A method and system for graduated warnings of safety information

By using a layered protection model and a dynamic security patrol layer, combined with access authorization codes and probes, the IP addresses of devices without access authorization codes are identified and marked, solving the problem of high false alarm rates in traditional security defense models and achieving efficient security threat identification and defense.

CN119520114BActive Publication Date: 2025-10-24GUIZHOU POWER GRID CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411685395.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-22
Publication Date
2025-10-24
Estimated Expiration
2044-11-22

AI Technical Summary

Technical Problem

Traditional security defense models have a high false alarm rate, resulting in a large number of false security alerts.

Method used

Establish a layered protection model, which includes a dynamic security inspection layer, an early warning protection layer, a security assessment layer, and an attack tracing layer. Combined with access authorization codes and probes, it dynamically monitors and analyzes network threats, identifies and marks the IP addresses of devices without access authorization codes, and establishes an access blacklist.

Benefits of technology

It reduces the false alarm rate of security incidents, improves the accuracy of security threat assessment and processing efficiency, provides real-time dynamic feedback and defense measures, and adapts to ever-changing network threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119520114B_ABST
    Figure CN119520114B_ABST
Patent Text Reader

Abstract

The application discloses a kind of security information hierarchical warning method and system, it is related to data model technical field, method includes: constructing hierarchical protection model, including security equipment;Ensure physical layer security by dynamic security module;Early warning module carries out intrusion detection;Security rating module determines attack level;Build overall situation awareness layer and attack traceability layer, obtain attack source information and execute security protection and counterattack.The system provides different levels of warning, reduces false positive rate, improves processing efficiency and security.Hierarchical warning system real-time, dynamic feedback, quickly identify and handle problems, constantly monitor network security state, dynamically adjust security policy to adapt to network threats.The application helps to respond to network security events in time, accurately, improves overall security protection capability, simplifies security management process, provides strong support for modern network security protection.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data models, and in particular to a security information hierarchical warning method and system. BACKGROUND

[0002] A hierarchical warning system helps users distinguish the severity of problems by providing different levels of warnings, so as to take corresponding measures. The design of such a system aims to improve the efficiency and effectiveness of problem handling and prevent more serious consequences due to improper handling. The implementation of a hierarchical warning system usually relies on data received from sensors or other monitoring systems. After analysis and processing, the data triggers a warning of a corresponding level according to the set threshold or condition. For example, the EICAS system receives signals from engine and aircraft system sensors, and completes data processing and display through an embedded real-time operating system.

[0003] In the field of network security, due to the large number of security points monitored by the server, some security warning modules are prone to have a defect of excessively high warning sensitivity threshold, so there are a large number of security warning false alarms, which leads to the defect of high false alarm rate of the traditional security defense model. SUMMARY

[0004] In view of the above problems, the present application is proposed.

[0005] Therefore, the technical problem solved by the present application is how to solve the problem of high false alarm rate of the traditional security defense model.

[0006] To solve the above technical problems, the present application provides the following technical solutions.

[0007] In a first aspect, the embodiments of the present application provide a security information hierarchical warning method, comprising:

[0008] Establishing a hierarchical protection model and incorporating security devices;

[0009] A dynamic security patrol layer is constructed through the dynamic security module of the hierarchical protection model, the IP address of each security device is received, and the security protection of the physical layer is ensured through access authorization codes and probe probes;

[0010] An early warning protection layer is constructed based on the early warning module of the hierarchical protection model, access request information is received, and intrusion detection is performed;

[0011] The dynamic security patrol layer and the early warning protection layer form a response connection;

[0012] A security evaluation layer is established based on the security rating module of the hierarchical protection model; through the vulnerability scanning result, the security device and its firewall level connected with the IP address are determined, so as to determine the hacking level of the IP address;

[0013] establishing a response connection between the early warning protection layer and the security assessment layer;

[0014] constructing an overall situation awareness layer and an attack tracing layer through the security assessment layer to obtain attack source information;

[0015] performing security protection and counterattack based on the attack source information of the attack tracing layer.

