Event auditing method and device in cloud environment
By intercepting events to be audited in real time in the cloud environment, using candidate key events and their correlations to determine whether they are future key events and further determine whether they are dangerous events, and executing corresponding security measures, the real-time and efficiency problems of traditional cloud computing security auditing are solved, achieving proactive security auditing and efficient security assurance.
Patent Information
- Application Number
- CN202411357846.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-26
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2044-09-26
AI Technical Summary
Traditional cloud security auditing methods can only detect violations after the fact, which cannot guarantee the real-time security of the cloud environment and requires a lot of manual work, thus reducing the efficiency of security auditing.
By acquiring auditable events in the cloud environment, the system uses candidate critical event information and correlations to determine whether an auditable event is a future critical event. If it is determined to be a future critical event, the system uses event parameter information to determine whether it is a dangerous event, thereby executing corresponding security measures.
It enables proactive security auditing of the cloud environment, improves the efficiency and accuracy of security auditing, allows for security measures to be taken before incidents occur, reduces potential security risks, and enhances the security of the cloud environment.
Smart Images

Figure CN119363385B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data security technology, and in particular to an event auditing method and apparatus in a cloud environment. Background Technology
[0002] With the advancement of network technology and the increasing demand for computing resources, cloud computing and its service applications have received widespread attention in recent years. In cloud computing, users can leverage powerful computing resources and obtain ample storage space in terms of cost efficiency and less manual management. Therefore, users are willing to outsource data to cloud servers to reduce maintenance costs and enhance accessibility and availability, but this may lead to various security issues. To defend against security threats in the cloud environment and build trust with cloud users, security audits can be used to verify security policies. However, traditional auditing methods in cloud security are retrospective, only discovering violations after the fact and failing to guarantee the security of the cloud environment; moreover, they require a significant amount of manual work, reducing the efficiency of security audits. Summary of the Invention
[0003] In view of the above problems, embodiments of this application provide an event auditing method and apparatus in a cloud environment that overcomes or at least partially solves the above problems.
[0004] Firstly, embodiments of this application provide an event auditing method in a cloud environment, the method comprising:
[0005] Obtain auditable events in the cloud environment;
[0006] Based on the candidate key event information, it is determined whether the event to be audited is a future key event. The candidate key event information includes: multiple candidate key events and the relationship between the candidate key events.
[0007] If the event to be audited is a future critical event, determine whether the event to be audited is a dangerous event based on the event parameter information of the event to be audited and the preset event parameter information;
[0008] If the event to be audited is determined to be a dangerous event, the first safety measure corresponding to the dangerous event shall be implemented.
[0009] Optionally, determining whether the event to be audited is a future key event based on the candidate key event information includes:
[0010] Determine whether the auditable event is included among the multiple candidate key events in the candidate key event information;
[0011] If the auditable event is included among the multiple candidate key events, a key event set is obtained, wherein the key event set includes multiple key events;
[0012] Based on the relationships between the candidate key events and the set of key events, determine whether the event to be audited is a future key event.
[0013] Optionally, determining whether the event to be audited is a future key event based on the correlation between the candidate key events and the set of key events includes:
[0014] Based on the relationships between the candidate key events, determine the target key event from the set of key events that the auditable event will transform after the current time.
[0015] Based on the transition probability between two related candidate key events in the candidate key event information, calculate the target transition probability of the audited event becoming the target key event;
[0016] If the target change probability is greater than the preset change probability, the event to be audited is determined to be a future critical event;
[0017] If the target transition probability is less than or equal to the preset transition probability, the event to be audited is determined to be a non-future critical event.
[0018] Optionally, when the event to be audited is a future critical event, determining whether the event to be audited is a dangerous event based on the event parameter information of the event to be audited and preset event parameter information includes:
[0019] If the event to be audited is a future critical event, obtain the event parameter information and preset event parameter information of the event to be audited. The preset event parameter information includes the event parameter information of each critical event in the critical event set.
[0020] If the preset event parameter information includes the event parameter information of the event to be audited, the event to be audited is determined to be a dangerous event.
[0021] If the event parameter information of the event to be audited is not included in the preset event parameter information, the event to be audited is determined to be a security event.
[0022] Optionally, the plurality of candidate key events includes at least two of the following:
[0023] The first incident of violating security policy;
[0024] A second event that has a contextual relationship with the first event;
[0025] A third event that has a strong dependency relationship with the first event;
[0026] A fourth event that has a time-dependent relationship with the first event;
[0027] A fifth event that has an environmental relationship with the first event.
[0028] Secondly, embodiments of this application also provide an event auditing device in a cloud environment, the device comprising:
[0029] The acquisition module is used to acquire auditable events in the cloud environment;
[0030] The first judgment module is used to determine whether the event to be audited is a future key event based on the candidate key event information. The candidate key event information includes: multiple candidate key events and the correlation between the candidate key events.
