A method, system, device and medium for processing alarm information
By obtaining the alarm information in the network threat detection results, judging that its characteristics match the target plug-in, obtaining auxiliary information and interpreting it, the problem of inaccurate interpretation of alarm information in the existing technology is solved, and a more comprehensive and accurate alarm interpretation is achieved.
Patent Information
- Application Number
- CN202410346221.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-25
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2044-03-25
AI Technical Summary
The existing network threat detection system generates a large number of alarm information and is poorly readable, making it difficult to provide accurate and detailed interpretation results, affecting the decision-making and response of operation and maintenance personnel.
By obtaining the alarm information in the network threat detection results, determining that its characteristics match the target plug-in, obtaining auxiliary information, and inputting it into the target model for interpretation, improving the comprehensiveness and accuracy of the interpretation of the alarm information.
By using auxiliary information to conduct targeted analysis of alarm information, the comprehensiveness and accuracy of alarm interpretation are improved, and operation and maintenance personnel can handle network threats more effectively.
Smart Images

Figure CN118264450B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular to an alarm information processing method, system, electronic device, and computer-readable storage medium. Background Art
[0002] With the rapid development of network technology, network traffic analysis (NTA) systems have emerged. Network threat detection systems analyze network traffic or network logs to detect potential threats in the network by combining rule-based detection technology with machine learning, feature analysis and other technologies.
[0003] Network threat detection systems can generate warning information for detected potential threats. However, due to the large number of warning information, the industry urgently needs a method that can accurately interpret the warning information. Summary of the invention
[0004] The present application provides a method for processing alarm information. The method improves the comprehensiveness and accuracy of the interpretation results of network threat detection results. The present application also provides a system, electronic device, computer-readable storage medium and computer program product corresponding to the above method.
[0005] In a first aspect, the present application provides a method for processing alarm information, the method comprising:
[0006] Obtaining a first network threat detection result, where the first network threat detection result includes at least one piece of alarm information;
[0007] In response to a feature included in the at least one piece of alarm information matching a target plug-in, acquiring first auxiliary information based on the target plug-in;
[0008] sending first prompt information generated at least based on the first network threat detection result and the first auxiliary information to a first target model, and receiving an interpretation result generated by the first target model for the first network threat detection result, wherein the first prompt information is used to instruct the first target model to generate an interpretation result;
[0009] The interpretation results are presented.
[0010] In a second aspect, the present application provides an alarm information processing system, the system comprising:
[0011] A first acquisition module, configured to acquire a first network threat detection result, wherein the first network threat detection result includes at least one piece of warning information;
[0012] A second acquisition module, configured to acquire first auxiliary information based on the target plug-in in response to a feature included in the at least one warning information matching the target plug-in;
[0013] a communication module, configured to send first prompt information generated at least based on the first network threat detection result and the first auxiliary information to a first target model, and receive an interpretation result generated by the first target model for the first network threat detection result, wherein the first prompt information is used to instruct the first target model to generate an interpretation result;
[0014] A presentation module is used to present the interpretation result.
[0015] In a third aspect, the present application provides an electronic device, the electronic device comprising a processor and a memory. The processor and the memory communicate with each other. The processor is used to execute instructions stored in the memory so that the electronic device performs the alarm information processing method in the first aspect or any implementation of the first aspect.
[0016] In a fourth aspect, the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores instructions, wherein the instructions instruct an electronic device to execute the alarm information processing method described in the first aspect or any one of the implementations of the first aspect.
[0017] In a fifth aspect, the present application provides a computer program product comprising instructions, which, when executed on an electronic device, enables the electronic device to execute the alarm information processing method described in the first aspect or any one of the implementations of the first aspect.
[0018] Based on the implementations provided in the above aspects, this application can also be further combined to provide more implementations.
[0019] It can be seen from the above technical solutions that this application has the following advantages:
[0020] The present application provides an alarm information processing method, which first obtains a first network threat detection result, wherein the first network threat detection result includes at least one alarm message, and in response to a feature included in the at least one alarm message matching a target plug-in, obtains first auxiliary information based on the target plug-in, then sends first prompt information generated based on at least the first network threat detection result and the first auxiliary information to a first target model, receives an interpretation result generated by the first target model for the first network threat detection result, wherein the first prompt information is used to instruct the first target model to generate an interpretation result, and then presents the interpretation result.
[0021] In this method, before interpreting the network threat detection results, it is first determined whether the alarm information involves features that match the plug-in. In the case where the features in the alarm information match the target plug-in, auxiliary information is obtained through the target plug-in, and the auxiliary information and the network threat detection results are input into the target model together. In this way, the target model can use the auxiliary information to conduct targeted analysis of the alarm information, thereby improving the comprehensiveness and accuracy of the alarm interpretation. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] In order to more clearly illustrate the technical method of the embodiments of the present application, the drawings required for use in the embodiments are briefly introduced below.
[0023] Figure 1 A flowchart of a method for processing alarm information provided by an embodiment of the present application;
[0024] Figure 2 A schematic diagram of a process for obtaining second auxiliary information provided in an embodiment of the present application;
[0025] Figure 3 A schematic diagram of a flow chart of generating an interpretation result provided in an embodiment of the present application;
[0026] Figure 4A and Figure 4B A schematic diagram of a network threat detection page provided in an embodiment of the present application;
[0027] Figure 5 A schematic diagram of a database synchronization process provided in an embodiment of the present application;
[0028] Figure 6 A schematic diagram of the structure of an alarm information processing system provided in an embodiment of the present application;
[0029] Figure 7 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0030] The terms "first" and "second" in the embodiments of the present application are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined as "first" and "second" may explicitly or implicitly include one or more of the features.
