Multi-source fusion log compression method and device for anomaly detection

By generating and integrating a source graph from system audit logs, application logs, and domain name system logs, the problems of dependency explosion and semantic gap are solved, enabling more efficient anomaly detection.

CN119420534BActive Publication Date: 2026-04-17INST OF ADVANCED TECH UNIV OF SCI & TECH OF CHINA
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
INST OF ADVANCED TECH UNIV OF SCI & TECH OF CHINA
Filing Date
2024-10-31
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

In existing technologies, when constructing a source graph from system audit logs for anomaly detection, there are problems of dependency explosion and semantic gap, which make attack detection difficult.

Method used

By generating source maps corresponding to system audit logs, application logs, and domain name system logs, and performing multi-source fusion, a richer fusion source map is generated, which alleviates the semantic gap and dependency explosion and provides a clear attack detection path.

Benefits of technology

The generated fusion traceability graph is clearer, reduces the amount of data, improves the efficiency and accuracy of anomaly detection, and provides a more intuitive representation of log information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119420534B_ABST
    Figure CN119420534B_ABST
Patent Text Reader

Abstract

This application discloses a multi-source fusion log compression method and apparatus for anomaly detection, belonging to the field of anomaly detection technology. The multi-source fusion log compression method for anomaly detection includes: generating an audit origination graph corresponding to the system audit log, an application origination graph corresponding to the application log, and a domain name origination graph corresponding to the domain name system log based on the system audit log corresponding to the electronic device, the application log corresponding to the target application in the electronic device, and the domain name system log corresponding to the electronic device; fusing the domain name origination graph into the application origination graph based on the domain name nodes in the application origination graph to obtain a sub-fused origination graph; fusing the audit origination graph into the sub-fused origination graph based on the event nodes in the audit origination graph to obtain a fused origination graph; and performing anomaly detection based on the fused origination graph. The multi-source fusion log compression method for anomaly detection in this application can alleviate the problems of semantic gap and dependency explosion.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of anomaly detection technology, and in particular relates to a multi-source fusion log compression method and apparatus for anomaly detection. Background Technology

[0002] Advanced persistent threat (APS) attack detection based on source graphs can promptly detect attacks and establish defense mechanisms to protect cyberspace security. Related technologies utilize system audit logs to construct source graphs for anomaly detection. However, the source graphs constructed by these methods suffer from dependency explosion and semantic gap problems. Summary of the Invention

[0003] This application aims to address at least one of the technical problems existing in related technologies. To this end, this application proposes a multi-source fusion log compression method and apparatus for anomaly detection, generating richer source graphs, alleviating the semantic gap and dependency explosion problems, and providing a clearer path for attack detection.

[0004] Firstly, this application provides a multi-source fusion log compression method for anomaly detection, the method comprising:

[0005] Based on the system audit logs corresponding to the electronic device, the application logs corresponding to the target application in the electronic device, and the domain name system logs corresponding to the electronic device, an audit tracing graph corresponding to the system audit logs, an application tracing graph corresponding to the application logs, and a domain name tracing graph corresponding to the domain name system logs are generated; the nodes in each tracing graph are used to represent the entities included in the logs corresponding to the tracing graph, and the edges in each tracing graph are used to represent the interaction relationships between the entities;

[0006] Based on the domain name nodes in the application tracing graph, the domain name tracing graph is merged into the application tracing graph to obtain a sub-merged tracing graph;

[0007] Based on the event nodes in the audit source graph, the audit source graph is merged into the sub-fused source graph to obtain the fused source graph;

[0008] Anomaly detection is performed based on the fused source map.

[0009] According to the multi-source fusion log compression method for anomaly detection proposed in this application, system audit logs, application logs, and domain name system logs are obtained, and audit traceability graphs, application traceability graphs, and domain name traceability graphs are generated respectively. By fusing the audit traceability graph, application traceability graph, and domain name traceability graph, a richer traceability graph is generated, which alleviates the problems of semantic gap and dependency explosion, and provides a clearer path for attack detection.

[0010] According to the multi-source fusion log compression method for anomaly detection in this application, the step of fusing the domain name fusion graph into the application fusion graph based on the domain name nodes in the application fusion graph to obtain a sub-fusion fusion graph includes:

[0011] The domain name nodes in the application origination graph are matched with the domain name nodes in the domain origination graph, and the matched domain name nodes in the application origination graph are merged with the domain name nodes in the domain origination graph.

[0012] Add the Internet Protocol address node corresponding to the domain name node in the domain name origination graph to the application origination graph to obtain the sub-fusion origination graph.

[0013] According to the multi-source fusion log compression method for anomaly detection in this application, the step of fusing the audit sourcing graph into the sub-fusion sourcing graph based on event nodes in the audit sourcing graph to obtain a fusion sourcing graph includes:

[0014] The event nodes in the audit tracing graph are matched with the event nodes in the sub-fusion tracing graph, and the matched event nodes in the audit tracing graph are merged with the event nodes in the sub-fusion tracing graph to obtain the fusion tracing graph.

[0015] According to the multi-source fusion log compression method for anomaly detection in this application, the step of matching event nodes in the audit tracing graph with event nodes in the sub-fusion tracing graph, and fusing the matched event nodes in the audit tracing graph with the event nodes in the sub-fusion tracing graph to obtain the fusion tracing graph includes:

[0016] The event nodes in the audit tracing graph are matched with the event nodes in the sub-fusion tracing graph, and the matched event nodes in the audit tracing graph are fused with the event nodes in the sub-fusion tracing graph to obtain the first fusion tracing graph.

[0017] Extract the path corresponding to the file download event and the path corresponding to the malicious domain name access event from the first fused source map to obtain a new first fused source map;

[0018] Based on the path corresponding to the file download event and the path corresponding to the malicious domain access event, a second fusion tracing map is obtained;

[0019] The fusion source map is obtained based on the new first fusion source map and the second fusion source map.

[0020] According to the multi-source fusion log compression method for anomaly detection in this application, the anomaly detection based on the fusion source map includes:

[0021] The fused source map is compressed to obtain the target source map;

[0022] The abnormal event is processed based on the target tracing graph.

[0023] According to the multi-source fusion log compression method for anomaly detection in this application, the step of compressing the fusion source map to obtain the target source map includes:

[0024] Delete redundant nodes and edges corresponding to the redundant nodes, as well as the first irrelevant node and its corresponding edges, from the target tracing graph.

[0025] and / or;

[0026] Merge the second irrelevant node and the edge corresponding to the second irrelevant node in the target source graph;

[0027] and / or;

[0028] The target source graph is obtained by merging the duplicate nodes and the edges corresponding to the duplicate nodes in the target source graph.

