A detection method, system, device and storage medium
Through the automated network access security detection method, the detection data is preprocessed and abnormal detection using adapters and decision-making tools, which solves the problems of dispersed and human participation of detection tools in the prior art, and achieves efficient and reliable network access security detection.
Patent Information
- Application Number
- CN202410896572.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-04
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2044-07-04
AI Technical Summary
Existing security detection tools for network access are scattered and require human participation, resulting in detection limitations and human errors, affecting detection reliability.
It provides an automated detection method, by receiving detection requirements and data, using adapters to match target decision-making tools, pre-processing and abnormal detection of detection data, determining network access results, and reducing manual intervention.
It realizes full-process automated network access security inspection, improves the reliability and efficiency of inspection, saves human resources, and reduces human error.
Smart Images

Figure CN118764247B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure generally relates to the field of network security, and particularly relates to a detection method, system, device, and storage medium. Background Art
[0002] Network access security detection is used to detect whether it is safe to access the network for servers, workstations, mobile devices, etc. before they need to connect to the enterprise's internal network or the public Internet, so as to ensure that there are no potential security vulnerabilities or configuration problems.
[0003] Currently, network access security detection needs to rely on various independently operating security tools, such as separate vulnerability scanning software, weak password detection programs, configuration audit systems, etc., and its detection method has certain limitations. Summary of the Invention
[0004] In view of the above-mentioned defects or deficiencies in the prior art, it is desirable to provide a detection method, system, device, and storage medium that can automatically perform network access security detection and improve the reliability of network access security detection.
[0005] In a first aspect, a detection method is provided, and the method includes:
[0006] In response to the occurrence of a target event, receiving a detection requirement and detection data for an object to be detected;
[0007] Based on the detection requirement, matching a target decision tool for the object to be detected, and preprocessing the detection data to obtain target data;
[0008] Performing anomaly detection on the target data according to the target decision tool, and determining the network access result of the object to be detected according to the detection result.
[0009] For the detection method provided in this application, considering that the current tools for network access security detection are relatively scattered and mostly require human participation, which has certain limitations, this application provides a detection method. This detection method can automatically match a corresponding target decision tool for the object to be detected according to the detection requirement and detection data of the object to be detected, so as to perform anomaly detection on the target data obtained after preprocessing the object to be detected through the target decision tool, and determine whether to allow the object to be detected to access the network according to the detection result of the anomaly detection. This system can automatically perform network access security detection on the object to be detected without human participation throughout the process. It can not only avoid the limitations of network access security detection, but also save human resources, and further avoid the situation where inaccurate detection is likely to occur due to human participation, so as to improve the reliability of network access security detection.
[0010] In a second aspect, a detection system is provided, and the system is used to execute the steps of the method provided in the first aspect.
[0011] In a third aspect, a computer device is provided, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps of the method provided in the first aspect are implemented.
[0012] In a fourth aspect, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps of the method provided in the first aspect are implemented. Description of the Drawings
[0013] By reading the detailed description of the non-limiting embodiments with reference to the following drawings, other features, objects, and advantages of the present application will become more apparent:
[0014] Figure 1 It is a scenario diagram of an application of a detection method provided by the present application;
[0015] Figure 2 It is a flowchart of a detection method provided by the present application;
[0016] Figure 3 It is a step flowchart of a detection method provided by the present application;
[0017] Figure 4 It is a step flowchart of a detection method provided by the present application;
[0018] Figure 5 It is a step flowchart of a detection method provided by the present application. Detailed Embodiments
[0019] The present application will be further described in detail below with reference to the drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the related invention and are not intended to limit the invention. Additionally, it should be noted that for the sake of description, only the parts related to the invention are shown in the drawings.
[0020] It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other. The present application will be described in detail below with reference to the drawings and embodiments.