[0031] First, some technical terms involved in the embodiments of the present application are introduced.
[0032] With the rapid development of network technology, network security issues have become increasingly prominent. Network threat detection (Network Traffic Analysis, NTA) systems have emerged and are widely used in many fields.
[0033] The network threat detection system combines rule-based detection technology with machine learning, feature analysis and other technologies to analyze network traffic or network logs to detect potential threats in the network.
[0034] Network threat detection systems can generate alert information for detected potential threats. Since network threat detection systems usually rely on pre-defined alert rules to identify potential threats, and considering the complexity and variability of network traffic, the generated alert information is usually large in number and poor in readability.
[0035] In the related art, professionals in the field of network security usually pre-configure information such as alarm rules, alarm types, and disposal suggestions. In this way, by matching specific fields in the alarm information, the alarm rules and alarm types can be determined, and then the corresponding disposal suggestions can be determined to generate interpretation results.
[0036] However, since the above methods rely on pre-configured alarm rules, alarm types and handling suggestions, the generated interpretation results are often brief and repetitive, making it difficult to provide detailed interpretations for different alarm information. In addition, the accuracy and comprehensiveness are poor, which makes it difficult for operation and maintenance personnel to make decisions and respond to alarm information.
[0037] In view of this, the present application provides a method for processing alarm information. The method first obtains a first network threat detection result, wherein the first network threat detection result includes at least one alarm message, in response to the feature included in the at least one alarm message matching the target plug-in, obtains first auxiliary information based on the target plug-in, then sends first prompt information generated based on at least the first network threat detection result and the first auxiliary information to a first target model, receives an interpretation result generated by the first target model for the first network threat detection result, wherein the first prompt information is used to instruct the first target model to generate an interpretation result, and then presents the interpretation result.
[0038] In this method, before interpreting the network threat detection results, it is first determined whether the alarm information involves features that match the plug-in. In the case where the features in the alarm information match the target plug-in, auxiliary information is obtained through the target plug-in, and the auxiliary information and the network threat detection results are input into the target model together. In this way, the target model can use the auxiliary information to conduct targeted analysis of the alarm information, thereby improving the comprehensiveness and accuracy of the alarm interpretation.
[0039] To facilitate understanding of the technical solution provided by the embodiments of the present application, it will be described below with reference to the accompanying drawings.
[0040] See also Figure 1The flowchart of a method for processing alarm information provided by an embodiment of the present application is shown, and the method specifically includes:
[0041] S101: Obtain a first network threat detection result.
[0042] The first network threat detection result can be understood as the result of detecting the network security status. In some possible implementations, the first network threat detection result can be generated by a network threat detection system. In other words, the user can use the network threat detection system to detect the network security status, and after the network threat detection system completes the detection, the first network threat detection result can be generated.
[0043] In some embodiments, the network threat detection system may be a software system. For example, the network threat detection system may be a software system deployed locally or online. In this case, the server provided in the embodiments of the present application for executing the alarm information processing method may be connected to the network threat detection system in the form of a plug-in, cloud service, etc.
[0044] In an embodiment of the present application, the first network threat detection result may include at least one warning information. The warning information may refer to information used to describe a network security threat event, for example, the warning information may include information such as the warning time, warning type, warning data, protocol, and Internet Protocol (IP) address.
[0045] That is, the network threat detection system can analyze and detect network traffic or network logs, detect network security threat events, and generate a first network threat detection result in the form of alarm information. The user can obtain the current network security status by viewing the first network threat detection result.
[0046] Considering that the first network threat detection result generated by the network threat detection system often contains many network-related professional terms and codes, which are difficult to read, in an embodiment of the present application, the server can obtain the first network threat detection result so as to subsequently process the first network threat detection result.
[0047] In a specific implementation, the first network threat detection result may be obtained in response to a trigger operation on a preset control in a network threat detection page.
[0048] The network threat detection page is used to present the first network threat detection result. In other words, the network threat detection page may be a page provided by the network threat detection system, and the user may view the first network threat detection result through the network threat detection page.
[0049] In an embodiment of the present application, a preset control is provided on the network threat detection page, and the preset control can be used to trigger the interpretation of the first network threat detection result. For example, the user can trigger the generation of the interpretation result of the first network threat detection result by clicking the preset control. For another example, the user can trigger the generation of the interpretation result of the first network threat detection result by sliding down the preset control. For another example, when the device used by the user supports voice interaction, the user can trigger the generation of the interpretation result of the first network threat detection result by sending a voice command.
[0050] That is to say, the user can directly trigger the interpretation of the first network threat detection result through the preset control in the network threat detection page, realize "one-click interpretation", simplify the user interaction process, and improve the user interaction efficiency.
[0051] S102: In response to a feature included in at least one piece of alarm information matching a target plug-in, obtaining first auxiliary information based on the target plug-in.
[0052] The plug-in may be understood as a tool for processing warning information to generate auxiliary information. The target plug-in may be understood as a plug-in that matches at least one warning information in the first network threat detection result.
[0053] That is to say, the server may first analyze the alarm information, determine the features in the alarm information, and obtain the corresponding first auxiliary information using a target plug-in that matches the alarm information, so as to subsequently interpret the alarm with the help of the first auxiliary information.
