A security event early warning method and system based on alarm data analysis

By constructing an alarm coordinate system and using Hough transform to detect linear patterns, the problem of difficulty in identifying security threats in low-priority alarms in the prior art is solved, and accurate threat identification and early warning in dynamic environments are achieved.

CN119227059BActive Publication Date: 2025-06-03ZHEJIANG TUYUE HLDG CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411389962.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-08
Publication Date
2025-06-03
Estimated Expiration
2044-10-08

AI Technical Summary

Technical Problem

It is difficult for the prior art to effectively identify and early warning of potential security threats in low-priority alarms, especially when the number of alarm data is large and fluctuates greatly.

Method used

By constructing an alarm coordinate system, non-important alarm data are converted into grayscale values, and a straight line mode is detected in the alarm image using Hough transform. When the confidence level of the straight line is greater than the preset value, it is determined that abnormal behavior may exist.

Benefits of technology

Without presetting the threshold of alarm count, it can accurately identify potential threats in a dynamically changing environment, reduce false alarms and underreporting problems, and improve early warning capabilities for security incidents.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119227059B_ABST
    Figure CN119227059B_ABST
Patent Text Reader

Abstract

The present invention belongs to the field of system security monitoring, and provides a security event early warning method and system based on alarm data analysis, including: constructing an alarm coordinate system for the first type of non-critical alarms with the alarm-triggering user as the first coordinate axis and the alarm-triggering asset as the second coordinate axis; obtaining the first type of non-critical alarm data in real time; obtaining the number of alarms corresponding to each user and each asset within the first time window; converting the number of alarms into a gray value; marking the gray value on the alarm coordinate system; transforming the alarm coordinate system into an alarm image, and performing line detection on the alarm image using the Hough transform; when the line confidence level is greater than a preset value, it is determined that the first type of non-critical alarms may be abnormal, and the alarm coordinate system is displayed on the first user interface. The above solution efficiently analyzes alarm data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of system security monitoring, and particularly relates to a security event early warning method and system based on alarm data analysis. Background Art

[0002] In the prior art, alarm levels are usually divided into emergency alarms, important alarms, minor alarms, and reminder alarms. Emergency alarms and important alarms can attract the attention of maintenance personnel in a timely manner. Non-important alarms, such as minor alarms and reminder alarms, are usually ignored by maintenance personnel. However, continuous low-priority alarms may pose a serious threat under specific conditions.

[0003] For example, an IP address continuously attempts to perform password attempts on different users multiple times, and each failed attempt triggers a low-priority login failure alarm. If an attacker uses a slow and scattered brute-force cracking method with a long interval between each attempt, it may not trigger a high-priority alarm. However, the accumulation of such continuous low-priority alarms may indicate that the attacker is conducting a planned brute-force cracking attack.

[0004] After an attacker invades a system, they may try to move laterally within the internal network to find higher-privilege accounts or more sensitive data. During this process, some low-priority alarms may be triggered, such as unauthorized attempts to access shared folders, low-priority user privilege escalation attempts, and abnormal service requests. Individually, these alarms may not pose a serious threat, but when the attacker moves laterally between multiple nodes or multiple services, the frequent occurrence of low-priority alarms may imply that the attacker has breached the initial defense line and is trying to expand their control range.

[0005] Although a single non-important alarm seems harmless, when they appear continuously, concentratedly, or in a certain pattern, it may imply that the attacker is preparing for a larger-scale and more concealed attack.

[0006] However, the number of non-important alarms is usually large, and with the change of the environment, the fluctuation of the number of alarms is also large. It is usually difficult to screen out potentially abnormal data from a large amount of alarm data by setting a fixed threshold, resulting in difficulty in identifying concealed attacks. Summary of the Invention

[0007] To solve the problems in the prior art, the present invention provides a security event early warning method based on alarm data analysis, and the method includes the following steps:

[0008] Construct an alarm coordinate system with the alarm-triggering user as the first coordinate axis and the alarm-triggering asset as the second coordinate axis for the first type of non-important alarms;

[0009] Obtain the first type of non - critical alarm data in real - time;

[0010] Obtain the number of alarms corresponding to each user and each asset within the first time window;

[0011] Convert the number of alarms into a grayscale value;

[0012] Mark the grayscale value on the alarm coordinate system;

[0013] Transform the alarm coordinate system into an alarm image, and use the Hough transform to detect lines in the alarm image; when the line confidence level is greater than a preset value, it is determined that the first type of non - critical alarm may be abnormal, and the alarm coordinate system is displayed on the first user interface.

