Method, device, electronic device and storage medium for reporting alarm logs

Through standardized processing and data supplementation of alarm logs, automatic matching of network assets and attack types and filtering of low-quality data are achieved, which solves the problems of manpower and material resource consumption and data accuracy in existing technologies and improves the efficiency and accuracy of alarm log reporting.

CN117938428BActive Publication Date: 2025-09-05BEIJING THREATBOOK TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311687137.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-12-08
Publication Date
2025-09-05
Estimated Expiration
2043-12-08

AI Technical Summary

Technical Problem

Existing technologies cannot automatically match network assets with attack types, and cannot filter low-quality alarm data, causing enterprises to spend a lot of manpower and material resources on massive alarm data and unable to automatically report data as required.

Method used

By standardizing and supplementing the incoming alarm logs, filtering out low-quality data, and automatically matching attack types with network assets, multiple reporting methods are used to ensure data accuracy and efficiency.

Benefits of technology

It improves the efficiency of alarm log reporting, reduces the consumption of manpower and material resources, ensures the accuracy and effectiveness of reported data, and supports multiple reporting methods to meet the needs of different enterprises.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117938428B_ABST
    Figure CN117938428B_ABST
Patent Text Reader

Abstract

The embodiments of the present application provide a method, device, electronic device, and storage medium for reporting an alarm log, wherein the method comprises: obtaining a user's alarm log; performing standardization processing on the alarm log to obtain standardized alarm log data; performing data addition on the standardized alarm log data to obtain data to be reported; filtering the data to be reported to obtain filtered data to be reported; and reporting the filtered data to be reported to obtain a reporting result. By implementing the embodiments of the present application, the accessed alarm logs can be uniformly analyzed and reported, and low-quality alarm data can be filtered according to user needs, thereby improving reporting efficiency, achieving automatic matching of attack types and network assets, and reducing the user's consumption of manpower and material resources.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular to a method, device, electronic device, and storage medium for reporting an alarm log. Background Art

[0002] As network security issues become more prominent, all walks of life are paying more and more attention to network security. Therefore, it is becoming increasingly important to establish a corresponding security situation awareness platform. By collecting alarm data from various units and related enterprises and conducting summary analysis, we can better display the current status of security issues in the entire industry, thereby better controlling and preventing known or unknown security risks.

[0003] Although existing technologies have achieved access and standardization of various security log data, there are still many problems. For example, the data does not support automatic reporting after being sorted, nor can it be reported based on the audit results. It cannot help enterprises free themselves from the complex and massive alarm data. In addition, in existing technologies, low-quality alarm data cannot be filtered as required before the data is reported, and relevant network assets and attack types cannot be automatically matched, resulting in enterprises having to spend more time and energy on the accuracy and effectiveness of the data, consuming a lot of manpower and material resources. Summary of the Invention

[0004] The purpose of the embodiments of the present application is to provide a reporting method, device, electronic device and storage medium for alarm logs, which can uniformly analyze and report the accessed alarm logs, filter low-quality alarm data according to user needs, improve reporting efficiency, realize automatic matching of attack types and network assets, and reduce the user's consumption of manpower and material resources.

[0005] In a first aspect, an embodiment of the present application provides a method for reporting an alarm log, the method comprising:

[0006] Get the user's alarm log;

[0007] Performing standardization processing on the alarm log to obtain standardized alarm log data;

[0008] Performing data supplementation on the standardized alarm log data to obtain data to be reported;

[0009] Filtering the data to be reported to obtain filtered data to be reported;

[0010] The filtered data to be reported is reported to obtain a reporting result.

[0011] In the above implementation process, by standardizing the alarm logs and then supplementing and filtering the data, the accessed alarm logs can be uniformly analyzed and reported, and low-quality alarm data can be filtered according to user needs to improve reporting efficiency, realize automatic matching of attack types and network assets, and reduce the user's consumption of manpower and material resources.

[0012] Furthermore, the step of performing standardization processing on the alarm log to obtain standardized alarm log data includes:

[0013] Parsing the alarm log to obtain a parsed alarm log;

[0014] Field mapping is performed on the parsed alarm log according to field rules to obtain the standardized alarm log data.

[0015] In the above implementation process, the alarm log is parsed and then the parsed alarm log is mapped to fields, which can achieve field-level data standardization and improve the accuracy of standardized alarm log data.

[0016] Furthermore, the step of supplementing the standardized alarm log data to obtain data to be reported includes:

[0017] Acquisition of web assets;

[0018] Supplementing the standardized alarm log data according to the network assets to obtain supplementary data;

[0019] The supplementary data is verified and processed to obtain the data to be reported.

[0020] In the above implementation process, the standardized alarm log data is supplemented according to the network assets to make the obtained supplementary data more complete, thereby improving the efficiency of the verification process and achieving faster verification.

[0021] Furthermore, the step of supplementing the standardized alarm log data according to the network assets to obtain supplementary data includes:

[0022] Matching the standardized alarm log data with the attack fields of the network assets to obtain initial supplementary data;

[0023] Match the initial supplementary data with the network asset by attack type to obtain the supplementary data.

[0024] In the above implementation process, matching the attack fields and attack types with the network assets can quickly expand the standardized alarm log data so that the obtained supplementary data contains more attack fields and attack types.

[0025] Furthermore, the step of matching the attack fields of the standardized alarm log data with the network assets to obtain initial supplementary data includes:

[0026] Matching the standardized alarm log data with the network assets to determine whether an attacked IP field exists in the standardized alarm log data;

[0027] If so, determining the attacked IP field as a first primary key, and obtaining the initial supplementary data according to the first primary key;

[0028] If not, the standardized alarm log data is determined as the initial supplementary data.

