abnormal information, the abnormal occurrence time information, and the preset abnormal score information corresponding to the specified abnormal type; according to the preset time window, the abnormal information of each different abnormal type with the same identification is generated according to the chronological order of the abnormal occurrence time, and the corresponding queuing event of the abnormal information in each time window is generated; for each queuing event corresponding to each abnormal information with the same identification, the cascading abnormal score corresponding to the queuing event is determined according to the preset abnormal score information corresponding to each abnormal type in the queuing event; if it is determined that each queuing event corresponding to the abnormal information is a high-risk queuing event of the abnormal information based on the cascading abnormal score of each queuing event corresponding to the abnormal information and the preset threshold, then the association confidence value corresponding to each high-risk queuing event of the abnormal information is determined according to the frequency of each high-risk queuing event of the abnormal information appearing in each time window and the lower limit of the confidence tolerance value, and the association confidence value represents the confidence of each high-risk queuing event of the abnormal information as an abnormal queuing event with an association relationship; the abnormal information is evaluated based on the association confidence value to obtain an evaluation result. In the embodiments of the present application, the corresponding preset abnormal score is set according to the different abnormal types of information in advance, for each abnormal information with the same identification obtained from the specified application, the queuing events of each different abnormal type of the abnormal information in each time window are generated according to the chronological order of the abnormal occurrence time according to the preset time window, and then the cascading abnormal score corresponding to each queuing event is determined, and the preset threshold is used to determine whether each queuing event is a high-risk queuing event corresponding to the abnormal information, if so, the association confidence value corresponding to each high-risk queuing event of the abnormal information is further determined, that is, the confidence of each high-risk queuing event as an abnormal queuing event with an association relationship. Since the user can specify the association information of the abnormal information obtained from multiple applications in advance, for each abnormal information with the same identification, the queuing events are generated by associating the abnormal information of different specified abnormal types, the cascading abnormal score of the queuing event is calculated to determine whether it is a high-risk queuing event, and the confidence of the high-risk queuing event of the abnormal information is evaluated, so that the root cause of the abnormal information can be more accurately evaluated, which is suitable for data security event analysis and tracing of multiple business-related applications in an enterprise, without the need to reconstruct and preset different security strategies for each application, and the efficiency of abnormal data analysis is improved.

[0140] Based on the same inventive concept, the embodiments of the present application also provide an abnormal data evaluation device. Since the principle of solving the problem of the above-mentioned abnormal data evaluation device is similar to that of the above-mentioned abnormal data evaluation method, the implementation of the above-mentioned device can be referred to the implementation of the method, and the repeated parts will not be described again.

[0141] As Figure 5 shown, it is a structural schematic diagram of an abnormal data evaluation device provided by an embodiment of the application, which can include:

[0142] The acquisition unit 51 is configured to acquire associated information of abnormal information of a specified abnormal type in a specified time range in a specified application, wherein the associated information of the abnormal information includes identification information of the abnormal information, abnormal occurrence time information, and preset abnormal score information corresponding to the specified abnormal type.

[0143] The generation unit 52 is configured to generate corresponding platoon events of the abnormal information in each time window according to the abnormal occurrence time in sequence of each different abnormal type of abnormal information identified in the same manner according to a preset time window.

[0144] The first determination unit 53 is configured to determine a cascading abnormal score corresponding to each platoon event according to the preset abnormal score information corresponding to each abnormal type in the platoon event for each platoon event corresponding to each abnormal information identified in the same manner.

[0145] The second determination unit 54 is configured to determine, if each platoon event corresponding to the abnormal information is a high-risk platoon event of the abnormal information based on the cascading abnormal score of each platoon event corresponding to the abnormal information and a preset threshold value, an associated trust value corresponding to each high-risk platoon event of the abnormal information according to the frequency of occurrence of each high-risk platoon event of the abnormal information in each time window and a lower limit of a trust tolerance value, wherein the associated trust value represents the trust degree of each high-risk platoon event of the abnormal information as abnormal platoon events having an associated relationship.

[0146] The evaluation unit 55 is configured to evaluate the abnormal information based on the associated trust value to obtain an evaluation result.

[0147] In an embodiment, the first determination unit 53 is specifically configured to determine a sub-cascading abnormal score corresponding to each platoon event in each time window according to the preset abnormal score information corresponding to each abnormal type in the platoon event for each platoon event corresponding to each abnormal information identified in the same manner in each time window; and determine the mean value of each sub-cascading abnormal score of each platoon event as the cascading abnormal score of each platoon event, respectively.