[0016] As a preferred solution of the security information hierarchical warning method, wherein:

[0017] The dynamic security patrol layer constructed by the dynamic security module of the hierarchical protection model comprises:

[0018] receiving the IP address of each security device through the dynamic security patrol layer: calling through the IP address of each security device to realize security protection of the physical layer and prevent unauthorized malicious devices from accessing or modifying data;

[0019] sending an access authorization code and a probe probe to each IP address: establishing an encrypted communication link through a data chain and deploying a probe probe on the communication link to detect and respond to network attacks;

[0020] using the data flow of the probe probe security device;

[0021] screening the data flow direction based on the access authorization code.

[0022] As a preferred solution of the security information hierarchical warning method, wherein:

[0023] The dynamic security patrol layer constructed by the dynamic security module of the hierarchical protection model further comprises:

[0024] receiving an access request through the dynamic security patrol layer and parsing the access authorization code in the access request;

[0025] determining whether the access authorization code in the access request matches the access authorization code of the corresponding IP address;

[0026] If the access authorization code in the access request does not match the access authorization code of the corresponding IP address, the access request information is passed to the early warning protection layer;

[0027] If the access authorization code in the access request matches the access authorization code of the corresponding IP address, the data flow of the probe probe security device is returned.

[0028] As a preferred solution of the security information hierarchical warning method, wherein:

[0029] The early warning module based on the hierarchical protection model constructs the early warning protection layer, comprising:

[0030] The access request information is received by the early warning protection layer, and the access request information is subjected to intrusion detection;

[0031] Based on the intrusion detection, it is determined whether the device corresponding to the access request has a security threat;

[0032] If the device corresponding to the access request does not have a security threat, the IP of the device corresponding to the access request is fed back to the security log;

[0033] If the device corresponding to the access request has a security threat, the IP address is further subjected to vulnerability scanning on the local data stream;

[0034] The result of the vulnerability scanning is sent to the security evaluation layer.

[0035] As a preferred solution of the security information grading warning method, wherein:

[0036] The security evaluation layer established by the security rating module based on the layered protection model includes:

[0037] Based on the result of the vulnerability scanning by the security evaluation layer, a security device with which the IP address has established contact is determined;

[0038] A security device with which the IP address has established contact is selected, and the firewall level of the security device is determined;

[0039] A security device with which the IP address has established contact is returned to be selected until all the security devices are selected;

[0040] The firewall level with the highest firewall level is selected as the compromise level of the IP address.

[0041] As a preferred solution of the security information grading warning method, wherein:

[0042] The attack source information includes:

[0043] All data streams of the firewall level corresponding to the compromise level are called, a data stream is selected, the data stream is analyzed based on the covert channel screening algorithm, and the IP address of the device without access authorization code is marked; a data stream is returned to be selected until all the data streams are selected;

[0044] The data stream is analyzed based on the covert channel screening algorithm, and the data stream is analyzed based on the covert channel screening algorithm.

[0045] It is determined whether the data stream is static information;

[0046] If the data stream is static information, source code analysis and taint analysis are performed on the data stream;

[0047] If the data stream is not static information, it is determined that the data stream is a real-time interactive data stream;

[0048] performing tracking analysis and fuzzing analysis on the data stream;

[0049] determining data transmission characteristics of the data stream based on the analysis results;

[0050] The IP address of the device without access authorization code includes:

[0051] calling data transmission rules;

[0052] Based on the data transmission characteristics of the data stream and the data classification of the data transmission rules, it is judged whether the data stream has interactive information of abnormal data type transmission;

[0053] If the data stream has interactive information of abnormal data type transmission, mark the IP address of the device outside the layered protection model;

[0054] If the data stream does not have interactive information of abnormal data type transmission, it is judged whether the data stream has unmarked interactive information;

[0055] If the data stream has unmarked interactive information, mark the IP address of the device outside the layered protection model;

[0056] If the data stream does not have unmarked interactive information, end the marking of the IP address of the device without access authorization code.

