A method and system for large-scale attack monitoring based on real-time computation

By employing a large-scale attack monitoring method based on real-time computing, and utilizing a distributed stream processing platform and threat intelligence database to analyze log data, the problem of existing systems being unable to respond in real time and accurately identify attacks has been solved. This enables rapid and accurate attack identification and defense, thereby enhancing network security protection capabilities.

CN119011184BActive Publication Date: 2025-11-07NARI INFORMATION & COMM TECH +4
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410862160.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-28
Publication Date
2025-11-07
Estimated Expiration
2044-06-28

AI Technical Summary

Technical Problem

Existing attack monitoring systems cannot detect and respond to attacks in real time, have weak attack correlation analysis capabilities, and cannot quickly and accurately identify attacks originating from the same source.

Method used

A large-scale attack monitoring method based on real-time computing is adopted. Log data is analyzed through a distributed stream processing platform, including two-level analysis based on common attack sources of C-segment, common attack analysis of vulnerability in business systems, and common attack analysis of attack maturity. Combined with threat intelligence database and security patch judgment, the real-time identification and tracing of attacks are achieved.

Benefits of technology

It enables rapid and accurate identification of abnormal behavior and attack patterns in network traffic, improves the accuracy and real-time nature of alarm data, enhances network security protection capabilities, and can promptly detect unknown threats and formulate effective defense measures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119011184B_ABST
    Figure CN119011184B_ABST
Patent Text Reader

Abstract

The application discloses a large-scale attack monitoring method and system based on real-time calculation, and the method comprises the following steps: acquiring log data; analyzing the log data through a distributed stream processing platform; analyzing two-stage analysis based on C-segment common attack sources; generating a first attention list according to the attack times of objects, obtaining the physical position of the attacked objects through position analysis, and obtaining the C-segment range to which the IP addresses of the attacked objects belong through threat intelligence library correlation; performing trend analysis on attack data in a first preset time period based on the first attention list information, and predicting the next attack time of the attacked objects; and performing correlation analysis on the whole network to obtain other attacked areas. The application realizes real-time calculation through three analysis methods, quickly and accurately identifies abnormal behaviors and attack modes, improves the accuracy and real-time performance of alarm data, and performs correlation analysis on attack sources, attack means and attacked business systems, integrates commonalities, and quickly forms disposal suggestions.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of computer information processing, and particularly relates to a large-scale attack monitoring method and system based on real-time computing. BACKGROUND

[0002] With the rapid development of network technology, network security problems are increasingly prominent, especially large-scale attack events occur frequently, which seriously threatens the normal operation and data security of enterprises. In order to cope with this challenge, attack monitoring technology has become an important research direction in the field of network security.

[0003] Traditional attack monitoring methods are mainly based on log analysis, but due to the diversity of log formats and large amount of data, it is difficult to achieve fast and accurate attack correlation and early warning. In addition, existing attack monitoring systems mostly only defend against known threats, and have limited ability to discover unknown potential threats. Overall, the main shortcomings of the prior art are as follows: traditional attack monitoring systems usually use batch processing to analyze logs, which cannot detect and respond to attack behavior in real time, resulting in the inability to respond in a timely manner when an attack occurs; attack correlation analysis capability is weak, and cannot quickly and accurately identify homologous attack events.

[0004] Therefore, how to improve the efficiency and accuracy of attack monitoring and discover unknown threats in a timely manner has become a problem to be solved. SUMMARY

[0005] In view of the above existing problems, the present application is proposed.

[0006] Therefore, the present application provides a large-scale attack monitoring method and system based on real-time computing to solve the problem that the existing attack monitoring system cannot analyze logs in real time to detect and respond to attack behavior, resulting in the inability to respond in a timely manner when an attack occurs; attack correlation analysis capability is weak, and cannot quickly and accurately identify homologous attack events.

