A multi-detection mode situation awareness method, system, terminal and storage medium
By dynamically selecting detection servers from a group of devices and utilizing system resources for situational awareness, the problems of excessive resource consumption and long response times in existing technologies are solved, achieving efficient data analysis and situational awareness.
Patent Information
- Application Number
- CN202411576443.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-06
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2044-11-06
AI Technical Summary
In existing technologies, setting up an additional detection server consumes system resources, and a single device cannot meet the complex data analysis needs for situational awareness, resulting in excessively long response times.
By dynamically selecting the detection server in the device group, utilizing the idle device resources in the system for situational awareness, adopting single-device detection mode or distributed detection mode, determining the detection mode based on device priority, quantity and number of data groups, and realizing data transfer and analysis.
It improves system resource utilization, shortens response time, and improves the efficiency and accuracy of data analysis.
Smart Images

Figure CN119561722B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of situational awareness technology, and in particular to a situational awareness method, system, terminal, and storage medium with multiple detection modes. Background Technology
[0002] Situational awareness involves perceiving environmental elements within a specific time and space, understanding their meaning, and ultimately predicting their future development. Utilizing big data analytics, situational awareness can classify, statistically analyze, and comprehensively examine attack events, threat alerts, and attack sources, enhancing the ability to detect, identify, analyze, and respond to security threats from a global perspective. Current situational awareness methods primarily involve setting up a dedicated detection server to identify abnormal devices and attack behaviors by analyzing data collected from various devices. However, setting up an additional detection server consumes significant system resources, and situational awareness on a single device is insufficient to meet the complex data analysis requirements, easily leading to excessively long response times. Therefore, existing technologies require further improvement and development. Summary of the Invention
[0003] The technical problem to be solved by the present invention is to provide a situational awareness method, system, terminal and storage medium with multiple detection modes, in order to address the above-mentioned defects of the prior art. The aim is to solve the problems that setting up an additional detection server in the prior art will consume certain system resources, and that a single device performing situational awareness is difficult to meet the complex data analysis needs and is prone to excessively long response time.
[0004] The technical solution adopted by this invention to solve the problem is as follows:
[0005] In a first aspect, embodiments of the present invention provide a situational awareness method with multiple detection modes, the method comprising:
[0006] Obtain the priority of each device in the group of devices to be detected, and determine the detection server for data transfer from the devices that meet the priority requirements;
[0007] The detection server acquires the collected data from each device, classifies the collected data from each device into several data groups, and determines the current detection mode based on at least one of the following: the number of devices that meet the priority requirements, the total number of devices, and the number of data groups.
[0008] If a distributed detection mode is currently adopted, several servers are determined for distributed detection based on the priority requirements of each device, and each data component is sent to each server for data analysis.
[0009] All data analysis results are obtained through the detection server, and abnormal devices are identified based on all data analysis results to obtain situational awareness results.
[0010] In one implementation, determining the current detection mode based on at least one of the following: the number of devices meeting priority requirements, the total number of devices, and the number of data groups, includes:
[0011] If the number of devices that meet the priority requirements is one, then the single-device detection mode is currently used.
[0012] If the total number of devices is less than the preset number, the single-device detection mode will be used.
[0013] If the number of data groups is less than the preset number, the current mode is single-device detection.
[0014] In one implementation, determining the current detection mode based on at least one of the following: the number of devices meeting priority requirements, the total number of devices, and the number of data groups, includes:
[0015] If the number of devices that meet the priority requirements is greater than one, and the total number of devices is greater than or equal to the preset number, and the number of data groups is greater than or equal to the preset number of groups, then the distributed detection mode is currently adopted.
[0016] In one implementation, determining the detection server for data relay from devices that meet priority requirements includes:
[0017] If the number of devices that meet the priority requirements is greater than one, then sort all devices that meet the priority requirements according to their network number.
[0018] The detection server used for data relay is determined based on the sorting results of the network numbers.
[0019] In one implementation, determining the detection server for data transfer based on the sorting results includes:
[0020] Obtain the status data corresponding to each device that meets the priority requirements; wherein, the status data includes at least one of computing resources and reliability.
[0021] The detection server used for data relay is determined based on the sorting results of the network numbers and the status data of all devices.
[0022] In one implementation, the step of determining several servers for distributed detection based on devices that meet priority requirements, and sending each data component to each server for data analysis, includes:
[0023] Obtain the computing resources of each device that meets the priority requirements, and determine several servers for distributed detection based on the devices whose computing resources are higher than the preset resource requirements;
[0024] A data group distribution strategy is determined based on all the data groups and all the server's computing resources;
[0025] According to the data component distribution strategy, each data component is sent to the corresponding server for data analysis.
[0026] In one embodiment, the method further includes:
[0027] The difficulty of data analysis is determined based on all the data sets described.
[0028] Based on the difficulty of the data analysis, determine whether to activate the backup data analysis node; wherein, the backup data analysis node is a super device and / or the cloud.
[0029] Secondly, embodiments of the present invention also provide a situational awareness system with multiple detection modes, the system comprising:
[0030] The detection server identifies devices that meet priority requirements from the group of devices to be detected and uses them for data transfer.