[0057] As a preferred scheme of the security information hierarchical warning method, wherein:

[0058] The attack source information based on the attack tracing layer is used to perform security protection and counterattack, including:

[0059] Receive all the marked device IP addresses, establish an access blacklist, and include all the marked device IP addresses in the access blacklist.

[0060] In a second aspect, the embodiments of the present application provide a security information hierarchical warning system, comprising:

[0061] The layered protection model establishment module is used to establish a layered protection model and include security devices;

[0062] The dynamic security patrol layer construction module is used to construct a dynamic security patrol layer through a dynamic security module of the layered protection model, receive the IP address of each security device, and ensure the security protection of the physical layer through access authorization codes and probe probes;

[0063] The early warning protection layer construction module is used to construct an early warning protection layer based on a warning module of the layered protection model, receive access request information and perform intrusion detection;

[0064] The first response contact establishing module is used for forming a response contact between the dynamic security patrol layer and the early warning protection layer.

[0065] The security evaluation layer constructing module is used for establishing a security evaluation layer based on a security rating module of the hierarchical protection model; the security equipment and its firewall level connected with the IP address are determined through the vulnerability scanning result, so that the attack level of the IP address is determined.

[0066] The second response contact establishing module is used for establishing a response contact between the early warning protection layer and the security evaluation layer.

[0067] The attack source information obtaining module is used for constructing a whole situation awareness layer and an attack tracing layer through the security evaluation layer, and obtaining attack source information.

[0068] The security protection and counterattack module is used for performing security protection and counterattack based on the attack source information of the attack tracing layer.

[0069] In a third aspect, an embodiment of the present application provides a computing device, comprising:

[0070] a memory and a processor;

[0071] The memory is used for storing computer executable instructions, and the processor is used for executing the computer executable instructions; when the one or more programs are executed by the one or more processors, the one or more processors implement the security information hierarchical warning method as described in any embodiment of the present application.

[0072] In a fourth aspect, an embodiment of the present application provides a computer readable storage medium, which stores computer executable instructions; when the computer executable instructions are executed by a processor, the security information hierarchical warning method is implemented.

[0073] The present application has the following beneficial effects: the present application provides a hierarchical warning system of different levels to help identify and solve problems in time, reduces the false positive rate of security events, and improves the processing efficiency and security. The hierarchical warning system can provide real-time and dynamic feedback to help the system quickly identify and handle problems. The network security state is constantly monitored through the hierarchical warning system, and the security strategy is dynamically adjusted to adapt to the changing network threats. BRIEF DESCRIPTION OF DRAWINGS

[0074] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced as follows: obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0075] Figure 1is the overall flowchart of the security information hierarchical warning method described in the first embodiment of the present application. DETAILED DESCRIPTION

[0076] In order to make the above objectives, features and advantages of the present application more apparent, the specific embodiments of the present application will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work should fall within the protection scope of the present application.

[0077] In the following description, a large number of specific details are set forth in order to facilitate a thorough understanding of the present application. However, the present application can also be implemented in other manners different from those described herein, and those skilled in the art can make similar generalizations without departing from the spirit and scope of the present application. Therefore, the present application is not limited to the specific embodiments disclosed below.

[0078] Secondly, the term "one embodiment" or "an embodiment" as used herein means that a specific feature, structure or characteristic described in the embodiment can be included in at least one implementation of the present application. The term "in one embodiment" appearing in different places in the specification does not mean the same embodiment, nor does it mean that the embodiments are mutually exclusive or alternative to each other.

[0079] Embodiment 1

[0080] Reference Figure 1 For the first embodiment of the present application, the embodiment provides a security information hierarchical warning method, comprising:

[0081] S1: Establish a hierarchical protection model and incorporate security devices;

[0082] S2: Construct a dynamic security patrol layer through the dynamic security module of the hierarchical protection model;

[0083] S3: Construct an early warning protection layer based on the early warning module of the hierarchical protection model;

[0084] S4: Form a response contact between the dynamic security patrol layer and the early warning protection layer.