[0007] To solve the above technical problems, the present application provides the following technical solutions:

[0008] In a first aspect, the present application provides a large-scale attack monitoring method based on real-time computing, comprising:

[0009] obtaining log data;

[0010] analyzing the log data through a distributed stream processing platform;

[0011] The analysis includes two-level analysis based on C-segment common attack sources, which generates a first attention list according to the number of times of being attacked by objects, and obtains the physical position of the attacked object through position analysis, obtains the C-segment range of the IP address of the attacked object through threat intelligence library association, and is used for perfecting the first attention list information.

[0012] Trend analysis is performed on attack data in a first preset time period based on the first attention list information, and the next attack time of the attacked object is predicted in combination with the trend analysis result.

[0013] Based on the first attention list and the trend analysis, the correlation analysis is performed on the whole network to obtain other attacked areas.

[0014] As a preferred scheme of the large-scale attack monitoring method based on real-time calculation, wherein: the first attention list is generated according to the number of times of being attacked by objects, including:

[0015] If the address of any object is attacked more than a preset number of times within a preset first time range, the C-segment address corresponding to the object is included in the first attention list.

[0016] As a preferred scheme of the large-scale attack monitoring method based on real-time calculation, wherein: based on the physical position and the associated threat intelligence, the trend analysis is performed on the attack in a first preset time period, including:

[0017] Attack source data in a second preset time period in the attention list is obtained, and the number of attacks at each time scale in the time period is obtained.

[0018] The number of attacks is compared horizontally in the same time scale to obtain the attack trend.

[0019] As a preferred scheme of the large-scale attack monitoring method based on real-time calculation, wherein: based on the first attention list and the trend analysis, the correlation analysis is performed on the whole network to obtain other attacked areas, including:

[0020] A total database is obtained, the total database includes all sub-databases accessed to the total database, and the sub-databases include C-segment addresses in the first attention list of the region to which they belong.

[0021] The C-segment addresses in the sub-database of the region are matched and compared with the attack sources in the sub-databases of the remaining regions in the total database at regular time intervals.

[0022] If matched, it indicates that the attacker attacks the region corresponding to the matched sub-database at the same time.

[0023] As a preferred scheme of the large-scale attack monitoring method based on real-time calculation, wherein: the analysis further comprises a business system vulnerability commonality attack analysis, and the business system vulnerability commonality attack analysis specifically comprises:

[0024] Real-time acquisition of the number of attacks on all business systems within a preset second time range based on log data, and if there is a business system with the number of attacks exceeding a set threshold, the business system is included in a second watch list;

[0025] Acquisition of the attack types received by each business system in the second watch list within a second preset time period;

[0026] Acquisition of the feasibility of the attack in combination with the properties of the business system and the attack types received by the business system;

[0027] Acquisition of the reachability of the attack in association with the topology information of the attack path;

[0028] Noise reduction of the acquired attack data to perfect the second watch list information;

[0029] Acquisition of attack source IPs of the business system within a third preset time period, and acquisition of commonality features of the attack in combination with the second watch list information for tracing and countermeasures.

[0030] As a preferred scheme of the large-scale attack monitoring method based on real-time calculation, wherein: the analysis further comprises a business system vulnerability commonality attack analysis, and the business system vulnerability commonality attack analysis specifically comprises:

[0031] Real-time acquisition of all attack means data based on log data, association of vulnerabilities with contents involved in the attack means, and inclusion of the attack means on the association in a third watch list;

[0032] Acquisition of business systems attacked within a fourth preset time period in the third watch list, and association with corresponding business system asset properties, and combination with security patches to determine whether the attack means will affect the business system;

[0033] Acquisition of attack sources within a fifth preset time period in the third watch list, and association with analysis of physical addresses and threat intelligence of the attack sources for tracing and countermeasures.

[0034] In a second aspect, the application provides a large-scale attack monitoring system based on real-time calculation, comprising:

[0035] An acquisition module for acquiring log data;

[0036] An analysis module for analyzing the log data through a distributed stream processing platform.