[0029] According to the multi-source fusion log compression method for anomaly detection in this application, the redundant nodes and the edges corresponding to the redundant nodes, as well as the first unrelated node and the edges corresponding to the first unrelated node, include:

[0030] The following are included: nodes unrelated to the file download event and the edges corresponding to those nodes; at least one domain name node and the edges corresponding to each domain name node between the node corresponding to the file download event and the target file corresponding to the file download event; read operation nodes and the edges corresponding to those read operation nodes; delete operation nodes and the edges corresponding to those delete operation nodes; and external nodes that do not interact with the local file system and the edges corresponding to those external nodes.

[0031] According to the multi-source fusion log compression method for anomaly detection in this application, the second irrelevant node and the edge corresponding to the second irrelevant node in the target tracing graph include:

[0032] The attack node is a node that does not participate in the attack. The attack node is a node that is not involved in the attack.

[0033] According to the multi-source fusion log compression method for anomaly detection in this application, the duplicate nodes and the edges corresponding to the duplicate nodes in the target tracing graph include:

[0034] The target node that matches the node corresponding to the local file operation in the node corresponding to the file download event, the edge corresponding to the target node, and the multiple edges between the first node and the second node in the fused tracing graph.

[0035] According to the multi-source fusion log compression method for anomaly detection in this application, the step of generating an audit tracing diagram corresponding to the system audit log, an application tracing diagram corresponding to the application log, and a domain name tracing diagram corresponding to the domain name system log based on the system audit log corresponding to the electronic device, the application log corresponding to the target application in the electronic device, and the domain name system log corresponding to the electronic device includes:

[0036] Extract at least one entity from the system audit log, the application log, and the domain name system log, as well as the relationships between the entities;

[0037] Based on the event nodes and Internet Protocol address nodes in the system audit log, and the relationship between the event nodes and Internet Protocol address nodes, the audit tracing graph is constructed.

[0038] Based on the event nodes and domain nodes in the application logs, and the relationships between the event nodes and the domain nodes, the application tracing graph is constructed.

[0039] Based on the domain name nodes and Internet Protocol address nodes in the domain name log, and the association between the domain name nodes and the Internet Protocol addresses, the domain name origin graph is constructed.

[0040] Secondly, this application provides a multi-source fusion log compression device for anomaly detection, the device comprising:

[0041] The first processing module is used to generate an audit tracing graph corresponding to the system audit log, an application tracing graph corresponding to the application log, and a domain name tracing graph corresponding to the domain name system log based on the system audit log corresponding to the electronic device, the application log corresponding to the target application in the electronic device, and the domain name system log corresponding to the electronic device; the nodes in each tracing graph are used to represent the entities included in the logs corresponding to the tracing graph, and the edges in each tracing graph are used to represent the interaction relationships between the entities;

[0042] The second processing module is used to merge the domain name origination graph into the application origination graph based on the domain name nodes in the domain name origination graph to obtain a sub-fused origination graph;

[0043] The third processing module is used to merge the audit source map into the sub-fused source map based on the event nodes in the audit source map to obtain the fused source map;

[0044] The third processing module is used to merge the audit source map into the sub-fused source map based on the event nodes in the audit source map to obtain the fused source map;

[0045] The fourth processing module is used to perform anomaly detection based on the fused traceability map.

[0046] According to the multi-source fusion log compression device for anomaly detection in this application, system audit logs, application logs and domain name system logs are acquired, and audit traceability graphs, application traceability graphs and domain name traceability graphs are generated respectively. By fusion of audit traceability graphs, application traceability graphs and domain name traceability graphs, a richer traceability graph is generated, which alleviates the problems of semantic gap and dependency explosion, and provides a clearer path for attack detection.

[0047] Thirdly, this application provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the multi-source fusion log compression method for anomaly detection as described in the first aspect above.

[0048] Fourthly, this application provides a non-transitory computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the multi-source fusion log compression method for anomaly detection as described in the first aspect above.

[0049] Fifthly, this application provides a computer program product, including a computer program that, when executed by a processor, implements the multi-source fusion log compression method for anomaly detection as described in the first aspect above.

[0050] The above-described one or more technical solutions in the embodiments of this application have at least one of the following technical effects:

[0051] By acquiring system audit logs, application logs, and domain name system logs, and generating audit source maps, application source maps, and domain name source maps respectively, and by merging the audit source maps, application source maps, and domain name source maps, a richer source map is generated, which alleviates the semantic gap and dependency explosion problems and provides a clearer path for attack detection.

[0052] Furthermore, by separating the path corresponding to the file download event and the path corresponding to the malicious domain access event, the first fusion traceability graph is effectively divided into multiple subgraphs, resulting in a more clearly structured and easier-to-analyze fusion traceability graph, thereby improving the efficiency of subsequent anomaly detection processing based on the fusion traceability graph.

[0053] Furthermore, by compressing the fused source map, the amount of data in the fused source map is effectively reduced, resulting in a target source map with a concise structure and rich information, which improves the efficiency of target source map analysis, thereby improving the efficiency and accuracy of subsequent abnormal event handling.

[0054] Furthermore, by extracting at least one entity from the system audit logs, application logs, and domain name system logs, as well as the relationships between these entities, and constructing a source graph for each log based on these relationships, the log information is effectively represented graphically, improving its readability and intuitiveness.

[0055] Additional aspects and advantages of this application will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of this application. Attached Figure Description

[0056] The above and / or additional aspects and advantages of this application will become apparent and readily understood from the description of the embodiments taken in conjunction with the following drawings, in which:

[0057] Figure 1 This is a flowchart illustrating the multi-source fusion log compression method for anomaly detection provided in an embodiment of this application;

[0058] Figure 2 This is one of the schematic diagrams illustrating the principle of the multi-source fusion log compression method for anomaly detection provided in this application embodiment;

[0059] Figure 3 This is the second schematic diagram illustrating the principle of the multi-source fusion log compression method for anomaly detection provided in this application embodiment;

[0060] Figure 4 This is the third schematic diagram illustrating the principle of the multi-source fusion log compression method for anomaly detection provided in this application embodiment;

[0061] Figure 5 This is the fourth schematic diagram illustrating the principle of the multi-source fusion log compression method for anomaly detection provided in this application embodiment;

[0062] Figure 6 This is the fifth schematic diagram illustrating the principle of the multi-source fusion log compression method for anomaly detection provided in this application embodiment;

[0063] Figure 7 This is the sixth schematic diagram illustrating the principle of the multi-source fusion log compression method for anomaly detection provided in this application embodiment;

[0064] Figure 8 This is the seventh schematic diagram illustrating the principle of the multi-source fusion log compression method for anomaly detection provided in this application embodiment;

[0065] Figure 9 This is the eighth schematic diagram illustrating the principle of the multi-source fusion log compression method for anomaly detection provided in this application embodiment;

[0066] Figure 10 This is the ninth schematic diagram illustrating the principle of the multi-source fusion log compression method for anomaly detection provided in the embodiments of this application;

[0067] Figure 11 This is the tenth schematic diagram illustrating the principle of the multi-source fusion log compression method for anomaly detection provided in the embodiments of this application;

[0068] Figure 12 This is eleventh of the schematic diagrams illustrating the principle of the multi-source fusion log compression method for anomaly detection provided in the embodiments of this application;

[0069] Figure 13 This is the twelfth schematic diagram of the principle of the multi-source fusion log compression method for anomaly detection provided in the embodiments of this application;

[0070] Figure 14 This is a schematic diagram of the structure of the multi-source fusion log compression method apparatus for anomaly detection provided in the embodiments of this application;

[0071] Figure 15 This is a schematic diagram of the structure of the electronic device provided in the embodiments of this application. Detailed Implementation

[0072] The technical solutions of the embodiments of this application will be clearly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application are within the scope of protection of this application.