[0148] In one embodiment, the first determining unit 53 is specifically configured to determine, for each queuing event corresponding to each abnormal information with the same identifier in each time window, a sub-cascade abnormality score corresponding to the queuing event in each time window in the following manner: determining a second-level abnormality score corresponding to the queuing event based on preset abnormality score information corresponding to the first abnormality type and the preset abnormality score information corresponding to the second abnormality type of the abnormal information in the queuing event in the time window; determining, for each level after the second level, a current-level abnormality score based on the preset abnormality score information of the current abnormality type of the abnormal information and the abnormality score of the previous level; and determining a sub-cascade abnormality score corresponding to the queuing event of the abnormal information in the time window based on the abnormality scores of each level.

[0149] In one embodiment, the second determining unit 54 is specifically configured to determine that each of the teaming events corresponding to the abnormal information is a high-risk teaming event corresponding to the abnormal information if the average of the cascade abnormality scores of the teaming events corresponding to the abnormal information is greater than the preset threshold.

[0150] In one embodiment, the second determining unit 54 is specifically configured to determine, for each high-risk teaming event corresponding to the abnormal information, a weight of the high-risk teaming event according to the frequency of occurrence of the high-risk teaming event in each time window; and determine an associated credible value corresponding to each high-risk teaming event of the abnormal information according to the weight corresponding to each high-risk teaming event and the lower limit of the credible tolerance score of each high-risk teaming event.

[0151] In one embodiment, the second determination unit is specifically used to determine the credible value corresponding to each high-risk teaming event according to the weight corresponding to each high-risk teaming event and the lower limit of the credible tolerance score of each high-risk teaming event, wherein the credible value corresponding to the high-risk teaming event represents the credibility of the high-risk teaming event as an abnormal teaming event; and determine the associated credible value corresponding to each high-risk teaming event according to the credible value corresponding to each high-risk teaming event.

[0152] Based on the same technical concept, the embodiment of the present application further provides an electronic device 600, referring to Figure 6 As shown, electronic device 600 is used to implement the abnormal data assessment method described in the above method embodiments. Electronic device 600 of this embodiment may include: memory 601, processor 602, and a computer program stored in the memory and executable on the processor, such as an abnormal data assessment program. When the processor executes the computer program, the steps of each of the above abnormal data assessment method embodiments are implemented.

[0153] The specific connection medium between the storage 601 and the processor 602 is not limited in the embodiments of the present application. In the embodiments of the present application, the storage 601 and the processor 602 are connected through a bus 603, and the bus 603 is represented by a thick line in the embodiments of the present application. Figure 6 The connection mode between other components is only schematically illustrated, and is not limited. The bus 603 can be divided into an address bus, a data bus, a control bus, etc. For convenience of representation, only one thick line is used to represent the bus 603 in the embodiments of the present application, but it does not mean that there is only one bus or only one type of bus. Figure 6 Figure 6

[0154] The storage 601 can be a volatile memory, for example, a random-access memory (RAM), or a non-volatile memory, for example, a read-only memory, a flash memory, a hard disk drive (HDD) or a solid-state drive (SSD), or the storage 601 can be any other medium capable of carrying or storing desired program codes in the form of instructions or data structures and capable of being accessed by a computer, but is not limited to this. The storage 601 can be a combination of the above storage.

[0155] The processor 602 is configured to implement the abnormal data evaluation method provided by the embodiments of the present application.

[0156] The embodiments of the present application further provide a computer readable storage medium storing computer executable instructions required for the processor to execute, which contains a program for the processor to execute.

[0157] In some possible implementation manners, each aspect of the abnormal data evaluation method provided by the present application can also be implemented in the form of a program product, which includes program codes for causing an electronic device to perform the steps in the abnormal data evaluation method according to the various exemplary embodiments of the present application described in the specification when the program product is run on the electronic device.

[0158] Those skilled in the art should understand that the embodiments of the present application can be provided in the form of a method, device, or computer program product. Therefore, the present application can be in the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can be in the form of a computer program product implemented on one or more computer usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer usable program codes.​​

[0159] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks. Figure 1 one or more flowcharts and / or blocks Figure 1 means for functionally implementing the steps listed in the flowchart block or blocks.