[0085] S5: Establish a security evaluation layer based on the security rating module of the hierarchical protection model;

[0086] S6: Establish a response contact between the early warning protection layer and the security evaluation layer;

[0087] S7: Construct an overall situation awareness layer and an attack tracing layer through the security evaluation layer to obtain attack source information;

[0088] S8: Perform security protection and counterattack based on the attack source information of the attack tracing layer.

[0089] It should be noted that each security device is included in the hierarchical protection model to form a hierarchical protection model associated with the security device, thereby improving the comprehensiveness of the security protection of the hierarchical protection model.

[0090] In the embodiment of the present application, the step S2 of constructing the dynamic security patrol layer through the dynamic security module of the hierarchical protection model comprises:

[0091] The IP address of each security device is received through the dynamic security patrol layer: the IP address of each security device is called to realize the security protection of the physical layer and prevent unauthorized malicious devices from accessing or modifying data;

[0092] An access authorization code and a probe probe are sent to each IP address: an encrypted communication link is established through the data chain, and a probe probe is deployed on the communication link to detect and respond to network attacks;

[0093] It should be noted that the access authorization code has two functions, one of which is encryption and identity verification. The other function is to configure a firewall.

[0094] The data flow of the probe probe security device is utilized;

[0095] It should be noted that through the established data transmission encryption channel, the confidentiality and integrity of data transmission can be ensured, and the restriction of data flow can be realized. These data have classification characteristics, can be marked, and can be restricted and detected in flow direction.

[0096] The flow direction of the data flow is screened based on the access authorization code.

[0097] It should be noted that the dynamic security patrol layer as the first layer of the hierarchical protection model can preliminarily probe the security threat, and further prevent false positives of security vulnerabilities from the root. At the same time, the dynamic security patrol layer can interact with each security device, has high flexibility and adaptability, and can adapt to the changing security threat.

[0098] In the embodiment of the present application, the step S2 of constructing the dynamic security patrol layer through the dynamic security module of the hierarchical protection model further comprises:

[0099] The access request is received through the dynamic security patrol layer, and the access authorization code in the access request is parsed;

[0100] It should be noted that the access authorization code can help the system quickly identify potential illegal intrusion or threat. Through the access authorization code mechanism, the security risk can be reduced, and the success rate of security threat judgment can be improved.

[0101] Further, the defense level of the access authorization code can be linked with the security level of the firewall, and the access authorization code can be adapted to the actual performance of the security device.

[0102] determining whether the access authorization code in the access request matches the access authorization code corresponding to the IP address;

[0103] If the access authorization code in the access request does not match the access authorization code corresponding to the IP address, the access request information is passed to the early warning protection layer.

[0104] It should be noted that the early warning protection layer can take prompt action to control and mitigate the impact of the event once the dynamic security patrol layer detects a security event.

[0105] If the access authorization code in the access request matches the access authorization code corresponding to the IP address, the data stream using the probe probe security device is returned.

[0106] It should be noted that the dynamic security patrol layer continuously monitors the network security state and dynamically adjusts the security policy to adapt to the changing network threats. The dynamic adjustment process of the dynamic security patrol layer relies on real-time warning information to guide response measures.

[0107] In the embodiments of the present application, the early warning module based on the layered protection model in step S3 builds the early warning protection layer, which includes:

[0108] The access request information is received through the early warning protection layer, and the access request information is subjected to intrusion detection.

[0109] Specifically, the intrusion detection is mainly implemented through the access permission of the firewall. It can also be implemented through abnormal traffic monitoring.

[0110] Based on the intrusion detection, it is determined whether the device corresponding to the access request has a security threat.

[0111] If the device corresponding to the access request does not have a security threat, the IP of the device corresponding to the access request is fed back to the security log.

[0112] Specifically, the security log will count the access times of the device corresponding to the IP address.

[0113] If the device corresponding to the access request has a security threat, the data stream of the IP address in the local is further subjected to vulnerability scanning.

[0114] Specifically, local scanning collects data in real-time and transmits it to the central management system for analysis and remediation. By sending network queries to different ports, it analyzes which ports are open, closed, or filtered to identify potential security vulnerabilities and misconfigurations of services. It automatically probes the structure of web applications to discover security vulnerabilities such as SQL injection, XSS, and others. Using port scanning, network mapping, and service identification techniques, it detects known flaws and outdated network application versions throughout the network, including security vulnerabilities in devices such as routers, switches, and firewalls.