[0054] In an embodiment of the present application, the server can determine the target plug-in through the second target model. The second target model can be a language model with natural language processing capabilities, that is, the second target model can understand the meaning of natural language and can handle a variety of natural language processing tasks. For example, the second target model can be a deep learning model trained using text data.
[0055] In specific implementation, the second target model can determine the target plug-in based on the prompt engineering technology. In some possible implementations, the server can send the second prompt information (prompt) generated based on at least one alarm information to the second target model, receive the target plug-in information returned by the second target model, and obtain the first auxiliary information based on the target plug-in indicated by the target plug-in information.
[0056] The second prompt information can be used to instruct the second target model to determine the target plug-in for obtaining the first auxiliary information. In this way, the second target model can analyze at least one piece of alarm information in combination with the prompt capability of the second prompt information, determine the characteristics of at least one piece of alarm information, and determine the target plug-in that matches the alarm information according to the different capabilities corresponding to different plug-ins, so that the server can call the target plug-in to obtain the first auxiliary information.
[0057] Different target plug-ins may correspond to different first auxiliary information. In some embodiments, the target plug-in includes an Internet search plug-in. Specifically, in response to at least one alarm information including information related to an unknown alarm indicator, the first auxiliary information is obtained based on the Internet search plug-in.
[0058] The unknown alarm indicator is an alarm indicator not included in the existing database. At this time, the first auxiliary information is related to the unknown alarm indicator.
[0059] Since there are many alarm indicators and they change quickly, it is difficult for existing databases to dynamically update information related to alarm indicators in real time. However, when the alarm information includes information related to unknown alarm indicators, it is difficult to generate accurate interpretation results without the information related to the unknown alarm indicators.
[0060] Therefore, when the alarm information includes information related to the unknown alarm indicator, the first auxiliary information related to the unknown alarm indicator is obtained by calling the Internet search plug-in, so that the first auxiliary information can be used to interpret the network threat detection result later.
[0061] The Internet search plug-in can be used to search based on an Internet search engine. The server can call the Internet search plug-in, pass the keywords to be searched and the number of search matches extracted from the alarm information to the Internet search plug-in, and receive the corresponding number of search results returned by the Internet search plug-in, and obtain the first auxiliary information based on the search results. In this way, with the help of the Internet search plug-in, real-time information related to the unknown alarm indicator is obtained from the Internet.
[0062] In some other embodiments, the target plug-in includes a uniform resource locator (URL) encoding and decoding plug-in. Specifically, in response to at least one warning message including URL-encoded content, the first auxiliary information is obtained based on the URL encoding and decoding plug-in. At this time, the first auxiliary information includes content after decoding the URL-encoded content.
[0063] In some other embodiments, the target plug-in includes a Base64 encoding and decoding plug-in for representing binary data based on 64 printable characters. Specifically, in response to at least one alarm message including Base64 encoded content, the first auxiliary information is obtained based on the Base64 encoding and decoding plug-in. At this time, the first auxiliary information includes content after decoding the Base64 encoded content.
[0064] When the alarm information includes encoded content (such as URL encoded content or Base64 encoded content), it is difficult to identify in the subsequent alarm interpretation process. Therefore, the encoded content in the alarm information is decoded by calling the target plug-in for decoding different formats, so that the first auxiliary information can be used to interpret the network threat detection results later.
[0065] In some other embodiments, the target plug-in includes a threat intelligence search plug-in. Specifically, in response to at least one warning message including a threat intelligence indicator to be identified, the first auxiliary information is obtained based on the threat intelligence search plug-in. At this time, the first auxiliary information is related to the threat intelligence indicator to be identified.
[0066] Among them, the threat intelligence search plug-in can be used to search from an existing database. The server can call the threat intelligence search plug-in, pass the threat intelligence indicator to be identified extracted from the alarm information to the threat intelligence search plug-in, and receive the search results returned by the threat intelligence search plug-in, and obtain the first auxiliary information based on the search results. In this way, with the help of the threat intelligence search plug-in, information related to the threat intelligence indicator to be identified is obtained from an existing database (such as a local existing database or an external existing database).
[0067] Based on the above description, it can be known that the training data of the second target model may include multiple URL encodings, multiple Base64 encodings, threat intelligence indicator data in an existing database, etc. The second target model is trained using the above training data. Combined with the natural language processing capabilities of the second target model, the second target model can analyze the alarm information and determine the matching target plug-in.
[0068] Furthermore, the server may also obtain auxiliary information in combination with the alarm knowledge base. In specific implementation, the server may obtain the second auxiliary information from the alarm knowledge base according to at least one alarm information.
[0069] The alarm knowledge base includes a plurality of historical alarm information and alarm context information corresponding to the plurality of historical alarm information. For example, the alarm context information may include network threat feature information, attack mode information, vulnerability details information, and the like.
[0070] That is, the server can obtain the second auxiliary information by using the knowledge retrieved from the alarm knowledge base based on the retrieval augmented generation (RAG) technology.
[0071] In some possible implementations, the alarm knowledge base may be a private database of the network threat detection system. It is understandable that when different users use the network threat detection system to perform network threat detection, multiple historical alarm information may be generated, such as common vulnerabilities & exposures (CVE) information, and different historical alarm information may have corresponding alarm context information. Therefore, the alarm knowledge base may include historical alarm information and alarm context information corresponding to the historical alarm information.