[0031] The second judgment module is used to determine whether the event to be audited is a dangerous event based on the event parameter information of the event to be audited and the preset event parameter information when the event to be audited is a future critical event.
[0032] The execution module is used to execute the first security measure corresponding to the dangerous event if the event to be audited is determined to be a dangerous event.
[0033] Optionally, the first determination module is specifically used for:
[0034] Determine whether the auditable event is included among the multiple candidate key events in the candidate key event information;
[0035] If the auditable event is included among the multiple candidate key events, a key event set is obtained, wherein the key event set includes multiple key events;
[0036] Based on the relationships between the candidate key events and the set of key events, determine whether the event to be audited is a future key event.
[0037] Optionally, when the first judgment module determines whether the event to be audited is a future key event based on the correlation between the candidate key events and the set of key events, it is specifically used for:
[0038] Based on the relationships between the candidate key events, determine the target key event from the set of key events that the auditable event will transform after the current time.
[0039] Based on the transition probability between two related candidate key events in the candidate key event information, calculate the target transition probability of the audited event becoming the target key event;
[0040] If the target change probability is greater than the preset change probability, the event to be audited is determined to be a future critical event;
[0041] If the target transition probability is less than or equal to the preset transition probability, the event to be audited is determined to be a non-future critical event.
[0042] Optionally, the second determination module specifically includes:
[0043] If the event to be audited is a future critical event, obtain the event parameter information and preset event parameter information of the event to be audited. The preset event parameter information includes the event parameter information of each critical event in the critical event set.
[0044] If the preset event parameter information includes the event parameter information of the event to be audited, the event to be audited is determined to be a dangerous event.
[0045] If the event parameter information of the event to be audited is not included in the preset event parameter information, the event to be audited is determined to be a security event.
[0046] Optionally, the plurality of candidate key events includes at least two of the following:
[0047] The first incident of violating security policy;
[0048] A second event that has a contextual relationship with the first event;
[0049] A third event that has a strong dependency relationship with the first event;
[0050] A fourth event that has a time-dependent relationship with the first event;
[0051] A fifth event that has an environmental relationship with the first event.
[0052] Thirdly, embodiments of this application also provide an electronic device, including a memory, a transceiver, and a processor:
[0053] A memory for storing computer programs; a transceiver for sending and receiving data under the control of a processor; and a processor for reading the computer programs from the memory and executing the method described in the first aspect above.
[0054] Fourthly, embodiments of this application also provide a processor-readable storage medium storing a computer program for causing the processor to perform the method described in the first aspect above.
[0055] The embodiments described above first intercept auditable events in the cloud environment. Then, based on multiple candidate key events and the relationships between them, it determines whether the auditable event is a future key event. If the auditable event is a future key event, it determines whether the auditable event is a dangerous event based on the event parameter information and preset event parameter information. If the auditable event is determined to be a dangerous event, the first security measure corresponding to the dangerous event is executed, i.e., proactive auditing of the auditable events in the cloud environment, improving the efficiency of security auditing. Furthermore, by determining whether the auditable event is a future key event, and if so, further determining whether it is a dangerous event, corresponding security measures can be taken before the event occurs, effectively preventing the occurrence of violations, reducing potential security risks, and improving the security of the cloud environment. Moreover, first determining whether it is a future key event, and then further determining whether it is a dangerous event based on the future key event, can improve the accuracy of security auditing and further ensure the security of the cloud environment. Attached Figure Description
[0056] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the description of the embodiments of this application will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0057] Figure 1 A flowchart of an event auditing method in a cloud environment provided in the embodiments of this application;
[0058] Figure 2 A detailed flowchart of the event auditing method in a cloud environment provided in the embodiments of this application;
[0059] Figure 3 A structural block diagram of an event auditing device in a cloud environment provided in the embodiments of this application;
[0060] Figure 4 A structural block diagram of an electronic device provided in an embodiment of this application. Detailed Implementation
[0061] The technical solutions of the embodiments of this application will be clearly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application are within the scope of protection of this application.
[0062] The terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such use of data can be interchanged where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first," "second," etc., are generally of the same class and the number of objects is not limited; for example, a first object can be one or more. Furthermore, in the specification and claims, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects are in an "or" relationship.
[0063] The event auditing method in the cloud environment provided by the embodiments of this application will be described in detail below with reference to the accompanying drawings, through specific embodiments and application scenarios.
[0064] Specifically, embodiments of this application provide an event auditing method in a cloud environment, such as... Figure 1 As shown, this method can be applied to an auditing system and may specifically include the following steps:
[0065] Step 101: Obtain the events to be audited in the cloud environment.
[0066] Specifically, the auditing system first intercepts auditable events running in the cloud environment in real time, and performs real-time security audits on the intercepted auditable events, which can improve security and reduce potential security risks.
[0067] A cloud environment refers to an ecosystem that provides computing resources and services via the Internet, including storage, processing power, networks, and software, enabling users to access and use resources on demand without the need to purchase and maintain physical hardware and infrastructure.