[0073] The terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such use of data can be interchanged where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first," "second," etc., are generally of the same class and the number of objects is not limited; for example, a first object can be one or more. Furthermore, in the specification and claims, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects are in an "or" relationship.

[0074] The following description, in conjunction with the accompanying drawings, details the multi-source fusion log compression method, multi-source fusion log compression device, electronic device, and readable storage medium for anomaly detection provided in this application, through specific embodiments and application scenarios.

[0075] Among them, the multi-source fusion log compression method for anomaly detection can be applied to the terminal, specifically executed by the hardware or software in the terminal.

[0076] The terminal includes, but is not limited to, portable communication devices such as mobile phones or tablets. It should also be understood that, in some embodiments, the terminal may not be a portable communication device, but rather a desktop computer.

[0077] The following embodiments describe a terminal including a display and a touch-sensitive surface. However, it should be understood that the terminal may include one or more other physical user interface devices such as a physical keyboard, mouse, and joystick.

[0078] The multi-source fusion log compression method for anomaly detection provided in this application embodiment can be executed by an electronic device or a functional module or entity in an electronic device that can implement the multi-source fusion log compression method for anomaly detection. The electronic devices mentioned in this application embodiment include, but are not limited to, mobile phones, tablets, computers, cameras, and wearable devices. The following uses an electronic device as the execution subject to illustrate the multi-source fusion log compression method for anomaly detection provided in this application embodiment.

[0079] like Figure 1 As shown, the multi-source fusion log compression method for anomaly detection includes steps 110, 120, 130, and 140.

[0080] Step 110: Based on the system audit logs corresponding to the electronic device, the application logs corresponding to the target application in the electronic device, and the domain name system logs corresponding to the electronic device, generate the audit source diagram corresponding to the system audit logs, the application source diagram corresponding to the application logs, and the domain name source diagram corresponding to the domain name system logs.

[0081] In this step, electronic devices include, but are not limited to, mobile phones, tablets, computers, cameras, and wearable devices.

[0082] The electronic device is the one that was attacked.

[0083] The target application is the application being attacked.

[0084] System audit logs are used to record security events on a computer system. These logs contain detailed information about various operations, such as user login, user logout, permission changes, system startup, system shutdown, and file operation-related events (e.g., creating, opening, and deleting files).

[0085] The events recorded in the system audit logs provide a reliable timeline for underlying operations and are the basis for tracing the origins of advanced persistent threat (APS) attacks.

[0086] Application logs are log information generated during the runtime of a target application. Application logs include various activities, events, and states of the target application.

[0087] Application logs record network requests and responses when users access web pages through their browsers, including information such as network requests, redirects, and file downloads.

[0088] Application logs can explain an attacker's actions in the browser and provide contextual clues for censorship through behaviors such as file downloads.

[0089] The Domain Name System (DNS) log is used to record information related to domain name resolution, mapping domain names to Internet Protocol (IP) addresses.

[0090] Domain Name System (DNS) logs can reveal potential malicious activities through DNS communication.

[0091] The source graph is an abstract directed graph obtained by transforming log information.

[0092] The nodes in each source graph represent the entities included in the log corresponding to the source graph, and the edges in each source graph represent the interaction relationships between the entities.

[0093] It should be noted that the information in the source graph can represent the control flow, data flow, and all execution history between system entities, and the source graph has rich semantics.

[0094] The audit source diagram is a source diagram obtained by transforming information in the system audit log.

[0095] The application source map is a source map obtained by transforming information in the application logs.

[0096] The domain origin diagram is a source diagram obtained by transforming information in the Domain Name System log.

[0097] In actual execution, the information in each log can be parsed to extract key information, such as the subject, object, and event. Based on the extracted subject, object, and event information, a source graph can be constructed.

[0098] like Figure 2As shown, the parser can capture the required fields from each log record, such as timestamp, source address of the data packet, destination address of the data packet, and operation type.

[0099] The captured fields can be used to build a source graph that captures key nodes and events in a system and network.

[0100] Step 120: Based on the domain name nodes in the application origination graph, merge the domain name origination graph into the application origination graph to obtain a sub-fused origination graph;

[0101] In this step, the domain name node in the source map is used as the address of the website that the user requested to access.

[0102] The sub-fusion source map is a source map obtained by fusing the application source map and the domain name source map.

[0103] Application traceability diagrams can reflect user actions in the browser, with each action corresponding to a domain name node.

[0104] Different operations may correspond to different domain name nodes.

[0105] In actual implementation, the domain name nodes in the application traceability diagram can be used as the basis. Based on the relationship between the domain name nodes in the application traceability diagram and the domain name traceability diagram, the domain name traceability diagram and the application function traceability diagram can be merged to obtain a sub-fused traceability diagram.

[0106] Step 130: Based on the event nodes in the audit source map, merge the audit source map into the sub-fused source map to obtain the fused source map;

[0107] In this step, the event nodes in the audit tracing diagram are the event nodes involved in the user's actions through the browser.

[0108] It is understandable that the entities corresponding to the event nodes may be different depending on the user's actions.

[0109] The entities corresponding to event nodes can include: files, processes, sockets, Internet Protocol addresses, and Uniform Resource Locators, etc.

[0110] The integrated traceability graph is a directed graph that includes key information from system audit logs, application logs, and domain name system logs.

[0111] When a user downloads a file through a browser, the interaction between the browser and the local file system can be characterized by audit and application source graphs related to the file download event.

[0112] In practice, the audit source map and the sub-fusion source map can be merged based on the relationship between the event nodes in the audit source map and the sub-fusion source map to obtain the fusion source map.

[0113] Step 140: Perform anomaly detection based on the fused source map.

[0114] In this step, the source graph is integrated to contain more contextual information.