[0029] In the above implementation process, by matching the IP field in the standardized alarm log data, it is possible to accurately obtain the attack field IP that may exist in the standardized alarm log data, thereby improving the ability to identify attacks on the data.

[0030] Furthermore, the step of obtaining the initial supplementary data according to the first primary key includes:

[0031] querying each piece of asset data in the network asset according to the first primary key;

[0032] If it is found that asset data corresponding to the first primary key exists in the network assets, the attribute information of the asset data corresponding to the first primary key is added to the standardized alarm log data to obtain the initial supplementary data; wherein, the attribute information includes the ownership system, branch name and region of the asset data corresponding to the first primary key.

[0033] In the above implementation process, each asset data of the network asset is queried according to the first primary key, and the attribute information is added to the standardized alarm log data one by one, which can quickly and accurately expand the standardized alarm log data and improve the generalization ability of the standardized alarm log data.

[0034] Furthermore, the step of matching the initial supplementary data with the network asset according to the attack type to obtain the supplementary data includes:

[0035] Matching the standardized alarm log data with the network assets to determine whether an attack subclassification field exists in the standardized alarm log data;

[0036] If so, determining the attack subclass field as a second primary key, and obtaining the supplementary data according to the second primary key;

[0037] If not, the initial supplementary data is determined as the supplementary data.

[0038] In the above implementation process, matching the attack sub-category field can accurately standardize the attack scope in the alarm log data, improve the efficiency of further confirmation of the attack field, and reduce the error and error probability.

[0039] Furthermore, the step of obtaining the supplementary data according to the second primary key includes:

[0040] querying attack type enumeration data in the network asset according to the second primary key;

[0041] If it is found that attack type enumeration data corresponding to the second primary key exists in the network asset, the attack type code of the attack type enumeration data corresponding to the second primary key is added to the initial supplementary data to obtain the supplementary data.

[0042] In the above implementation process, adding the attack type code to the attack type enumeration data can avoid the subsequent search process for the attack type code, improve the accuracy of matching and query, and make the supplementary data more complete.

[0043] Furthermore, the step of verifying the supplementary data to obtain the data to be reported includes:

[0044] Determine whether the secondary review interface is enabled based on the supplementary data;

[0045] When the secondary review interface is enabled, determining whether the supplementary data meets the conditions for the secondary review; if so, caching the supplementary data and awaiting secondary review; and if not, determining the supplementary data as the data to be reported and updating the status of the data to be reported to "to be reported"; the conditions for the secondary review include the system to which it belongs, the attack type / virus type, and whether it matches malicious intelligence;

[0046] In a case where the secondary audit interface is not enabled, the supplementary data is determined as the data to be reported, and the status of the data to be reported is updated to to be reported.

[0047] In the above implementation process, the supplementary data is checked and processed, and different processing is performed on the supplementary data according to the opening status of the secondary audit interface, so that the attack fields in the supplementary data can be further checked to avoid omissions.

[0048] Furthermore, the step of filtering the data to be reported to obtain filtered data to be reported includes:

[0049] Filtering the data to be reported according to the filtering rules to obtain filtered data to be reported, and updating the status of the filtered data to be reported to filtered;

[0050] The filtering rules include repeated alarm filtering, attack IP filtering, traffic threshold alarm filtering and non-current alarm filtering.

[0051] In the above implementation process, the data to be reported is filtered according to the filtering rules, which reduces the possibility of false filtering during the filtering process and makes the filtered data to be reported more accurate.

[0052] Furthermore, the step of reporting the filtered data to be reported and obtaining a reporting result includes:

[0053] Reporting the filtered data to be reported according to the first reporting method, the second reporting method, and the third reporting method in sequence to obtain corresponding first reporting results, second reporting results, and third reporting results;

[0054] If any one of the first reporting result, the second reporting result, and the third reporting result is a successful report, determining that the reporting result is a successful report, and recording the reporting method corresponding to the successful report result among the first reporting result, the second reporting result, and the third reporting result;

[0055] If the first reporting result, the second reporting result, and the third reporting result are all reporting failures, it is determined that the reporting result is reporting failure.

[0056] In the above implementation process, by reporting according to different reporting methods, the reporting method in which the data is successfully reported can be intuitively known, providing a basis for subsequent data reporting and avoiding repeated reporting failures.

[0057] Furthermore, the step of reporting the filtered data to be reported according to the first reporting method, the second reporting method, and the third reporting method in sequence to obtain the corresponding first reporting result, the second reporting result, and the third reporting result includes:

[0058] Determine whether the interface for the first reporting method is enabled;

[0059] If so, reporting the filtered data to be reported according to the first reporting method to obtain a first reporting result;

[0060] If not, determining whether the interface for the second reporting method is enabled;

[0061] If the interface of the second reporting mode is enabled, reporting the filtered data to be reported according to the second reporting mode to obtain the second reporting result;

[0062] If the interface for the second reporting method is not enabled, determining whether the interface for the third reporting method is enabled;

[0063] If the interface of the third reporting method is enabled, the filtered data to be reported is reported according to the third reporting method to obtain the third reporting result.

[0064] In the above implementation process, the filtered data to be reported is reported in sequence through the first reporting method, the second reporting method and the third reporting method, which can realize the reporting quickly, accurately and effectively, and improve the reporting efficiency.