[0031] The data collection server is used to collect data from devices in the device group to be sensed that do not meet the priority requirements.
[0032] The detection server is also used to acquire the collected data from all devices, classify the collected data from each device to obtain several data groups, and determine the current detection mode based on at least one of the following: the number of devices that meet the priority requirements, the total number of devices, and the number of data groups.
[0033] If a distributed detection mode is currently adopted, several servers are determined for distributed detection based on the priority requirements of each device, and each data component is sent to each server for data analysis.
[0034] All data analysis results are obtained through the detection server, and abnormal devices are identified based on all data analysis results to obtain situational awareness results.
[0035] Thirdly, embodiments of the present invention also provide a terminal, the terminal including a memory and one or more processors; the memory stores one or more programs; the programs include instructions for executing the situational awareness method with multiple detection modes as described above; the processor is used to execute the programs.
[0036] Fourthly, embodiments of the present invention also provide a computer-readable storage medium having stored thereon a plurality of instructions adapted to be loaded and executed by a processor to implement the steps of the situational awareness method with multiple detection modes as described above.
[0037] The beneficial effects of this invention are as follows: In this embodiment, one or more devices are dynamically selected from a device group to perform analysis services, eliminating the need for a dedicated additional detection server. This allows for full utilization of idle device resources in the system for situational awareness, improving system resource utilization. Furthermore, in distributed detection mode, multiple devices collaborate to complete data analysis tasks, effectively improving response speed. Attached Figure Description
[0038] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0039] Figure 1 This is a flowchart illustrating the situational awareness method with multiple detection modes provided in an embodiment of the present invention.
[0040] Figure 2 This is a schematic diagram illustrating the relationship between device priority and function in the distributed detection mode provided in this embodiment of the invention.
[0041] Figure 3 This is a schematic diagram illustrating the relationship between device priority and function in the single-device detection mode provided in this embodiment of the invention.
[0042] Figure 4 This is a schematic diagram illustrating the selection process for different detection modes provided in the embodiments of the present invention.
[0043] Figure 5 This is a schematic diagram of the function confirmation process based on network number provided in an embodiment of the present invention.
[0044] Figure 6 This is a schematic diagram of the device initialization process provided in an embodiment of the present invention.
[0045] Figure 7 This is a schematic diagram of the data acquisition instruction arrangement process provided in the embodiments of the present invention.
[0046] Figure 8 This is a schematic diagram of data integration provided in an embodiment of the present invention.
[0047] Figure 9 This is a schematic diagram of data distribution provided in an embodiment of the present invention.
[0048] Figure 10 This is a schematic diagram of data reception and detection under the distributed detection mode provided in the embodiment of the present invention.
[0049] Figure 11 This is a schematic diagram of the composition of the situational awareness system with multiple detection modes provided in an embodiment of the present invention.
[0050] Figure 12 This is a schematic diagram illustrating the interaction between the agent, the detection server, and the distributed detection server provided in this embodiment of the invention.
[0051] Figure 13 This is a schematic diagram of the internal modules of the agent provided in an embodiment of the present invention.
[0052] Figure 14 This is a schematic diagram of the initialization process of the agent provided in an embodiment of the present invention.
[0053] Figure 15 This is a schematic diagram of the internal modules of the detection server provided in an embodiment of the present invention.
[0054] Figure 16 This is a schematic diagram illustrating the initialization process of devices providing different functional services according to embodiments of the present invention.
[0055] Figure 17 This is a schematic diagram of the module of the terminal provided in an embodiment of the present invention. Detailed Implementation
[0056] This invention discloses a situational awareness method, system, terminal, and storage medium with multiple detection modes. To make the objectives, technical solutions, and effects of this invention clearer and more explicit, the invention is further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only for explaining the invention and are not intended to limit the invention.
[0057] To address the aforementioned shortcomings of existing technologies, this invention provides a situational awareness method with multiple detection modes, such as... Figure 1 As shown, the method specifically includes:
[0058] Step S100: Obtain the priority of each device in the device group to be sensed, and determine the detection server for data transfer from the devices that meet the priority requirements;
[0059] Step S200: Obtain the collected data from each device through the detection server, classify the collected data from each device to obtain several data groups, and determine the current detection mode based on at least one of the following: the number of devices that meet the priority requirements, the total number of devices, and the number of data groups.
[0060] Step S300: If a distributed detection mode is currently used, then determine several servers for distributed detection based on the priority requirements of each device, and send each data component to each server for data analysis.
[0061] Step S400: Obtain all data analysis results through the detection server, and determine abnormal devices based on all data analysis results to obtain situational awareness results.