[0072] In some embodiments, the server can obtain the second auxiliary information from the alarm knowledge base through similarity retrieval. Figure 2 A process diagram for obtaining second auxiliary information is shown, in which the server can determine the vector representation corresponding to at least one alarm information, and respectively calculate the similarity between the vector representation corresponding to at least one alarm information and the vector representations corresponding to multiple historical alarm information in the alarm knowledge base, and then determine the alarm context information corresponding to the target historical alarm information based on the target historical alarm information whose similarity meets the set conditions, and determine the second auxiliary information based on the alarm context information corresponding to the target historical alarm information.
[0073] That is to say, the historical alarm information and alarm context information in the alarm knowledge base can be stored in the form of vectors. For example, the historical alarm information and alarm context information can be segmented into texts to generate text knowledge blocks, and then the vector representation of the text knowledge blocks can be determined with the help of vector models to generate a vector database.
[0074] In the process of obtaining the second auxiliary information, the server can use the vector model to determine the vector representation of the alarm information in the network threat detection results, and then perform a similarity search with the vector representation corresponding to the historical alarm information in the vector database to determine the vector representation corresponding to the target historical alarm information whose similarity meets the set conditions (for example, the similarity is greater than the similarity threshold), and then restore the vector representation corresponding to the target historical alarm information and the vector representation of the alarm context information corresponding to the target historical alarm information to text to determine the second auxiliary information.
[0075] S103: Sending first prompt information generated at least based on the first network threat detection result and the first auxiliary information to the first target model, and receiving an interpretation result generated by the first target model for the first network threat detection result.
[0076] In an embodiment of the present application, the warning information in the first network threat detection result is analyzed with the help of the first target model, so as to generate an interpretation result that is highly readable and easy to understand.
[0077] The first target model may be a language model with natural language processing capabilities, that is, the first target model can understand the meaning of natural language and can handle a variety of natural language processing tasks. For example, the first target model may be a deep learning model trained using text data.
[0078] In some embodiments, the first target model can be deployed in the server, and the server can directly interpret the alarm through the first target model. In other embodiments, considering the large size of the first target model, the first target model can also be deployed externally, and the server can interpret the network threat detection results by calling the external first target model interface.
[0079] See also Figure 3 A flow chart of the generation of an interpretation result is shown. Considering the user information security issue, before the server sends the first prompt information generated based on the first network threat detection result and the first auxiliary information to the first target model, the server can also extract key identification information from at least one alarm message, and then encrypt the key identification information to update the first network threat detection result.
[0080] Among them, the key identification information can be information related to the user information, for example, the key identification information can be network identification information (such as an IP address). By extracting the key identification information from the alarm information and encrypting the key identification information, the key identification information in the first network threat detection result sent to the first target model is encrypted and desensitized, thereby protecting the user's information security.
[0081] like Figure 3 As shown, the server can encrypt the key identification information in the alarm information, obtain the first auxiliary information through the target plug-in, obtain the second auxiliary information through the alarm knowledge base, and interpret the first network threat detection result using the first target model.
[0082] It should be noted that the embodiment of the present application does not limit the execution order of the three steps of encrypting the key identification information in the alarm information, obtaining the first auxiliary information by calling the target plug-in, and obtaining the second auxiliary information through the alarm knowledge base. For example, the server can first encrypt the key identification information in the alarm information, and then obtain the second auxiliary information by calling the target plug-in and obtaining the second auxiliary information through the alarm knowledge base.
[0083] In addition, the first target model used to generate the interpretation result and the second target model used to determine the target plug-in can be the same language model or different language models, which is not limited in this embodiment of the present application.
[0084] Similarly, the first target model can generate an interpretation result based on the prompt engineering technology. In specific implementation, the server can generate the first prompt information based on at least the first network threat detection result and the first auxiliary information. In this way, the first target model can analyze the first network threat detection result in combination with the first auxiliary information under the prompt capability of the first prompt information, and generate an interpretation result for the first network threat detection result that meets the user's needs.
[0085] In case that the server also obtains other auxiliary information (i.e., the second auxiliary information), the server can generate first prompt information based on at least the first network threat detection result, the first auxiliary information, and the second auxiliary information, send the first prompt information to the first target model, and receive the interpretation result generated by the first target model for the first network threat detection result.
[0086] It should be noted that in the embodiments of the present application, in addition to the first network threat detection result and the first auxiliary information (some embodiments also include the second auxiliary information), the first prompt information can also be generated based on other information, for example, based on instruction information for the first target model, background information related to the alarm interpretation, information related to the output format, etc., the first prompt information can be generated together.
[0087] By sending the second auxiliary information together with the first network threat detection result and the first auxiliary information to the first target model, the first target model can integrate the alarm information and various types of auxiliary information. In this way, the first target model can use the rich auxiliary information to conduct a more comprehensive analysis of the alarm information, thereby improving the detail and accuracy of the interpretation results.
[0088] Specifically, the interpretation result may indicate at least one of the following: the type of alarm information, the meaning of the alarm data associated with the alarm information, the level of the alarm information, the impact scope of the alarm information, and reference information related to the interpretation result.
[0089] Among them, the type of alarm information may refer to the interpretation information for the alarm information, such as alarm indicators, alarm rules, etc. The meaning of the alarm data associated with the alarm information may refer to the interpretation information for the code data packet, such as explaining the meaning of the code data packet in natural language. The level of the alarm information may refer to the severity of the alarm information, such as low, medium, and high. The scope of impact of the alarm information may refer to servers, hosts and other devices affected by the alarm information. The reference information related to the interpretation results may refer to the reference materials used when the first target model generates the interpretation results, such as auxiliary information.