[0037] As a preferred solution of the large-scale attack monitoring system based on real-time calculation of the application, wherein: further comprising,

[0038] The first analysis module is used for two-level analysis of the C-segment common attack source;

[0039] The second analysis module is used for common attack analysis based on the business system vulnerability;

[0040] The third analysis module is used for common attack analysis based on the attack means maturity.

[0041] In a third aspect, the application provides a computing device, comprising:

[0042] A memory and a processor;

[0043] The memory is used for storing computer executable instructions, and the processor is used for executing the computer executable instructions, and the computer executable instructions, when executed by the processor, realize the steps of the large-scale attack monitoring method based on real-time calculation.

[0044] In a fourth aspect, the application provides a computer readable storage medium, which stores computer executable instructions, and the computer executable instructions, when executed by the processor, realize the steps of the large-scale attack monitoring method based on real-time calculation.

[0045] Compared with the prior art, the application has the beneficial effects that: the application realizes real-time calculation through three analysis methods, so that the abnormal behavior and attack mode in the network traffic can be quickly and accurately identified, the accuracy and real-time performance of the alarm data are improved, and the network security protection capability is improved by carrying out correlation analysis on the attack source, attack means and attacked business system, integrating common attacks and quickly forming disposal suggestions. BRIEF DESCRIPTION OF DRAWINGS

[0046] In order to more clearly illustrate the technical solutions of the embodiments of the application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the application, and for those skilled in the art, other drawings can also be obtained without creative labor on the basis of these drawings.

[0047] Figure 1 The overall flowchart of the large-scale attack monitoring method based on real-time calculation of an embodiment of the application;

[0048] Figure 2 The analysis type diagram in the large-scale attack monitoring method based on real-time calculation of an embodiment of the application;

[0049] Figure 3A two-stage analysis flowchart based on C-segment common attack source in the large-scale attack monitoring method based on real-time calculation according to an embodiment of the present application is shown in the figure.

[0050] Figure 4 A timing diagram of two-stage analysis based on C-segment common attack source in the large-scale attack monitoring method based on real-time calculation according to an embodiment of the present application is shown in the figure.

[0051] Figure 5 A timing diagram of service system vulnerability common attack in the large-scale attack monitoring method based on real-time calculation according to an embodiment of the present application is shown in the figure.

[0052] Figure 6 A timing diagram of attack means maturity common attack in the large-scale attack monitoring method based on real-time calculation according to an embodiment of the present application is shown in the figure. DETAILED DESCRIPTION

[0053] In order to make the above objectives, features and advantages of the present application more obvious and easy to understand, the specific embodiments of the present application will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor should fall within the scope of protection of the present application.

[0054] Embodiment 1

[0055] Reference Figures 1-6 According to an embodiment of the present application, a large-scale attack monitoring method based on real-time calculation is provided, comprising,

[0056] S100: As Figure 1 , log data is obtained;

[0057] It should be noted that the log data can include: intrusion prevention system (IPS) log, intrusion detection system (IDS) log, Web application firewall (WAF) log, unknown threat detection (sky eye) log, attack tracing device (wise eye) log, traffic analysis probe (NTA) log.

[0058] The above log data is stored for subsequent log preprocessing and data analysis.

[0059] It should also be noted that preprocessing is required before data analysis, and preprocessing mainly includes identification, deduplication, denoising, normalization and data enhancement processing of log data.

[0060] Specifically, data denoising: from the collected log data, the data with inconsistent format, number of attributes and requirements is directly deleted to improve data quality. Data deduplication: the data after data denoising is deduplicated. Within a specified time interval interval, if the same record appears multiple times only with different times and the same attributes, only the last record in the repeated record is retained. Data normalization: the log data after deduplication is normalized to convert various different expressions of the log into a unified description form. The normalization fields provided by the system include log receiving time, log generating time, log duration, user name, source address, source MAC address, source port, operation, destination address, destination MAC address, destination port, log event name, summary, level, original level, original type, network protocol, network application protocol, device address, device name, device type, etc. The analyst does not have to be familiar with different log information of different manufacturers, thereby greatly improving the analysis and auditing efficiency. Finally, the normalized data is sent to the analysis queue for subsequent two-level analysis based on C segment common attack source, analysis based on business system vulnerability common attack, and analysis based on attack means maturity common attack.