[0014] On the other hand, the present invention also provides a security event warning system based on alarm data analysis, and the system includes the following modules:

[0015] A setting module, used to construct an alarm coordinate system for the first type of non - critical alarm with the alarm - triggering user as the first coordinate axis and the alarm - triggering asset as the second coordinate axis;

[0016] An obtaining module, used to obtain the first type of non - critical alarm data in real - time;

[0017] A calculation module, used to obtain the number of alarms corresponding to each user and each asset within the first time window;

[0018] A conversion module, used to convert the number of alarms into a grayscale value;

[0019] A marking module, used to mark the grayscale value on the alarm coordinate system;

[0020] A judgment module, used to transform the alarm coordinate system into an alarm image, and use the Hough transform to detect lines in the alarm image; when the line confidence level is greater than a preset value, it is determined that the first type of non - critical alarm may be abnormal, and the alarm coordinate system is displayed on the first user interface.

[0021] Through the above - mentioned technical solutions, the present invention can produce the following beneficial effects:

[0022] Different from the traditional alarm system based on fixed thresholds, the present invention uses an image - based alarm data analysis method and does not require pre - setting thresholds based on the number of alarms. In the traditional method, fluctuations in the number of alarms and environmental changes often result in the set thresholds being unable to effectively capture abnormal situations. However, the present invention can directly identify potential abnormal behaviors from the alarm image through image - processing technologies such as the Hough transform. Even when the number of alarms changes significantly, the system can still accurately identify potential threats.

[0023] In the present invention, when an abnormal situation occurs in the system, an obvious linear image will automatically appear in the alarm image. This linear pattern is usually triggered by multiple related alarm events and represents highly correlated activities or attack behaviors between users and assets. Since this method is based on image pattern recognition, regardless of how the quantity of alarm data fluctuates or changes, the system can effectively detect abnormal behaviors and ensure early warning of security events.

[0024] The present invention does not rely on a fixed alarm quantity threshold, and thus can adapt to various dynamically changing environments. Whether in a high-load network environment or in a scenario with large fluctuations in alarm data, the system can reliably identify abnormal situations through image processing means. This characteristic enables the system to have stronger adaptability and stability when dealing with complex and changeable security threats.

[0025] Since it no longer relies on a fixed threshold, the present invention effectively reduces the problems of false alarms and missed alarms caused by improper threshold setting. Through the obvious linear features in the image, the system can more accurately identify actual abnormal behaviors and will not miss potential threats due to insufficient alarm quantity or short-term fluctuations.

[0026] The present invention can be applied to various alarm types and system environments, whether it is a financial system, an industrial control system, or an enterprise network management platform. Through image-based alarm analysis and linear feature detection, the system can effectively play its role in different application scenarios and ensure timely early warning of security threats in different environments. BRIEF DESCRIPTION OF THE DRAWINGS

[0027] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required to be used in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0028] Figure 1 is a flowchart of the method of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0029] Next, in combination with the drawings and the specific embodiments, a preferred description of the invention will be made.

[0030] This embodiment solves the above problems through the following steps:

[0031] In one embodiment, referring to Figure 1 , the present invention provides a security event early warning method based on alarm data analysis.

[0032] A security event early warning method based on alarm data analysis, which detects regular or repetitive abnormal behaviors hidden in unimportant alarms that are usually ignored by maintenance personnel.

[0033] The classification of alarms may vary in different systems. Unimportant alarms refer to those warning messages that frequently appear in the system but usually do not immediately attract attention, such as minor alarms, prompt alarms, etc. These alarms may be triggered due to minor system errors, temporary network fluctuations, or improper user operations. Since they seem harmless and usually do not have a significant impact on the normal operation of the system, maintenance personnel often ignore these alarms.