[0090] Continue as Figure 3 As shown, after the first target model generates an interpretation result, considering that the server can encrypt the key identification information in the first network threat detection result, in order to present the complete interpretation result to the user, the server can also extract the result information associated with the key identification information in the interpretation result, decrypt the result information associated with the key identification information, and update the interpretation result.
[0091] That is to say, for the interpretation results generated by the first target model, the server can restore the desensitized key identification information (such as the IP address). By encrypting the key identification information before sending the alarm information to the first target model, and decrypting the result information associated with the key identification information before presenting the interpretation results to the user, it not only protects the user's information security, but also presents the user with complete and detailed interpretation results, helping the user to quickly understand the network threat detection results and make timely and effective responses.
[0092] In the embodiment of the present application, the above-mentioned process of encrypting key identification information, determining the target plug-in to obtain the first auxiliary information, obtaining the second auxiliary information from the alarm knowledge base, generating the interpretation result, and decrypting the result information associated with the key identification information can be implemented based on the language model agent. Among them, the language model agent is an intelligent model system generated by combining language model, retrieval enhancement generation technology, processing tools, and workflow orchestration. The language model agent can be orchestrated as follows: Figure 3 In the workflow shown, the server executes each node in the workflow to realize the functions of encryption, auxiliary information acquisition, interpretation result generation, and decryption.
[0093] S103: Presenting the interpretation results.
[0094] After the first target model generates an interpretation result, the server can present the interpretation result on the network threat detection page.
[0095] See also Figure 4A and Figure 4B A schematic diagram of a network threat detection page is shown in Figure 4AAs shown, the network threat detection page 40 includes an alarm information presentation area 401. The alarm information presentation area 401 is used to present at least one alarm information. Figure 4A The following describes the process of presenting an alarm message as an example.
[0096] Specifically, the alarm information presentation area 401 can present the contents of multiple fields related to the alarm information. For example, the alarm information presentation area 401 can present the alarm host, attack direction, processing status, alarm time, alarm type (i.e., threat name), source IP, protocol, destination IP, destination port, attack result, and code data packet. In some embodiments, the alarm information presentation area 401 can also present a detailed legend of the alarm information so that the user can intuitively understand the alarm information through the legend.
[0097] Further, in the embodiment of the present application, the network threat detection page 40 provides a preset control 402, which can be used to trigger the generation of an interpretation result of the first network threat detection result. Specifically, the user can click the preset control 402 to achieve a one-click interpretation of the network threat detection result, reduce the interactive dialogue between the user and the language model, and improve the interpretation efficiency.
[0098] like Figure 4B As shown, after the user triggers the generation of the interpretation result of the first network threat detection result, the network threat detection page 40 can display the interpretation result presentation area 403. Among them, the interpretation result presentation area 403 can be used to present the interpretation result. Specifically, the interpretation result may include the contents of multiple fields, such as the "alarm interpretation" field, the "data packet interpretation" field, the "level analysis" field, the "scope of impact" field, the "handling suggestions" field, and the "reference material" field. The user can quickly understand the nature, severity, and handling method of the alarm information through the interpretation results presented in the interpretation result presentation area 403, which provides a decision-making basis for the user to handle the alarm information.
[0099] In some possible implementations, the interpretation result presentation area 403 may present the interpretation result to the user sentence by sentence in a streaming manner, thereby enhancing the interactive experience, reducing the user's anxiety while waiting for the generation of the interpretation result, and improving the user's experience.
[0100] Based on the above description, an embodiment of the present application provides a method for processing alarm information. The method first obtains a first network threat detection result, wherein the first network threat detection result includes at least one alarm message, in response to the feature included in the at least one alarm message matching the target plug-in, obtains first auxiliary information based on the target plug-in, then sends the first prompt information generated by at least the first network threat detection result and the first auxiliary information to the first target model, receives the interpretation result generated by the first target model for the first network threat detection result, wherein the first prompt information is used to instruct the first target model to generate the interpretation result, and then presents the interpretation result.
[0101] In this method, before interpreting the network threat detection results, it is first determined whether the alarm information involves features that match the plug-in. In the case where the features in the alarm information match the target plug-in, auxiliary information is obtained through the target plug-in, and the auxiliary information and the network threat detection results are input into the target model together. In this way, the target model can use the auxiliary information to conduct targeted analysis of the alarm information, thereby improving the comprehensiveness and accuracy of the alarm interpretation.
[0102] The above article introduces the alarm information processing method provided by this application. In the specific implementation, the server can use a multi-instance method to process the alarm interpretation requests submitted by different users, or the alarm interpretation requests submitted by the same user multiple times. In other words, the alarm interpretation requests submitted by different users can be assigned to different instances for information processing, and the alarm interpretation requests submitted by the same user multiple times can also be assigned to different instances for information processing.
[0103] See also Figure 5 As shown in the flowchart of a database synchronization, after obtaining the first network threat detection result, the server can generate a first identifier corresponding to the first network threat detection result, and the first identifier can be used to uniquely identify the first network threat detection result.
[0104] Next, the server can query whether the first identifier exists in the cache. It is understandable that after generating the interpretation result, the server can store the interpretation result in the cache of the current instance. Therefore, after the server obtains the first network threat detection result, the first identifier can be used as an index to query whether there is an interpretation result corresponding to the first identifier in the cache.
[0105] If the first identifier does not exist in the cache, the server can add the first identifier to the database and update the database so that other instances can update the cache synchronously. Further, the server can generate an interpretation result, add the interpretation result, expiration time and analysis status corresponding to the first identifier to the database, and update the database again to achieve data synchronization of the caches of multiple instances in the database.