[0061] S200: analyzing the log data through the distributed stream processing platform;

[0062] It should be noted that the distributed stream processing platform is mainly used to build high-throughput, low-latency data pipelines and real-time data stream applications.

[0063] For example, the distributed stream processing platform can be Kafka, Apache Pulsar, or Pravega, etc.

[0064] Preferably, the processed data can be sent to the analysis queue of Kafka for subsequent data analysis.

[0065] S201: as Figure 2 , the analysis includes two-level analysis based on C segment common attack source.

[0066] S201-1: as Figure 3 and Figure 4 , a first attention list is generated according to the number of times of being attacked by the object, and the physical location of the attacked object is obtained through location analysis. The C segment range to which the IP address of the attacked object belongs is obtained through threat intelligence library association, which is used to perfect the first attention list information.

[0067] In one possible implementation, generating a first attention list according to the number of times of being attacked by the object includes:

[0068] If the address of any object is attacked more than a preset number of times within a preset first time range, the C segment address corresponding to the object is included in the first attention list.

[0069] The address of any object refers to the IP address of a host in a unit.

[0070] For example, the preset first time range can be 5 minutes, 10 minutes, or a custom time range according to actual conditions; and the preset number of times can be 10, 15, or other custom number of times.

[0071] It should be noted that after the C segment address corresponding to the attacked object is included in the first attention list, the C segment range to which the IP address of the subsequent attacked object belongs refers to the entire C segment range to which the IP segment belongs, so as to perfect the first attention list information. Internationally, the C class IP address network segment range covers the address space from 192.0.0.0 to 223.255.255.255, and has specific binary representation, network number and host number allocation, default subnet mask, and application scenarios.

[0072] It should also be noted that the threat intelligence library is used to associate the C segment range of the attacked object IP address. C segment analysis can reveal specific network segments or service providers that attackers may target, which supplements the first attention list information and helps identify potential larger-scale attack strategies or attacker preferences.

[0073] S201-2: Based on the first attention list information, trend analysis is performed on the attack data within a first preset time period, and the next attack time of the attacked object is predicted based on the trend analysis result.

[0074] For example, the first preset time period can be the previous week (7 days) or other custom time period.

[0075] In one possible implementation, the trend analysis includes:

[0076] Obtaining attack source data within the first preset time period in the attention list, and the number of attacks at each time scale within the time period;

[0077] Horizontally comparing the number of attacks within the same time scale to obtain the attack trend.

[0078] For example, the time scale can be divided by hours, and the trend graph is formed by horizontally comparing within the time scale to obtain the attack trend.

[0079] The trend analysis can also perfect the first attention list information while obtaining the attack trend, for the blue team commander or the traceability analysis group to conduct traceability countermeasures.

[0080] Based on the trend analysis results, the next attack time of the attacked object can be predicted. The time period can be segmented and analyzed based on the generated trend chart or trend data, and a prediction algorithm such as the Holt-Winters method or LSTM neural network can be used to predict the next attack time of the address segment.

[0081] It should be noted that this step of trend analysis aims to identify the changes in attack frequency and intensity over time, as well as whether there are periodic or other predictable patterns. Using this information, it is possible to attempt to predict the next possible attack time of a high-risk object, so as to deploy defense measures in advance.

[0082] S201-3: Correlation analysis of the entire network based on the first watchlist and trend analysis to obtain other attacked areas.

[0083] In one possible implementation, the correlation analysis of the entire network based on the first watchlist and trend analysis to obtain other attacked areas includes:

[0084] Obtain a total database, which includes all sub-databases of the access total database, and the sub-databases include C segment addresses in the first watchlist of the region to which they belong;

[0085] Match and compare the C segment addresses in the sub-database of the region with the attack sources in the sub-databases of the remaining regions in the total database at regular intervals;

[0086] If matched, it means that the attacker has attacked the region corresponding to the matched sub-database at the same time.