[0034] First, for the first type of unimportant alarms, construct an alarm coordinate system with the alarm-triggering user as the first coordinate axis and the alarm-triggering asset as the second coordinate axis.

[0035] There may be many types of unimportant alarms, such as network alarms, account alarms, file alarms, etc. The first type of unimportant alarms is one category among various unimportant alarms. In the present invention, an alarm coordinate system will be established for each category of alarms separately.

[0036] The alarm-triggering user refers to the user or account that causes the alarm event. Whenever a user performs certain operations in the system (such as logging in, accessing files, modifying configurations, etc.), the system may generate alarms according to preset security policies. These alarms record the user's activities and help the security team identify and track potential abnormal behaviors. The alarm-triggering user is usually related to the source of the alarm and is an important basis for analyzing user behaviors and detecting potential threats.

[0037] The alarm-triggering asset refers to the system resources or devices that are affected or related to in the alarm event. Assets can be servers, databases, network devices, applications, etc. Whenever an asset detects an abnormal operation or status, corresponding alarms will be triggered. Alarm-triggering assets are crucial in security analysis because they represent possible attack targets or fault points.

[0038] The alarm coordinate system is a two-dimensional space representation method used to graphically express alarm events. In this coordinate system, the two coordinate axes represent different variables (the alarm-triggering user and the alarm-triggering asset) respectively. Through this representation method, security analysts can intuitively observe and analyze the distribution of alarm events between users and assets, thus making it easier to identify abnormal behavior patterns or attack paths. In the follow-up of the present invention, analysis is carried out through image recognition means to improve the recognition efficiency.

[0039] Obtain the first type of unimportant alarm data in real time.

[0040] At various important nodes of the network, including servers, network devices, security devices, etc. These nodes use technical means such as security agents, log collectors, or monitoring probes to capture all alarm events occurring in the system in real time.

[0041] On the centralized management platform, the alarm data obtained in real time will be immediately stored in an efficient database. NoSQL databases (such as MongoDB, Cassandra) or distributed databases (such as HBase) can be used to support the fast reading and writing of large-scale data. At the same time, the data processing module will perform real-time analysis on the newly obtained alarm data, including data cleaning, formatting, feature extraction, etc., to prepare for subsequent alarm pattern recognition and anomaly detection.

[0042] To achieve real-time analysis, the system can also introduce a stream processing framework (such as Apache Kafka, Apache Flink) to process the alarm data stream. Through this real-time processing mechanism, the system can capture any possible security threats within a millisecond-level response time.

[0043] Obtain the number of alarms corresponding to each user and each asset within the first time window.

[0044] In the security event warning system, analyzing the alarm behavior between users and assets is a key step in identifying potential security threats. By counting the number of alarms triggered by each user for each asset within a specific time period, the system can reveal the pattern of alarm distribution and identify abnormal user behaviors or abnormal asset usage. The definition of the first time window determines the time sensitivity of the system to data. This time window can be minutes, hours, a day, etc., depending on the monitoring requirements and the accuracy of alarm analysis.

[0045] Suitable for environments that require high-frequency monitoring, such as financial trading systems or network traffic monitoring, the time window may be set from a few minutes to a few hours to capture rapidly changing attack behaviors.

[0046] Suitable for analyzing alarm trends over a long period, such as user behavior analysis or long-term network health status monitoring, the time window may be set to a day or a week.

[0047] This embodiment does not specifically limit the first time window, and those skilled in the art can select according to the above rules according to system requirements.

[0048] Within the time window, the system traverses all alarm events one by one and counts them into the counter of the corresponding user-asset pair. Read the user ID and asset ID of each alarm event and find the corresponding rows and columns in the user-asset matrix.

[0049] Once the corresponding user-asset pair is found, the system increments the alarm counter for that pair by 1, indicating that the user has triggered an alarm for that asset within that time window.

[0050] This process continues until the end of the time window. The statistical results will show how many alarms each user has generated for which assets within a specific time period.

[0051] Convert the number of alarms into a grayscale value.

[0052] In a security event warning system, visualizing alarm data can more intuitively analyze and identify potential security threats. To achieve this visualization effect, the number of alarms needs to be converted into a grayscale value and presented in the form of an image. The application of grayscale values can simplify complex digital information into visual information, enabling security analysts to more quickly and intuitively identify alarm patterns and abnormal behaviors. At the same time, obvious patterns in the image can also be identified through image processing means.