[0115] In actual implementation, malicious attack events can be extracted by analyzing and integrating the information contained in each node and edge of the source tracing graph, thereby enabling anomaly detection.

[0116] During the research and development process, the inventors discovered that using source graphs for advanced persistent threat (APT) attack detection can promptly detect attacks and establish defense mechanisms to protect cyberspace security. However, in related technologies, source graphs constructed using system audit logs for anomaly detection suffer from dependency explosion and semantic gap problems.

[0117] In this case, the dependency explosion is an output event in the source graph that is assumed to be causally dependent on all previous input events, making attack detection very difficult.

[0118] The semantic gap arises because attacks leave different traces in logs from different types and levels of sources. A single level of logs cannot reveal the full picture of an attack, and for downstream detection tasks, relying solely on system audit logs will miss more effective information.

[0119] This application obtains system audit logs, application logs, and domain name system logs, analyzes the fields in each log that can capture key nodes and events in the system and network, and constructs audit source maps, application source maps, and domain name source maps respectively to provide a basic system behavior model. By fusing the audit source maps, application source maps, and domain name source maps, higher-level application information is added to the lower-level log information, generating richer source maps oriented towards anomaly detection, alleviating the semantic gap problem, and providing a clearer path for attack detection. By fusing the audit source maps, application source maps, and domain name source maps, a fused source map is obtained, which effectively addresses the dependency explosion problem caused by anomaly detection through audit source maps.

[0120] According to the multi-source fusion log compression method for anomaly detection provided in the embodiments of this application, system audit logs, application logs and domain name system logs are obtained, and audit traceability graphs, application traceability graphs and domain name traceability graphs are generated respectively. By fusing the audit traceability graph, application traceability graph and domain name traceability graph, a richer traceability graph is generated, which alleviates the problems of semantic gap and dependency explosion, and provides a clearer path for attack detection.

[0121] Continue to refer to Figure 3 In some embodiments, step 110 may further include:

[0122] Extract at least one entity from the system audit log, application log, and domain name system log, and the relationships between these entities.

[0123] Based on the event nodes and Internet Protocol address nodes in the system audit log, and the relationship between the event nodes and Internet Protocol address nodes, an audit tracing graph is constructed;

[0124] Based on the event nodes and domain nodes in the application logs, and the relationships between the event nodes and domain nodes, an application tracing graph is constructed.

[0125] A domain origin graph is constructed based on the domain name nodes and Internet Protocol address nodes in the domain name logs, as well as the relationship between the domain name nodes and Internet Protocol addresses.

[0126] In this embodiment, such as Figure 3 As shown, in the actual execution process, after obtaining the system audit logs, application logs, and domain name system logs, the log parser can be used to parse the system audit logs, application logs, and domain name system logs to obtain different log fields and event operation information, and then convert the parsed log fields and event operation information into nodes and edges in the source graph.

[0127] like Figure 4 As shown, the entities corresponding to the nodes in the source graph include, but are not limited to: processes, files, sockets, domain names, and Uniform Resource Locators.

[0128] like Figure 5 As shown, the source graph can also include multiple events, such as events corresponding to processes and files, and events corresponding to files and processes.

[0129] In a source graph, the attributes of an edge include: source node, target node, operation type, timestamp, and operation specific form (rel).

[0130] The attributes of a node include: a unique identifier (nodeid) and a type (type).

[0131] It should be noted that different types of entities in the system, such as processes, files, and Internet Protocol addresses, may share the same identifier, such as PID or ObjID.

[0132] In actual execution, the uniqueness of each node can be ensured by combining multiple fields.

[0133] For example, combining fields such as pname, ppname, u_name, and d_ip can represent a node.

[0134] Node type is used to identify the type of node, such as process node, event node, user node, and Internet Protocol address node.

[0135] Event nodes in the system audit log can be used as entities connected by directed edges in the tracing graph.

[0136] The event corresponding to the event node can be file creation or process startup, etc.

[0137] By analyzing the fields in the system audit logs, the operational processes within the system can be visualized, revealing potential attack behaviors and yielding results such as... Figure 6 The audit traceability diagram shown.

[0138] Application logs record events such as network jumps, redirects, file downloads, and file requests. These events can be identified as nodes and edges in a source graph, generating data reflecting user actions in the browser, such as... Figure 7 The application traceability diagram is shown.

[0139] Each event corresponds to an Internet Protocol address node.

[0140] For example, when a user performs a file download event, that file download event corresponds to an Internet Protocol address node.

[0141] Using source maps is crucial for identifying attacks carried out through malicious web pages, especially since malicious code may be hidden in file downloads and redirection operations.

[0142] like Figure 8 As shown, in the domain name origin graph, the domain name node and the Internet Protocol address node are the nodes of the origin graph. When the domain name node is resolved to the corresponding Internet Protocol address node, a directed edge is established from the domain name node to the Internet Protocol address node.

[0143] Domain origin maps reveal the domain name resolution relationships in the network and can help identify the source of malicious domain names and potential malicious traffic.

[0144] According to the multi-source fusion log compression method for anomaly detection provided in the embodiments of this application, at least one entity and the relationship between each entity are extracted from the system audit log, application log and domain name system log respectively. Based on the relationship between each entity, a source tracing graph corresponding to each log is constructed, which effectively represents the log information in a graphical way and improves the readability and intuitiveness of the log information.

[0145] In some embodiments, step 120 may further include:

[0146] Match the domain name nodes in the domain name origination diagram with the domain name nodes in the application origination diagram, and then merge the domain name nodes in the application origination diagram with the domain name nodes in the domain name origination diagram.

[0147] Add the Internet Protocol address nodes corresponding to the domain name nodes in the domain name origin graph to the application origin graph to obtain the sub-fusion origin graph.

[0148] In this embodiment, the domain name origin graph includes multiple domain name nodes, and the application origin graph also includes multiple domain name nodes.

[0149] In practice, the domain origin map can reveal the correspondence between each domain name node and the Internet Protocol address node.

[0150] In the process of merging the domain name origin graph and the application origin graph, each domain name node in the application origin graph can be matched with the node in the domain name origin graph. The Internet Protocol address node corresponding to the domain name node in the domain name origin graph that is the same as the domain name node in the application origin graph can be added to the application origin graph to obtain the sub-merged origin graph.

[0151] The sub-fusion tracing graph can also record the operation and timestamp of the event node corresponding to the domain name node.

[0152] When a request in the application source map involves a specific domain name, the Internet Protocol address corresponding to the domain name that matches the specific domain name in the application source map can be linked to form a cross-level source map path.

[0153] According to the multi-source fusion log compression method for anomaly detection provided in the embodiments of this application, by matching the domain name nodes in the domain name tracing graph and the domain name nodes in the application tracing graph, the domain name tracing graph and the application tracing graph are fused through the same domain name nodes. This effectively adds the Internet Protocol address nodes in the domain name tracing graph to the application tracing graph, improves the accuracy of tracing graph fusion, and enriches the information included in the tracing graph.