[0087] For example, the total database can be the data of the entire network (headquarters + network provinces), and the sub-database is the database of each network province. Upload the C network segment addresses analyzed by each network province to the headquarters database. Compare the C network segment addresses found by the network province with the attack sources of other network provinces at regular intervals. If matched, it means that the attacker has attacked other network provinces at the same time, and the relevant personnel of the network province are notified by short message to pay attention and handle it in time.

[0088] It should be noted that the correlation analysis of the entire network based on the information obtained from the first watchlist and trend analysis aims to discover other regions that are similar to known attack patterns but have not been directly listed as watchpoints. Such analysis can reveal potential attack paths, weaknesses that have not been fully recognized, or new targets that attackers may be exploring, thereby prompting the security team to expand the monitoring range and implement more comprehensive protection strategies.

[0089] S202: As Figure 2 and Figure 5 Based on the business system vulnerability common attack analysis, it specifically includes:

[0090] Real-time acquisition of the number of attacks on all business systems in a preset second time range based on log data, if there is a business system whose number of attacks exceeds a set threshold, it is included in the second watch list;

[0091] For example, the preset second time range can be the current day or other time range that meets the actual needs. If the number of attacks on a business system exceeds the set threshold, the top three attack numbers can be taken as the set threshold, and the corresponding attacked business system is added to the second watch list.

[0092] Acquire the attack types received by each business system in the second watch list in a second preset time period;

[0093] For example, the second preset time period can be the previous week (7 days) or other custom time period.

[0094] In combination with the properties of the business system itself and the attack types received by the business system, the feasibility of the attack is acquired;

[0095] Specifically, the properties of the business system itself include development language, framework, middleware, etc.

[0096] Specifically, the attack feasibility judgment can be achieved by analyzing the relevance and historical data of the attack behavior, identifying attack rules and trends, considering the purpose and action plan of the attack, and evaluating its pertinence and purpose, so that the feasibility of network attack evaluation can be more generally judged.

[0097] It should be noted that the evaluation of feasibility helps to prioritize the processing of systems that are both frequently attacked and easily broken, prioritize and optimize resource allocation, effectively reduce security risks, and improve overall security level.

[0098] In combination with the topology information of the attack path, the reachability of the attack is acquired;

[0099] For example, if this attack is discovered by an IPS, WAF blocking device, the attack is not reachable; if it is discovered by a bypass monitoring device, the attack is reachable.

[0100] It should be noted that the evaluation of reachability can help monitoring personnel decide whether to close unnecessary network access paths, reinforce network structure, and reduce attack surface.

[0101] Noise reduction is performed on the acquired attack data to perfect the second watch list information;

[0102] Acquire the attack source IP of the business system in a third preset time period, and acquire the common features of the attack in combination with the second watch list information for tracing and countermeasures.

[0103] For example, the third preset time period can be one hour or other customized time period.

[0104] It should be noted that the purpose of obtaining the attack source IP in this step is to obtain high-frequency IP, attack times, physical location, threat intelligence, and the like, so as to mine common characteristics by personnel experience or related analysis system. The identification of the common characteristics is helpful for constructing a more effective prevention mechanism, early warning and interception of similar future attacks, and traceability analysis by a blue team commander or a traceability analysis group for traceability countermeasures, and evaluation and reinforcement of the attacked business system.

[0105] S203: As Figure 2 and Figure 6 The attack means maturity common attack analysis specifically includes:

[0106] Based on the log data, all attack means data are obtained in real time, the vulnerabilities are associated with the contents involved in the attack means, and the attack means on the association are included in the third watch list.

[0107] Specifically, the vulnerabilities mainly come from the vulnerabilities involved in the early warning sheet or the vulnerability library.