[0053] A grayscale value is a numerical representation between 0 and 255, where 0 usually represents black, 255 represents white, and values in between represent different shades of gray. In image processing, grayscale values are used to represent the brightness of each pixel point in an image. In the visualization of alarm data, the level of the grayscale value can be used to represent the number of alarms:

[0054] Low grayscale value (dark color): Represents a smaller number of alarms, which may mean less interaction or more normal interaction between the user and the asset.

[0055] High grayscale value (light color): Represents a larger number of alarms, which may imply frequent interaction between the user and the asset, or potential abnormal behavior.

[0056] Before converting the number of alarms into a grayscale value, it is necessary to standardize the original alarm number data. This is because there may be significant differences in the number of alarms between different users and assets, and directly using these raw data may result in unclear contrast in the grayscale image.

[0057] Min-max standardization can be used: By normalizing the alarm number data to a specific range (usually 0 to 1), it is ensured that all data can be compared on a unified scale. The formula is as follows:

[0058]

[0059] where x represents the original number of alarms, x′ represents the normalized value, x min and x max represent the minimum and maximum values of the number of alarms respectively.

[0060] The logarithmic transformation can also be used. For cases where the difference in the number of alarms is extremely large, the logarithmic transformation can be used to compress the range of data, so that a large number of alarms will not overly affect the conversion of grayscale values. The formula is as follows:

[0061] x′ = log(1 + x)

[0062] The logarithmic transformation can effectively reduce the gap between extreme values and enhance the visualization effect of the image.

[0063] After completing the data normalization process, the system needs to convert the normalized number of alarms into grayscale values. The grayscale values are usually between 0 and 255 and are mapped through the following steps:

[0064] Linear mapping: Directly map the normalized number of alarms to the range of grayscale values. Assuming the normalized value is between 0 and 1, the formula for the corresponding grayscale value is:

[0065] GrayValue = x′ × 255

[0066] Non - linear mapping: In some cases, non - linear mapping (such as exponential mapping or gamma correction) can be used to adjust the distribution of grayscale values to enhance the contrast in a specific range. For example:

[0067] GrayValue = (x′) γ × 255

[0068] Among them, γ is an adjustable parameter used to control the non - linear degree of the mapping. A larger γ value will make the grayscale values more concentrated at the darker or brighter end, thus highlighting the difference in the number of alarms.

[0069] Label the grayscale values on the alarm coordinate system.

[0070] In the previous steps, we have constructed an alarm coordinate system. The horizontal axis (X - axis) of this coordinate system represents the users who trigger the alarms, and the vertical axis (Y - axis) represents the assets related to the alarms. Through this two - dimensional representation, the alarm relationships between different users and different assets can be intuitively displayed. Each user - asset pair corresponds to a position in the coordinate system, that is, a point.

[0071] The system converts the alarm quantity of each previously calculated user - asset pair into grayscale values. These grayscale values need to be accurately mapped to the corresponding positions on the alarm coordinate system:

[0072] Mapping of users and assets: For each user - asset pair, the system will find the corresponding coordinate point in the alarm coordinate system. For example, assume that for a certain user A, the position on the X - axis in the coordinate system is X A , and for a certain asset B, the position on the Y - axis is Y B, then the grayscale value converted from the number of alerts between user A and asset B should be marked at the coordinate (X A , Y B ).

[0073] Grayscale value marking: The system will mark the corresponding grayscale value at each found coordinate point. This grayscale value represents the alert frequency of the user for the asset, and during the subsequent image generation process, this grayscale value will be used to define the brightness of that point on the image.

[0074] In the alert coordinate system, the intersection of each user and asset can be regarded as a pixel point on the image. The brightness of each pixel point in the image is determined by its corresponding grayscale value. The following is the specific implementation process:

[0075] Definition of image pixel points: Assume that the resolution of the alert image to be generated by the system is

[0076] M×N, where M is the number of users and N is the number of assets. Then, each pixel point (i, j) in the image corresponds to a user-asset pair (Xi, Yj) in the alert coordinate system.