[0021] Please refer to Figure 1 , Figure 1It is an application scenario diagram of a detection method provided by this application. In this application scenario diagram, it includes a server 100 to be detected that needs to perform network access security detection, a security tool 200, and a detection service device 300 equipped with the detection system provided by this application. When the server 100 to be detected needs to perform network access security detection, the security tool 200 obtains corresponding detection data from the server 100 to be detected, and sends the obtained detection data to the detection service device 300. In addition, the user inputs corresponding detection requirements through an input module set on the detection service device 300, and the detection service device 300 performs anomaly detection on the detection data according to the detection requirements, so as to determine the network access result of the server 100 to be detected based on the detection result of the anomaly detection. Among them, the security tool 200 is a data collection and data forwarding tool provided by a third party. The detection service device 300 is a single server, a server cluster, etc.
[0022] Next, the detection method provided by this application will be described.
[0023] As Figure 2 shown, Figure 2 It is a step flowchart of a detection method provided by this application. The method includes:
[0024] Step S20: Receive a detection requirement and detection data for the object to be detected;
[0025] Among them, taking the application of this operation to the above-mentioned detection service device as an example for description. The detection service device can receive the detection data of the object to be detected from the security tool and the detection requirement sent by the user when detecting that there is a new device connected or receiving a new detection instruction, etc.
[0026] It should be noted here that different security tools are required for collecting detection data for different objects to be detected. In order to achieve the data efficacy between different security tools, this application provides different adapters. Each adapter provides services such as conversion output, automatic learning, and configuration adjustment for the corresponding security tool to automatically optimize data conversion and mapping rules. Setting different adapters can better cope with the compatibility challenges brought by the version upgrade of different security tools or the access of new security tools, and improve the flexibility and scalability of the system.
[0027] Each adapter is responsible for realizing the adaptive conversion and integration of the data output by different security tools. Each adapter provides the following standardized interfaces:
[0028] Adapter interface:
[0029] Input parameters:
[0030] tool_name: The name of the security tool
[0031] tool_version: Version number of the security tool
[0032] raw_data: Raw data output by the security tool
[0033] Export parameters:
[0034] normalized_data: Security data converted to a unified format
[0035] tool_capability: Functional features of the security tool
[0036] confidence_score: Confidence score of the conversion result
[0037] The object to be detected is any server, workstation, mobile device, etc. that needs to undergo network access security detection, and there is no limitation here.
[0038] The detection data is, for example, software configuration parameters, running data, etc. of the object to be detected.
[0039] The detection requirement is the information sent by the object that needs to perform network access security detection on the object to be detected to the detection service device. This information can include the dimensions for performing security detection on the object to be detected, the priority levels of detection for each dimension, etc.
[0040] Step S30: Preprocess the detection data to obtain target data, and based on the detection requirement, match a target decision tool for the target data;
[0041] Among them, after receiving the detection data from the security tool and obtaining the detection requirement, the above-mentioned detection service device can first store the detection data and the corresponding detection requirement in the central data warehouse of the system for subsequent use. The central data warehouse set up in the system of the present application can store the data collected from various security tools, and its setting can process and store a large amount of heterogeneous data.
[0042] After storing the data, the detection service device can perform the operation of matching a corresponding decision tool for the detection data. Since there are problems such as invalid data, different data sources, and different data formats in the detection data, before performing anomaly detection on the detection data, it is necessary to preprocess the detection data. Generally speaking, the goal of preprocessing is to unify the different detection data to facilitate subsequent anomaly detection and improve the efficiency and accuracy of anomaly detection.
[0043] To detect whether the data matches the target decision tool and perform anomaly detection on the detected data in a targeted manner, it can determine the dimensions of security detection based on the detection requirements to match the target decision tool according to the dimensions; it can also determine the detection priority based on the detection requirements and match the target decision tool according to the priority. This application does not limit this. It should be noted that different decision tools have different security detection functions. For example, the first decision tool is used to perform vulnerability scanning, the second decision tool is used to perform weak password detection, the third decision tool is used to perform configuration verification, and the fourth decision tool is used to perform code auditing. For a detection object to be detected, it is not limited to only performing anomaly detection on the detection object through one of the decision tools. Therefore, the target decision tool is not limited to one tool.