[0108] The business system attacked in the fourth preset time period in the third watch list is obtained, and the corresponding business system asset attributes attacked are associated, and whether the attack means will affect the business system is judged in combination with the security patch.

[0109] For example, the fourth preset time period can be the previous week (7 days) or other customized time period.

[0110] Specifically, the asset attributes include development language, framework, middleware and the like.

[0111] For example, whether the attack means will affect the business system is judged in combination with the security patch, for example, SQL injection may leak sensitive data, and DDoS attack may cause system paralysis.

[0112] It should be noted that the analysis of the attack in the third watch list and the influence on the business system in this step is helpful for prioritizing the protection of the most important or most vulnerable system, ensuring the effective allocation of resources, and formulating an emergency repair plan according to the status of the security patch to reduce the risk exposure.

[0113] The attack source in the fifth preset time period in the third watch list is obtained, and the physical address and threat intelligence of the attack source are associated and analyzed for traceability analysis.

[0114] For example, the fifth preset time period can be the previous week (7 days) or other customized time period.

[0115] It should be noted that the correlation analysis finally obtains the geographical information of the attack and whether it hits the threat intelligence, thereby assisting the blue team commander or the traceability analysis group to further analyze the attack organization. The traceability analysis not only helps to understand the motivation, skill level and action pattern of the attacker, but also can provide a basis for formulating a defense strategy, such as implementing a targeted firewall rule and enhancing access control in a specific region.

[0116] In summary, the method of real-time calculation can quickly and accurately identify abnormal behaviors and attack patterns in network traffic, improving the accuracy and real-time performance of alarm data. The three analysis methods conduct correlation analysis on attack sources, attack means and attacked business systems, and integrate common attacks. From the perspective of attack sources, it is explored whether there is a common characteristic of C network segment. If this characteristic exists, the data of the entire headquarters network is viewed to determine whether the attack also attacks other network provinces, thereby obtaining a more valuable attack source. Then, from the analysis of attack means, it is analyzed what means are used to attack, how to counterattack, and which business systems are attacked, thereby performing security reinforcement and business system vulnerability search. The three analysis methods are progressive, but can also be analyzed in parallel or individually according to the needs.

[0117] The above is a schematic scheme of the large-scale attack monitoring method based on real-time calculation of the embodiment. It should be noted that the technical scheme of the large-scale attack monitoring system based on real-time calculation belongs to the same concept as the technical scheme of the large-scale attack monitoring method based on real-time calculation described above. The technical scheme of the large-scale attack monitoring system based on real-time calculation in the embodiment is not described in detail, and the description of the technical scheme of the large-scale attack monitoring method based on real-time calculation can be referred to.

[0118] The large-scale attack monitoring system based on real-time calculation in the embodiment includes:

[0119] The acquisition module is configured to acquire log data.

[0120] The analysis module is configured to analyze the log data through a distributed stream processing platform.

[0121] Further, it further includes,

[0122] The first analysis module is configured to perform two-level analysis based on C segment common attack sources.

[0123] The second analysis module is configured to perform common attack analysis based on business system vulnerability.

[0124] The third analysis module is configured to perform common attack analysis based on attack means maturity.

[0125] The embodiment also provides a computing device suitable for the case of large-scale attack monitoring based on real-time computing, comprising:

[0126] The memory is used for storing computer executable instructions, and the processor is used for executing the computer executable instructions to realize the method for implementing large-scale attack monitoring based on real-time computing proposed in the above embodiment.

[0127] The embodiment also provides a storage medium having a computer program stored thereon, and the program is executed by a processor to realize the method for implementing large-scale attack monitoring based on real-time computing proposed in the above embodiment.

[0128] The storage medium proposed in the embodiment belongs to the same inventive concept as the method for implementing large-scale attack monitoring based on real-time computing proposed in the above embodiment, and the technical details not described in the embodiment can be referred to the above embodiment, and the embodiment has the same beneficial effects as the above embodiment.

