Network security incident handling methods, equipment, devices and readable storage media

CN116996275BActive Publication Date: 2026-08-14CHINA MOBILE GROUP JIANGSU +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-07-18
Publication Date
2026-08-14

AI Technical Summary

Technical Problem

[0005]本发明的主要目的在于提供一种网络安全事件处理方法、设备、装置及可读存储介质,旨在解决现有网络安全事件处理方式,难以应对复杂的网络安全事件的技术问题

Benefits of technology

[0046]在本发明提供的一个技术方案中,电子政务区块链平台根据处理请求的节点类型标识,确定对应的目标事件处理节点,进而根据监管对象和所涉及的办理渠道,确定对应的智能合约,最后采用该智能合约对网络安全事件进行处理。本方案按照监管对象和办理渠道,采用对应的智能合约,能够实现针对不同节点和安全程度的特定化处理,做到了细粒度区分响应不同类型网络安全事件,使得不同情况的网络安全事件都可以得到妥善处理,满足电子政务的安全需求。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116996275B_ABST
    Figure CN116996275B_ABST
Patent Text Reader

Abstract

This invention discloses a method, device, apparatus, and readable storage medium for handling cybersecurity incidents, belonging to the field of security technology. The method includes: when an e-government blockchain platform receives a request for handling a cybersecurity incident, determining the target incident handling node corresponding to the request based on the node type identifier of the request; determining the corresponding smart contract based on the supervised object of the target incident handling node and the relevant processing channels; and processing the cybersecurity incident according to the smart contract. This invention employs different smart contracts to handle cybersecurity incidents sent from different types of e-government nodes, aiming to meet the security needs of e-government.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of security technology, and in particular to methods, devices, apparatuses and readable storage media for handling network security incidents. Background Technology

[0002] In the process of serving the public, government agencies can fully utilize modern information technology, network technology, and office automation technology for office work, management, and providing public services to the public.

[0003] In the process of e-government management, a general approach is adopted to handle cybersecurity incidents. This involves automatically collecting cybersecurity incidents through detection programs, then performing security incident analysis, such as classifying them according to preset event types and security levels, to determine the events that need to be handled, and finally generating security alerts and sending them to the corresponding processing nodes.

[0004] However, cybersecurity incidents are becoming increasingly diverse. Some are relatively simple and can be handled easily, while others are more complex and require more sophisticated measures. Applying the same generic approach to all cybersecurity incidents would not meet the security requirements of e-government. Summary of the Invention

[0005] The main objective of this invention is to provide a network security incident handling method, device, apparatus, and readable storage medium, aiming to solve the technical problem that existing network security incident handling methods are unable to cope with complex network security incidents.

[0006] To achieve the above objectives, the present invention provides a network security incident handling method, which includes the following steps:

[0007] When the e-government blockchain platform receives a request to process a cybersecurity incident, it determines the target event processing node corresponding to the request based on the node type identifier of the request.

[0008] Based on the regulatory object of the target event processing node and the processing channels involved, determine the corresponding smart contract;

[0009] The cybersecurity incident is handled according to the smart contract.

[0010] Optionally, the step of determining the corresponding smart contract based on the supervised object of the target event processing node and the processing channel involved includes:

[0011] If the target event processing node only includes e-government processing nodes; or

[0012] The target event processing node includes the e-government processing node and the e-government channel supervision node, and the channel identifiers corresponding to the two nodes are different, then the first smart contract is determined;

[0013] The processing request includes a type identifier for the cybersecurity incident and an identifier for the e-government processing channel. The steps for processing the cybersecurity incident according to the smart contract include:

[0014] Based on the type identifier of the cybersecurity incident, determine the type of cybersecurity incident, and based on the e-government processing channel identifier, determine the corresponding target channel supervision node;

[0015] If the type of the network security incident is a nuisance, then the corresponding target incident processing node shall be assigned reporting authority and the authority to suspend government affairs processing and eliminate risks.

[0016] The target event processing node reports the network security event to the target channel monitoring node based on the reporting authority;

[0017] The target event processing node, based on the government affairs processing suspension and risk elimination permissions, takes government affairs processing suspension and risk elimination actions.

[0018] Optionally, after the step of the target event processing node reporting the network security event to the target channel monitoring node based on the reporting authority, the process includes:

[0019] The target event processing node sends the reporting permission to the target channel monitoring node;

[0020] The target channel monitoring node sends the reporting permission to the e-government blockchain platform and receives the notification permission returned by the e-government blockchain platform;

[0021] The target channel monitoring node sends a network security incident notification based on the notification permissions.

[0022] Optionally, after the steps of determining the type of network security incident based on the type identifier of the network security incident and determining the corresponding target channel supervision node based on the e-government processing channel identifier, the method further includes:

[0023] If the type of the cybersecurity incident is non-harmful, then the target channel monitoring node is assigned the authority to handle public opinion suppression.

[0024] Based on the public opinion elimination and processing authority, the target channel monitoring node sends public opinion clarification information to the e-government processing nodes within the monitoring area and the servers of the corresponding channel operators.