[0160] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the function specified in the flowchart block or blocks. Figure 1 one or more flowcharts and / or blocks Figure 1 means for functionally implementing the steps listed in the flowchart block or blocks.

[0161] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks. Figure 1 one or more flowcharts and / or blocks Figure 1 means for functionally implementing the steps listed in the flowchart block or blocks.

[0162] While the preferred embodiments of the application have been described, additional variations and modifications can be employed by those skilled in the art. Therefore, the claimed application is intended to cover all such additional variations and modifications as fall within the true spirit and scope of the application. The appended claims are intended to be construed to embrace all such additional variations and modifications.

[0163] Obviously, numerous modifications and variations of the present application are possible in light of the above teachings. It is therefore to be understood that within the scope of the appended claims and their equivalents, the application can be practiced otherwise than as specifically described.< / abnormalevents>

Claims

1. An abnormal data evaluation method characterized by, The method comprises: obtaining associated information of abnormal information of a specified abnormal type in a specified time range in a specified application, the associated information of the abnormal information comprising identification information of the abnormal information, abnormal occurrence time information, and preset abnormal score information corresponding to the specified abnormal type; generating corresponding platoon events of the abnormal information in each time window according to the order of abnormal occurrence time of each abnormal information of different abnormal types with the same identification according to a preset time window; for each platoon event corresponding to each abnormal information with the same identification, determining a cascading abnormal score corresponding to the platoon event according to preset abnormal score information corresponding to each abnormal type in the platoon event, specifically comprising: for each platoon event corresponding to each abnormal information with the same identification in each time window, determining a sub-cascading abnormal score corresponding to the platoon event in the each time window according to preset abnormal score information corresponding to each abnormal type in the platoon event; determining the mean value of each sub-cascading abnormal score of each platoon event as the cascading abnormal score of each platoon event; wherein for each platoon event corresponding to each abnormal information with the same identification in each time window, the sub-cascading abnormal score corresponding to the platoon event in the each time window is determined by: determining a two-layer abnormal score corresponding to the platoon event according to preset abnormal score information corresponding to a first abnormal type and preset abnormal score information corresponding to a second abnormal type of the abnormal information in the platoon event in the time window; for each layer after the two-layer, determining a current layer abnormal score according to preset abnormal score information of a current abnormal type of the abnormal information and a previous layer abnormal score; determining the sub-cascading abnormal score corresponding to the platoon event of the abnormal information in the time window according to each layer abnormal score; if it is determined that each platoon event corresponding to the abnormal information is a high-risk platoon event of the abnormal information based on the cascading abnormal score of each platoon event corresponding to the abnormal information and a preset threshold, determining an associated trust value corresponding to each high-risk platoon event of the abnormal information according to the frequency of occurrence of each high-risk platoon event of the abnormal information in each time window and a lower limit of a trust tolerance value, the associated trust value representing the trust degree of each high-risk platoon event of the abnormal information as abnormal platoon events with an associated relationship; performing evaluation on the abnormal information based on the associated trust value to obtain an evaluation result.

2. The method of claim 1, wherein, determining that each platoon event corresponding to the abnormal information is a high-risk platoon event of the abnormal information based on the cascading abnormal score of each platoon event corresponding to the abnormal information and a preset threshold, specifically comprising: if it is determined that the mean value of the cascading abnormal score of each platoon event corresponding to the abnormal information is greater than the preset threshold, it is determined that each platoon event corresponding to the abnormal information is a high-risk platoon event of the abnormal information.

3. The method of claim 1, wherein, The associated trust value corresponding to each high-risk convoy event of the abnormal information is determined according to the frequency of occurrence of each high-risk convoy event of the abnormal information in each time window and the lower limit of the trust tolerance score value, and specifically includes: For each high-risk convoy event corresponding to the abnormal information, the weight of the high-risk convoy event is determined according to the frequency of occurrence of the high-risk convoy event in each time window. The associated trust value corresponding to each high-risk convoy event of the abnormal information is determined according to the weight corresponding to each high-risk convoy event and the lower limit of the trust tolerance score value of each high-risk convoy event.