[0068] Auditing refers to the process of protecting data and auditing systems by reviewing, monitoring, and evaluating security controls in a cloud environment. It can identify security vulnerabilities, ensure compliance, and improve overall security.
[0069] Step 102: Based on the candidate key event information, determine whether the event to be audited is a future key event. The candidate key event information includes: multiple candidate key events and the relationship between the candidate key events.
[0070] Specifically, candidate key event information includes, but is not limited to, multiple candidate key events and the relationships between them. By examining multiple candidate key events and their relationships, it is determined whether the audited event will become a future key event. In other words, by examining multiple candidate key events and their relationships, it is predicted whether the audited event will become a key event in the future.
[0071] Among them, the relationship refers to the interrelationship and influence between different events in the cloud environment. These relationships help the audit system understand that the occurrence of a certain event may lead to the occurrence of other events, thereby enabling effective prediction and management in the security audit and verification process.
[0072] Step 103: If the event to be audited is a future critical event, determine whether the event to be audited is a dangerous event based on the event parameter information of the event to be audited and the preset event parameter information.
[0073] Specifically, if the event to be audited is not a future critical event, then the task corresponding to the audited event is executed. If the event to be audited is a future critical event, then the event parameter information and preset event parameter information of the event to be audited are obtained, and the event to be audited is determined to be either a dangerous event or a safe event based on the event parameter information and preset event parameter information.
[0074] Step 104: If the event to be audited is determined to be a dangerous event, execute the first security measure corresponding to the dangerous event.
[0075] Specifically, if the event to be audited is determined to be a dangerous event, the first security measure corresponding to the dangerous event is implemented, which means taking mandatory measures to prohibit the execution of the task corresponding to the audit event. If the event to be audited is determined to be a safe event, the second security measure corresponding to the safe event is implemented, which means the task corresponding to the audit event is executed.
[0076] The embodiments described above first intercept and acquire auditable events in the cloud environment. Then, based on multiple candidate key events and the correlation between them, it determines whether the auditable event is a future key event. If the auditable event is a future key event, it determines whether the auditable event is a dangerous event based on the event parameter information and preset event parameter information. If the auditable event is determined to be a dangerous event, the first security measure corresponding to the dangerous event is executed, i.e., proactive auditing of the auditable events in the cloud environment, thereby improving the efficiency of security auditing. Furthermore, by determining whether the auditable event is a future key event, and if so, further determining whether it is a dangerous event, corresponding security measures can be taken before the event occurs, effectively preventing the occurrence of violations, reducing potential security risks, and improving the security of the cloud environment. Moreover, first determining whether it is a future key event, and then further determining whether it is a dangerous event based on the future key event, can improve the accuracy of security auditing and further ensure the security of the cloud environment.
[0077] As an optional specific embodiment, the plurality of candidate key events includes, but is not limited to, at least two of the following five:
[0078] The first type: The first incident that violates the security policy.
[0079] Specifically, the auditing system collects cloud configuration data (such as status data and event log data) from different cloud services (such as cloud computing and cloud storage), and then converts the configuration data into the format of the offline auditing tool. The offline auditing tool judges events that violate security policies based on the configuration data, and designates events that violate security policies as first events. The number of first events can be one or more.
[0080] For example, the first event could be an operation such as updating the port or deleting a virtual machine.
[0081] It should be noted that a security strategy refers to a set of regulations and controls designed to ensure the security, compliance, and reliability of a cloud computing environment, including security requirements, operational guidelines, and audit standards for cloud service providers and cloud users.
[0082] Offline auditing tools refer to auditing tools applied to OpenStack. They convert collected configuration data into the tool's corresponding format and verify the current cloud service configuration data, enabling the detection of violations caused by events. OpenStack refers to an open-source cloud computing management platform project, which is a combination of a series of open-source software projects.
[0083] The second type: a second event that has a contextual relationship with the first event.
[0084] Specifically, the data of the context events related to the first event are the second events that have a contextual relationship with the first event, and there can be one or more second events.
[0085] For example, the first event is the update port event, and the context data of the create port event will affect the subsequent update port events, that is, the create port event is the second event.
[0086] The third type: a third event that has a strong dependency relationship with the first event.
[0087] Specifically, the event that will definitely occur after the first event is the third event with a strong dependency relationship, and there can be one or more third events.
[0088] For example, creating a network event depends on creating a subnet event, and there is a strong dependency relationship between creating a network event and creating a subnet event.
[0089] The fourth type: a fourth event that has a time-dependent relationship with the first event.
[0090] Specifically, an event that occurs within a certain period of time before or after the first event is considered a fourth event that is time-dependent on the first event, and there can be one or more fourth events.
[0091] For example, if the average time interval between the network creation event (i.e., the first event) and the subnet creation event (the fourth event) is 5 minutes, then the subnet creation event will be predicted to occur within 5 minutes after the network creation event.
[0092] The fifth type: a fifth event that has an environmental relationship with the first event.