[0065] In a second aspect, an embodiment of the present application further provides a device for reporting an alarm log, the device comprising:

[0066] Acquisition module, used to obtain the user's alarm log;

[0067] A standardization module, configured to perform standardization processing on the alarm log to obtain standardized alarm log data;

[0068] A supplement module, configured to supplement the standardized alarm log data to obtain data to be reported;

[0069] A filtering module, configured to filter the data to be reported to obtain filtered data to be reported;

[0070] The reporting module is used to report the filtered data to be reported and obtain a reporting result.

[0071] In the above implementation process, by standardizing the alarm logs and then supplementing and filtering the data, the accessed alarm logs can be uniformly analyzed and reported, and low-quality alarm data can be filtered according to user needs to improve reporting efficiency, realize automatic matching of attack types and network assets, and reduce the user's consumption of manpower and material resources.

[0072] In a third aspect, an embodiment of the present application provides an electronic device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the method described in any one of the first aspects when executing the computer program.

[0073] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, on which instructions are stored. When the instructions are executed on a computer, the computer executes the method as described in any one of the first aspects.

[0074] In a fifth aspect, an embodiment of the present application provides a computer program product, which, when running on a computer, enables the computer to execute the method as described in any one of the first aspects.

[0075] Other features and advantages of the present disclosure will be set forth in the following description, or some features and advantages may be inferred or unambiguously determined from the description, or may be learned by practicing the above-mentioned technology of the present disclosure.

[0076] It can be implemented according to the contents of the specification. The following is a detailed description of the preferred embodiments of the present application with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0077] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments of the present application. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the range values. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without creative work.

[0078] Figure 1 A flowchart of a method for reporting an alarm log provided in an embodiment of the present application;

[0079] Figure 2 A schematic diagram of the structure of the alarm log reporting device provided in an embodiment of the present application;

[0080] Figure 3 A schematic diagram of the structural composition of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0081] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.

[0082] It should be noted that similar reference numerals and letters represent similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined or explained in subsequent drawings. At the same time, in the description of this application, the terms "first", "second", etc. are only used to distinguish the description and should not be understood as indicating or implying relative importance.

[0083] The following embodiments are used to illustrate the present invention, but are not intended to limit the scope of the present invention.

[0084] Example 1

[0085] Figure 1 This is a flow chart of the method for reporting alarm logs provided by the embodiment of the present application, such as Figure 1 As shown, the method includes:

[0086] S1, obtain the user's alarm log;

[0087] S2, standardize the alarm log to obtain standardized alarm log data;

[0088] S3, fill in the standardized alarm log data to obtain the data to be reported;

[0089] S4, filtering the data to be reported to obtain filtered data to be reported;

[0090] S5: reporting the filtered data to be reported to obtain a reporting result.

[0091] In the above implementation process, by standardizing the alarm logs and then supplementing and filtering the data, the accessed alarm logs can be uniformly analyzed and reported, and low-quality alarm data can be filtered according to user needs to improve reporting efficiency, realize automatic matching of attack types and network assets, and reduce the user's consumption of manpower and material resources.

[0092] An embodiment of the present application provides a method for automatically reporting alarm logs, which can report standardized log data in a variety of ways, and provide an audit mechanism before reporting, only reporting data that has passed the audit, filtering out low-quality alarm data or alarm data that the enterprise is unwilling to report, and realizing standardized access to alarm logs.

[0093] Furthermore, S2 includes:

[0094] Parse the alarm log to obtain the parsed alarm log;

[0095] The parsed alarm log is mapped to fields according to the field rules to obtain standardized alarm log data.

[0096] In the above implementation process, the alarm log is parsed and then the field mapping is performed on the parsed alarm log, which can standardize the field-level data and improve the accuracy of the standardized alarm log data.

[0097] After accessing the alarm log, you can use regular expressions, JSON data (JavaScript Object Notation), and delimiters to parse the data. After parsing, field mapping is performed according to the field matching rules. For example, the alert_ip in the log data is mapped to the ip field in the system. Similarly, the alarm log is standardized into a JSON data (i.e., standardized alarm log data).

[0098] Furthermore, S3 includes:

[0099] Acquisition of web assets;

[0100] Supplement the standardized alarm log data based on network assets to obtain supplementary data;

[0101] The supplementary data is verified and processed to obtain the data to be reported.

[0102] In the above implementation process, the standardized alarm log data is supplemented according to the network assets to make the obtained supplementary data more complete, thereby improving the efficiency of the verification process and achieving faster verification.

[0103] Furthermore, the step of supplementing the standardized alarm log data according to the network assets to obtain supplementary data includes:

[0104] Match the attack fields of standardized alarm log data with network assets to obtain initial supplementary data;

[0105] The initial supplementary data is matched with the network assets by attack type to obtain supplementary data.

[0106] In the above implementation process, matching the attack fields and attack types with the network assets can quickly expand the standardized alarm log data so that the obtained supplementary data contains more attack fields and attack types.

[0107] Furthermore, the step of matching the standardized alarm log data with the attack fields of the network assets to obtain the initial supplementary data includes:

[0108] Match standardized alarm log data with network assets to determine whether the attacked IP field exists in the standardized alarm log data;

[0109] If yes, the attacked IP field is determined as the first primary key, and the initial supplementary data is obtained based on the first primary key;

[0110] If not, the standardized alarm log data is determined as the initial supplementary data.