[0044] In an alternative embodiment, as Figure 3 shown, the detection service device can match the target decision tool for the detected data through the following method:
[0045] Step S301, perform semantic analysis on the detection requirements to obtain an analysis result;
[0046] Among them, the adapter provided in this application has a semantic analysis function and can perform semantic analysis on the detection requirements. This semantic analysis includes, for example: field division of the detection requirements, semantic recognition for each field, keyword extraction from the detection requirements, and parsing of the keywords, etc.
[0047] After performing semantic analysis on the detection requirements, the detection purpose can be comprehensively understood, that is, the analysis result is obtained. This analysis result is, for example, that the detection requirements are to detect vulnerabilities, detect weak passwords, and verify configurations. It should be noted here that the analysis method used by the tool for performing semantic analysis on the detection requirements can be related to or the same as the parsing method used by the tool for parsing the security functions of each decision tool.
[0048] Step S302, obtain the security function parsing information of each decision tool in the decision tool library;
[0049] Among them, there are multiple decision tools in the system, and the multiple decision tools form a decision tool library. Each decision tool in the decision tool library can correspond to different detection functions. The decision tool library has a description of the security function parsing information (that is, what detection functions it has) for each decision tool. This description can correspond to the name of each decision tool to obtain the security function parsing information. This security function parsing information is, for example:
[0050] The first decision tool is used to perform vulnerability scanning
[0051] The second decision tool is used to perform weak password detection
[0052] The third decision-making tool is used to perform configuration verification
[0053] The fourth decision-making tool is used to perform code auditing
[0054] Therefore, by obtaining the security function parsing information, the functions of each decision-making tool can be obtained
[0055] Step S303: Match the analysis result with the security function parsing information of each decision-making tool, and determine all the decision-making tools with successful matching as the target decision-making tools
[0056] Among them, according to the analysis result obtained by semantic analysis of the detection requirements, the purpose of the detection is determined. At the same time, the security function parsing information of each decision-making tool is obtained. Since the analysis result includes the security function parsing information of some decision-making tools among each decision-making tool, by matching the analysis result with the security function parsing information of each decision-making tool, the target decision-making tool can be obtained by matching
[0057] Exemplarily, if the analysis result is to detect vulnerabilities, detect weak passwords, and verify configurations, then the target decision-making tools obtained by matching can be: the first decision-making tool, the second decision-making tool, and the third decision-making tool
[0058] After matching the target decision-making tool according to the above method, only the target decision-making tool needs to be called
[0059] In another optional embodiment, as Figure 4 shown Figure 4 The steps for preprocessing the detection data for the system provided by this application are as follows. This step includes
[0060] Step S401: Perform data cleaning operations on the detection data to obtain intermediate data
[0061] Among them, data cleaning is used to remove invalid data in the detection data or detection data with a difference greater than the difference threshold from other detection data, so as to initially screen the detection data to obtain intermediate data
[0062] Step S402: Identify the field meaning and organizational structure of the intermediate data according to the historical knowledge base
[0063] Among them, the historical knowledge base can be preset in the central data warehouse of the system, and it includes the result of identifying the meaning of each field and the result of identifying the organizational structure obtained according to the historical data parsing result. Therefore, after dividing the fields of the intermediate data, matching the divided fields with the historical knowledge base can obtain the result of identifying the field meaning and organizational structure of the intermediate data
[0064] Step S403: Perform format conversion on the intermediate data according to the recognition result and the preset conversion rules to obtain the target data.