[0077] Grayscale value filling: For each user-asset pair, find its corresponding coordinate point in the alert coordinate system, and then fill its grayscale value into the corresponding pixel point of the image. Specifically, assume that the grayscale value converted from the number of alerts between user Ui and asset Aj is Gij, then the brightness of the pixel point located at (i, j) in the image will be set to Cij.

[0078] After completing the marking of the grayscale value, the system will generate an alert image, where the brightness of each pixel point represents the alert frequency of the corresponding user-asset pair.

[0079] Furthermore, move users with the same permissions to adjacent positions in the coordinate system, and move assets of the same type to adjacent positions in the coordinate system.

[0080] To more effectively analyze and identify patterns and abnormal behaviors in the alert data, clustering users with the same permissions and assets of the same type and moving them to adjacent positions in the alert coordinate system helps to reveal potential correlations and abnormal behaviors. This operation can not only enhance the visualization effect of the data but also make it easier for the system to discover and analyze the alert trends and abnormal distributions among users or assets of the same type.

[0081] In a typical enterprise or organization, user permissions are usually defined based on their positions, responsibilities, and roles. Permissions may involve the ability to access certain key resources, perform certain operations, or manage specific assets. For example:

[0082] Administrator user: Has the highest permissions and can access and modify almost all system resources.

[0083] Regular user: Has lower permissions and can only access some resources related to their work.

[0084] Guest user: Has the least permissions and usually can only view some public information or perform limited operations.

[0085] Based on different permissions, users can be divided into different categories. For users with the same permissions, the operations they perform and the resources they access in the system often have similarities, so they may show similar behavior patterns in alarm analysis.

[0086] To better analyze the alarm data among users with the same permissions, these users can be moved to adjacent positions in the alarm coordinate system. The specific operation steps are as follows:

[0087] User sorting: First, sort all users according to their permission levels. They can be arranged in order from the user with the highest permissions to the user with the lowest permissions, or adjusted according to specific business requirements for other sorting methods.

[0088] User rearrangement: Arrange the sorted users in sequence on the X-axis of the alarm coordinate system so that users with the same permissions are adjacent to each other. This arrangement ensures that in the alarm image, the alarm data among users with the same or similar permissions is easier to identify and compare.

[0089] User clustering display: In the generated alarm image, users with the same permissions will be concentrated and displayed in one area, enabling analysts to quickly identify the alarm correlation and potential abnormal behaviors among these users.

[0090] By moving users with the same permissions to adjacent positions, the system can more intuitively display the alarm patterns among users with similar permissions. This method has the following advantages:

[0091] Correlation analysis: It is easier to analyze whether there are common behavior patterns or abnormalities among users in the same permission group. For example, whether multiple administrator accounts triggered similar alarms within the same time period.

[0092] Enhanced visualization effect: Makes the alarm of the same type of users in the alarm image more structured and regular, facilitating the quick identification of abnormalities.

[0093] Asset types are usually classified according to the nature and use of resources in the system. Common asset types include:

[0094] Servers: Used to run applications and services and are usually the main targets of attackers.

[0095] Database: Stores important data, which is highly sensitive and requires strict access control.

[0096] Network devices: Such as routers and switches, responsible for data transmission and network management.

[0097] Application programs: Include internal applications, SaaS services, etc. Users perform daily operations through these applications.

[0098] The types of these assets determine their functions and importance in the system. Different types of assets often face different security threats. Therefore, in alarm analysis, placing assets of the same type together helps to better understand the security status of specific types of assets.

[0099] To analyze asset alarm data more effectively, assets of the same type can be moved to adjacent positions in the alarm coordinate system. The specific operation steps are as follows:

[0100] Asset type classification: First, classify all assets and group them according to their types (such as servers, databases, network devices, etc.).

[0101] Asset sorting and rearrangement: Arrange the classified assets in sequence on the Y-axis of the alarm coordinate system so that assets of the same type are adjacent. This arrangement ensures that the correlation between assets can be more clearly displayed in the alarm image.

[0102] Asset clustering display: In the generated alarm image, assets of the same type will be concentrated and displayed in one area, making it easier to observe the alarm frequency and distribution of these assets within a specific time window.