[0111] In the above implementation process, by matching the IP field in the standardized alarm log data, it is possible to accurately obtain the attack field IP that may exist in the standardized alarm log data, thereby improving the ability to identify attacks on the data.

[0112] If there is an attacked IP field, the attacked IP field in the standardized alarm log data is extracted as the primary key of the network asset, and all network assets cached in the system are queried based on the first primary key.

[0113] Furthermore, the step of obtaining initial supplementary data according to the first primary key includes:

[0114] Query each asset data in the network asset based on the first primary key;

[0115] If asset data corresponding to the first primary key is found in the network assets, the attribute information of the asset data corresponding to the first primary key is added to the standardized alarm log data to obtain initial supplementary data; wherein the attribute information includes the ownership system, branch name and region of the asset data corresponding to the first primary key.

[0116] In the above implementation process, each asset data of the network asset is queried according to the first primary key, and the attribute information is added to the standardized alarm log data one by one, which can quickly and accurately expand the standardized alarm log data and improve the generalization ability of the standardized alarm log data.

[0117] If the asset data corresponding to the first primary key is queried, the corresponding system, branch name and region of the institution will be added to the data; if the asset data is not queried, the first primary key will be saved in the system, waiting for the user to query and add the asset data corresponding to the primary key.

[0118] Furthermore, the step of matching the initial supplementary data with the attack type of the network asset to obtain the supplementary data includes:

[0119] Matching standardized alarm log data with network assets to determine whether attack subclassification fields exist in the standardized alarm log data;

[0120] If yes, determine the attack sub-category field as the second primary key, and obtain supplementary data based on the second primary key;

[0121] If not, the initial supplementary data is determined as the supplementary data.

[0122] In the above implementation process, matching the attack sub-category field can accurately standardize the attack scope in the alarm log data, improve the efficiency of further confirmation of the attack field, and thus reduce errors and lower the probability of errors.

[0123] Furthermore, the step of obtaining supplementary data according to the second primary key includes:

[0124] Query attack type enumeration data in network assets based on the second primary key;

[0125] If attack type enumeration data corresponding to the second primary key is found in the network asset, the attack type code of the attack type enumeration data corresponding to the second primary key is added to the initial supplementary data to obtain the supplementary data.

[0126] In the above implementation process, adding the attack type code to the attack type enumeration data can avoid the subsequent search process for the attack type code, improve the accuracy of matching and query, and make the supplementary data more complete.

[0127] If the standardized alarm log data contains an attack subcategory field, the attack subcategory field is extracted as the second primary key, and the attack type enumeration data cached in the system is queried. If the data is found, the corresponding attack type code is added according to the attack type. If the data is not found, the data is also saved for the user to query and add the relevant data of the attack type.

[0128] Furthermore, the steps of verifying and processing the supplementary data to obtain the data to be reported include:

[0129] Determine whether the secondary review interface is enabled based on the supplementary data;

[0130] When the secondary review interface is enabled, determine whether the supplementary data meets the secondary review conditions. If so, cache the supplementary data and wait for the secondary review. If not, identify the supplementary data as pending data and update its status to pending. The secondary review conditions include the system to which it belongs, the attack type / virus type, and whether it matches malicious intelligence.

[0131] When the secondary review interface is not opened, the supplementary data will be determined as data to be reported, and the status of the data to be reported will be updated to pending reporting.

[0132] In the above implementation process, the supplementary data is checked and processed, and different processing is performed on the supplementary data according to the opening status of the secondary audit interface, so that the attack fields in the supplementary data can be further checked to avoid omissions.

[0133] Optionally, the secondary review can be a manual review method to determine whether the supplementary data requires manual review. The specific conditions for determining whether manual review is required include: the system to which it belongs, the attack type / virus type, and whether it hits the malicious intelligence. That is, if the system to which the asset data corresponding to the supplementary data belongs is not found in the network assets, and the attack type / virus type corresponding to the supplementary data is not found in the network assets, and the supplementary data does not hit the malicious intelligence, when the data meets the above three conditions at the same time, manual review is required, and it can only be reported after the manual review is passed, and stored in the storage medium, waiting to be reported.

[0134] The embodiment of the present application uses a manual review mechanism to reduce the intrusion of massive alarm data. Different types of alarm log data have different filtering rules, which are highly flexible. At the same time, manual review also supports flexible configuration of multiple conditions, helping enterprises intercept and re-confirm the data that needs to be reported, and ensure that the data to be reported is effective and accurate.

[0135] Furthermore, S4 includes:

[0136] Filter the data to be reported according to the filtering rules to obtain the filtered data to be reported, and update the status of the filtered data to be reported to filtered;

[0137] Filtering rules include duplicate alarm filtering, attack IP filtering, traffic threshold alarm filtering, and non-current alarm filtering.

[0138] In the above implementation process, the data to be reported is filtered according to the filtering rules, which reduces the possibility of false filtering during the filtering process and makes the filtered data to be reported more accurate.

[0139] The specific filtering methods of the filtering rules are as follows: Duplicate alarm filtering, different types of data to be reported have different rules for determining duplication, which can be divided into deduplication according to attack source IP and attack sub-category, deduplication according to destination IP and occurrence time, deduplication according to infected IP and virus name, and deduplication according to sender source IP and email title. At the same time, you can select the time range for deduplication. Within the selected time range, for example, within 24 hours, if two pieces of network attack type data are accessed within 24 hours, and the attack source IP and attack sub-category are the same, then the second piece of data will be filtered. However, after 24 hours, you can continue to access and report the data to be reported that has the same attack source IP and attack sub-category as the first piece of data.