[0065] Among them, the purpose of format conversion is to perform an operation to unify the formats of the intermediate data with inconsistent formats. In the system, preset conversion rules can be set. According to the recognition result obtained by recognizing the intermediate data and the preset conversion rules, the intermediate data with inconsistent formats can be converted into data with unified formats, and then the target data can be obtained.
[0066] Optionally, the system can also perform normalization processing on the data to process the data within an appropriate range.
[0067] In addition, since the intermediate data can be from different positions of the object to be detected, the system in this application can also perform data fusion processing on the intermediate data from different sources. This data fusion processing can fuse the intermediate data based on the recognition result of the field meaning of the data, the recognition result of the organizational structure, the data content, the relevance between the data, the connectivity between the data, etc., to obtain the target data, so as to enhance the overall value of the target data and facilitate subsequent anomaly detection.
[0068] After the system provided in this application obtains the target data by processing the detection data and determines the target decision tool for anomaly detection for the target data, it is necessary to input the target data into the target decision tool for anomaly detection. However, before the system sends the target data to the target decision tool, in order to ensure the processing effect of the detection data, the following operations are also performed:
[0069] Evaluate the credibility of the conversion result and generate the corresponding confidence score;
[0070] Among them, the credibility is used to evaluate the processing effect of the preprocessing result of the detection data and is quantified as a confidence score. Evaluating the credibility of the conversion result can be achieved through a credibility evaluation model, algorithm, etc., which will not be elaborated here.
[0071] Determine whether to send the target data to the target decision tool according to the confidence score and the score threshold.
[0072] Among them, the score threshold can be a judgment criterion determined according to historical experience, experimental data, etc. for defining whether to send the target data to the target decision tool. It can be understood that when the confidence score is higher than the score threshold, it can be determined to send the target data to the target decision tool. On the contrary, when the confidence score is lower than the score threshold, it can be determined to reject sending the target data to the target decision tool.
[0073] Then, after determining to reject sending the target data to the target decision tool, an operation of preprocessing the detection data again can be performed, repeating the above steps until a result with a confidence score higher than the score threshold is obtained, and then the obtained target data is sent to the target decision tool.
[0074] Step S40: Perform anomaly detection on the target data according to the target decision tool, and determine the network access result of the object to be detected according to the detection result.
[0075] Among them, after the target data is sent to the target decision tool, each target decision tool can perform operations such as classifying and clustering the target data through the K-means clustering algorithm and identifying abnormal patterns in the target data through the isolation forest algorithm to achieve anomaly detection of the target data.
[0076] The K-means clustering algorithm assigns the target data to K clusters and classifies and clusters it in a way that minimizes the distance between each target data and its nearest mean (cluster center). This method can help identify different types of security events and patterns, such as common attack types, abnormal traffic patterns, etc.
[0077] The isolation forest algorithm isolates observations by randomly selecting features and randomly selecting the cut-off value of the feature. Abnormal data is usually easier to isolate and thus has a shorter path length. The system can use this algorithm to quickly identify abnormal patterns in the data, such as non-standard network access operation modes or unauthorized access, etc.
[0078] It should be noted here that as long as one target decision tool identifies an anomaly among each target decision tool, it is determined that the network access result of the object to be detected is prohibited from network access. On the contrary, if all target decision tools identify no anomaly, it is determined that the network access result of the object to be detected is allowed to access the network. Of course, there can also be other determination methods, such as determining according to the proportion of anomalies in the detection results, the ratio of anomalies to normal, etc., and determining according to requirements, which are not limited here.
[0079] During the process of the target decision tool performing anomaly detection on the target data, the system can also perform the following operations:
[0080] During the process of performing anomaly detection on the target data according to the target decision tool, intercept the intermediate detection results in real time;
[0081] Among them, during the process of the target decision-making tool performing anomaly detection on the target data, it can output corresponding intermediate detection results in real time. The intermediate detection results are not used as the final detection results, and are only used to provide data support for adjusting the execution order and operation parameters of the target decision-making tool. The intermediate detection results can be intercepted according to time periods. For example, the target decision-making tool can output an intermediate detection result every 1 second. Then, the target decision-making tool can perform multiple anomaly detections or perform a predetermined number of anomaly detections during continuous adjustment to obtain more accurate detection results.