[0115] The results of the vulnerability scan are sent to the security assessment layer.

[0116] It should be noted that the early warning protection layer is not limited to intrusion detection, but also includes real-time monitoring and notification of abnormal behavior. This includes data aggregation and analysis from various sources such as network traffic logs, security events, and key performance indicators.

[0117] In the embodiments of the present application, the security assessment layer established by the security rating module based on the layered protection model in step S5 above includes:

[0118] Based on the results of the vulnerability scan, the security assessment layer determines the security devices with which the IP address has established contact;

[0119] Select one of the security devices that have established contact and determine the firewall level of that security device;

[0120] Specifically, the firewall levels of different security devices are different. When the IP address of the device with the attack has established communication contact with the security device, it can be determined that the security device has been compromised.

[0121] The highest firewall level among these security devices is the compromise level of the IP address. By checking the corresponding level of the firewall in the system, other temporary security vulnerabilities in the system can be discovered.

[0122] Return to select one of the security devices that have established contact until all security devices have been selected;

[0123] Select the highest firewall level as the compromise level of the IP address.

[0124] It should be noted that when abnormal behavior is detected, the security assessment layer not only provides real-time security warnings, but also serves as a basis for evaluating the maturity of the system's security engineering. By analyzing the efficiency and effectiveness of warning handling, the organization's security capabilities can be quantitatively evaluated to promote continuous improvement of security management.

[0125] In the embodiments of the present application, the attack source information obtained in step S7 above includes:

[0126] Call the corresponding firewall level of all data streams, select a data stream, based on the covert channel screening algorithm to analyze the data stream, mark the IP address of the device without access authorization code; return to select a data stream until all data streams are selected.

[0127] It should be noted that in a large-scale network environment, through data analysis, mining and intelligent deduction, the hierarchical warning system can accurately understand and quantify the current network space security situation. Using the hierarchical warning system structure, various attack events in the network space can be effectively detected, and the security elements causing the situation change can be traced back. It embodies the multi-dimensional and multi-level security protection concept. From basic early warning and counterattack, to multi-level comprehensive protection, to continuous improvement of system security engineering capability, and with the help of data analysis and intelligent deduction for security situation awareness and attack event tracing, these models and strategies together build a comprehensive, dynamic and intelligent network security defense system. This effectively improves the accuracy of security threat judgment and reduces the misjudgment rate.

[0128] In the embodiments of the present application, the above analysis of the data stream based on the covert channel screening algorithm includes:

[0129] Determine whether the data stream is static information;

[0130] It should be noted that attack events often pass through covert channels. Covert channels are abnormal communication paths in computer systems that may be used to transfer unauthorized information. Through data stream screening, such channels can be effectively identified and blocked, thereby preventing potential security risks.

[0131] Using the information flow model, strict data transmission rules can be set, such as data classification, labeling and flow direction restriction, to ensure that sensitive information can only be accessed by authorized subjects, greatly reducing the risk of information leakage.

[0132] If the data stream is static information, perform source code analysis and taint analysis on the data stream;

[0133] Specifically, static analysis focuses on the source code and static characteristics of the program, such as source code analysis and taint analysis.

[0134] Since the data stream monitors information interaction devices, information and three through data chains, the communication legality of information interaction devices can be determined through source code analysis and taint analysis.

[0135] If the data stream is not static information, determine that the data stream is real-time interactive data stream;

[0136] Specifically, dynamic analysis focuses on runtime state, including trace analysis and fuzz testing.

[0137] performing tracking analysis and fuzzing analysis on the data stream;

[0138] It should be noted that the tracking analysis and the fuzzing analysis can collect the analysis information through data transmission control, transmission channel control, and access object control, or monitor the amount of overall traffic.

[0139] Based on the analysis result, the data transmission feature of the data stream is determined.