[0106] If the first identifier exists in the cache, the server can determine whether the interpretation result corresponding to the first identifier is expired. If the interpretation result is expired, the server can clear the interpretation result, expiration time and analysis status corresponding to the first identifier, and update the database. Furthermore, the server can generate a re-interpretation result, add the interpretation result, expiration time and analysis status corresponding to the first identifier to the database, and update the database again to achieve data synchronization of caches of multiple instances in the database.
[0107] If the interpretation result has not expired, the server can determine whether the analysis status corresponding to the first identifier is completed. If so, the server can directly obtain the interpretation result from the cache without calling the first target model to regenerate the interpretation result, thereby improving the efficiency of alarm interpretation. If not, it indicates that other instances are processing alarm information at this time. The server can wait for the analysis status to change to completed before obtaining the interpretation result from the cache, effectively avoiding repeated submission of interpretation generation requests for the same network threat detection result and saving computing resources.
[0108] Combination of the above Figures 1 to 5 The alarm information processing method provided in the embodiment of the present application is introduced in detail. The system and equipment provided in the embodiment of the present application will be introduced in conjunction with the accompanying drawings.
[0109] See also Figure 6 The structural diagram of the alarm information processing system shown in FIG. 60 includes:
[0110] A first acquisition module 601 is used to acquire a first network threat detection result, where the first network threat detection result includes at least one warning information;
[0111] A second acquisition module 602 is configured to acquire first auxiliary information based on the target plug-in in response to a feature included in the at least one warning information matching the target plug-in;
[0112] A communication module 603 is used to send first prompt information generated based on at least the first network threat detection result and the first auxiliary information to a first target model, and receive an interpretation result generated by the first target model for the first network threat detection result, wherein the first prompt information is used to instruct the first target model to generate an interpretation result;
[0113] The presentation module 604 is used to present the interpretation result.
[0114] In some possible implementations, the target plug-in includes an Internet search plug-in; and the second acquisition module 602 is specifically configured to:
[0115] In response to the at least one alarm information including information related to an unknown alarm indicator, first auxiliary information is obtained based on the Internet search plug-in, the unknown alarm indicator is an alarm indicator not included in the existing database, and the first auxiliary information is related to the unknown alarm indicator.
[0116] In some possible implementations, the target plug-in includes a URL encoding and decoding plug-in; and the second acquisition module 602 is specifically configured to:
[0117] In response to the at least one warning message including URL-encoded content, first auxiliary information is acquired based on the URL encoding and decoding plug-in, where the first auxiliary information includes content after decoding the URL-encoded content.
[0118] In some possible implementations, the target plug-in includes a Base64 encoding and decoding plug-in; and the second acquisition module 602 is specifically configured to:
[0119] In response to the at least one warning information including Base64-encoded content, first auxiliary information is acquired based on the Base64 encoding and decoding plug-in, where the first auxiliary information includes content after decoding the Base64-encoded content.
[0120] In some possible implementations, the target plug-in includes a threat intelligence search plug-in; and the second acquisition module 602 is specifically configured to:
[0121] In response to the at least one piece of alarm information including a threat intelligence indicator to be identified, first auxiliary information is acquired based on the threat intelligence search plug-in, where the first auxiliary information is related to the threat intelligence indicator to be identified.
[0122] In some possible implementations, the first acquisition module 601 is specifically configured to:
[0123] In response to a trigger operation on a preset control in a network threat detection page, a first network threat detection result is obtained, wherein the preset control is used to trigger an interpretation of the first network threat detection result.
[0124] In some possible implementations, the second obtaining module 602 is specifically configured to:
[0125] sending second prompt information generated at least based on the at least one warning information to a second target model, and receiving target plug-in information returned by the second target model, wherein the second prompt information is used to indicate that the second target model determines a plug-in for obtaining the first auxiliary information;
[0126] Based on the target plug-in indicated by the target plug-in information, first auxiliary information is acquired.
[0127] In some possible implementations, the second obtaining module 602 is further configured to:
[0128] Acquire second auxiliary information from an alarm knowledge base according to the at least one alarm information, the alarm knowledge base comprising a plurality of historical alarm information and alarm context information corresponding to the plurality of historical alarm information;
[0129] The communication module 603 is specifically used for:
[0130] Sending first prompt information generated at least based on the first network threat detection result, the first auxiliary information and the second auxiliary information to a first target model, and receiving an interpretation result generated by the first target model for the first network threat detection result.
[0131] In some possible implementations, the second obtaining module 602 is specifically configured to:
[0132] Determine a vector representation corresponding to the at least one piece of warning information;
[0133] Respectively calculating the similarity between the vector representation corresponding to the at least one piece of alarm information and the vector representations corresponding to the plurality of pieces of historical alarm information in the alarm knowledge base;
[0134] Determining alarm context information corresponding to the target historical alarm information according to the target historical alarm information whose similarity meets the set condition;
[0135] The second auxiliary information is determined according to the alarm context information corresponding to the target historical alarm information.
[0136] In some possible implementations, the system 60 further includes an encryption and decryption module, and the encryption and decryption module is used to:
[0137] Extracting key identification information from the at least one warning message;
[0138] The key identification information is encrypted, and the first network threat detection result is updated.
[0139] In some possible implementations, the encryption and decryption module is further used to:
[0140] Extracting result information associated with key identification information from the interpretation result;
[0141] The result information associated with the key identification information is decrypted, and the interpretation result is updated.