[0103] The practice of moving assets of the same type to adjacent positions has significant advantages in alarm analysis:

[0104] Comparison between asset types: Through this arrangement, the alarm situations of assets of the same type can be quickly compared to identify which assets face greater security risks.

[0105] Centralized management: For the management and protection of specific types of assets, more targeted security policies can be formulated by analyzing the alarm data of adjacent positions.

[0106] Transform the alarm coordinate system into an alarm image, and use the Hough transform to perform line detection on the alarm image; when the line confidence is greater than a preset value, it is judged that the first type of non-important alarm may be abnormal, and the alarm coordinate system is displayed on the first user interface.

[0107] In the previous step, the system has constructed an alarm coordinate system based on the information of users and assets, and has performed grayscale value conversion on the alarm data. The system needs to convert this alarm coordinate system into a two-dimensional image for subsequent image processing and analysis.

[0108] Pixel matrix generation: The system maps each user-asset pair in the alarm coordinate system to a pixel point in the image. Specifically, the grayscale value of each pixel point represents the number of alarms triggered between the user and the asset within a specified time window. In this way, a pixel matrix containing grayscale values is generated.

[0109] Image construction: Using the generated pixel matrix, the system constructs a two-dimensional grayscale image. The X-axis of this image represents users, the Y-axis represents assets, and the brightness of each pixel reflects the frequency of alarms triggered by the user for the asset.

[0110] The main advantage of converting the alarm coordinate system into an image is that it can display a large amount of complex data in an intuitive way, enabling the system to use mature image processing techniques to identify hidden patterns and anomalies in the data. This method also facilitates human analysts to quickly understand the distribution of data and potential risks.

[0111] The Hough transform is a classic image processing algorithm widely used to detect straight lines or other geometric shapes in images. In this system, the role of the Hough transform is to identify possible straight line patterns in the alarm image. The presence of a straight line usually indicates a highly correlated alarm event between users and assets, and this correlation may suggest potential abnormal behavior or attacks.

[0112] The system applies the Hough transform algorithm to the generated alarm image, analyzes the brightness distribution in the image pixel by pixel, and converts the regular change of the alarm quantity into the Hough space. In the Hough space, a straight line is represented as a series of points with the highest votes, and an accumulator is used to record possible straight line parameters (such as the slope and intercept of the straight line).

[0113] Through the Hough transform, the system can detect which areas in the image may form straight lines. These straight lines may indicate concentrated alarms from multiple users for the same or similar assets, or frequent alarms from the same user for a series of related assets. The system will record the detected straight line parameters for further analysis.

[0114] The straight lines detected in the alarm image may represent potential abnormal patterns in the alarm data. For example, if multiple different users issue a large number of alarms for the same asset in a short period of time, this phenomenon may indicate a coordinated attack on the asset or a system configuration error. By identifying these straight lines, the system can detect and warn of possible security issues in advance.

[0115] The results of the Hough transform can be used to judge the significance of lines through confidence evaluation. Confidence refers to the degree of confidence of the system in whether the detected lines actually exist, usually calculated based on the number of votes in the accumulator.

[0116] In the Hough space, the confidence of a line is determined by the maximum number of votes in the accumulator. The more votes there are, the higher the probability that the corresponding pixel points in the image are on the line, and thus the greater the likelihood that the line exists.

[0117] The system will set a confidence threshold. When the confidence of the detected line is higher than this threshold, the system will consider that the line may represent an abnormal pattern in the alarm data.

[0118] Once lines with high confidence are detected, the system will further analyze the alarm data patterns represented by these lines and judge whether there are potential abnormal behaviors.

[0119] If a line represents concentrated alarms of multiple users for the same asset or concentrated alarms of one user for multiple assets, and these alarm behaviors do not conform to the normal operation mode, the system will identify these alarms as possible abnormal behaviors.

[0120] When it is confirmed that there are potential abnormal behaviors, the system will trigger an early warning mechanism to notify relevant security personnel to take further investigation and response measures.

[0121] To facilitate quick understanding and response by security analysts, the system will display the generated alarm images and detection results on the user interface. This process involves visually presenting the graphical information of the alarm data to the user, enabling them to quickly identify the abnormal areas and take actions.