[0140] Attack IP filtering filters alarm logs where the attack IP is an asset IP. This feature is effective for all types of data. If the attack IP matches the system asset IP, the data to be reported will be filtered.

[0141] Traffic threshold alarm filtering filters alarms with attack traffic below the threshold. This is only applicable to DDoS type alarm log data, and can filter out alarm logs with low attack traffic.

[0142] Non-current alarm filtering: filters alarms that are not generated on the same day. This function is effective for all types of data. It filters out alarm log data that are not generated on the same day based on the time when the alarm log occurs.

[0143] Furthermore, S5 includes:

[0144] Report the filtered data to be reported according to the first reporting method, the second reporting method, and the third reporting method in sequence to obtain the corresponding first reporting result, the second reporting result, and the third reporting result;

[0145] If any one of the first reporting result, the second reporting result, and the third reporting result is a successful report, the reporting result is determined to be a successful report, and the reporting method corresponding to the successful report result among the first reporting result, the second reporting result, and the third reporting result is recorded;

[0146] If the results of the first reporting result, the second reporting result, and the third reporting result are all reporting failures, the reporting result is determined to be reporting failure.

[0147] In the above implementation process, by reporting according to different reporting methods, the reporting method in which the data is successfully reported can be intuitively known, providing a basis for subsequent data reporting and avoiding repeated reporting failures.

[0148] The embodiment of the present application can report through three methods: Kafka, API, and Syslog. The manufacturer can turn on or off the switch of any reporting method according to actual conditions, and then report according to the selected reporting method.

[0149] Furthermore, the steps of reporting the filtered data to be reported according to the first reporting method, the second reporting method, and the third reporting method in sequence to obtain the corresponding first reporting result, the second reporting result, and the third reporting result include:

[0150] Determine whether the interface of the first reporting method is enabled;

[0151] If so, reporting the filtered data to be reported according to the first reporting method to obtain a first reporting result;

[0152] If not, determine whether the interface for the second reporting method is enabled;

[0153] If the interface of the second reporting method is enabled, the filtered data to be reported is reported according to the second reporting method to obtain a second reporting result;

[0154] If the interface for the second reporting method is not enabled, determine whether the interface for the third reporting method is enabled;

[0155] If the interface of the third reporting method is enabled, the filtered data to be reported is reported according to the third reporting method to obtain a third reporting result.

[0156] In the above implementation process, the filtered data to be reported is reported in sequence through the first reporting method, the second reporting method and the third reporting method, which can realize the reporting quickly, accurately and effectively, and improve the reporting efficiency.

[0157] Specifically, the data to be reported will be checked in the order of Kafka, API, and Syslog to see if the corresponding reporting switch is turned on. If it is turned on, it will be reported using this method, and the success or failure status of the report will be recorded. If the report is successful, the reporting status will be updated to successful reporting, and then the reporting methods used for the data will be recorded, such as Kafka+API, for enterprises to review retrospectively. Finally, the data after successful reporting will be saved and separated from the unsuccessfully reported / filtered data / data to be reported.

[0158] For example, two alarm logs are obtained, and the first one is reported first. Since the data with the same attack IP and attack subcategory as the alarm log cannot be found in the reported list, it meets the reporting conditions. Then it is successfully reported through syslog, and its successful reporting status is marked. The record in the list to be reported is deleted, and the record is transferred to the storage medium of the successful reporting list.

[0159] Then the second alarm log is reported. Since the first report is successful, when filtering the data, it can be found that there is a data in the successful report list that has the same attack IP and attack type subcategory as the data, so it will be marked as duplicate data, and the status of the data will be marked as not meeting the reporting conditions. The status is updated to the storage medium, and the reporting process is terminated.

[0160] This application automatically accesses, organizes, and standardizes alarm logs from different manufacturers. It also helps enterprises clean and extract truly useful security alerts from massive alarm logs through manual review and data filtering, ensuring the validity and accuracy of reported data. It supports reporting in multiple ways (Kafka, Syslog, API) and enhances enterprise security capabilities.

[0161] This embodiment of the application can help manufacturers identify gaps and improve relevant asset and attack type data sets. Finally, after a successful report is submitted, the reported data is stored separately from other data, eliminating the possibility of data contamination at the source and supporting enterprise users to retroactively audit all access data.

[0162] Example 2

[0163] In order to execute the method corresponding to the above embodiment 1 and achieve the corresponding functions and technical effects, a reporting device for an alarm log is provided below, such as Figure 2 As shown, the device includes:

[0164] Acquisition module 1, used to obtain the user's alarm log;

[0165] Standardization module 2, used for standardizing the alarm log to obtain standardized alarm log data;

[0166] Supplement module 3, used to supplement the standardized alarm log data to obtain the data to be reported;

[0167] Filtering module 4, used to filter the data to be reported to obtain filtered data to be reported;

[0168] The reporting module 5 is used to report the filtered data to be reported and obtain a reporting result.

[0169] In the above implementation process, by standardizing the alarm logs and then supplementing and filtering the data, the accessed alarm logs can be uniformly analyzed and reported, and low-quality alarm data can be filtered according to user needs to improve reporting efficiency, realize automatic matching of attack types and network assets, and reduce the user's consumption of manpower and material resources.

[0170] Furthermore, the standardization module 2 is also used to:

[0171] Parse the alarm log to obtain the parsed alarm log;

[0172] The parsed alarm log is mapped to fields according to the field rules to obtain standardized alarm log data.