[0082] Adjust the execution order and operation parameters of the target decision-making tool according to the intermediate detection results.
[0083] Among them, since the target decision-making tool includes more than one decision-making tool, there can be an execution order among the various decision-making tools. In addition, each decision-making tool has its own operation parameters. In order to make the detection results more accurate, after the system continuously intercepts the intermediate detection results, it can adjust the execution order and operation parameters of the target decision-making tool according to the intermediate detection results to optimize the detection process and improve the accuracy of the detection results.
[0084] Exemplarily, when the target decision-making tools are the first decision-making tool, the second decision-making tool, and the third decision-making tool, the initial execution order is to first perform anomaly detection on the target data through the first decision-making tool, then perform anomaly detection on the target data through the second decision-making tool, and finally perform anomaly detection on the target data through the third decision-making tool. After obtaining the intermediate detection results for the first time, the execution order can be adjusted to first perform anomaly detection on the target data through the second decision-making tool, then perform anomaly detection on the target data through the third decision-making tool, and finally perform anomaly detection on the target data through the first decision-making tool.
[0085] In another alternative embodiment, the system can also determine the anomaly trend of the object to be detected according to the number of anomaly data in the detection results and historical data. For example, use the change trend of the number of anomaly data over time to determine whether the number of future anomaly data will increase, etc. Provide a basis for repair for the user by performing predictive analysis on the object to be detected, which is convenient for the user to improve the object to be detected.
[0086] It should be noted here that the system of the present application also provides a platform for user interface interaction. By setting up this interaction platform, it is possible to enable the user to interact with the system so that the system can receive the user's detection requirements. In addition, the system can also display the detection results obtained from the detection, the determined network access results, etc., so as to facilitate the user to quickly understand the detection results.
[0087] The platform for user interface interaction can support customized views and reports to meet the needs of different users.
[0088] In addition, the automated network access security detection system provided by this application can not only determine whether the object to be detected can access the network, but also monitor the object to be detected and perform emergency response after the object to be detected accesses the network. For example Figure 5 As shown, it specifically includes the following steps:
[0089] It should be noted that the system can monitor the object to be detected according to the set event-driven module, and trigger corresponding automated security responses based on the detected abnormal events. The core interfaces of this architecture are as follows:
[0090] Event-driven module interface:
[0091] Input parameters:
[0092] event_type: The type of security event detected
[0093] event_data: The original data related to the event
[0094] event_time: The timestamp when the event occurred
[0095] event_source: The source device or system of the event
[0096] Output parameters:
[0097] risk_assessment: The risk assessment of the event
[0098] response_strategy: The automated response strategy
[0099] notification_target: The security administrator who needs to be notified
[0100] The event-driven module incorporates an efficient real-time monitoring sub-module. The real-time monitoring sub-module is used to continuously collect and analyze network traffic, system logs, and other security-related data sources. This monitoring sub-module adopts streaming data processing technology and can detect and process real-time generated data streams, rather than relying on periodic scans.
[0101] In addition, the event-driven module also integrates a predictive analysis function, which can use historical data to train machine learning models to predict possible future security events and trends. Compared with other big data-based denoising and cleaning solutions, this solution can achieve the predictive analysis function of the event-driven module without the need for denoising and cleaning by using the machine learning module.
[0102] Step S501, obtain the operation data of the object to be detected;
[0103] Among them, the operation data of the object to be detected can be obtained through the corresponding security tool and sent to the system. The operation data includes, for example, log files, network traffic, security data, etc.
[0104] Step S502: Input the operation data into the prediction model for risk identification to obtain the identification result.