[0122] The system will directly display the alarm image processed by the Hough transform in the user interface, where the lines mark the possible abnormal behavior areas. Users can zoom in, zoom out, or move the view to view these areas in detail.

[0123] The system will highlight the lines with high confidence in the image and attach relevant alarm information, such as the users, assets, and alarm types involved. This kind of annotation helps users quickly locate the root cause of the problem.

[0124] Furthermore, users can click on the lines or other annotated areas in the image, and the system will pop up detailed alarm information, including the time, the users and assets involved, the specific content of the alarm, etc.

[0125] Furthermore, based on the displayed alarm information, users can quickly judge the severity of the problem and take corresponding security measures, such as blocking accounts, isolating assets, or adjusting firewall rules, etc.

[0126] On the other hand, the present invention also provides a security event early warning system based on alarm data analysis, including:

[0127] A setting module, configured to construct an alarm coordinate system for the first type of non-critical alarms, with the alarm-triggering user as the first coordinate axis and the alarm-triggering asset as the second coordinate axis;

[0128] An acquisition module, configured to acquire the first type of non-critical alarm data in real time;

[0129] A calculation module, configured to obtain the number of alarms corresponding to each user and each asset within the first time window; a conversion module, configured to convert the number of alarms into a gray value;

[0130] A marking module, configured to mark the gray value on the alarm coordinate system;

[0131] A judgment module, configured to transform the alarm coordinate system into an alarm image, and perform line detection on the alarm image using the Hough transform; when the line confidence level is greater than a preset value, it is judged that the first type of non-critical alarms may be abnormal, and the alarm coordinate system is displayed on the first user interface.

[0132] Furthermore, the specific implementation methods of the above-mentioned security event early warning system based on alarm data analysis are all the same as those of a security event early warning method based on alarm data analysis. All further technical solutions in a security event early warning method based on alarm data analysis are fully introduced into a security event early warning system based on alarm data analysis.

[0133] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that: it is still possible to modify the specific implementation manners of the present invention or make equivalent replacements, and any modification or equivalent replacement without departing from the spirit and scope of the present invention shall be covered by the protection scope of the claims of the present invention.

[0134] For the part of the module structure not specifically defined in the present invention, it shall be subject to the content recorded in the prior art. The prior art mentioned in the foregoing background art part and specific embodiment part of the present invention can be used as a part of the present invention to understand the meaning of some technical features or parameters. The protection scope of the present invention shall be subject to the content actually recorded in the claims.

Claims

1. A security incident early warning method based on alarm data analysis, characterized in that The method comprises the following steps: For the first type of non-important alarms, an alarm coordinate system is constructed with the alarm triggering user as the first coordinate axis and the alarm triggering asset as the second coordinate axis. The alarm triggering user refers to the user or account that causes the alarm event, and the alarm triggering asset refers to the system resources or devices affected or related to the alarm event. Obtain the first type of non-critical alarm data in real time; Get the number of alarms corresponding to each user and each asset in the first time window. In the first time window, traverse all alarm events one by one and count them in the counter of the corresponding user-asset pair. Read the user ID and asset ID of each alarm event and find the corresponding row and column in the user-asset matrix. Once the corresponding user-asset pair is found, the system will increase the alarm counter of the pair by 1, indicating that the user triggered an alarm for the asset in the time window, until the end of the time window; Normalizing the original alarm quantity data to a range of 0 to 1, mapping the normalized value to a range of 0 to 255, and converting the alarm quantity into a grayscale value according to the mapped value; For each user-asset pair, find the corresponding coordinate point in the alarm coordinate system, mark the corresponding grayscale value on each coordinate point found, and mark the grayscale value in the alarm coordinate system; Each user-asset pair in the alarm coordinate system is mapped to a pixel point in the image, the grayscale value of each pixel point represents the number of alarms triggered between the user and the asset within a specified time window, a pixel matrix containing grayscale values ​​is generated, a two-dimensional grayscale image is constructed using the generated pixel matrix, the alarm coordinate system is transformed into an alarm image, the brightness distribution in the alarm image is analyzed pixel by pixel using Hough transform to perform straight line detection; the straight line represents concentrated alarms of multiple users on the same or similar assets; when the confidence of the straight line is greater than a preset value, it is determined that the first type of non-important alarm may be abnormal, and the alarm coordinate system is displayed on a first user interface.