4. The method of claim 3, wherein, The associated trust value corresponding to each high-risk convoy event of the abnormal information is determined according to the weight corresponding to each high-risk convoy event and the lower limit of the trust tolerance score value of each high-risk convoy event, and specifically includes: The trust value corresponding to each high-risk convoy event is determined according to the weight corresponding to each high-risk convoy event and the lower limit of the trust tolerance score value of each high-risk convoy event, respectively. The trust value corresponding to the high-risk convoy event represents the trustworthiness of the high-risk convoy event as an abnormal convoy event. The associated trust value corresponding to each high-risk convoy event is determined according to the trust value corresponding to each high-risk convoy event.

5. An abnormal data evaluation device characterized by comprising: It includes: An acquisition unit is configured to acquire associated information of abnormal information of a specified abnormal type in a specified time range in a specified application, wherein the associated information of the abnormal information includes identification information of the abnormal information, abnormal occurrence time information, and preset abnormal score information corresponding to the specified abnormal type; A generation unit is configured to generate corresponding convoy events of the abnormal information in each time window according to the order of abnormal occurrence time of each different abnormal type of abnormal information with the same identification according to a preset time window. A first determination unit is configured to determine a cascade abnormal score corresponding to each convoy event for each abnormal information with the same identification according to preset abnormal score information corresponding to each abnormal type in the convoy event. The first determination unit is specifically configured to determine a sub-cascade abnormal score corresponding to each convoy event in each time window for each abnormal information with the same identification according to preset abnormal score information corresponding to each abnormal type in the convoy event. The average of each sub-cascade abnormal score of each convoy event is determined as the cascade abnormal score of each convoy event. The first determining unit is specifically configured to determine, for each queuing event corresponding to the same abnormal information in each time window, a sub cascade abnormal score of the queuing event in the time window by: determining a two-level abnormal score corresponding to the queuing event according to preset abnormal score information corresponding to a first abnormal type and preset abnormal score information corresponding to a second abnormal type of the abnormal information in the queuing event in the time window; and determining, for each level after the two levels, a current level abnormal score according to preset abnormal score information of a current abnormal type of the abnormal information and a previous level abnormal score. The sub cascade abnormal score of the queuing event of the abnormal information in the time window is determined according to the abnormal scores of the respective levels. The second determining unit is configured to determine, if it is determined that the queuing events corresponding to the abnormal information are high-risk queuing events of the abnormal information based on the cascade abnormal scores of the queuing events corresponding to the abnormal information and a preset threshold, a correlation credibility value corresponding to each high-risk queuing event of the abnormal information according to a frequency of occurrence of each high-risk queuing event of the abnormal information in each time window and a lower limit of a credible tolerance score of the high-risk queuing event, the correlation credibility value representing a credibility of the high-risk queuing event of the abnormal information as an abnormal queuing event having a correlation relationship. The evaluation unit is configured to evaluate the abnormal information based on the correlation credibility value to obtain an evaluation result.

6. The apparatus of claim 5, wherein The second determining unit is specifically configured to determine, if it is determined that a mean value of the cascade abnormal scores of the queuing events corresponding to the abnormal information is greater than the preset threshold, that the queuing events corresponding to the abnormal information are high-risk queuing events of the abnormal information.

7. The apparatus of claim 5, wherein The second determining unit is specifically configured to determine, for each high-risk queuing event of the abnormal information, a weight of the high-risk queuing event according to a frequency of occurrence of the high-risk queuing event in each time window; and determine a correlation credibility value corresponding to each high-risk queuing event of the abnormal information according to the respective weights of the high-risk queuing events and the lower limit of the credible tolerance score of each high-risk queuing event.

8. The apparatus of claim 7, wherein The second determining unit is specifically configured to determine, for each high-risk queuing event, a credibility value corresponding to the high-risk queuing event according to the respective weight of the high-risk queuing event and the lower limit of the credible tolerance score of the high-risk queuing event, the credibility value corresponding to the high-risk queuing event representing a credibility of the high-risk queuing event as an abnormal queuing event; and determine the correlation credibility value corresponding to the high-risk queuing events according to the credibility values corresponding to the high-risk queuing events. The processor implements the abnormal data evaluation method of any one of claims 1-4 when executing the program. The program is executed by the processor to implement the steps in the abnormal data evaluation method of any one of claims 1-4.

9. An electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, ​ 10. A computer-readable storage medium having stored thereon a computer program, characterized in that, ​

Citation Information

Patent Citations

  • Cybersecurity risk analysis and anomaly detection using active and passive external reconnaissance

    US20210360032A1