[0173] In the above implementation process, the alarm log is parsed and then the parsed alarm log is mapped to fields, which can achieve field-level data standardization and improve the accuracy of standardized alarm log data.

[0174] Furthermore, the supplementary module 3 is also used to:

[0175] Acquisition of web assets;

[0176] Supplement the standardized alarm log data based on network assets to obtain supplementary data;

[0177] The supplementary data is verified and processed to obtain the data to be reported.

[0178] In the above implementation process, the standardized alarm log data is supplemented according to the network assets to make the obtained supplementary data more complete, thereby improving the efficiency of the verification process and achieving faster verification.

[0179] Furthermore, the supplementary module 3 is also used to:

[0180] Match the attack fields of standardized alarm log data with network assets to obtain initial supplementary data;

[0181] The initial supplementary data is matched with the network assets by attack type to obtain supplementary data.

[0182] In the above implementation process, matching the attack fields and attack types with the network assets can quickly expand the standardized alarm log data so that the obtained supplementary data contains more attack fields and attack types.

[0183] Furthermore, the supplementary module 3 is also used to:

[0184] Match standardized alarm log data with network assets to determine whether the attacked IP field exists in the standardized alarm log data;

[0185] If yes, the attacked IP field is determined as the first primary key, and the initial supplementary data is obtained based on the first primary key;

[0186] If not, the standardized alarm log data is determined as the initial supplementary data.

[0187] In the above implementation process, by matching the IP field in the standardized alarm log data, it is possible to accurately obtain the attack field IP that may exist in the standardized alarm log data, thereby improving the ability to identify attacks on the data.

[0188] Furthermore, the supplementary module 3 is also used to:

[0189] Query each asset data in the network asset based on the first primary key;

[0190] If asset data corresponding to the first primary key is found in the network assets, the attribute information of the asset data corresponding to the first primary key is added to the standardized alarm log data to obtain initial supplementary data; wherein the attribute information includes the ownership system, branch name and region of the asset data corresponding to the first primary key.

[0191] In the above implementation process, each asset data of the network asset is queried according to the first primary key, and the attribute information is added to the standardized alarm log data one by one, which can quickly and accurately expand the standardized alarm log data and improve the generalization ability of the standardized alarm log data.

[0192] Furthermore, the supplementary module 3 is also used to:

[0193] Matching standardized alarm log data with network assets to determine whether attack subclassification fields exist in the standardized alarm log data;

[0194] If yes, determine the attack sub-category field as the second primary key, and obtain supplementary data based on the second primary key;

[0195] If not, the initial supplementary data is determined as the supplementary data.

[0196] In the above implementation process, matching the attack sub-category field can accurately standardize the attack scope in the alarm log data, improve the efficiency of further confirmation of the attack field, and reduce the error and error probability.

[0197] Furthermore, the supplementary module 3 is also used to:

[0198] Query attack type enumeration data in network assets based on the second primary key;

[0199] If attack type enumeration data corresponding to the second primary key is found in the network asset, the attack type code of the attack type enumeration data corresponding to the second primary key is added to the initial supplementary data to obtain the supplementary data.

[0200] In the above implementation process, adding the attack type code to the attack type enumeration data can avoid the subsequent search process for the attack type code, improve the accuracy of matching and query, and make the supplementary data more complete.

[0201] Furthermore, the supplementary module 3 is also used to:

[0202] Determine whether the secondary review interface is enabled based on the supplementary data;

[0203] When the secondary review interface is enabled, determine whether the supplementary data meets the secondary review conditions. If so, cache the supplementary data and wait for the secondary review. If not, identify the supplementary data as pending data and update its status to pending. The secondary review conditions include the system to which it belongs, the attack type / virus type, and whether it matches malicious intelligence.

[0204] When the secondary review interface is not opened, the supplementary data will be determined as data to be reported, and the status of the data to be reported will be updated to pending reporting.

[0205] In the above implementation process, the supplementary data is checked and processed, and different processing is performed on the supplementary data according to the opening status of the secondary audit interface, so that the attack fields in the supplementary data can be further checked to avoid omissions.

[0206] Furthermore, the filtering module 4 is also used for:

[0207] Filter the data to be reported according to the filtering rules to obtain the filtered data to be reported, and update the status of the filtered data to be reported to filtered;

[0208] Filtering rules include duplicate alarm filtering, attack IP filtering, traffic threshold alarm filtering, and non-current alarm filtering.

[0209] In the above implementation process, the data to be reported is filtered according to the filtering rules, which reduces the possibility of false filtering during the filtering process and makes the filtered data to be reported more accurate.

[0210] Furthermore, the reporting module 5 is further configured to:

[0211] Report the filtered data to be reported according to the first reporting method, the second reporting method, and the third reporting method in sequence to obtain the corresponding first reporting result, the second reporting result, and the third reporting result;

[0212] If any one of the first reporting result, the second reporting result, and the third reporting result is a successful report, the reporting result is determined to be a successful report, and the reporting method corresponding to the successful report result among the first reporting result, the second reporting result, and the third reporting result is recorded;

[0213] If the results of the first reporting result, the second reporting result, and the third reporting result are all reporting failures, the reporting result is determined to be reporting failure.

[0214] In the above implementation process, by reporting according to different reporting methods, the reporting method in which the data is successfully reported can be intuitively known, providing a basis for subsequent data reporting and avoiding repeated reporting failures.