[0025] Optionally, the step of determining the corresponding smart contract based on the supervised object of the target event processing node and the processing channel involved includes:

[0026] If the target event processing node only includes e-government channel supervision nodes; or

[0027] The target event processing node includes the e-government processing node and the e-government channel supervision node, and the channel identifiers corresponding to the two nodes are different, then the second smart contract is determined;

[0028] The processing request includes a type identifier of the cybersecurity incident and an identifier of the regulated processing channel. The steps for processing the cybersecurity incident according to the smart contract include:

[0029] Based on the type identifier of the cybersecurity incident, determine the type of cybersecurity incident, and based on the identifier of the monitored processing channel, determine the corresponding channel operator and the corresponding e-government processing node;

[0030] If the network security incident is of the type of attack with strong diffusion, then the corresponding target event processing node shall be assigned notification permissions;

[0031] Based on the notification permissions, the target event processing node sends event notification information to each of the e-government processing nodes and the channel operator.

[0032] Optionally, after the steps of determining the type of network security incident based on the type identifier of the network security incident, and determining the corresponding channel operator and the corresponding e-government processing node based on the identifier of the monitored processing channel, the process includes:

[0033] If the network security incident is of a non-aggressive, high-spreading type, then assign public opinion suppression processing permissions to the corresponding target event processing node.

[0034] Based on the public opinion elimination processing authority, the target event processing node sends public opinion clarification information to each of the e-government processing nodes.

[0035] Optionally, the step of determining the corresponding smart contract based on the supervised object of the target event processing node and the processing channel involved includes:

[0036] If the target event processing node includes an e-government processing node and an e-government channel supervision node, and the channel identifiers corresponding to the two nodes are the same, then a third smart contract is determined.

[0037] The processing request includes an e-government processing channel identifier and an e-government type identifier. The steps for processing the cybersecurity incident according to the smart contract include:

[0038] Based on the identified channel for processing under supervision, the corresponding channel operator is determined, and based on the identified type of e-government, the corresponding type of e-government is determined.

[0039] The e-government type identifier is sent to the channel operator, and the channel operator's server, upon receiving the e-government type identifier, refuses to process the application.

[0040] Furthermore, to achieve the above objectives, the present invention also provides a network security incident handling device, the device comprising:

[0041] The first determining module is used to determine the target event processing node corresponding to the processing request based on the node type identifier of the processing request when receiving a processing request for a network security event.

[0042] The second determining module determines the corresponding smart contract based on the regulatory object of the target event processing node and the processing channels involved.

[0043] The processing module processes the network security event according to the smart contract.

[0044] Furthermore, to achieve the above objectives, the present invention also provides a network security incident handling device. The device includes: a memory, a processor, and a network security incident handling program stored in the memory and executable on the processor. The network security incident handling program is configured to implement the steps of the network security incident handling method.

[0045] In addition, to achieve the above objectives, the present invention also provides a readable storage medium storing a network security incident handling program, which, when executed by a processor, implements the steps of the network security incident handling method.

[0046] In one technical solution provided by this invention, the e-government blockchain platform determines the corresponding target event processing node based on the node type identifier of the processing request. Then, based on the regulated object and the involved processing channel, it determines the corresponding smart contract, and finally uses this smart contract to process the cybersecurity incident. This solution, by using corresponding smart contracts according to the regulated object and processing channel, enables specific processing for different nodes and security levels. It achieves fine-grained differentiation and response to different types of cybersecurity incidents, ensuring that cybersecurity incidents in various situations can be properly handled and meeting the security requirements of e-government. Attached Figure Description

[0047] Figure 1 This is a flowchart illustrating the first embodiment of the network security incident handling method of the present invention;

[0048] Figure 2 This is a flowchart illustrating the second embodiment of the network security incident handling method of the present invention;

[0049] Figure 3 This is a flowchart illustrating the second embodiment of the network security incident handling method of the present invention;

[0050] Figure 4 This is a flowchart illustrating the second embodiment of the network security incident handling method of the present invention;

[0051] Figure 5 This is a flowchart illustrating the third embodiment of the network security incident handling method of the present invention;

[0052] Figure 6 This is a flowchart illustrating the fourth embodiment of the network security incident handling method of the present invention;

[0053] Figure 7 This is a schematic diagram of the network security event processing device in the hardware operating environment involved in the embodiments of the present invention.

[0054] The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0055] It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.

[0056] Government agencies utilize e-government to improve management and services. Since e-government involves the data of these agencies, how to efficiently handle cybersecurity incidents related to e-government is a current research hotspot.

[0057] The general approach is to automatically collect network security incidents through a detection program, analyze them to determine the incidents that need to be handled, generate security alerts, and send them to the corresponding processing nodes for processing.

[0058] However, cybersecurity incidents are diverse, and the difficulty of handling each type of incident varies. If the above-mentioned general handling methods are used for all of them, the security requirements of e-government cannot be met.

[0059] To address the aforementioned issues, this application employs different smart contracts to handle cybersecurity events sent from different types of e-government nodes, aiming to meet the security requirements of e-government.