[0142] In some possible implementations, the first target model or the second target model includes a language model with natural language processing capabilities.
[0143] In some possible implementations, the interpretation result indicates at least one of the following: the type of alarm information, the meaning of alarm data associated with the alarm information, the level of the alarm information, the impact scope of the alarm information, and reference information related to the interpretation result.
[0144] The alarm information processing system 60 according to the embodiment of the present application may correspond to executing the method described in the embodiment of the present application, and the above and other operations and / or functions of each module / unit of the alarm information processing system 60 are respectively to implement Figure 1 For the sake of brevity, the corresponding processes of each method in the illustrated embodiment are not described in detail here.
[0145] The present application also provides an electronic device. The electronic device is specifically used to implement Figure 6 The functions of the alarm information processing system 60 in the illustrated embodiment.
[0146] Figure 7 A schematic diagram of the structure of an electronic device 700 is provided. Figure 7 As shown, the electronic device 700 includes a bus 701, a processor 702, a communication interface 703 and a memory 704. The processor 702, the memory 704 and the communication interface 703 communicate with each other via the bus 701.
[0147] The bus 701 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 7 Only one thick line is used in the diagram, but this does not mean that there is only one bus or only one type of bus.
[0148] The processor 702 may be any one or more of a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).
[0149] The communication interface 703 is used for communicating with the outside. For example, the communication interface 703 can be used for communicating with a terminal.
[0150] The memory 704 may include a volatile memory, such as a random access memory (RAM). The memory 704 may also include a non-volatile memory, such as a read-only memory (ROM), a flash memory, a hard disk drive (HDD), or a solid state drive (SSD).
[0151] The memory 704 stores executable codes, and the processor 702 executes the executable codes to perform the aforementioned alarm information processing method.
[0152] Specifically, in implementing Figure 6 In the case of the embodiment shown, and Figure 6 When each module or unit of the alarm information processing system 60 described in the embodiment is implemented by software, the execution Figure 6 The software or program code required for the functions of each module / unit in the system may be partially or completely stored in the memory 704. The processor 702 executes the program code corresponding to each unit stored in the memory 704 to perform the above-mentioned alarm information processing method.
[0153] The embodiment of the present application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that can be stored by the computing device or a data storage device such as a data center containing one or more available media. The available medium can be a magnetic medium (such as a floppy disk, a hard disk, a tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid-state hard disk). The computer-readable storage medium includes instructions that instruct the computing device to execute the above-mentioned alarm information processing method applied to the alarm information processing system 60.
[0154] The embodiment of the present application further provides a computer program product, which includes one or more computer instructions. When the computer instructions are loaded and executed on a computing device, the process or function described in the embodiment of the present application is generated in whole or in part.
[0155] The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from one website, computer or data center to another website, computer or data center via wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means.
[0156] When the computer program product is executed by a computer, the computer executes any of the aforementioned alarm information processing methods. The computer program product may be a software installation package, and when any of the aforementioned alarm information processing methods is needed, the computer program product may be downloaded and executed on a computer.
[0157] The flow chart and block diagram in the accompanying drawings illustrate the possible architecture, function and operation of the system, method and computer program product according to each embodiment of the present application. In this regard, each square box in the flow chart or block diagram can represent a module, a program segment or a part of a code, and the module, the program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some implementations as replacements, the functions marked in the square box can also occur in a sequence different from that marked in the accompanying drawings. For example, two square boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each square box in the block diagram and / or flow chart, and the combination of the square boxes in the block diagram and / or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0158] The units involved in the embodiments described in this application may be implemented by software or hardware, wherein the name of the unit / module does not, in some cases, constitute a limitation on the unit itself.
[0159] The functions described above herein may be performed at least in part by one or more hardware logic components. For example, without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), complex programmable logic devices (CPLDs), and the like.
[0160] In the context of the present application embodiment, machine-readable medium can be a tangible medium that can contain or store a program for use by an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. Machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. Machine-readable medium can include but is not limited to electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination of the above. More specific examples of machine-readable storage media can include electrical connections based on one or more lines, portable computer disks, hard disks, random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM or flash memory), optical fibers, portable compact disk read-only memories (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above.
[0161] It should be noted that the various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments, and the same or similar parts between the various embodiments can be referred to each other. For the system or device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part description.
[0162] It should be understood that in the present application, "at least one (item)" means one or more, and "plurality" means two or more. "And / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the objects associated before and after are in an "or" relationship. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.
[0163] It should also be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the presence of other identical elements in the process, method, article or device including the elements.
[0164] The steps of the method or algorithm described in conjunction with the embodiments disclosed herein may be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.
[0165] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present application. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but will conform to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A method for processing alarm information, comprising: Obtaining a first network threat detection result, where the first network threat detection result includes at least one piece of warning information, where the warning information includes information used to describe a network security threat event; sending second prompt information generated at least based on the at least one alarm information to a second target model, receiving target plug-in information returned by the second target model, and acquiring first auxiliary information based on a target plug-in indicated by the target plug-in information, wherein the second prompt information is used to instruct the second target model to determine a plug-in for acquiring the first auxiliary information, and the first auxiliary information is used to assist in alarm interpretation; The target plug-in includes one or more of an Internet search plug-in, a URL encoding and decoding plug-in, a Base64 encoding and decoding plug-in, and a threat intelligence search plug-in; and, acquiring second auxiliary information from an alarm knowledge base according to the at least one alarm information, the alarm knowledge base comprising a plurality of historical alarm information and alarm context information corresponding to the plurality of historical alarm information; sending first prompt information generated at least based on the first network threat detection result, the first auxiliary information, and the second auxiliary information to a first target model, and receiving an interpretation result generated by the first target model for the first network threat detection result, wherein the first prompt information is used to instruct the first target model to generate the interpretation result, and the first target model and the second target model are language models with natural language processing capabilities, and are used to understand natural language meanings and process natural language tasks; The interpretation results are presented.