[0093] Specifically, if the first event occurs in a specific environment, the event that will happen in the future is called the fifth event, and there can be one or more fifth events.
[0094] For example, in a specific environment, a security group is always created after a virtual machine event is created, so creating a security group is a predictable fifth event.
[0095] By using the aforementioned multiple candidate critical events, dangerous events can be identified more effectively, improving the accuracy of proactive security audits.
[0096] As an optional specific embodiment, step 102, based on the candidate key event information, determines whether the event to be audited is a future key event, specifically including steps 1021 to 1023:
[0097] Step 1021: Determine whether the auditable event is included among the multiple candidate key events in the candidate key event information.
[0098] Specifically, since the candidate key event information includes multiple candidate key events, the process iterates through these multiple candidate key events to determine whether any of them contain a candidate key event that is the same as the event to be audited. In other words, it determines whether the event to be audited is one of the multiple candidate key events. If the multiple candidate key events include the event to be audited, then step 1022 is executed; if the multiple candidate key events do not include the event to be audited, then the task corresponding to the event to be audited is executed.
[0099] Step 1022: If the event to be audited is included among the multiple candidate key events, obtain a set of key events, wherein the set of key events includes multiple key events.
[0100] Specifically, if the candidate key events include the event to be audited, a preset key event set is obtained, which includes multiple key events.
[0101] The process of determining the set of key events is explained below:
[0102] First, identify the cloud services related to the security policy violation, collect the configuration data of the cloud services, and the audit system identifies the event type through the configuration data. Then, filter out the five types of events that do not belong to the candidate critical events to obtain multiple candidate critical events from the candidate critical event information.
[0103] Obtain the Application Programming Interface (API) documentation of the cloud platform, filter multiple candidate key events through the API documentation, filter out candidate key events that do not belong to the API documentation, and form a set of key events by retaining the candidate key events.
[0104] Step 1023: Based on the correlation between the candidate key events and the set of key events, determine whether the event to be audited is a future key event.
[0105] Specifically, since the candidate key event information also includes the relationships between candidate key events, the relationships between candidate key events and the key event set are used to determine whether the above-mentioned audited event will become a future key event. In other words, the relationships between candidate key events and the key event set are used to predict whether the above-mentioned audited event will become a key event in the future.
[0106] The above embodiments, by predicting future critical events, enable the implementation of security measures before the events occur, achieving proactive security auditing and effectively preventing security violations from happening.
[0107] Further, step 1023, based on the correlation between the candidate key events and the set of key events, determines whether the event to be audited is a future key event, specifically including:
[0108] Based on the relationships between the candidate key events, determine the target key event from the set of key events that the auditable event will transform after the current time.
[0109] Based on the transition probability between two related candidate key events in the candidate key event information, calculate the target transition probability of the audited event becoming the target key event;
[0110] If the target change probability is greater than the preset change probability, the event to be audited is determined to be a future critical event;
[0111] If the target transition probability is less than or equal to the preset transition probability, the event to be audited is determined to be a non-future critical event.
[0112] Specifically, by examining the relationships between candidate key events, we can determine which event the audited event will transform into in the future (i.e., after the current time). Then, by examining the key event set, we can determine which of the events the audited event will transform into in the future is the key event, thereby identifying the target key event that the audited event will transform into in the future.
[0113] The candidate key event information also includes the transition probability between two related candidate key events. Based on the transition probability between two candidate key events, the target transition probability of the audited event becoming the target key event can be calculated.
[0114] For example: If the event to be audited is event A and the target key event is event C, and it is known from the correlation between the candidate key events that event A can directly transform into event C, then the transformation probability from event A to event C in the candidate key event information is obtained, and the transformation probability from event A to event C is used as the target transformation probability.
[0115] For example, if the event to be audited is event A and the target key event is event C, and based on the relationship between the candidate key events, we know that event A first transforms into event B, and then event B transforms into event C, then we obtain the transformation probability from event A to event B in the candidate key event information, and obtain the transformation probability from event B to event C. We add the transformation probability from event A to event B and the transformation probability from event B to event C and calculate the average value. The average value is the target transformation probability.
[0116] After obtaining the target transformation probability, the target transformation probability is compared with the preset transformation probability. If the target transformation probability is greater than the preset transformation probability, the event to be audited is determined to be a future critical event. Conversely, if the target transformation probability is less than or equal to the preset transformation probability, the event to be audited is determined to be a non-future critical event.
[0117] The process of determining the transition probability between two candidate key events is explained below:
[0118] The system acquires configuration data from different cloud services. Event log data within this configuration data records the operation and transformation processes of events in the cloud environment. This yields the frequency and average time interval between the transformations of two events within a given period. For example, if event A transforms into event B once within a period, the average time interval between this transformation and the next transformation is the mean time interval. The system stores the frequency and average time interval of the transformations of two events. This data is then fed into a time series predictor via a Bayesian network. The time series predictor processes the frequency and average time interval, outputting the transformation probability of the two events. The transformation probability represents the strength of the relationship between the two events; a higher transformation probability indicates a stronger relationship.