[0060] To better understand the above technical solutions, exemplary embodiments of this application will be described in more detail below with reference to the accompanying drawings. Although exemplary embodiments of this application are shown in the drawings, it should be understood that this application can be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided to enable a more thorough understanding of this application and to fully convey the scope of this application to those skilled in the art.

[0061] This invention provides a method for handling network security incidents, referring to... Figure 1 , Figure 1 This is a flowchart illustrating a first embodiment of a network security incident handling method according to the present invention.

[0062] In this embodiment, the network security incident handling method includes:

[0063] Step S11: When the e-government blockchain platform receives a request to process a cybersecurity incident, it determines the target event processing node corresponding to the processing request based on the node type identifier of the processing request.

[0064] E-government matters can include administrative powers and public services. Administrative powers include administrative licensing, administrative penalties, administrative decisions, administrative payments, administrative supervision, administrative rewards, administrative enforcement, administrative confirmation, administrative levies, and other powers. Public services include economic public services, public safety services, and social public services, such as applications for resident permits and student entrepreneurship subsidies.

[0065] E-government processing procedures can be derived through software by streamlining and designing existing e-government service processes. For example, the process for obtaining a residence permit might be: applicant applies - neighborhood committee accepts - neighborhood committee verifies - public security bureau issues - public security bureau produces the permit - public security bureau distributes - public security bureau issues, etc. Generally, e-government processing procedures include several sequentially connected nodes, and each node includes multiple data items that need to be submitted.

[0066] It is understandable that this solution involves e-government processing nodes, e-government channel supervision nodes, and an e-government blockchain platform.

[0067] E-government processing nodes are device nodes that execute the e-government service processing procedures and are responsible for handling e-government matters. Upon receiving a service request initiated by a user through a processing channel, the e-government processing node begins executing the e-government processing procedure. It is understandable that while e-government processing nodes do not concern themselves with the network security of the processing channel, they can obtain the identifier of the channel used by the user for service processing; for example, by parsing the user's service request to obtain the identifier of the corresponding processing channel.

[0068] E-government channel supervision nodes are the equipment nodes that supervise the channels used for processing. These channels include at least: WeChat official accounts, WeChat mini-programs, short video platforms, and browsers; supervision methods include at least: identifying potential risks to the channels and notifying the channel operators of potential risks to their servers.

[0069] The e-government blockchain platform is responsible for allocating permissions to e-government processing nodes and e-government channel supervision nodes, as well as determining the node that sends a cybersecurity incident, the permissions assigned to that node, and the specific content of the cybersecurity incident.

[0070] It is important to note that e-government processing nodes focus solely on the cybersecurity of the e-government processing workflow, while e-government channel supervision nodes focus solely on the cybersecurity of the processing channel itself. In other words, the two types of nodes are responsible for supervising different entities. Furthermore, technical personnel can pre-assign different node type identifiers to the two types of nodes; for example, e-government processing nodes correspond to node type 01, and e-government channel supervision nodes correspond to node type 02.

[0071] Optionally, if a cybersecurity incident is detected during the processing of e-government matters (such as household registration information processing), the e-government processing node will send a cybersecurity incident handling request to the e-government blockchain platform. This request may include: a node type identifier, a cybersecurity incident type identifier, an e-government processing channel identifier, and an e-government type identifier. For example, it can be determined whether a web browsing request sent to the e-government processing node via a browser client has been subjected to a cyberattack, thus determining whether a "cyberattack incident" has occurred during the e-government processing.

[0072] Optionally, if a monitoring node for e-government channels detects a cybersecurity incident on a processing channel (such as a WeChat official account), it will send a cybersecurity incident processing request to the e-government blockchain platform. This request may include: a node type identifier, a cybersecurity incident type identifier, and the identifier of the monitored processing channel. For example, regarding whether a channel poses a risk, it can be determined whether there is a risk of information leakage, i.e., whether an "information breach incident" has occurred; or, it can be determined whether an "information content security incident" has occurred.

[0073] Furthermore, after receiving a request to process a cybersecurity incident, the e-government blockchain platform can determine the corresponding target incident processing node based on the node type identifier carried in the request. For example, if the node type identifier is 01, it corresponds to the e-government processing node; if the node type identifier is 02, it corresponds to the e-government channel supervision node.

[0074] Step S12: Determine the corresponding smart contract based on the supervised object of the target event processing node and the processing channels involved;

[0075] It is understandable that the regulatory targets of e-government processing nodes and e-government channel supervision nodes are different, and the regulatory focus, regulatory methods, and regulatory processes involved in different regulatory targets are different, so different smart contracts need to be preset.

[0076] Optionally, the corresponding smart contract is determined based on the regulatory object of the target event processing node. When the target event processing node only includes e-government processing nodes, its regulatory object is the e-government processing procedure, corresponding to the first smart contract; when the target event processing node only includes e-government channel regulatory nodes, its regulatory object is the processing channel, corresponding to the second smart contract.

[0077] Optionally, when determining which smart contract to use, in addition to referring to the regulatory objects of the target event processing node, the channel identifiers involved by the target event processing node can also be referenced.