[0215] Furthermore, the reporting module 5 is further configured to:

[0216] Determine whether the interface of the first reporting method is enabled;

[0217] If so, reporting the filtered data to be reported according to the first reporting method to obtain a first reporting result;

[0218] If not, determine whether the interface for the second reporting method is enabled;

[0219] If the interface of the second reporting method is enabled, the filtered data to be reported is reported according to the second reporting method to obtain a second reporting result;

[0220] If the interface for the second reporting method is not enabled, determine whether the interface for the third reporting method is enabled;

[0221] If the interface of the third reporting method is enabled, the filtered data to be reported is reported according to the third reporting method to obtain a third reporting result.

[0222] In the above implementation process, the filtered data to be reported is reported in sequence through the first reporting method, the second reporting method and the third reporting method, which can realize the reporting quickly, accurately and effectively, and improve the reporting efficiency.

[0223] The above-mentioned alarm log reporting device can implement the method of the above-mentioned embodiment 1. The options in the above-mentioned embodiment 1 are also applicable to this embodiment and will not be described in detail here.

[0224] The rest of the contents of the embodiments of this application can refer to the contents of the above-mentioned embodiment 1, and will not be repeated in this embodiment.

[0225] Example 3

[0226] An embodiment of the present application provides an electronic device, including a memory and a processor, wherein the memory is used to store a computer program, and the processor runs the computer program to enable the electronic device to execute the alarm log reporting method of embodiment 1.

[0227] Optionally, the above-mentioned electronic device may be a server.

[0228] See Figure 3 , Figure 3 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. The electronic device may include a processor 31, a communication interface 32, a memory 33, and at least one communication bus 34. The communication bus 34 is used to enable direct communication between these components. The communication interface 32 of the device in this embodiment of the present application is used to communicate signaling or data with other node devices. The processor 31 may be an integrated circuit chip with signal processing capabilities.

[0229] The processor 31 can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of this application. A general-purpose processor can be a microprocessor, or the processor 31 can also be any conventional processor.

[0230] The memory 33 may be, but is not limited to, a random access memory (RAM), a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), etc. The memory 33 stores computer-readable instructions. When the computer-readable instructions are executed by the processor 31, the device can perform the above-mentioned operations. Figure 1 The various steps involved in the method embodiment.

[0231] Optionally, the electronic device may further include a memory controller and an input / output unit. The memory 33, memory controller, processor 31, peripheral interface, and input / output unit are electrically connected to each other, directly or indirectly, to enable data transmission or interaction. For example, these components may be electrically connected to each other via a communication bus 34. The processor 31 is configured to execute executable modules stored in the memory 33, such as software function modules or computer programs included in the device.

[0232] The input and output unit is used to provide users with the ability to create tasks and to create optional start time periods or preset execution times for the tasks to enable interaction between the user and the server. The input and output unit can be, but is not limited to, a mouse and keyboard.

[0233] I understand. Figure 3 The structure shown is only for illustration, and the electronic device may also include Figure 3 More or fewer components than shown, or with Figure 3 Different configurations shown. Figure 3 Each component shown in the figure can be implemented by hardware, software or a combination thereof.

[0234] In addition, an embodiment of the present application further provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the alarm log reporting method of the first embodiment.

[0235] An embodiment of the present application further provides a computer program product, which, when running on a computer, enables the computer to execute the method described in the method embodiment.

[0236] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions and operations of the devices, methods and computer program products according to the multiple embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a portion of code, and the module, program segment or a portion of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart, can be implemented using a dedicated hardware-based device that performs the specified function or action, or can be implemented using a combination of dedicated hardware and computer instructions.

[0237] In addition, the functional modules in each embodiment of the present application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0238] If the functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a ROM, a RAM, a magnetic disk, or an optical disk.

[0239] The foregoing is merely an embodiment of the present application and is not intended to limit the scope of protection of the present application. For those skilled in the art, the present application may have various modifications and variations. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application should be included within the scope of protection of the present application. It should be noted that similar numbers and letters represent similar items in the following figures. Therefore, once an item is defined in one figure, it does not need to be further defined or explained in subsequent figures.

[0240] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present application should be included within the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.

[0241] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply the existence of any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device comprising the element.

Claims

1. A method for reporting an alarm log, characterized in that: The method comprises: Get the user's alarm log; Performing standardization processing on the alarm log to obtain standardized alarm log data; Performing data supplementation on the standardized alarm log data to obtain data to be reported; Filtering the data to be reported to obtain filtered data to be reported; Reporting the filtered data to be reported to obtain a reporting result; The step of supplementing the standardized alarm log data to obtain data to be reported includes: Acquisition of web assets; Supplementing the standardized alarm log data according to the network assets to obtain supplementary data; Verifying and processing the supplementary data to obtain the data to be reported; The step of supplementing the standardized alarm log data according to the network assets to obtain supplementary data includes: Matching the standardized alarm log data with the attack fields of the network assets to obtain initial supplementary data; Matching the initial supplementary data with the network asset by attack type to obtain the supplementary data; The step of matching the attack fields of the standardized alarm log data with the network assets to obtain initial supplementary data includes: Matching the standardized alarm log data with the network assets to determine whether an attacked IP field exists in the standardized alarm log data; If so, determining the attacked IP field as a first primary key, and obtaining the initial supplementary data according to the first primary key; If not, the standardized alarm log data is determined as the initial supplementary data.

2. The method for reporting an alarm log according to claim 1, wherein: The step of performing standardization processing on the alarm log to obtain standardized alarm log data includes: Parsing the alarm log to obtain a parsed alarm log; Field mapping is performed on the parsed alarm log according to field rules to obtain the standardized alarm log data.