[0129] Through the above description of the embodiments, those skilled in the art can clearly understand that the present application can be realized by means of software and necessary general hardware, and of course can also be realized by hardware, but in many cases the former is a better embodiment. Based on such understanding, the technical solutions of the present application can be embodied in the form of a software product, which can be stored in a computer readable storage medium, such as a floppy disk, a read-only memory (ROM), a random access memory (RAM), a FLASH memory, a hard disk or an optical disk, etc., including a number of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute the methods of various embodiments of the present application.

[0130] Embodiment 2

[0131] Referring to Table 1, based on the previous embodiment, the present embodiment provides an application and comparison case of the method for large-scale attack monitoring based on real-time computing to illustrate the implementability of the scheme.

[0132] Detection data: The attack logs of the intrusion prevention device, the Web application protection device, the unknown threat discovery device, the terminal tracing analysis device and the threat monitoring probe device of the Internet area of the State Grid Information and Communication Company, the Tianjin Company and the Liaoning Company from the end of February 2023 to March 14 were analyzed.

[0133] There are many fields for each type of attack log, and the following 17 key feature fields are extracted, which are shown in Table 1.

[0134] Table 1 Feature field

[0135]

[0136]

[0137] Environment configuration: 3 machines, CPU of each machine: 16 cores, memory: 64G, disk: 512G, operating system: Redhat 7.5

[0138] Based on two-stage analysis of C segment commonality attack source, it is found for the first time that it is through a web application firewall with an address of 172.16.228.206, and the analysis shows that the attack source IP is 115.171.170.98, from the Internet area, the destination IP is 172.16.229.12, and the system belongs to the external resource pool host, and the attack is more than 10 times within 5 minutes, after the association C segment analysis, similar addresses 115.171.170.96 are found, which belong to the external resource pool host, and after trend analysis, it is predicted that 115.171.170.0 / 24 will continue to attack.

[0139] Based on the vulnerability of the business system, the top three addresses of the attacker are obtained, and the IP is 61.151.159.19 / 61.151.150.10 and 218.61.28.250, the device 172.16.228.206 is obtained, and the attack number is 3414, which is included in the second attention list, the attack type is, such as threat intelligence hit, unknown virus, etc., and the source is traced back.

[0140] Based on the maturity of the attack means, the attacked business system is the external resource pool host system (172.16.229.12) which is attacked 3468 times, the power transaction system (172.16.229.12) which is attacked 1705 times, etc., and the attack source is obtained for trace analysis.

[0141] A comparison between the scheme of the application and the traditional monitoring means is shown in Table 2.

[0142] Table 2 comparison parameters

[0143]

[0144]

[0145] It can be found from Table 2 that the three-stage analysis of our side can quickly monitor a large number of logs in real time, and the accuracy and prediction ability are better than the original batch processing analysis. The attack impact assessment based on business system vulnerability and attack means maturity analysis also includes business system impact degree, asset loss prediction, delay emergency response time, and is more comprehensive. Traditional tracing is inefficient and difficult to quickly take countermeasures. Our side realizes fast tracing based on C-stage analysis and attack means maturity analysis combined with threat intelligence library.

[0146] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present application and are not limiting. Although the present application has been described in detail with reference to the preferred embodiments, it should be understood by those skilled in the art that the technical solutions of the present application can be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present application, which should be covered by the scope of the claims of the present application.