[0078] For example, when the target event processing node includes an e-government processing node and an e-government channel supervision node, its supervision objects include the e-government processing process and the processing channel. Based on this, if the two nodes involve different processing channels (such as WeChat official accounts and browsers), then the first smart contract and the second smart contract are used; conversely, if the two nodes involve the same processing channel (such as WeChat official accounts), it indicates that the channel is likely to have very serious security problems, so the third smart contract is used.

[0079] Step S13: Process the network security incident according to the smart contract.

[0080] Optionally, cybersecurity incidents can be handled by referring to the corresponding smart contract and in accordance with its specified security measures, notification recipients, notification methods, etc.

[0081] For example, the first smart contract, corresponding to a cybersecurity event at an e-government processing node, includes measures such as encrypting communication between nodes and performing vulnerability scanning and virus detection on each node; the second smart contract, corresponding to a cybersecurity event at an e-government channel supervision node, includes measures such as notifying the server of the corresponding channel operator to take measures and reminding users of the risks; the third smart contract includes measures such as prohibiting access to the processing channel, etc. This embodiment does not impose specific limitations.

[0082] The server of the channel operator refers to the server of the company that operates the specific channel, such as the WeChat server or the browser client server. The channel operator's server has risk mitigation functions for the channel. For example, it can send public opinion clarification information to users using the channel, upgrade the firewall level of the network devices operated by the operator in the channel, and remove viruses that may be infected by the network devices, etc.

[0083] Understandably, this solution uses an e-government blockchain platform to allocate permissions, which leverages the traceability advantage of blockchain. It allows for subsequent queries to see what cybersecurity incidents different nodes have reported, what permissions they have been assigned, and what risk management measures have been taken. This information is beneficial for analyzing and mining cybersecurity incident handling rules.

[0084] In one technical solution provided in this embodiment, the e-government blockchain platform determines the corresponding target event processing node based on the node type identifier of the processing request. Then, based on the regulated object and the involved processing channel, it determines the corresponding smart contract, and finally uses this smart contract to process the cybersecurity incident. This solution, by using corresponding smart contracts according to the regulated object and processing channel, enables specific processing for different nodes and security levels. It achieves fine-grained differentiation and response to different types of cybersecurity incidents, ensuring that cybersecurity incidents in various situations can be properly handled and meeting the security requirements of e-government.

[0085] Furthermore, refer to Figure 2 A second embodiment of the network security incident handling method of the present invention is proposed. Based on the above... Figure 1 In the illustrated embodiment, the step of determining the corresponding smart contract based on the monitored object of the target event processing node and the relevant processing channel includes:

[0086] Step S21: If the target event processing node only includes e-government processing nodes; or

[0087] The target event processing node includes the e-government processing node and the e-government channel supervision node, and the channel identifiers corresponding to the two nodes are different, then the first smart contract is determined;

[0088] Optionally, the application scenario of the first smart contract is limited, that is, the target event processing node only includes e-government processing nodes; or the target event processing node includes e-government processing nodes and e-government channel supervision nodes. In this case, the channels involved are determined according to the processing requests sent by the two nodes, such as the e-government processing channel identifier in the former request and the supervised processing channel identifier in the latter request. When the processing channel identifier and the supervised processing channel identifier are different, the first smart contract is determined.

[0089] The processing request includes a type identifier for the cybersecurity incident and an identifier for the e-government processing channel. The steps for processing the cybersecurity incident according to the smart contract include:

[0090] Step S22: Determine the type of network security incident based on the type identifier of the network security incident, and determine the corresponding target channel supervision node based on the e-government processing channel identifier;

[0091] Understandably, cybersecurity incidents, including malicious program incidents, cyberattack incidents, information destruction incidents, information content security incidents, equipment and facility failures, catastrophic incidents, and other cybersecurity incidents, are pre-assigned corresponding identifiers for each type of cybersecurity incident; processing channels include WeChat official accounts, WeChat mini programs, short video platforms, browsers, etc., and each processing channel is pre-assigned corresponding identifiers, such as 01 for WeChat official accounts and 02 for WeChat mini programs.

[0092] Optionally, since the processing request includes a type identifier for the cybersecurity incident, the type of cybersecurity incident can be determined based on the pre-defined correspondence between processing channels and identifiers. Similarly, the corresponding processing channel can be determined, and then the e-government channel supervision node corresponding to that processing channel can be identified and defined as the target channel supervision node.

[0093] Step S23: If the type of the network security incident is a nuisance type, then assign reporting permissions and government affairs processing suspension and risk elimination permissions to the corresponding target event processing node;

[0094] Understandably, technical personnel categorize cybersecurity incidents into disruptive and non-disruptive types based on whether they affect the normal operation of e-government. Disruptive incidents include malicious program incidents, cyberattack incidents, and information destruction incidents, while non-disruptive incidents include information content security incidents.

[0095] Optionally, if the type of network security incident is a nuisance, then the corresponding target incident processing node (in this solution, the e-government processing node) is assigned reporting permissions and permissions to suspend government processing and eliminate risks.