[0154] In some embodiments, step 130 may further include:

[0155] The event nodes in the audit source map are matched with the event nodes in the sub-fusion source map, and the event nodes in the matched audit source map are merged with the event nodes in the sub-fusion source map to obtain the fusion source map.

[0156] In this embodiment, the audit tracing graph may include different event nodes, and the sub-fusion tracing graph may include different event nodes.

[0157] Users may perform different actions on the corresponding event nodes.

[0158] For example, the event node is for performing a file download operation.

[0159] For example, an event node might be for performing a file creation operation.

[0160] In actual execution, the operations corresponding to the event nodes in the audit sourcing diagram can be matched with the operations corresponding to the event nodes in the sub-fusion sourcing diagram. For example, if both the event node in the audit sourcing diagram and the event node in the sub-fusion sourcing diagram match the file download, the event node in the matched audit sourcing diagram can be merged with the event node in the sub-fusion sourcing diagram to obtain the fusion sourcing diagram.

[0161] In some embodiments, audit traceability diagrams and application traceability diagrams can also be merged using preset fusion rules.

[0162] In this embodiment, the preset fusion rules are pre-defined based on the association relationships between each event node.

[0163] In actual execution, when the operation corresponding to an event node meets the conditions of file download or other related conditions, the relevant operation information can be merged, that is, the audit tracing graph and the sub-tracing graph can be merged to obtain, as shown below. Figure 3 The diagram showing the fusion and tracing of origins is shown.

[0164] According to the multi-source fusion log compression method for anomaly detection provided in this application, by matching event nodes in the audit tracing graph with event nodes in the sub-fusion tracing graph, the association between the audit tracing graph and the sub-fusion tracing graph is effectively constructed, event nodes that perform the same or related operations are obtained, and based on the event nodes, the audit tracing graph and the sub-fusion tracing graph are fused to obtain a fusion tracing graph that includes information from system audit logs, application logs, and domain name system logs. This effectively obtains a tracing graph that includes contextual information, improving the accuracy of subsequent attack detection.

[0165] In some embodiments, the event nodes in the audit tracing graph are matched with the event nodes in the sub-fusion tracing graph, and the event nodes in the matched audit tracing graph are fused with the event nodes in the sub-fusion tracing graph to obtain a fusion tracing graph. This may further include:

[0166] Match the event nodes in the audit source map with the event nodes in the sub-fusion source map, and then fuse the event nodes in the matched audit source map with the event nodes in the sub-fusion source map to obtain the first fusion source map.

[0167] Extract the paths corresponding to file download events and malicious domain access events from the first fusion source map to obtain a new first fusion source map;

[0168] Based on the paths corresponding to file download events and malicious domain access events, a second fusion tracing diagram is obtained.

[0169] Based on the new first fusion source map and the second fusion source map, a fusion source map is obtained.

[0170] In this embodiment, the first fused source map is the source map obtained by fusing the audit source map with the sub-fused source map.

[0171] By fusing the audit source map with the sub-fusion source map, we can obtain the following: Figure 9 The first fusion tracing diagram is shown.

[0172] The path corresponding to a file download event is the path formed by the nodes and edges involved in the source graph when a user performs a file download operation through a browser.

[0173] The path corresponding to a malicious domain access event is the path formed by the nodes and edges involved in the source graph when a user accesses a malicious domain through a browser.

[0174] The new first fusion source map is the first fusion source map that does not include the paths corresponding to file download events and the paths corresponding to malicious domain access events.

[0175] The second fused source map is a source map composed of the path corresponding to the file download event and the path corresponding to the malicious domain access event.

[0176] In practical implementation, to address the dependency explosion problem of browser nodes, a path separation approach can be adopted. The paths corresponding to critical file download operations and malicious domain access events can be extracted from the dependency relationships of the first fused origination graph, resulting in a new first fused origination graph. Using this new first fused origination graph and the second fused origination graph, the dependency relationships can be determined as follows: Figure 10 The diagram showing the fusion and tracing of origins is shown.

[0177] According to the multi-source fusion log compression method for anomaly detection provided in the embodiments of this application, by separating the path corresponding to the file download event and the path corresponding to the malicious domain name access event, the first fusion tracing graph is effectively divided into multiple sub-graphs, resulting in a fusion tracing graph with a clearer structure and easier analysis, thereby improving the efficiency of subsequent anomaly detection processing based on the fusion tracing graph.

[0178] In some embodiments, step 140 may further include:

[0179] The fused source map is compressed to obtain the target source map;

[0180] Anomaly detection is performed based on the target source map.

[0181] In this embodiment, the target source map is a simplified source map obtained while retaining the key information of the fused source map.

[0182] The integrated source graph incorporates information from system audit logs, application logs, and domain name system logs, resulting in richer semantics. However, the source graph data volume is very large, which may not be suitable for real-time or efficient attack detection.

[0183] In actual implementation, information unrelated to anomaly detection can be deleted from the fusion traceability graph, and duplicate nodes and information can be removed.

[0184] In actual execution, compression functions can be pre-defined, such as the types of nodes to be deleted and the types of edges to be deleted.

[0185] The compression function can be determined based on the actual situation of the malicious attack, such as deleting nodes and edges that are not related to the malicious attack.

[0186] like Figure 11 As shown, compression functions can be functions that determine the relationship between two nodes, as well as functions that connect two nodes, etc.

[0187] In actual execution, the fused source map can be compressed based on the set compression function to obtain a simplified target source map. Based on the target source map, the information of malicious attack events recorded in the target source map can be analyzed to perform anomaly detection.

[0188] like Figure 3 As shown, compressing the fused source graph can reduce the number of nodes and edges in the resulting source graph.

[0189] During the research and development process, the inventors discovered that the traceability graph data constructed in the relevant technologies is large in volume, which affects the efficiency of anomaly detection.

[0190] This application compresses the obtained fusion source graph, effectively reducing the number of nodes and edges while retaining key information, resulting in a simplified target source graph, thereby improving the efficiency of subsequent anomaly detection based on the target source graph.

[0191] According to the multi-source fusion log compression method for anomaly detection provided in the embodiments of this application, by compressing the fusion source map, the data volume of the fusion source map is effectively reduced, resulting in a target source map with a concise structure and rich information, thereby improving the analysis efficiency of the target source map and thus improving the efficiency and accuracy of subsequent anomaly event handling.

[0192] In some embodiments, compressing the fused source map to obtain the target source map may further include:

[0193] Delete redundant nodes and their corresponding edges, as well as the first irrelevant node and its corresponding edge, from the target source graph.