2. A security incident early warning method based on alarm data analysis according to claim 1, characterized in that: When obtaining the first type of non-important alarm data in real time, a stream processing framework is introduced to process the alarm data stream.

3. The security incident early warning method based on alarm data analysis according to claim 1 is characterized by: Converting the alarm quantity into a grayscale value will normalize the alarm quantity.

4. The security incident early warning method based on alarm data analysis according to claim 1 is characterized in that: Move users with the same permissions to adjacent positions in the coordinate system, and move assets of the same asset type to adjacent positions in the coordinate system.

5. The security incident early warning method based on alarm data analysis according to claim 1 is characterized by: When the straight line confidence is greater than the preset value, it is judged that the first type of non-important alarm may be abnormal. After the user clicks the straight line or marked area in the image, the system will pop up detailed alarm information, including time, users and assets involved, and specific content of the alarm.

6. A security incident early warning system based on alarm data analysis, characterized in that The system includes the following modules: A setting module is used to construct an alarm coordinate system for the first type of non-important alarms with the alarm triggering user as the first coordinate axis and the alarm triggering asset as the second coordinate axis. The alarm triggering user refers to the user or account that causes the alarm event to be generated, and the alarm triggering asset refers to the system resources or devices affected or related to the alarm event; An acquisition module is used to acquire the first type of non-important alarm data in real time; The calculation module is used to obtain the number of alarms corresponding to each user and each asset in the first time window. In the first time window, all alarm events are traversed one by one, and the statistics are added to the counter of the corresponding user-asset pair. The user ID and asset ID of each alarm event are read, and the corresponding row and column are found in the user-asset matrix. Once the corresponding user-asset pair is found, the system will increase the alarm counter of the pair by 1, indicating that the user has triggered an alarm for the asset in the time window, until the end of the time window; A conversion module, used to normalize the original alarm quantity data to the interval of 0 to 1, map the normalized value to the interval of 0 to 255, and convert the alarm quantity into a grayscale value according to the mapped value; A marking module, for finding corresponding coordinate points in the alarm coordinate system for each user-asset pair, marking corresponding grayscale values ​​on each coordinate point found, and marking the grayscale values ​​in the alarm coordinate system; A judgment module is used to map each user-asset pair in the alarm coordinate system to a pixel point in the image, the grayscale value of each pixel point represents the number of alarms triggered between the user and the asset within a specified time window, generate a pixel matrix containing grayscale values, use the generated pixel matrix to construct a two-dimensional grayscale image, transform the alarm coordinate system into an alarm image, use Hough transform to analyze the brightness distribution in the alarm image pixel by pixel to perform straight line detection; the straight line represents the concentrated alarms of multiple users on the same or similar assets; when the confidence of the straight line is greater than a preset value, it is judged that the first type of non-important alarm may be abnormal, and the alarm coordinate system is displayed on the first user interface.

7. A security incident early warning system based on alarm data analysis according to claim 6, characterized in that: When obtaining the first type of non-important alarm data in real time, a stream processing framework is introduced to process the alarm data stream.

8. The security incident early warning system based on alarm data analysis according to claim 6 is characterized in that: Converting the alarm quantity into a grayscale value will normalize the alarm quantity.

9. The security incident early warning system based on alarm data analysis according to claim 6 is characterized in that: Move users with the same permissions to adjacent positions in the coordinate system, and move assets of the same asset type to adjacent positions in the coordinate system.

10. The security incident early warning system based on alarm data analysis according to claim 6, characterized in that: When the straight line confidence is greater than the preset value, it is judged that the first type of non-important alarm may be abnormal. After the user clicks the straight line or marked area in the image, the system will pop up detailed alarm information, including time, users and assets involved, and specific content of the alarm.

Citation Information

Patent Citations

  • Image type fire flame identification method

    CN103886344A

  • Method and system for generating network security warning distribution map

    CN107294776A