[0119] As an optional specific embodiment, step 103, when the event to be audited is a future critical event, determines whether the event to be audited is a dangerous event based on the event parameter information of the event to be audited and preset event parameter information, specifically including:
[0120] If the event to be audited is a future critical event, obtain the event parameter information and preset event parameter information of the event to be audited. The preset event parameter information includes the event parameter information of each critical event in the critical event set.
[0121] If the preset event parameter information includes the event parameter information of the event to be audited, the event to be audited is determined to be a dangerous event.
[0122] If the event parameter information of the event to be audited is not included in the preset event parameter information, the event to be audited is determined to be a security event.
[0123] Specifically, if the event to be audited is a future critical event, then the event parameter information (e.g., event identifier) and preset event parameter information of the event to be audited are obtained. The preset event parameter information includes the event parameter information corresponding to each critical event in the critical event set. If the preset event parameter information includes the event parameter information of the event to be audited, then the event to be audited is determined to be a dangerous event; otherwise, if the preset event parameter information does not include the event parameter information of the event to be audited, then the event to be audited is determined to be a safe event.
[0124] In addition, the auditing system may also include a user interface module, which provides a real-time monitoring interface to display the auditing events recently initiated by the user and the corresponding security measures taken by the auditing system, so as to help users understand the operating status of the auditing system and the security audit results of each event.
[0125] The above solution will be illustrated below through a specific embodiment:
[0126] like Figure 2 As shown, step 201 involves obtaining the events to be audited in the cloud environment.
[0127] Step 202: Determine whether the candidate key events among the multiple candidate key events in the candidate key event information include the event to be audited; if yes, proceed to step 203; if no, proceed to step 209.
[0128] Step 203: Based on the relationships between candidate key events, determine the target key event from the set of key events that will be transformed after the current time for the event to be audited.
[0129] Step 204: Calculate the target conversion probability of the audited event becoming the target key event based on the conversion probability between two related candidate key events in the candidate key event information.
[0130] Step 205: Determine whether the target transition probability is greater than the preset transition probability. If yes, proceed to step 206; if no, proceed to step 209.
[0131] Step 206: Obtain the event parameter information and preset event parameter information of the event to be audited.
[0132] Step 207: Determine whether the preset event parameter information includes the event parameter information of the event to be audited. If yes, proceed to step 208; if no, proceed to step 209.
[0133] Step 208: Implement the first safety measure corresponding to the hazardous event.
[0134] Step 209: Implement the second security measure corresponding to the security incident.
[0135] In summary, the above embodiments of this application enable the audit system to intercept events awaiting auditing in the cloud environment in real time for security auditing, thereby improving security and reducing potential security risks. Furthermore, by using multiple candidate critical events, dangerous events can be identified more effectively, improving the accuracy of proactive security auditing. By predicting future critical events, security measures can be taken before events occur, achieving proactive security auditing and effectively preventing security violations. Moreover, by first determining whether an event is a future critical event, and then further determining whether it is a dangerous event based on the future critical event, the accuracy of security auditing can be further improved, and the security of the cloud environment can be further guaranteed. Furthermore, the above solution can be integrated into different cloud management platforms and can be ported to other cloud platforms, exhibiting good scalability and enhancing the universality and applicability of the audit system.
[0136] The above describes the event auditing method in a cloud environment provided by the embodiments of this application. The event auditing device in a cloud environment provided by the embodiments of this application will be described below with reference to the accompanying drawings.
[0137] like Figure 3 As shown in the illustration, this application also provides an event auditing device 300 in a cloud environment, the device comprising:
[0138] The acquisition module 301 is used to acquire auditable events in the cloud environment;
[0139] The first judgment module 302 is used to determine whether the event to be audited is a future key event based on the candidate key event information. The candidate key event information includes: multiple candidate key events and the relationship between the candidate key events.
[0140] The second judgment module 303 is used to determine whether the event to be audited is a dangerous event based on the event parameter information of the event to be audited and the preset event parameter information when the event to be audited is a future critical event.
[0141] The execution module 304 is used to execute the first security measure corresponding to the dangerous event if the event to be audited is determined to be a dangerous event.
[0142] The embodiments described above first intercept and acquire auditable events in the cloud environment. Then, based on multiple candidate key events and the correlation between them, it determines whether the auditable event is a future key event. If the auditable event is a future key event, it determines whether the auditable event is a dangerous event based on the event parameter information and preset event parameter information. If the auditable event is determined to be a dangerous event, the first security measure corresponding to the dangerous event is executed, i.e., proactive auditing of the auditable events in the cloud environment, thereby improving the efficiency of security auditing. Furthermore, by determining whether the auditable event is a future key event, and if so, further determining whether it is a dangerous event, corresponding security measures can be taken before the event occurs, effectively preventing the occurrence of violations, reducing potential security risks, and improving the security of the cloud environment. Moreover, first determining whether it is a future key event, and then further determining whether it is a dangerous event based on the future key event, can improve the accuracy of security auditing and further ensure the security of the cloud environment.