[0096] Step S24: The target event processing node reports the network security event to the target channel monitoring node based on the reporting authority;

[0097] Step S25: The target event processing node, based on the government affairs processing suspension and risk elimination permissions, takes government affairs processing suspension and risk elimination operations.

[0098] On one hand, the address of the target channel's monitoring node is used as the reporting target. Then, the target event processing node (i.e., the e-government processing node), based on its reporting authority, reports the cybersecurity incident to the reporting target according to this address. The purpose of this reporting is to enable the target channel's monitoring node to take risk control measures. For example, it can send risk notifications to each e-government processing node within its monitoring scope and the server of the channel operator, notifying each e-government processing node to enable the highest level of firewall and notifying the channel operator to take risk avoidance measures, thereby achieving the goal of avoiding potential cybersecurity incidents faced by e-government processing nodes that handle this type of e-government through this channel.

[0099] On the other hand, the target event processing node, based on the authority to suspend government affairs processing and eliminate risks, suspends government affairs processing and eliminates risks, such as by running antivirus software or notifying operations personnel to eliminate risks.

[0100] Reference Figure 3 After step S24, the following steps are included:

[0101] Step S241: The target event processing node sends the reporting permission to the target channel monitoring node;

[0102] Step S242: The target channel supervision node sends the reporting permission to the e-government blockchain platform and receives the notification permission returned by the e-government blockchain platform;

[0103] Step S243: The target channel monitoring node sends a network security incident notification based on the notification permission.

[0104] Understandably, when target channel monitoring nodes take certain risk control measures, such as sending risk notifications, they may need authorization from the e-government blockchain platform.

[0105] Optionally, in order to enable the target channel monitoring node to easily obtain authorization, in this solution, when the target event processing node (i.e., the e-government processing node) reports a network security incident to the target channel monitoring node, it can simultaneously send its own obtained reporting authority to the target channel monitoring node.

[0106] Furthermore, the target channel monitoring node can use this reporting permission as a credential for obtaining authorization and send it to the e-government blockchain platform. Correspondingly, upon receiving this reporting permission, the e-government blockchain platform can directly assign notification permissions to the target channel monitoring node, including event notification permissions for processing nodes and event notification permissions for channel parties.

[0107] On the one hand, the target channel monitoring node sends security risk event notifications to e-government processing nodes using the corresponding channels based on the event notification permissions for the processing nodes, so as to trigger these processing nodes to take corresponding security precautions, such as raising the firewall level or directly deleting virus programs by running antivirus programs.

[0108] On the other hand, the target channel monitoring node, based on the event notification permissions for the channel party, sends security risk event notifications to the server of the corresponding channel operator to trigger the implementation of corresponding security precautions, such as risk control measures for the channel.

[0109] Reference Figure 4 After step S22, the following is included:

[0110] Step S221: If the type of the network security incident is non-harmful, then assign public opinion elimination processing authority to the target channel monitoring node;

[0111] Step S222: Based on the public opinion elimination processing authority, the target channel monitoring node sends public opinion clarification information to the e-government processing nodes within the monitoring area and the corresponding channel operator's server.

[0112] Optionally, if the type of cybersecurity incident is non-harmful, then the target channel monitoring node is assigned the authority to handle public opinion suppression.

[0113] Furthermore, based on their authority to handle public opinion elimination, the target channel monitoring nodes can, on the one hand, send public opinion clarification information to the e-government processing nodes within their monitoring area. The specific content of the public opinion clarification information can be pre-set, such as reminding users that there is some false information circulating and advising them not to believe it. On the other hand, depending on the processing channel monitored by the target channel monitoring node, they can send public opinion elimination notifications to the servers of the corresponding channel operators to remind them to take public opinion elimination measures, such as sending public opinion clarification information through that channel.

[0114] In one technical solution provided in this embodiment, the application scenario of the first smart contract is specified, and different processing procedures are set for the types of interference and non-interference. In addition, certain permissions are granted to the e-government processing node and the target channel supervision node. In this way, the normal processing of e-government can be carried out without affecting the user's awareness, and the processing of such network events can be completed.

[0115] Furthermore, refer to Figure 5 A third embodiment of the network security incident handling method of the present invention is proposed. Based on the above... Figure 1 In the illustrated embodiment, the step of determining the corresponding smart contract based on the monitored object of the target event processing node and the relevant processing channel includes:

[0116] Step S31: If the target event processing node only includes e-government channel supervision nodes; or

[0117] The target event processing node includes the e-government processing node and the e-government channel supervision node, and the channel identifiers corresponding to the two nodes are different, then the second smart contract is determined;

[0118] Optionally, the application scenario of the second smart contract is limited, that is, the target event processing node only includes the e-government channel supervision node; or the target event processing node includes the e-government processing node and the e-government channel supervision node, and the channel identifiers corresponding to the two nodes are different. The principle of determining the second smart contract is the same as that of the second embodiment, and will not be repeated here.