[0140] Specifically, the data transmission feature is composed of a classification feature, a marking feature, and a flow direction feature.

[0141] For example, a certain data set does not belong to an SQL input item and does not have a queryable mark, but flows to an SQL database. In this case, the IP address of the sending device of the data set will be marked.

[0142] In another possible implementation, the data stream is parsed in the following manner: different probe scripts are transmitted to the suspected device through the data channel in the form of data packets. The probe traverses the database of the suspected device and returns the probe conclusion through the communication channel between the suspected device and the system.

[0143] In the embodiments of the present application, the IP address of the device without the access authorization code includes:

[0144] The data transmission rule is called;

[0145] Specifically, the common data transmission rules include the big-endian mode, the data type of transmission, the compatibility of the protocol and the corresponding access interface, the encryption rule, and the like.

[0146] Based on the data classification of the data transmission feature and the data transmission rule of the data stream, it is determined whether the data stream has abnormal data type transmission interaction information;

[0147] Specifically, since the data type of the transmission of the local database has specificity, an illegal connection can cause a data type error of the stored information. Based on the error, the data sending device can be traced back.

[0148] If the data stream has the abnormal data type transmission interaction information, the IP address of the device outside the layered protection model is marked;

[0149] If the data stream does not have the abnormal data type transmission interaction information, it is determined whether the data stream has unmarked interaction information;

[0150] If the data stream has the unmarked interaction information, the IP address of the device outside the layered protection model is marked;

[0151] Specifically, in some security protection systems, when there is unmarked data, it indicates that the sending device of the data stream does not have an access authorization code.

[0152] If the data stream does not have unmarked interaction information, the IP address of the device without an access authorization code is marked.

[0153] It should be noted that the assessment information of the security evaluation layer can build the overall situation awareness layer and the attack tracing layer. Through data analysis, mining and intelligent deduction, the hierarchical warning system can accurately understand and quantify the current security situation of the network space. This not only includes warning of existing threats, but also predicts the development trend of future security situation, providing strategic guidance for network security, thereby greatly reducing the false alarm rate of security risks. The overall situation awareness layer can effectively detect various attack events in the network space and trace the security elements that cause the situation to change. By providing different levels of warning help system, it can identify and solve problems in a timely manner, reducing the false alarm rate of security events, thereby improving processing efficiency and security. The hierarchical warning system can provide real-time and dynamic feedback to help the system quickly identify and handle problems. Through the hierarchical warning system, the network security state is constantly monitored, and dynamic adjustment of security strategies is implemented to adapt to the changing network threats.

[0154] It should be noted that the attack tracing layer can issue early warnings through the layered protection model, take preventive measures in advance, and effectively counterattack after being attacked.

[0155] In the embodiments of the present application, the security protection and counterattack based on the attack source information of the attack tracing layer in the above step S8 include:

[0156] Receive all the marked device IP addresses, establish an access blacklist, and include all the marked device IP addresses in the access blacklist.

[0157] It should be noted that the establishment of the blacklist can achieve the defense of the attack device. This ensures that the model can flexibly cope with various situations, from simple threats to complex and sustained attacks. This also improves the accuracy of security threat warnings and reduces the false alarm rate.

[0158] The above is an illustrative scheme of the security information hierarchical warning method of the present embodiment. It should be noted that the technical scheme of the security information hierarchical warning system belongs to the same concept as the technical scheme of the above security information hierarchical warning method. The technical scheme of the security information hierarchical warning system in the present embodiment is not described in detail, and the description of the technical scheme of the above security information hierarchical warning method can be referred to.

[0159] The security information hierarchical warning system in the present embodiment includes:

[0160] The hierarchical protection model establishing module is configured to establish a hierarchical protection model and incorporate the security device into the hierarchical protection model.

[0161] The dynamic security patrol layer constructing module is configured to construct a dynamic security patrol layer through a dynamic security module of the hierarchical protection model, receive an IP address of each security device, and ensure security protection of the physical layer through an access authorization code and a probe probe.

[0162] The early warning protection layer constructing module is configured to construct an early warning protection layer based on an early warning module of the hierarchical protection model, receive access request information, and perform intrusion detection.