[0143] Optionally, the first determination module 302 is specifically used for:
[0144] Determine whether the auditable event is included among the multiple candidate key events in the candidate key event information;
[0145] If the auditable event is included among the multiple candidate key events, a key event set is obtained, wherein the key event set includes multiple key events;
[0146] Based on the relationships between the candidate key events and the set of key events, determine whether the event to be audited is a future key event.
[0147] Optionally, when the first judgment module 302 determines whether the event to be audited is a future key event based on the correlation between the candidate key events and the set of key events, it is specifically used for:
[0148] Based on the relationships between the candidate key events, determine the target key event from the set of key events that the auditable event will transform after the current time.
[0149] Based on the transition probability between two related candidate key events in the candidate key event information, calculate the target transition probability of the audited event becoming the target key event;
[0150] If the target change probability is greater than the preset change probability, the event to be audited is determined to be a future critical event;
[0151] If the target transition probability is less than or equal to the preset transition probability, the event to be audited is determined to be a non-future critical event.
[0152] Optionally, the second determination module 303 specifically includes:
[0153] If the event to be audited is a future critical event, obtain the event parameter information and preset event parameter information of the event to be audited. The preset event parameter information includes the event parameter information of each critical event in the critical event set.
[0154] If the preset event parameter information includes the event parameter information of the event to be audited, the event to be audited is determined to be a dangerous event.
[0155] If the event parameter information of the event to be audited is not included in the preset event parameter information, the event to be audited is determined to be a security event.
[0156] Optionally, the plurality of candidate key events includes at least two of the following:
[0157] The first incident of violating security policy;
[0158] A second event that has a contextual relationship with the first event;
[0159] A third event that has a strong dependency relationship with the first event;
[0160] A fourth event that has a time-dependent relationship with the first event;
[0161] A fifth event that has an environmental relationship with the first event.
[0162] In addition, such as Figure 3 As shown, the event auditing device in the cloud environment described above may also include a user interface module 305, which provides a real-time monitoring interface to display the recently initiated events to be audited by the user and the corresponding security measures taken by the auditing system, so as to help the user understand the operating status of the auditing system and the security audit results of each event.
[0163] It should be noted that the event auditing device in the cloud environment provided in this application embodiment can implement all the method steps implemented in the event auditing method embodiment in the cloud environment and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0164] In summary, the above embodiments of this application enable the audit system to intercept events awaiting auditing in the cloud environment in real time for security auditing, thereby improving security and reducing potential security risks. Furthermore, by using multiple candidate critical events, dangerous events can be identified more effectively, improving the accuracy of proactive security auditing. By predicting future critical events, security measures can be taken before events occur, achieving proactive security auditing and effectively preventing security violations. Moreover, by first determining whether an event is a future critical event, and then further determining whether it is a dangerous event based on the future critical event, the accuracy of security auditing can be further improved, and the security of the cloud environment can be further guaranteed. Furthermore, the above solution can be integrated into different cloud management platforms and can be ported to other cloud platforms, exhibiting good scalability and enhancing the universality and applicability of the audit system.
[0165] It should be noted that the division of units in the embodiments of this application is illustrative and only represents one logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated units described above can be implemented in hardware or as software functional units.
[0166] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a processor-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0167] like Figure 4As shown, embodiments of this application also provide an electronic device, including a memory 420, a transceiver 410, and a processor 400:
[0168] Memory 420 is used to store computer programs;
[0169] Transceiver 410 is used to send and receive data under the control of the processor;
[0170] Processor 400 is used to read computer programs from memory and perform the following steps:
[0171] Obtain auditable events in the cloud environment;
[0172] Based on the candidate key event information, it is determined whether the event to be audited is a future key event. The candidate key event information includes: multiple candidate key events and the relationship between the candidate key events.
[0173] If the event to be audited is a future critical event, determine whether the event to be audited is a dangerous event based on the event parameter information of the event to be audited and the preset event parameter information;
[0174] If the event to be audited is determined to be a dangerous event, the first safety measure corresponding to the dangerous event shall be implemented.
[0175] The embodiments described above first intercept and acquire auditable events in the cloud environment. Then, based on multiple candidate key events and the correlation between them, it determines whether the auditable event is a future key event. If the auditable event is a future key event, it determines whether the auditable event is a dangerous event based on the event parameter information and preset event parameter information. If the auditable event is determined to be a dangerous event, the first security measure corresponding to the dangerous event is executed, i.e., proactive auditing of the auditable events in the cloud environment, thereby improving the efficiency of security auditing. Furthermore, by determining whether the auditable event is a future key event, and if so, further determining whether it is a dangerous event, corresponding security measures can be taken before the event occurs, effectively preventing the occurrence of violations, reducing potential security risks, and improving the security of the cloud environment. Moreover, first determining whether it is a future key event, and then further determining whether it is a dangerous event based on the future key event, can improve the accuracy of security auditing and further ensure the security of the cloud environment.