Claims

1. A method for monitoring large-scale attacks based on real-time computation, characterized in that, The method comprises the following steps: acquiring log data; analyzing the log data through a distributed stream processing platform; the analysis comprises two-level analysis based on C-segment commonality attack sources, the two-level analysis based on C-segment commonality attack sources generates a first attention list according to the number of attacks on objects, and the physical location of the attacked objects is obtained through location analysis, the C-segment range to which the IP address of the attacked objects belongs is obtained through threat intelligence library correlation, and the first attention list information is perfected; trend analysis is performed on attack data in a first preset time period based on the first attention list information, and the next attack time of the attacked objects is predicted in combination with the trend analysis result; correlation analysis is performed on the entire network based on the first attention list and the trend analysis to obtain other attacked areas; the analysis further comprises attack analysis based on business system vulnerability commonality, and the attack analysis based on business system vulnerability commonality specifically comprises: all business system attack frequencies in a preset second time range are acquired in real time based on log data, if there is a business system whose attack frequency exceeds a set threshold, the business system is included in a second attention list; attack types to which each business system in the second attention list is subjected in a second preset time period are acquired; attack feasibility is acquired in combination with the properties of the business system itself and the attack types to which the business system is subjected; attack reachability is acquired in combination with the topology information of the attack path; noise reduction is performed on the acquired attack data to perfect the second attention list information; attack source IPs of the business system in a third preset time period are acquired, and commonality characteristics of the attacks are acquired in combination with the second attention list information to provide traceability for countermeasures.

2. The real-time computation based large-scale attack monitoring method of claim 1, wherein, the first attention list is generated according to the number of attacks on objects, and the method comprises the following steps: in a preset first time range, if the address of any object is attacked more than a preset number of times, the C-segment address corresponding to the object is included in the first attention list.

3. The real-time computation based large-scale attack monitoring method according to claim 1 or 2, wherein, trend analysis is performed on attacks in a first preset time period based on the physical location and correlation threat intelligence, and the method comprises the following steps: attack source data in the first preset time period in the first attention list and the number of attacks at each time scale in the time period are acquired; horizontal comparison is performed on the number of attacks at the same time scale to acquire attack trends.

4. The large-scale attack monitoring method based on real-time calculation according to claim 3, wherein correlation analysis is performed on the entire network based on the first attention list and the trend analysis to obtain other attacked areas, and the method comprises the following steps: a total database is acquired, the total database comprises all sub-databases accessed to the total database, and the sub-databases comprise C-segment addresses in the first attention list of the regions to which the sub-databases belong; C-segment addresses in the sub-database of the region are matched and compared with attack sources in the sub-databases of the remaining regions in the total database at regular time intervals; if the C-segment addresses match the attack sources, it indicates that the attack sources attack the regions to which the corresponding matched sub-databases belong at the same time.

5. The real-time computation based large-scale attack monitoring method of claim 4, wherein, the analysis further comprises attack analysis based on attack means maturity commonality, and the attack analysis based on attack means maturity commonality specifically comprises: all attack means data are acquired in real time based on log data, vulnerabilities are associated with contents involved in the attack means, and the attack means on the association are included in a third attention list; Obtaining the business system attacked in the fourth preset time period in the third attention list, and associating the corresponding attacked business system asset attribute, combining the security patch to judge whether the attack means will affect the business system; Obtaining the attack source in the fifth preset time period in the third attention list, and associating and analyzing the physical address and threat intelligence of the attack source to perform traceability analysis.

6. A system for applying the method of real-time computation based mass attack monitoring according to claim 1, characterized in that, Comprise: An acquisition module for acquiring log data; An analysis module for analyzing the log data through a distributed stream processing platform.

7. The real-time computation based large-scale attack monitoring system of claim 6, wherein, Further comprising, A first analysis module for two-level analysis based on C-segment common attack sources; A second analysis module for common attack analysis based on business system vulnerability; A third analysis module for common attack analysis based on attack means maturity. 8.An electronic device comprising: A memory and a processor; The memory is used to store computer executable instructions, and the processor is used to execute the computer executable instructions, which realize the steps of the large-scale attack monitoring method based on real-time calculation in any one of claims 1 to 5 when executed by the processor. 9.A computer readable storage medium storing computer executable instructions, which realize the steps of the large-scale attack monitoring method based on real-time calculation in any one of claims 1 to 5 when executed by the processor.

Citation Information

Patent Citations

  • Cooperative type active defense method based on honeynets

    CN103561003A

  • Prediction method, system and equipment for potential security events and medium

    CN116318885A