[0194] and / or;

[0195] Merge the second irrelevant node and the edges corresponding to the second irrelevant node in the target source graph;

[0196] and / or;

[0197] Merge duplicate nodes and their corresponding edges in the target source graph to obtain the target source graph.

[0198] In this embodiment, the redundant node and the first unrelated node are nodes that are unrelated to the attack.

[0199] Redundant nodes and first unrelated nodes include: reading and writing temporary files and running unrelated processes.

[0200] Understandably, redundant nodes and unrelated first nodes make the fusion tracing graph large and complex, interfering with the analysis of attack paths.

[0201] The second irrelevant node is a node that records the entity corresponding to the same event in different forms.

[0202] It should be noted that the second irrelevant node provides different details about the attack event, but in attack detection, too much detail can distract the analyst and reduce analysis efficiency.

[0203] In actual implementation, multiple second-irrelevant nodes can be merged, and the edges corresponding to each second-irrelevant node can be merged to simplify the path of irrelevant operations and retain the key operation nodes.

[0204] Duplicate nodes are nodes where the same entity or operation is recorded repeatedly at multiple locations in the source graph.

[0205] In actual implementation, after obtaining the fusion source graph, nodes and edges in the fusion source graph can be deleted or merged.

[0206] like Figure 13 As shown, in the actual execution process, after obtaining the fusion source map, irrelevant information in the fusion source map can be deleted, irrelevant information can be merged, and duplicate nodes in the source map can be merged to obtain the target source map.

[0207] According to the multi-source fusion log compression method for anomaly detection provided in the embodiments of this application, the fusion tracing graph is effectively compressed by deleting redundant nodes and first irrelevant nodes, merging second irrelevant nodes and duplicate nodes, and deleting or merging the edges corresponding to the nodes. Without losing key attack information, the redundancy of the tracing graph is effectively reduced, the structure of the target tracing graph is optimized, and the target tracing graph is more suitable for attack detection tasks, thereby improving the accuracy and efficiency of attack detection.

[0208] In some embodiments, the redundant node and the edge corresponding to the redundant node, as well as the first unrelated node and the edge corresponding to the first unrelated node, may include:

[0209] The following are included: nodes unrelated to the file download event and their corresponding edges; domain nodes and their corresponding edges between the node corresponding to the file download event and the target file corresponding to the file download event; read operation nodes and their corresponding edges; delete operation nodes and their corresponding edges; and external nodes that do not interact with the local file system and their corresponding edges.

[0210] In this embodiment, the target file is the file operated on by the file download event.

[0211] In file download scenarios, more attention is paid to the Internet protocol address of the file download. Similarly, some Internet protocol address nodes that do not interact with the local file system can be removed from the source graph as redundant nodes, and the edges corresponding to the redundant nodes can be removed to simplify the fusion of the source graph.

[0212] like Figure 12 As shown, in actual execution, nodes unrelated to the file download event and edges corresponding to nodes unrelated to the file download event can be deleted using the compression function F1.

[0213] The Internet Protocol address of the file download event is concatenated with the target file using the compression function F2, and the intermediate domain name nodes and their corresponding edges are removed.

[0214] The compression function F3 is used to delete temporary event nodes that only have read operations and the edges corresponding to those read operation nodes in the system.

[0215] The compression function F4 is used to delete temporary event nodes that only contain deletion operations and the edges corresponding to the deletion operation nodes in the system.

[0216] The compression function F5 is used to delete external nodes that do not interact with the local file system, as well as the edges corresponding to those external nodes.

[0217] According to the multi-source fusion log compression method for anomaly detection provided in the embodiments of this application, by determining the specific types of redundant nodes and first irrelevant nodes, nodes in the fusion tracing graph are effectively deleted based on the determined redundant nodes and first irrelevant nodes, thereby reducing the data volume of the fusion tracing graph.

[0218] Continue to refer to Figure 12 In some embodiments, the second irrelevant node in the target tracing graph and the edge corresponding to the second irrelevant node include:

[0219] At least one of the following: a redirect node and its corresponding edge, a jump operation node and its corresponding edge, and a benign node and its corresponding edge.

[0220] In this embodiment, during actual execution, the redirection node and its corresponding edge, as well as the jump operation node and its corresponding edge, in the access request can be merged using the compression function F6.

[0221] The compression function F6 can retain only the root node and affected nodes that are relevant to the attack.

[0222] Benign nodes can be merged using the compression function F7.

[0223] Benign nodes are those that do not participate in attacks.

[0224] The behavior of benign nodes follows certain patterns.

[0225] The compression function F7 can reduce redundancy associated with file input or output operations.

[0226] According to the multi-source fusion log compression method for anomaly detection provided in the embodiments of this application, by determining the type of the second irrelevant node, the second irrelevant node can be accurately screened from the fusion tracing graph, and multiple second irrelevant nodes can be merged, effectively reducing the complexity of the fusion tracing graph, enabling attack detection personnel to focus on the potential attack paths of the target tracing graph, and improving detection efficiency.

[0227] Continue to refer to Figure 12 In some embodiments, the repeated nodes and the edges corresponding to the repeated nodes in the target tracing graph may include:

[0228] The target node and the edge corresponding to the target node that match the node corresponding to the local file operation in the node corresponding to the file download event, as well as the multiple edges between the first node and the second node in the fusion traceability graph.

[0229] In this embodiment, the target node is the same node in the node corresponding to the file download event as the node corresponding to the local file operation.

[0230] The first node is any node in the fusion source graph.

[0231] The second node is the node connected to the first node in the fusion tracing graph.

[0232] In actual execution, the file download events in the application log can be matched with the local file events in the system audit log using the compression function F9 to reduce duplicate nodes.

[0233] The compression function F10 can be used to retain one edge between two nodes, and the information of other edges can be merged into the retained edge. For the same operation, a count can be performed.

[0234] According to the multi-source fusion log compression method for anomaly detection provided in the embodiments of this application, by determining the type of duplicate nodes, duplicate nodes in the fusion traceability graph can be quickly found, improving the fusion efficiency of duplicate nodes, reducing the impact of duplicate nodes and redundant edges, optimizing the scale and structure of the target traceability graph, thereby improving the accuracy and efficiency of subsequent anomaly detection based on the target traceability graph.

[0235] The multi-source fusion log compression method for anomaly detection provided in this application can be executed by a multi-source fusion log compression device for anomaly detection. This application uses an example of a multi-source fusion log compression device for anomaly detection executing the multi-source fusion log compression method for anomaly detection to illustrate the multi-source fusion log compression device for anomaly detection provided in this application.

[0236] This application also provides a multi-source fusion log compression device for anomaly detection.

[0237] like Figure 14 As shown, the multi-source fusion log compression device for anomaly detection includes: a first processing module 1410, a second processing module 1420, a third processing module 1430, and a fourth processing module 1440.