[0176] Optionally, when the processor 400 determines whether the event to be audited is a future key event based on the candidate key event information, it specifically performs the following:
[0177] Determine whether the auditable event is included among the multiple candidate key events in the candidate key event information;
[0178] If the auditable event is included among the multiple candidate key events, a key event set is obtained, wherein the key event set includes multiple key events;
[0179] Based on the relationships between the candidate key events and the set of key events, determine whether the event to be audited is a future key event.
[0180] Optionally, when the processor 400 determines whether the event to be audited is a future key event based on the correlation between the candidate key events and the set of key events, it specifically performs the following:
[0181] Based on the relationships between the candidate key events, determine the target key event from the set of key events that the auditable event will transform after the current time.
[0182] Based on the transition probability between two related candidate key events in the candidate key event information, calculate the target transition probability of the audited event becoming the target key event;
[0183] If the target change probability is greater than the preset change probability, the event to be audited is determined to be a future critical event;
[0184] If the target transition probability is less than or equal to the preset transition probability, the event to be audited is determined to be a non-future critical event.
[0185] Optionally, when the event to be audited is a future critical event, the processor 400, based on the event parameter information of the event to be audited and preset event parameter information, determines whether the event to be audited is a dangerous event, specifically by:
[0186] If the event to be audited is a future critical event, obtain the event parameter information and preset event parameter information of the event to be audited. The preset event parameter information includes the event parameter information of each critical event in the critical event set.
[0187] If the preset event parameter information includes the event parameter information of the event to be audited, the event to be audited is determined to be a dangerous event.
[0188] If the event parameter information of the event to be audited is not included in the preset event parameter information, the event to be audited is determined to be a security event.
[0189] Optionally, the plurality of candidate key events includes at least two of the following:
[0190] The first incident of violating security policy;
[0191] A second event that has a contextual relationship with the first event;
[0192] A third event that has a strong dependency relationship with the first event;
[0193] A fourth event that has a time-dependent relationship with the first event;
[0194] A fifth event that has an environmental relationship with the first event.
[0195] Among them, Figure 4 In this context, the bus architecture can include any number of interconnected buses and bridges, specifically linking various circuits together, represented by one or more processors (processor 400) and memory (memory 420). The bus architecture can also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. The transceiver 410 can be multiple elements, including transmitters and receivers, providing a unit for communicating with various other devices over transmission media, including wireless channels, wired channels, optical fibers, etc. The processor 400 is responsible for managing the bus architecture and general processing, and the memory 420 can store data used by the processor 400 during operation.
[0196] The processor 400 can be a central processing unit (CPU), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or a complex programmable logic device (CPLD). The processor can also adopt a multi-core architecture.
[0197] In summary, the above embodiments of this application enable the audit system to intercept events awaiting auditing in the cloud environment in real time for security auditing, thereby improving security and reducing potential security risks. Furthermore, by using multiple candidate critical events, dangerous events can be identified more effectively, improving the accuracy of proactive security auditing. By predicting future critical events, security measures can be taken before events occur, achieving proactive security auditing and effectively preventing security violations. Moreover, by first determining whether an event is a future critical event, and then further determining whether it is a dangerous event based on the future critical event, the accuracy of security auditing can be further improved, and the security of the cloud environment can be further guaranteed. Furthermore, the above solution can be integrated into different cloud management platforms and can be ported to other cloud platforms, exhibiting good scalability and enhancing the universality and applicability of the audit system.
[0198] The processor executes the event auditing method in the cloud environment provided in this application embodiment by calling a computer program stored in memory, according to the obtained executable instructions. The processor and memory can also be physically separated.
[0199] It should be noted that the electronic device provided in this application embodiment can implement all the method steps implemented in the above-mentioned event auditing method embodiment in the cloud environment, and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0200] Embodiments of this application also provide a processor-readable storage medium storing a computer program for causing the processor to execute the event auditing method described above in a cloud environment.
[0201] The processor-readable storage medium can be any available medium or data storage device that the processor can access, including but not limited to magnetic memory (e.g., floppy disk, hard disk, magnetic tape, magneto-optical disk (MO)), optical memory (e.g., CD, DVD, BD, HVD), and semiconductor memory (e.g., ROM, EPROM, EEPROM, non-volatile memory (NAND FLASH), solid-state drive (SSD)).
[0202] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage) containing computer-usable program code.