3. The method for reporting an alarm log according to claim 1, wherein: The step of obtaining the initial supplementary data according to the first primary key includes: querying each piece of asset data in the network asset according to the first primary key; If it is found that asset data corresponding to the first primary key exists in the network assets, the attribute information of the asset data corresponding to the first primary key is added to the standardized alarm log data to obtain the initial supplementary data; wherein, the attribute information includes the ownership system, branch name and region of the asset data corresponding to the first primary key.

4. The method for reporting an alarm log according to claim 1, wherein: The step of matching the initial supplementary data with the network asset by attack type to obtain the supplementary data includes: Matching the standardized alarm log data with the network assets to determine whether an attack subclassification field exists in the standardized alarm log data; If so, determining the attack subclass field as a second primary key, and obtaining the supplementary data according to the second primary key; If not, the initial supplementary data is determined as the supplementary data.

5. The method for reporting an alarm log according to claim 4, wherein: The step of obtaining the supplementary data according to the second primary key includes: querying attack type enumeration data in the network asset according to the second primary key; If it is found that attack type enumeration data corresponding to the second primary key exists in the network asset, the attack type code of the attack type enumeration data corresponding to the second primary key is added to the initial supplementary data to obtain the supplementary data.

6. The method for reporting an alarm log according to claim 1, wherein: The step of verifying the supplementary data to obtain the data to be reported includes: Determine whether the secondary review interface is enabled based on the supplementary data; When the secondary review interface is enabled, determining whether the supplementary data meets the conditions for the secondary review; if so, caching the supplementary data and awaiting secondary review; and if not, determining the supplementary data as the data to be reported and updating the status of the data to be reported to "to be reported"; the conditions for the secondary review include the system to which it belongs, the attack type / virus type, and whether it matches malicious intelligence; When the supplementary data meets all three of the above conditions, it needs to be manually reviewed and then reported after passing the manual review. It will be stored in the storage medium and wait for reporting. In a case where the secondary audit interface is not enabled, the supplementary data is determined as the data to be reported, and the status of the data to be reported is updated to to be reported.

7. The method for reporting an alarm log according to claim 1, wherein: The step of filtering the data to be reported to obtain filtered data to be reported includes: Filtering the data to be reported according to the filtering rules to obtain filtered data to be reported, and updating the status of the filtered data to be reported to filtered; The filtering rules include repeated alarm filtering, attack IP filtering, traffic threshold alarm filtering and non-current alarm filtering.

8. The method for reporting an alarm log according to claim 1, wherein: The step of reporting the filtered data to be reported and obtaining a reporting result includes: Reporting the filtered data to be reported according to the first reporting method, the second reporting method, and the third reporting method in sequence to obtain corresponding first reporting results, second reporting results, and third reporting results; If any one of the first reporting result, the second reporting result, and the third reporting result is a successful report, determining that the reporting result is a successful report, and recording the reporting method corresponding to the successful report result among the first reporting result, the second reporting result, and the third reporting result; If the first reporting result, the second reporting result, and the third reporting result are all reporting failures, it is determined that the reporting result is reporting failure.

9. The method for reporting an alarm log according to claim 8, wherein: The step of reporting the filtered data to be reported according to the first reporting method, the second reporting method, and the third reporting method in sequence to obtain the corresponding first reporting result, the second reporting result, and the third reporting result includes: Determine whether the interface for the first reporting method is enabled; If so, reporting the filtered data to be reported according to the first reporting method to obtain a first reporting result; If not, determining whether the interface for the second reporting method is enabled; If the interface of the second reporting mode is enabled, reporting the filtered data to be reported according to the second reporting mode to obtain the second reporting result; If the interface for the second reporting method is not enabled, determining whether the interface for the third reporting method is enabled; If the interface of the third reporting method is enabled, the filtered data to be reported is reported according to the third reporting method to obtain the third reporting result.

10. A device for reporting alarm logs, characterized in that: The device comprises: Acquisition module, used to obtain the user's alarm log; A standardization module, configured to perform standardization processing on the alarm log to obtain standardized alarm log data; A supplement module, configured to supplement the standardized alarm log data to obtain data to be reported; A filtering module, configured to filter the data to be reported to obtain filtered data to be reported; A reporting module, configured to report the filtered data to be reported and obtain a reporting result; The supplementary module is also used to: Acquisition of web assets; Supplementing the standardized alarm log data according to the network assets to obtain supplementary data; Verifying and processing the supplementary data to obtain the data to be reported; Matching the standardized alarm log data with the attack fields of the network assets to obtain initial supplementary data; Matching the initial supplementary data with the network asset by attack type to obtain the supplementary data; Matching the standardized alarm log data with the network assets to determine whether an attacked IP field exists in the standardized alarm log data; If so, determining the attacked IP field as a first primary key, and obtaining the initial supplementary data according to the first primary key; If not, the standardized alarm log data is determined as the initial supplementary data.

11. An electronic device, characterized in that: The electronic device comprises a memory and a processor, wherein the memory is used to store a computer program, and the processor runs the computer program to enable the electronic device to execute the alarm log reporting method according to any one of claims 1 to 9.

12. A storage medium, characterized in that: It stores a computer program, which, when executed by a processor, implements the method for reporting an alarm log according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Network security log alarm processing method based on big data analysis technology

    CN113676464A

  • A log analysis template generation method, a log analysis method, a log analysis device and log analysis equipment

    CN114035789A