[0238] The first processing module 1410 is used to generate an audit tracing graph corresponding to the system audit log, an application tracing graph corresponding to the application log, and a domain name tracing graph corresponding to the domain name system log based on the system audit log corresponding to the electronic device, the application log corresponding to the target application in the electronic device, and the domain name system log corresponding to the electronic device; the nodes in each tracing graph are used to represent the entities included in the logs corresponding to the tracing graph, and the edges in each tracing graph are used to represent the interaction relationships between the entities.

[0239] The second processing module 1420 is used to merge the domain name origination graph into the application origination graph based on the domain name nodes in the domain name origination graph to obtain a sub-fused origination graph.

[0240] The third processing module 1430 is used to merge the audit source map into the sub-fusion source map based on the event nodes in the audit source map to obtain the fusion source map;

[0241] The fourth processing module 1440 is used for anomaly detection based on the fused traceability graph.

[0242] According to the multi-source fusion log compression device for anomaly detection provided in the embodiments of this application, system audit logs, application logs and domain name system logs are acquired, and audit traceability graphs, application traceability graphs and domain name traceability graphs are generated respectively. By fusing the audit traceability graph, application traceability graph and domain name traceability graph, a richer traceability graph is generated, which alleviates the problems of semantic gap and dependency explosion, and provides a clearer path for attack detection.

[0243] In some embodiments, the second processing module 1420 may also be used for:

[0244] Match the domain name nodes in the application source map with the domain name nodes in the domain source map, and then merge the matched domain name nodes in the application source map with the domain name nodes in the domain source map.

[0245] Add the Internet Protocol address nodes corresponding to the domain name nodes in the domain name origin graph to the application origin graph to obtain the sub-fusion origin graph.

[0246] In some embodiments, the third processing module 1430 can also be used for:

[0247] The event nodes in the audit source map are matched with the event nodes in the sub-fusion source map, and the event nodes in the matched audit source map are merged with the event nodes in the sub-fusion source map to obtain the fusion source map.

[0248] In some embodiments, the third processing module 1430 can also be used for:

[0249] Match the event nodes in the audit source map with the event nodes in the sub-fusion source map, and then fuse the event nodes in the matched audit source map with the event nodes in the sub-fusion source map to obtain the first fusion source map.

[0250] Extract the paths corresponding to file download events and malicious domain access events from the first fusion source map to obtain a new first fusion source map;

[0251] Based on the paths corresponding to file download events and malicious domain access events, a second fusion tracing diagram is obtained.

[0252] Based on the new first fusion source map and the second fusion source map, a fusion source map is obtained.

[0253] In some embodiments, the fourth processing module 1440 can also be used for:

[0254] The fused source map is compressed to obtain the target source map;

[0255] Handle abnormal events based on the target source graph.

[0256] In some embodiments, the fourth processing module 1440 can also be used for:

[0257] Delete redundant nodes and their corresponding edges, as well as the first irrelevant node and its corresponding edge, from the target source graph.

[0258] and / or;

[0259] Merge the second irrelevant node and the edges corresponding to the second irrelevant node in the target source graph;

[0260] and / or;

[0261] Merge duplicate nodes and their corresponding edges in the target source graph to obtain the target source graph.

[0262] The multi-source fusion log compression device for anomaly detection in this application embodiment can be an electronic device or a component within an electronic device, such as an integrated circuit or a chip. The electronic device can be a terminal or other devices besides a terminal. For example, the electronic device can be a mobile phone, tablet computer, laptop computer, PDA, in-vehicle electronic device, mobile internet device (MID), augmented reality (AR) / virtual reality (VR) device, robot, wearable device, ultra-mobile personal computer (UMPC), netbook, or personal digital assistant (PDA), etc. It can also be a server, network attached storage (NAS), personal computer (PC), television (TV), ATM, or self-service machine, etc. This application embodiment does not specifically limit the specific type of device.

[0263] The multi-source fusion log compression device for anomaly detection in this application embodiment can be a device with an operating system. This operating system can be Android, iOS, or other possible operating systems; this application embodiment does not specifically limit it.

[0264] The multi-source fusion log compression device for anomaly detection provided in this application embodiment can achieve… Figures 1 to 13 The various processes implemented in the method implementation examples will not be described again here to avoid repetition.

[0265] In some embodiments, such as Figure 15 As shown, this application embodiment also provides an electronic device 1500, including a processor 1501, a memory 1502, and a computer program stored on the memory 1502 and executable on the processor 1501. When the program is executed by the processor 1501, it implements the various processes of the above-described multi-source fusion log compression method embodiment for anomaly detection and achieves the same technical effect. To avoid repetition, it will not be described again here.

[0266] It should be noted that the electronic devices in the embodiments of this application include the mobile electronic devices and non-mobile electronic devices described above.

[0267] This application also provides a non-transitory computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it implements the various processes of the above-described multi-source fusion log compression method embodiment for anomaly detection and achieves the same technical effect. To avoid repetition, it will not be described again here.

[0268] The processor is the processor in the electronic device described in the above embodiments. The readable storage medium includes computer-readable storage media, such as computer read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk.

[0269] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described multi-source fusion log compression method for anomaly detection.

[0270] The processor is the processor in the electronic device described in the above embodiments. The readable storage medium includes computer-readable storage media, such as computer read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk.

[0271] This application embodiment also provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run programs or instructions to implement the various processes of the above-described multi-source fusion log compression method embodiment for anomaly detection, and can achieve the same technical effect. To avoid repetition, it will not be described again here.

[0272] It should be understood that the chip mentioned in the embodiments of this application may also be referred to as a system-on-a-chip, system chip, chip system, or system-on-a-chip, etc.

[0273] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element. Furthermore, it should be noted that the scope of the methods and apparatuses in the embodiments of this application is not limited to performing functions in the order shown or discussed, but may also include performing functions substantially simultaneously or in the reverse order, depending on the functions involved. For example, the described methods may be performed in a different order than described, and various steps may be added, omitted, or combined. Additionally, features described with reference to certain examples may be combined in other examples.

[0274] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the related technology, can be embodied in the form of a computer software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of this application.

[0275] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of this application without departing from the spirit and scope of the claims, and all of these forms are within the protection scope of this application.

[0276] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "illustrative embodiment," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of this application. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0277] Although embodiments of this application have been shown and described, those skilled in the art will understand that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of this application, the scope of which is defined by the claims and their equivalents.