[0203] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-executable instructions. These computer-executable instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0204] These processor-executable instructions may also be stored in a processor-readable memory that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the processor-readable memory produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0205] These processors can execute instructions that can also be loaded onto a computer or other programmable data processing device, causing a series of operational steps to be performed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable device for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0206] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. An event auditing method in a cloud environment, characterized in that, The method includes: Obtain auditable events in the cloud environment; Based on the candidate key event information, it is determined whether the event to be audited is a future key event. The candidate key event information includes: multiple candidate key events and the relationship between the candidate key events. If the event to be audited is a future critical event, determine whether the event to be audited is a dangerous event based on the event parameter information of the event to be audited and the preset event parameter information; If the event to be audited is determined to be a dangerous event, the first security measure corresponding to the dangerous event shall be implemented; The step of determining whether the event to be audited is a future key event based on the candidate key event information includes: Determine whether the auditable event is included among the multiple candidate key events in the candidate key event information; If the auditable event is included among the multiple candidate key events, a key event set is obtained, wherein the key event set includes multiple key events; Based on the relationships between the candidate key events and the set of key events, it is determined whether the event to be audited is a future key event; The step of determining whether the event to be audited is a future key event based on the correlation between the candidate key events and the set of key events includes: Based on the relationships between the candidate key events, determine the target key event from the set of key events that the auditable event will transform after the current time. Based on the transition probability between two related candidate key events in the candidate key event information, calculate the target transition probability of the audited event becoming the target key event; If the target change probability is greater than the preset change probability, the event to be audited is determined to be a future critical event; If the target transition probability is less than or equal to the preset transition probability, the event to be audited is determined to be a non-future critical event.
2. The method according to claim 1, characterized in that, When the event to be audited is a future critical event, determining whether the event to be audited is a dangerous event based on the event parameter information of the event to be audited and preset event parameter information includes: If the event to be audited is a future critical event, obtain the event parameter information and preset event parameter information of the event to be audited. The preset event parameter information includes the event parameter information of each critical event in the critical event set. If the preset event parameter information includes the event parameter information of the event to be audited, the event to be audited is determined to be a dangerous event. If the event parameter information of the event to be audited is not included in the preset event parameter information, the event to be audited is determined to be a security event.
3. The method according to claim 1, characterized in that, The plurality of candidate key events includes at least two of the following: The first incident of violating security policy; A second event that has a contextual relationship with the first event; A third event that has a strong dependency relationship with the first event; A fourth event that has a time-dependent relationship with the first event; A fifth event that has an environmental relationship with the first event.
4. An event auditing device in a cloud environment, characterized in that, The device includes: The acquisition module is used to acquire auditable events in the cloud environment; The first judgment module is used to determine whether the event to be audited is a future key event based on the candidate key event information. The candidate key event information includes: multiple candidate key events and the correlation between the candidate key events. The second judgment module is used to determine whether the event to be audited is a dangerous event based on the event parameter information of the event to be audited and the preset event parameter information when the event to be audited is a future critical event. The execution module is used to execute the first security measure corresponding to the dangerous event if the event to be audited is determined to be a dangerous event; The first judgment module is specifically used for: Determine whether the auditable event is included among the multiple candidate key events in the candidate key event information; If the auditable event is included among the multiple candidate key events, a key event set is obtained, wherein the key event set includes multiple key events; Based on the relationships between the candidate key events and the set of key events, it is determined whether the event to be audited is a future key event; When the first judgment module determines whether the event to be audited is a future key event based on the correlation between the candidate key events and the set of key events, it is specifically used for: Based on the relationships between the candidate key events, determine the target key event from the set of key events that the auditable event will transform after the current time. Based on the transition probability between two related candidate key events in the candidate key event information, calculate the target transition probability of the audited event becoming the target key event; If the target change probability is greater than the preset change probability, the event to be audited is determined to be a future critical event; If the target transition probability is less than or equal to the preset transition probability, the event to be audited is determined to be a non-future critical event.
5. The apparatus according to claim 4, characterized in that, The second judgment module specifically includes: If the event to be audited is a future critical event, obtain the event parameter information and preset event parameter information of the event to be audited. The preset event parameter information includes the event parameter information of each critical event in the critical event set. If the preset event parameter information includes the event parameter information of the event to be audited, the event to be audited is determined to be a dangerous event. If the event parameter information of the event to be audited is not included in the preset event parameter information, the event to be audited is determined to be a security event.
6. The apparatus according to claim 4, characterized in that, The plurality of candidate key events includes at least two of the following: The first incident that violates security policy; A second event that has a contextual relationship with the first event; A third event that has a strong dependency relationship with the first event; A fourth event that has a time-dependent relationship with the first event; A fifth event that has an environmental relationship with the first event.
7. An electronic device, characterized in that, Includes memory, transceiver, and processor: Memory, used to store computer programs; Transceiver, used to send and receive data under the control of the processor; A processor for reading a computer program from the memory and executing the event auditing method in a cloud environment as described in any one of claims 1 to 3.
8. A processor-readable storage medium, characterized in that, The processor-readable storage medium stores a computer program for causing the processor to perform the event auditing method in a cloud environment as described in any one of claims 1 to 3.
Citation Information
Patent Citations
Discovering linkages between changes and incidents in information technology systems
US20170178038A1
System and method of processing information security events to detect cyberattacks
US20210400058A1