[0105] Among them, the prediction model is a model trained by using machine learning algorithms such as time series analysis and anomaly detection based on the security event data collected historically. This prediction model can be stored in the central data warehouse of the system and can be directly called when risk identification is required.
[0106] The prediction model is used for risk identification. Therefore, inputting the operation data of the object to be detected into the prediction model can perform risk prediction on the operation situation of the object to be detected. The prediction model can output identification results of "at risk" or "not at risk". It can also output the corresponding risk level, which is not limited here.
[0107] Step S503: If the identification result is abnormal, generate abnormal information, where the abnormal information includes operation data, abnormal type, occurrence event, and abnormal source.
[0108] Among them, if the identification result output by the prediction model is abnormal, the system can generate abnormal information based on the operation data, abnormal type, occurrence event, and abnormal source. This abnormal information is used to record the abnormal situation of the object to be detected in more detail and provide a reliable basis for subsequent risk assessment.
[0109] Step S504: Input the abnormal information into the risk assessment model to obtain the risk assessment score.
[0110] Among them, the risk assessment model is also a pre-trained model and is stored in the central data warehouse of the system. When risk assessment is required, it can be directly called.
[0111] The risk assessment model is used to perform risk assessment on the object to be detected according to the abnormal information and output the corresponding risk assessment score.
[0112] Step S505: Determine the risk remediation strategy according to the corresponding information and the risk assessment score, where the corresponding information includes multiple risk assessment scores and the risk remediation strategies corresponding to each risk assessment score.
[0113] Among them, the corresponding information is, for example:
[0114] First risk assessment score First risk remediation strategy
[0115] Second risk assessment score Second risk remediation strategy
[0116] Third risk assessment score, third risk remediation strategy
[0117] Fourth risk assessment score, fourth risk remediation strategy
[0118] The corresponding information can be pre-set and stored in the central data warehouse of the system. After obtaining the risk assessment score according to the risk assessment model, the risk assessment score is matched with the corresponding information, and then the risk remediation strategy can be obtained. The risk remediation strategy is used to avoid, eliminate or mitigate the risks generated by the object to be detected. The risk remediation strategy is, for example, isolating the affected device, blocking suspicious traffic, triggering patch deployment, notifying the security team, etc. The system designs an automated response process to enable rapid and effective execution of security measures when a threat is detected, reducing manual intervention.
[0119] In addition, in the case where the risk assessment score is greater than the score threshold, the present application can also generate corresponding alarm information and send the alarm information to the administrator of the object to be detected. So as to inform the administrator in a timely manner, ensure that the administrator can view the risk remediation strategy in a timely manner and make a response. The alarm information can be displayed in the form of a security report and provide key information and suggestions, so that the user can more intuitively and detailedly understand the risks existing in the object to be detected and the corresponding risk removal methods. This can improve the user experience.
[0120] In another embodiment, the system also creates a security knowledge base, which includes historical security events, known vulnerabilities and repair strategies, etc. The prediction model is continuously learned and trained through machine learning algorithms to obtain a more accurate detection model and improve the recognition accuracy of the model.
[0121] Regarding the detection method provided by the present application, considering that the tools for performing network access security detection are currently relatively scattered and mostly require human participation, which has certain limitations, the present application provides a detection method. This detection method can automatically match the corresponding target decision-making tool for the object to be detected according to the detection requirements and detection data of the object to be detected, and perform anomaly detection on the target data obtained after preprocessing the object to be detected through the target decision-making tool, so as to determine whether to allow the object to be detected to access the network according to the detection result of the anomaly detection. This system can automatically perform network access security detection on the object to be detected without human participation throughout the process. It can not only avoid the limitations of network access security detection, but also save human resources, and further avoid the situation where inaccurate detection is likely to occur due to human participation, achieving the improvement of the reliability of network access security detection.
[0122] It should be noted that although the operations of the method of the present invention are described in a specific order in the accompanying drawings, this does not require or imply that these operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. On the contrary, the order of the steps depicted in the flowchart can be changed. For example,... Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step for execution, and / or one step may be decomposed into multiple steps for execution. For example,...