[0163] The first response contact establishing module is configured to form a response contact between the dynamic security patrol layer and the early warning protection layer.

[0164] The security evaluation layer constructing module is configured to establish a security evaluation layer based on a security rating module of the hierarchical protection model, determine a security device and a firewall level thereof in contact with the IP address through a vulnerability scanning result, and thus determine a compromise level of the IP address.

[0165] The second response contact establishing module is configured to establish a response contact between the early warning protection layer and the security evaluation layer.

[0166] The attack source information obtaining module is configured to construct an overall situation awareness layer and an attack tracing layer through the security evaluation layer, and obtain attack source information.

[0167] The security protection and counterattack module is configured to perform security protection and counterattack based on the attack source information of the attack tracing layer.

[0168] The embodiment also provides a computing device suitable for the security information hierarchical warning method, and the computing device comprises:

[0169] The memory is configured to store computer executable instructions, and the processor is configured to execute the computer executable instructions to implement the security information hierarchical warning method proposed in the above embodiment.

[0170] The embodiment also provides a storage medium having a computer program stored thereon, and the program is executed by a processor to implement the security information hierarchical warning method proposed in the above embodiment.

[0171] The storage medium proposed in the embodiment and the security information hierarchical warning method proposed in the above embodiment belong to the same inventive concept, and the technical details not described in the embodiment can be referred to the above embodiment, and the embodiment has the same beneficial effects as the above embodiment.

[0172] It should be noted that the above examples are only used to illustrate the technical solutions of the present application but not limit the present application. Although the present application is described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present application can be modified or equivalently replaced, without departing from the spirit and scope of the technical solutions of the present application, which should be covered in the scope of the claims of the present application.

Claims

1. A method for graduated warning of safety information, characterized in that, The application relates to a layered protection model and security equipment. A dynamic security patrol layer is constructed through a dynamic security module of the layered protection model, IP addresses of each security equipment are received, and the security of a physical layer is ensured through access authorization codes and exploration probes; An early warning protection layer is constructed through an early warning module of the layered protection model, access request information is received, and intrusion detection is performed; The dynamic security patrol layer and the early warning protection layer are in response contact; A security evaluation layer is established through a security rating module of the layered protection model; the security equipment connected with the IP address and the firewall level of the security equipment are determined through a vulnerability scanning result, so that the attack level of the IP address is determined; The early warning protection layer and the security evaluation layer are in response contact; An overall situation awareness layer and an attack tracing layer are constructed through the security evaluation layer, and attack source information is obtained; Security protection and counterattacks are performed based on the attack source information of the attack tracing layer. The dynamic security patrol layer is constructed through the dynamic security module of the layered protection model, and the dynamic security patrol layer includes the following steps: The IP addresses of each security equipment are received through the dynamic security patrol layer; the security of the physical layer is ensured through the IP addresses of each security equipment; unauthorized malicious equipment is prevented from accessing or modifying data; Access authorization codes and exploration probes are sent to each IP address; an encrypted communication link is established through a data chain, and an exploration probe is deployed on the communication link to detect and respond to network attacks; Data streams of the exploration probe security equipment are utilized; Data stream directions are screened based on the access authorization codes; The dynamic security patrol layer constructed through the dynamic security module of the layered protection model further includes the following steps: Access requests are received through the dynamic security patrol layer, and access authorization codes in the access requests are analyzed; It is judged whether the access authorization codes in the access requests match the access authorization codes of the corresponding IP addresses; If the access authorization codes in the access requests do not match the access authorization codes of the corresponding IP addresses, the access request information is transmitted to the early warning protection layer; If the access authorization codes in the access requests match the access authorization codes of the corresponding IP addresses, the data streams of the exploration probe security equipment are returned. The early warning protection layer is constructed through the early warning module of the layered protection model, and the early warning protection layer includes the following steps:

2. The safety information hierarchical warning method of claim 1, wherein, Access request information is received through the early warning protection layer, and intrusion detection is performed on the access request information; It is judged whether the equipment corresponding to the access request has a security threat based on the intrusion detection; If the equipment corresponding to the access request does not have a security threat, the IP of the equipment is fed back to a security log; If the equipment corresponding to the access request has a security threat, a vulnerability scan is further performed on the data stream of the IP address in the local; The vulnerability scanning result is sent to the security evaluation layer. The security evaluation layer is established through the security rating module of the layered protection model, and the security evaluation layer includes the following steps:

3. The method of claim 2, wherein the security information classification is one of a plurality of security information classifications, and the security information classification is determined based on a security classification of the information and a security classification of the user. The security equipment connected with the IP address is determined through the security evaluation layer based on the vulnerability scanning result; A security device is selected, and the firewall level of the security device is determined; All security devices are selected until the selection of all security devices is completed; The firewall level with the highest firewall level is selected as the attack level of the IP address. ​ 4. The method of claim 3, wherein the security information classification is one of a plurality of security information classifications, and the security information classification is determined based on a security classification of the information and a security classification of the user. The acquisition of attack source information includes: Call all data streams of the firewall level corresponding to the penetration level, select a data stream, analyze the data stream based on the covert channel screening algorithm, and mark the IP address of the device without access authorization code; return to select a data stream until all data streams are selected; The analysis of the data stream based on the covert channel screening algorithm includes: Determine whether the data stream is static information; If the data stream is static information, perform source code analysis and taint analysis on the data stream; If the data stream is not static information, determine that the data stream is real-time interactive data stream; Perform tracking analysis and fuzzing analysis on the data stream; Based on the analysis result, determine the data transmission characteristics of the data stream; The marking of the IP address of the device without access authorization code includes: Call data transmission rules; Determine whether the data stream has abnormal data type transmission interaction information based on the data transmission characteristics of the data stream and the data classification of the data transmission rules; If the data stream has abnormal data type transmission interaction information, mark the IP address of the device outside the layered protection model; If the data stream does not have abnormal data type transmission interaction information, determine whether the data stream has unmarked interaction information; If the data stream has unmarked interaction information, mark the IP address of the device outside the layered protection model; If the data stream does not have unmarked interaction information, end the marking of the IP address of the device without access authorization code.

5. The method of claim 4, wherein the security information classification warning is provided in a form of a pop-up window. The security protection and counterattack based on the attack source information of the attack source layer includes: Receive all marked device IP addresses, establish an access blacklist, and include all marked device IP addresses in the access blacklist.

6. A system employing the security information hierarchical warning method according to any one of claims 1 to 5, characterized by It includes: A layered protection model establishment module for establishing a layered protection model and including security devices; A dynamic security patrol layer construction module for constructing a dynamic security patrol layer through a dynamic security module of the layered protection model, receiving an IP address of each security device, and ensuring the security protection of the physical layer through access authorization codes and probe probes; A pre-warning protection layer construction module for constructing a pre-warning protection layer based on a pre-warning module of the layered protection model, receiving access request information and performing intrusion detection; A first response contact establishment module for forming a response contact between the dynamic security patrol layer and the pre-warning protection layer; A security evaluation layer construction module for establishing a security evaluation layer based on a security rating module of the layered protection model; determine the security device and its firewall level associated with the IP address through the vulnerability scanning result, so as to determine the penetration level of the IP address; A second response contact establishment module for establishing a response contact between the pre-warning protection layer and the security evaluation layer; An attack source information acquisition module for constructing an overall situation awareness layer and an attack source layer through the security evaluation layer, and acquiring attack source information; A security protection and counterattack module for performing security protection and counterattack based on the attack source information of the attack source layer.

7. A computing device, comprising: a memory and a processor; The memory is configured to store computer-executable instructions, and the processor is configured to execute the computer-executable instructions, which, when executed by the processor, implement the steps of the safety information hierarchical warning method according to any one of claims 1 to 5.

8. A computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the steps of the safety information hierarchical warning method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Data security analysis method and system and readable storage medium

    CN115776411A

  • Detecting and preventing distributed data exfiltration attacks

    US20230153425A1