[0119] The processing request includes a type identifier of the cybersecurity incident and an identifier of the regulated processing channel. The steps for processing the cybersecurity incident according to the smart contract include:

[0120] Step S32: Determine the type of network security incident based on the type identifier of the network security incident, and determine the corresponding channel operator and the corresponding e-government processing node based on the identifier of the monitored processing channel;

[0121] Optionally, the processing request includes a type identifier of the cybersecurity incident and an identifier of the regulated processing channel. Based on the type identifier of the cybersecurity incident, the type of cybersecurity incident is determined, in the same principle as the second embodiment. Based on the identifier of the regulated processing channel, the corresponding processing channel is determined. On the one hand, the channel operator corresponding to the processing channel is determined. On the other hand, the corresponding e-government processing node is determined by querying the pre-set correspondence between processing channels and e-government processing nodes.

[0122] Step S33: If the network security event is of the type of attack with strong diffusion, then assign notification permissions to the corresponding target event processing node;

[0123] Understandably, technical personnel categorize cybersecurity incidents into high-proliferation and non-high-proliferation types based on whether they exhibit strong attack propagation characteristics. High-proliferation types are those that can spread through data downloads and program execution, such as worm incidents and Trojan horse incidents.

[0124] Optionally, if the network security incident is a type of attack with strong diffusion, then notification permissions are assigned to the corresponding target incident processing node (in this solution, the e-government channel supervision node), including incident notification permissions for the processing node and incident notification permissions for the channel party.

[0125] Step S34: The target event processing node sends event notification information to each of the e-government processing nodes and the channel operator based on the notification permissions.

[0126] On the one hand, the target event processing node (i.e., the e-government channel supervision node) obtains the address of the aforementioned e-government processing node based on the event notification permission for the processing node, and then sends security risk event notifications to the e-government processing node according to these addresses, so as to trigger these nodes to take corresponding security precautions, such as increasing the firewall level or directly deleting the virus program by running antivirus programs.

[0127] On the other hand, the target event processing node (i.e., the e-government channel supervision node) sends a security risk event notification to the server of the corresponding channel operator based on the event notification authority of the channel party, so as to trigger the implementation of corresponding security precautions, such as risk control measures for the channel.

[0128] Step S35: If the type of the network security incident is a non-aggressive, high-spreading type, then assign public opinion elimination processing permissions to the corresponding target event processing node;

[0129] Step S36: The target event processing node sends public opinion clarification information to each of the e-government processing nodes based on the public opinion elimination processing authority.

[0130] Optionally, if the type of network security incident is non-aggressive and prone to widespread attack, then the corresponding target incident processing node is assigned the authority to resolve public opinion.

[0131] Furthermore, the target event processing node obtains the addresses of the aforementioned e-government processing nodes based on its public opinion elimination processing authority, and then sends public opinion clarification information to the e-government processing nodes according to these addresses. The specific content of the public opinion clarification information can be preset, such as reminding users that there is some false information circulating and reminding them not to believe it.

[0132] In one technical solution provided in this embodiment, the application scenario of the first smart contract is specified, and different processing procedures are set for attack types with strong diffusion and non-attack types with strong diffusion. In addition, certain permissions are granted to the target channel supervision node. This can be done without affecting the normal processing of e-government and complete the processing of such network events without the user's awareness.

[0133] Furthermore, refer to Figure 6 A fourth embodiment of the network security incident handling method of the present invention is proposed. Based on the above... Figure 1 In the illustrated embodiment, the step of determining the corresponding smart contract based on the monitored object of the target event processing node and the relevant processing channel includes:

[0134] Step S41: If the target event processing node includes an e-government processing node and an e-government channel supervision node, and the channel identifiers corresponding to the two nodes are the same, then determine the third smart contract;

[0135] Optionally, the application scenario of the third smart contract is limited, that is, the target event processing node includes the e-government processing node and the e-government channel supervision node, and the channel identifiers corresponding to the two nodes are the same. The principle of determining the third smart contract is the same as that of the second embodiment, and will not be repeated here.

[0136] The processing request includes an e-government processing channel identifier and an e-government type identifier. The steps for processing the cybersecurity incident according to the smart contract include:

[0137] Step S42: Determine the corresponding channel operator based on the monitored channel identifier, and determine the corresponding e-government type based on the e-government type identifier;

[0138] Optionally, the processing request includes an e-government processing channel identifier and an e-government type identifier. Based on the monitored processing channel identifier, the corresponding processing channel is determined, and then the channel operator corresponding to the processing channel is determined. Based on the e-government type identifier, the corresponding e-government type is determined, in the same principle as the second embodiment.

[0139] Step S43: Send the e-government type identifier to the channel operator, wherein the server of the channel operator, upon receiving the e-government type identifier, refuses to process the application.

[0140] Optionally, by querying the pre-stored channel identifier and the server address of the channel operator, the current server address of the channel operator can be determined, and then a network security incident handling notification, including the e-government type identifier, can be sent to the server of the channel operator based on that address.

[0141] Furthermore, based on the processing notification and the e-government type identifier contained in the notification, the channel operator's server temporarily rejects the user's request to process that type of e-government through the channel, and takes corresponding security precautions, such as raising the firewall level and having technical personnel run antivirus programs to directly delete virus programs.