[0123] In another embodiment, the present application further provides a detection system for performing the above detection method.
[0124] In an alternative embodiment, the present application further provides a detection device, which includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the above detection method is implemented.
[0125] As another aspect, the present application further provides a computer-readable storage medium, which may be the computer-readable storage medium included in the device in the above embodiment; or it may exist alone and be a computer-readable storage medium not assembled into the device. The computer-readable storage medium stores one or more programs, and the one or more programs are used by one or more processors to execute the formula input method described in the present application.
[0126] The above description is only a preferred embodiment of the present application and an explanation of the applied technical principles. Those skilled in the art should understand that the scope of the invention involved in the present application is not limited to the technical solution formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the inventive concept. For example, the technical solutions formed by mutually replacing the above features with the (but not limited to) technical features having similar functions disclosed in the present application.
Claims
1. A detection method, characterized in that, The method includes: Receiving a detection requirement and detection data for an object to be detected; the detection data includes software configuration parameters and operation data of the object to be detected, and the detection requirement includes dimensions for performing security detection on the object to be detected and priority levels for detection in each dimension; Preprocessing the detection data to obtain target data, and matching a target decision tool for the target data based on the detection requirement; Performing anomaly detection on the target data according to the target decision tool, and determining the network access result of the object to be detected according to the detection result; Among them, the matching of the target decision tool for the target data based on the detection requirement includes: Performing semantic analysis on the detection requirement to obtain an analysis result; the semantic analysis includes field division of the detection requirement, semantic recognition for each field, keyword extraction from the detection requirement, and parsing of the keywords; Obtaining security function parsing information of each decision tool in a decision tool library, where the decision tool library includes multiple decision tools and security function parsing information corresponding to each decision tool; Matching the analysis result with the security function parsing information of each decision tool, and determining all the decision tools with successful matching as the target decision tools.
2. The method according to claim 1, wherein The preprocessing of the detection data to obtain target data includes: Performing a data cleaning operation on the detection data to obtain intermediate data; Identifying the field meaning and organizational structure of the intermediate data according to a historical knowledge base, where the historical knowledge base includes the result of identifying the meaning of each field and the result of identifying the organizational structure obtained according to historical data parsing results; Performing format conversion on the intermediate data according to the identification result and a preset conversion rule to obtain the target data.
3. The method according to claim 2, wherein The method further includes: After obtaining the target data, evaluating the credibility of the conversion result of the format conversion, and generating a corresponding confidence score; Determining whether to send the target data to the target decision tool according to the confidence score and a score threshold.
4. The method according to claim 1, characterized in that, The method further includes: After determining that the network access result of the object to be detected is allowed to access the network, obtaining the operation data of the object to be detected; Inputting the operation data into a prediction model for risk identification to obtain an identification result; If the identification result is abnormal, generating abnormal information, where the abnormal information includes the operation data, abnormal type, occurrence event, and abnormal source; Inputting the abnormal information into a risk assessment model to obtain a risk assessment score; Determining a risk remedy strategy according to the corresponding information and the risk assessment score, where the corresponding information includes multiple risk assessment scores and risk remedy strategies corresponding to each risk assessment score.
5. The method according to claim 1, characterized in that, The method further includes: During the process of performing anomaly detection on the target data according to the target decision tool, intercepting intermediate detection results in real time; Adjusting the execution order and operation parameters of the target decision tool according to the intermediate detection results.
6. The method according to claim 4, characterized in that The method further includes: If the risk assessment score is greater than the score threshold, generating an alarm message; Sending the alarm message to the administrator of the object to be detected.
7. A detection device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method described in any one of claims 1 to 6.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the method described in any one of claims 1 to 6.
Citation Information
Patent Citations
Decision recommendation method and device
CN117478358A