Claims

1. A multi-source fusion log compression method for anomaly detection, characterized in that, include: Based on the system audit logs corresponding to the electronic device, the application logs corresponding to the target application in the electronic device, and the domain name system logs corresponding to the electronic device, an audit tracing graph corresponding to the system audit logs, an application tracing graph corresponding to the application logs, and a domain name tracing graph corresponding to the domain name system logs are generated; the nodes in each tracing graph are used to represent the entities included in the logs corresponding to the tracing graph, and the edges in each tracing graph are used to represent the interaction relationships between the entities; Based on the domain name nodes in the application origination graph, the domain name origination graph is merged into the application origination graph to obtain a sub-merged origination graph; Based on the event nodes in the audit source graph, the audit source graph is merged into the sub-fused source graph to obtain the fused source graph; Anomaly detection is performed based on the fused source map; The step of fusing the domain name origination graph into the application origination graph based on the domain name nodes in the application origination graph to obtain a sub-fused origination graph includes: The domain name nodes in the application origination graph are matched with the domain name nodes in the domain origination graph, and the matched domain name nodes in the application origination graph are merged with the domain name nodes in the domain origination graph. Add the Internet Protocol address node corresponding to the domain name node in the domain name origination diagram to the application origination diagram to obtain the sub-fusion origination diagram; Matching event nodes in the audit tracing graph with event nodes in the sub-fusion tracing graph, and then fusing the matched event nodes in the audit tracing graph with the event nodes in the sub-fusion tracing graph to obtain the fusion tracing graph, includes: The event nodes in the audit tracing graph are matched with the event nodes in the sub-fusion tracing graph, and the matched event nodes in the audit tracing graph are fused with the event nodes in the sub-fusion tracing graph to obtain the first fusion tracing graph. Extract the path corresponding to the file download event and the path corresponding to the malicious domain name access event from the first fused source map to obtain a new first fused source map; Based on the path corresponding to the file download event and the path corresponding to the malicious domain access event, a second fusion tracing map is obtained; The fusion source map is obtained based on the new first fusion source map and the second fusion source map.

2. The multi-source fusion log compression method for anomaly detection according to claim 1, characterized in that, The process of fusing the audit source map into the sub-fused source map based on the event nodes in the audit source map to obtain the fused source map includes: The event nodes in the audit tracing graph are matched with the event nodes in the sub-fusion tracing graph, and the matched event nodes in the audit tracing graph are merged with the event nodes in the sub-fusion tracing graph to obtain the fusion tracing graph.

3. The multi-source fusion log compression method for anomaly detection according to any one of claims 1-2, characterized in that, The anomaly detection based on the fused source map includes: The fused source map is compressed to obtain the target source map; The anomaly is processed based on the target source map.

4. The multi-source fusion log compression method for anomaly detection according to claim 3, characterized in that, The step of compressing the fused source map to obtain the target source map includes: Delete redundant nodes and edges corresponding to the redundant nodes, as well as the first irrelevant node and its corresponding edges, from the target tracing graph. and / or; Merge the second irrelevant node and the edge corresponding to the second irrelevant node in the target source graph; and / or; The target source graph is obtained by merging the duplicate nodes and the edges corresponding to the duplicate nodes in the target source graph.

5. The multi-source fusion log compression method for anomaly detection according to claim 4, characterized in that, The redundant nodes and their corresponding edges, as well as the first unrelated node and its corresponding edges, include: The following are included: nodes unrelated to the file download event and the edges corresponding to those nodes; at least one domain name node and the edges corresponding to each domain name node between the node corresponding to the file download event and the target file corresponding to the file download event; read operation nodes and the edges corresponding to those read operation nodes; delete operation nodes and the edges corresponding to those delete operation nodes; and external nodes that do not interact with the local file system and the edges corresponding to those external nodes.

6. The multi-source fusion log compression method for anomaly detection according to claim 4, characterized in that, The second irrelevant node and the edge corresponding to the second irrelevant node in the target tracing graph include: The attack node is a node that does not participate in the attack. The attack node is a node that is not involved in the attack.

7. The multi-source fusion log compression method for anomaly detection according to claim 4, characterized in that, The repeated nodes and the edges corresponding to the repeated nodes in the target tracing graph include: The target node that matches the node corresponding to the local file operation in the node corresponding to the file download event, the edge corresponding to the target node, and the multiple edges between the first node and the second node in the fused tracing graph.

8. The multi-source fusion log compression method for anomaly detection according to any one of claims 1-2, characterized in that, The process of generating an audit origination diagram corresponding to the system audit log, an application origination diagram corresponding to the application log, and a domain name origination diagram corresponding to the domain name system log based on the system audit log corresponding to the electronic device, the application log corresponding to the target application in the electronic device, and the domain name system log corresponding to the electronic device includes: Extract at least one entity from the system audit log, the application log, and the domain name system log, as well as the relationships between the entities; Based on the event nodes and Internet Protocol address nodes in the system audit log, and the relationship between the event nodes and Internet Protocol address nodes, the audit tracing graph is constructed. Based on the event nodes and domain nodes in the application logs, and the relationships between the event nodes and the domain nodes, the application tracing graph is constructed. Based on the domain name nodes and Internet Protocol address nodes in the Domain Name System log, and the association between the domain name nodes and the Internet Protocol addresses, the domain name origin graph is constructed.

9. A multi-source fusion log compression device for anomaly detection, suitable for control using the multi-source fusion log compression method for anomaly detection as described in any one of claims 1-8, characterized in that, include: The first processing module is used to generate an audit tracing graph corresponding to the system audit log, an application tracing graph corresponding to the application log, and a domain name tracing graph corresponding to the domain name system log based on the system audit log corresponding to the electronic device, the application log corresponding to the target application in the electronic device, and the domain name system log corresponding to the electronic device; the nodes in each tracing graph are used to represent the entities included in the logs corresponding to the tracing graph, and the edges in each tracing graph are used to represent the interaction relationships between the entities; The second processing module is used to merge the domain name tracing graph into the application tracing graph based on the domain name nodes in the application tracing graph to obtain a sub-fused tracing graph; The third processing module is used to merge the audit source map into the sub-fused source map based on the event nodes in the audit source map to obtain the fused source map; The fourth processing module is used to perform anomaly detection based on the fused source map; The step of fusing the domain name origination graph into the application origination graph based on the domain name nodes in the application origination graph to obtain a sub-fused origination graph includes: The domain name nodes in the application origination graph are matched with the domain name nodes in the domain origination graph, and the matched domain name nodes in the application origination graph are merged with the domain name nodes in the domain origination graph. Add the Internet Protocol address node corresponding to the domain name node in the domain name origination graph to the application origination graph to obtain the sub-fusion origination graph.

10. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the multi-source fusion log compression method for anomaly detection as described in any one of claims 1-8.

11. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the computer program implements the multi-source fusion log compression method for anomaly detection as described in any one of claims 1-8.

12. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the multi-source fusion log compression method for anomaly detection as described in any one of claims 1-8.

Citation Information

Patent Citations

  • Traceability graph construction method and device, computer equipment, storage medium and product

    CN116915455A