[0142] In one technical solution provided in this embodiment, the application scenario of the third smart contract is specified, and relevant notifications are sent to the channel operator through the e-government blockchain platform so that the channel operator can perform corresponding processing operations to ensure government security.

[0143] This invention provides an anomaly recording processing device, the device comprising:

[0144] The first determining module is used to determine the target event processing node corresponding to the processing request based on the node type identifier of the processing request when receiving a processing request for a network security event.

[0145] The second determining module determines the corresponding smart contract based on the regulatory object of the target event processing node and the processing channels involved.

[0146] The processing module processes the network security event according to the smart contract.

[0147] Since the embodiments of the apparatus section correspond to the embodiments of the method section, please refer to the description of the embodiments of the method section for the embodiments of the apparatus section, and they will not be repeated here.

[0148] Reference Figure 7 , Figure 7 This is a schematic diagram of the network security event processing device structure of the hardware operating environment involved in the embodiments of the present invention.

[0149] like Figure 7As shown, the network security incident handling device may include: a processor 1001, such as a central processing unit (CPU), a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. The communication bus 1002 is used to enable communication between these components. The user interface 1003 may include a display screen or an input unit such as a keyboard; optionally, the user interface 1003 may also include a standard wired interface or a wireless interface. The network interface 1004 may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface). The memory 1005 may be a high-speed random access memory (RAM) or a stable non-volatile memory (NVM), such as a disk drive. The memory 1005 may also optionally be a storage device independent of the aforementioned processor 1001.

[0150] Those skilled in the art will understand that Figure 7 The structure shown does not constitute a limitation on network security incident handling equipment and may include more or fewer components than shown, or combine certain components, or have different component arrangements.

[0151] like Figure 7 As shown, the memory 1005, which serves as a storage medium, may include an operating system, a data storage module, a network communication module, a user interface module, and a network security incident handling program.

[0152] exist Figure 7 In the network security incident handling device shown, the network interface 1004 is mainly used for data communication with other devices; the user interface 1003 is mainly used for data interaction with users; the processor 1001 and the memory 1005 in the network security incident handling device of the present invention can be set in the network security incident handling device, and the network security incident handling device calls the network security incident handling program stored in the memory 1005 through the processor 1001 and executes the network security incident handling method provided in the embodiment of the present invention.

[0153] This invention provides a readable storage medium storing a computer program, which, when executed by a processor, implements the steps in any of the above embodiments of the network security incident handling method.

[0154] Since the embodiments of the readable storage medium portion correspond to the embodiments of the method portion, please refer to the description of the embodiments of the method portion for the embodiments of the readable storage medium portion, and will not be repeated here.

[0155] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or system that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or system. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or system that includes that element.

[0156] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0157] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above, and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of the present invention.

[0158] The above are merely preferred embodiments of the present invention and do not limit the scope of the patent. Any equivalent structural or procedural transformations made based on the description and drawings of the present invention, or direct or indirect applications in other related technical fields, are similarly included within the scope of patent protection of the present invention.

Claims

1. A method for handling network security incidents, characterized in that, The network security incident handling method includes the following steps: When the e-government blockchain platform receives a request to process a cybersecurity incident, it determines the target event processing node corresponding to the request based on the node type identifier of the request. Based on the regulatory object of the target event processing node and the processing channels involved, determine the corresponding smart contract; The network security incident is handled according to the smart contract; The step of determining the corresponding smart contract based on the monitored object of the target event processing node and the processing channel involved includes: If the target event processing node only includes e-government processing nodes; or The target event processing node includes the e-government processing node and the e-government channel supervision node, and the channel identifiers corresponding to the two nodes are different, then the first smart contract is determined; the e-government processing node is a device node that executes the e-government matter processing procedure, and the e-government channel supervision node is a device node that supervises the processing channel; The processing request includes a type identifier for the cybersecurity incident and an identifier for the e-government processing channel. The steps for processing the cybersecurity incident according to the smart contract include: Based on the type identifier of the cybersecurity incident, determine the type of cybersecurity incident, and based on the e-government processing channel identifier, determine the corresponding target channel supervision node; If the type of the network security incident is a nuisance, then the corresponding target incident processing node shall be assigned reporting authority and the authority to suspend government affairs processing and eliminate risks. The target event processing node reports the network security event to the target channel monitoring node based on the reporting authority; The target event processing node, based on the government affairs processing suspension and risk elimination permissions, takes government affairs processing suspension and risk elimination operations; The step of determining the corresponding smart contract based on the monitored object of the target event processing node and the processing channel involved includes: If the target event processing node only includes e-government channel supervision nodes; or The target event processing node includes the e-government processing node and the e-government channel supervision node, and the channel identifiers corresponding to the two nodes are different, then the second smart contract is determined; The processing request includes a type identifier of the cybersecurity incident and an identifier of the regulated processing channel. The steps for processing the cybersecurity incident according to the smart contract include: Based on the type identifier of the cybersecurity incident, determine the type of cybersecurity incident, and based on the identifier of the monitored processing channel, determine the corresponding channel operator and the corresponding e-government processing node; If the network security incident is of the type of attack with strong diffusion, then the corresponding target event processing node shall be assigned notification permissions; Based on the notification permissions, the target event processing node sends event notification information to each of the e-government processing nodes and the channel operator.