2. The method according to claim 1, characterized in that The target plug-in includes an Internet search plug-in; The target plug-in based on the target plug-in information indication obtains the first auxiliary information, including: in response to the at least one alarm information including information related to an unknown alarm indicator, obtaining the first auxiliary information based on the Internet search plug-in, the unknown alarm indicator is an alarm indicator not included in the existing database, and the first auxiliary information is related to the unknown alarm indicator.
3. The method according to claim 1, characterized in that The target plug-in includes a URL encoding and decoding plug-in; The target plug-in based on the target plug-in information indication obtains the first auxiliary information, including: in response to the at least one alarm information including URL-encoded content, obtaining the first auxiliary information based on the URL encoding and decoding plug-in, the first auxiliary information including content decoded from the URL-encoded content.
4. The method according to claim 1, characterized in that: The target plug-in includes a Base64 encoding and decoding plug-in; The target plug-in based on the target plug-in information indication obtains the first auxiliary information, including: in response to the at least one alarm information including Base64 encoded content, obtaining the first auxiliary information based on the Base64 encoding and decoding plug-in, the first auxiliary information including content decoded from the Base64 encoded content.
5. The method according to claim 1, characterized in that The target plug-in includes a threat intelligence search plug-in; The target plug-in based on the target plug-in information indication obtains the first auxiliary information, including: in response to the at least one alarm information including the threat intelligence indicator to be identified, obtaining the first auxiliary information based on the threat intelligence search plug-in, wherein the first auxiliary information is related to the threat intelligence indicator to be identified.
6. The method according to claim 1, characterized in that The obtaining of the first network threat detection result includes: In response to a trigger operation on a preset control in a network threat detection page, a first network threat detection result is obtained, wherein the preset control is used to trigger an interpretation of the first network threat detection result.
7. The method according to claim 1, characterized in that The acquiring second auxiliary information from an alarm knowledge base according to the at least one alarm information includes: Determine a vector representation corresponding to the at least one piece of warning information; Respectively calculating the similarity between the vector representation corresponding to the at least one piece of alarm information and the vector representations corresponding to the plurality of pieces of historical alarm information in the alarm knowledge base; Determining alarm context information corresponding to the target historical alarm information according to the target historical alarm information whose similarity meets the set condition; The second auxiliary information is determined according to the alarm context information corresponding to the target historical alarm information.
8. The method according to claim 1, characterized in that Before sending the first prompt information generated based on the first network threat detection result, the first auxiliary information, and the second auxiliary information to the first target model, the method further includes: Extracting key identification information from the at least one warning message; The key identification information is encrypted, and the first network threat detection result is updated.
9. The method according to claim 8, characterized in that Before presenting the interpretation result, the method further includes: Extracting result information associated with key identification information from the interpretation result; The result information associated with the key identification information is decrypted, and the interpretation result is updated.
10. The method according to any one of claims 1 to 9, characterized in that: The interpretation result indicates at least one of the following: the type of alarm information, the meaning of the alarm data associated with the alarm information, the level of the alarm information, the impact scope of the alarm information, and reference information related to the interpretation result.
11. An alarm information processing system, characterized in that: The system comprises: A first acquisition module, configured to acquire a first network threat detection result, wherein the first network threat detection result includes at least one piece of warning information, and the warning information includes information for describing a network security threat event; A second acquisition module is used to send second prompt information generated at least based on the at least one alarm information to a second target model, receive target plug-in information returned by the second target model, and acquire first auxiliary information based on the target plug-in indicated by the target plug-in information, wherein the second prompt information is used to indicate the plug-in determined by the second target model to acquire the first auxiliary information, and the first auxiliary information is used to assist in alarm interpretation; the target plug-in includes one or more of an Internet search plug-in, a URL encoding and decoding plug-in, a Base64 encoding and decoding plug-in, and a threat intelligence search plug-in; and, based on the at least one alarm information, acquire the second auxiliary information from an alarm knowledge base, wherein the alarm knowledge base includes multiple historical alarm information and alarm context information corresponding to the multiple historical alarm information; A communication module, configured to send first prompt information generated based at least on the first network threat detection result, the first auxiliary information, and the second auxiliary information to a first target model, and receive an interpretation result generated by the first target model for the first network threat detection result, wherein the first prompt information is used to instruct the first target model to generate the interpretation result, and the first target model and the second target model are language models with natural language processing capabilities, and are used to understand natural language meanings and process natural language tasks; A presentation module is used to present the interpretation result.
12. An electronic device, characterized in that: The electronic device comprises a processor and a memory; The processor is configured to execute instructions stored in the memory, so that the electronic device performs the method according to any one of claims 1 to 10.
13. A computer-readable storage medium, characterized in that: The method comprises instructions, wherein the instructions instruct an electronic device to execute the method according to any one of claims 1 to 10.
Citation Information
Patent Citations
Attack detection method and device, terminal equipment and storage medium
CN117240598A
Safety management method for multi-source data joint processing, electronic equipment and storage medium
CN117521124A