2. The network security incident handling method as described in claim 1, characterized in that, After the step of the target event processing node reporting the network security event to the target channel monitoring node based on the reporting authority, the following steps are included: The target event processing node sends the reporting permission to the target channel monitoring node; The target channel monitoring node sends the reporting permission to the e-government blockchain platform and receives the notification permission returned by the e-government blockchain platform; The target channel monitoring node sends a network security incident notification based on the notification permissions.

3. The network security incident handling method as described in claim 1, characterized in that, After the steps of determining the type of network security event based on the type identifier of the network security event, and determining the corresponding target channel supervision node based on the e-government processing channel identifier, the following steps are included: If the type of the cybersecurity incident is non-harmful, then the target channel monitoring node is assigned the authority to handle public opinion suppression. Based on the public opinion elimination and processing authority, the target channel monitoring node sends public opinion clarification information to the e-government processing nodes within the monitoring area and the servers of the corresponding channel operators.

4. The network security incident handling method as described in claim 1, characterized in that, After the steps of determining the type of network security incident based on the type identifier of the network security incident, and determining the corresponding channel operator and the corresponding e-government processing node based on the identifier of the monitored processing channel, the following steps are included: If the network security incident is of a non-aggressive, high-spreading type, then assign public opinion suppression processing permissions to the corresponding target event processing node. Based on the public opinion elimination processing authority, the target event processing node sends public opinion clarification information to each of the e-government processing nodes.

5. The network security incident handling method as described in claim 1, characterized in that, The step of determining the corresponding smart contract based on the monitored object of the target event processing node and the processing channel involved includes: If the target event processing node includes an e-government processing node and an e-government channel supervision node, and the channel identifiers corresponding to the two nodes are the same, then a third smart contract is determined. The processing request includes an e-government processing channel identifier and an e-government type identifier. The steps for processing the cybersecurity incident according to the smart contract include: Based on the identified channel for processing under supervision, the corresponding channel operator is determined, and based on the identified type of e-government, the corresponding type of e-government is determined. The e-government type identifier is sent to the channel operator, and the channel operator's server, upon receiving the e-government type identifier, refuses to process the application.

6. A network security incident handling device, characterized in that, The device includes: The first determining module is used to determine the target event processing node corresponding to the processing request based on the node type identifier of the processing request when receiving a processing request for a network security event. The second determining module determines the corresponding smart contract based on the regulatory object of the target event processing node and the processing channels involved. The processing module processes the network security incident according to the smart contract; The step of determining the corresponding smart contract based on the monitored object of the target event processing node and the processing channel involved includes: If the target event processing node only includes e-government processing nodes; or The target event processing node includes the e-government processing node and the e-government channel supervision node, and the channel identifiers corresponding to the two nodes are different, then the first smart contract is determined; the e-government processing node is a device node that executes the e-government matter processing procedure, and the e-government channel supervision node is a device node that supervises the processing channel; The processing request includes a type identifier for the cybersecurity incident and an identifier for the e-government processing channel. The steps for processing the cybersecurity incident according to the smart contract include: Based on the type identifier of the cybersecurity incident, determine the type of cybersecurity incident, and based on the e-government processing channel identifier, determine the corresponding target channel supervision node; If the type of the network security incident is a nuisance, then the corresponding target incident processing node shall be assigned reporting authority and the authority to suspend government affairs processing and eliminate risks. The target event processing node reports the network security event to the target channel monitoring node based on the reporting authority; The target event processing node, based on the government affairs processing suspension and risk elimination permissions, takes government affairs processing suspension and risk elimination operations; The step of determining the corresponding smart contract based on the monitored object of the target event processing node and the processing channel involved includes: If the target event processing node only includes e-government channel supervision nodes; or The target event processing node includes the e-government processing node and the e-government channel supervision node, and the channel identifiers corresponding to the two nodes are different, then the second smart contract is determined; The processing request includes a type identifier of the cybersecurity incident and an identifier of the regulated processing channel. The steps for processing the cybersecurity incident according to the smart contract include: Based on the type identifier of the cybersecurity incident, determine the type of cybersecurity incident, and based on the identifier of the monitored processing channel, determine the corresponding channel operator and the corresponding e-government processing node; If the network security incident is of the type of attack with strong diffusion, then the corresponding target event processing node shall be assigned notification permissions; Based on the notification permissions, the target event processing node sends event notification information to each of the e-government processing nodes and the channel operator.

7. A network security incident handling device, characterized in that, The device includes: a memory, a processor, and a network security incident handler stored in the memory and executable on the processor, the network security incident handler being configured to implement the steps of the network security incident handling method as described in any one of claims 1 to 5.

8. A readable storage medium, characterized in that, The readable storage medium stores a network security incident handling program, which, when executed by a processor, implements the steps of the network security incident handling method as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Internet of things alarm management system and method based on block chain

    CN109687993A

  • Network security event processing method and system, block chain platform, electronic equipment and storage medium

    CN114710296A