[0062] Specifically, a specific group of devices is first defined within the system as the group to be monitored. This group contains a series of network devices, each of which can be considered a service; different types of devices provide different types of services. Within this group, different devices may have different priorities, which are related to their performance. In practical applications, devices meeting specific priority requirements are selected from this group. If the number of such devices is greater than one, it indicates that multiple devices have high performance. One of these is selected as the detection server for data relay, performing routing functions, i.e., collecting and distributing data. The detection server issues collection instructions to each device. Each device collects local or system data according to the received instructions and reports the collected data to the detection server. The detection server receives the collected data from each device and classifies all the collected data according to specific rules, resulting in multiple data groups. The appropriate detection mode is determined by comprehensively considering the number of devices meeting the priority requirements, the total number of devices, and the number of data groups. This could be a single-device detection mode or a distributed detection mode. In the distributed detection mode, each data group is distributed to multiple servers for data analysis. The detection server waits for and collects all data analysis results returned by other servers, using this information to identify which devices in the network may be abnormal. Finally, it analyzes the network status and / or potential problems through the identified abnormal devices, thus obtaining situational awareness results. In short, this embodiment separates data collection and data analysis tasks. Ordinary devices, i.e., agents, perform the collection service, only responsible for collection and not containing analysis logic, minimizing resource overhead. Then, each agent delivers data to the detection server for analysis via a distributed soft bus. In distributed detection mode, the detection server distributes data requiring timely processing to multiple servers for analysis via the distributed soft bus to ensure response time. Furthermore, the technical solution of this embodiment can be used in conjunction with the HarmonyOS system.
[0063] For example, a group of devices with the highest priority and a priority level higher than a preset level can be selected from the group of devices to be detected, and a detection server can be determined from this group. The functions of the detection server are: generating and issuing instructions, and performing threat detection on the data reported by the agent. Priority can be divided into three categories: low, medium, and high. Low-priority devices have weak performance and only receive response data, without participating in detection; medium-priority devices are general devices that can perform distributed data processing; high-priority devices are usually high-performance devices that can process all data independently, and can be further subdivided if necessary. This embodiment limits the tasks such as issuing instructions, receiving and collecting data, data relay, and data analysis to only devices that meet specific priority conditions through preset levels, thereby avoiding situations where device performance does not match the task. If the priority is classified as low, medium, and high, then only devices with a priority higher than low priority can perform data analysis tasks, for example, medium-priority and high-priority devices can perform data analysis tasks.
[0064] In one implementation, determining the current detection mode based on at least one of the following: the number of devices meeting priority requirements, the total number of devices, and the number of data groups, includes:
[0065] If the number of devices that meet the priority requirements is one, then the single-device detection mode is currently used.
[0066] If the total number of devices is less than the preset number, the single-device detection mode will be used.
[0067] If the number of data groups is less than the preset number, the current mode is single-device detection.
[0068] If the number of devices that meet the priority requirements is greater than one, and the total number of devices is greater than or equal to the preset number, and the number of data groups is greater than or equal to the preset number of groups, then the distributed detection mode is currently adopted.
[0069] Specifically, if no device in the network meets the priority requirements (e.g., all devices in the network have low priority), detection is not possible. If multiple devices in the network meet the priority requirements and have the same priority, it means that these devices can all perform data reception and data analysis tasks. If only one device in the network meets the priority requirements (e.g., only one high-priority device), all data is sent to this device, i.e., a single-device detection mode is adopted, where this device performs data relay and data analysis tasks.
[0070] like Figure 2As shown, devices in a network can be categorized into different operating models. When multiple devices in the network meet priority requirements, the detection task is shared by the services of these devices, which can be described as a distributed detection mode. Figure 3 As shown, if there is only one device in the network that meets the priority requirements, the service of that device will undertake all the detection tasks, i.e., a single-device detection mode is adopted. Furthermore, if the number of devices in the network is too small, or the number of valid data groups after data packetization is too small, then a distributed detection mode is unnecessary, and a single-device detection mode can be used.
[0071] In addition to considering equipment priority, it is also necessary to further consider the total number of devices and the number of data groups after data classification to comprehensively determine the appropriate detection mode. For example... Figure 4 As shown, in single-device detection mode, the detection server caches the first received user, user group, environment variable, and scheduled task data for persistent detection. In distributed detection mode, when there are more than N devices (at least 3) in the subnet and there are devices capable of performing detection services, distributed detection begins. The detection server groups the first received data, for example, based on data source, acquisition method, data performance, data type, and data value. Multiple data groups may ultimately be generated. A group is considered valid if it contains more than N (at least 3) data items; otherwise, it is considered invalid, and invalid groups are not subject to distributed detection. Furthermore, when a new device joins or a device goes offline, the service function initialization and detection data initialization processes can be restarted.
[0072] In one implementation, determining the detection server for data relay from devices that meet priority requirements includes:
[0073] If the number of devices that meet the priority requirements is greater than one, then sort all devices that meet the priority requirements according to their network number.
[0074] The detection server used for data relay is determined based on the sorting results of the network numbers.
[0075] Specifically, Figure 5The process for confirming functional roles is demonstrated as follows: The services of devices within a subnet (the group of devices to be detected) are grouped according to priority. When a device meets the priority requirements, the service role of each device is determined. The highest-priority group of devices is selected and sorted by network ID. The device at the top priority can perform data relay services, acting as the detection server. Other devices connect to this device's service to upload local probe data and receive distributed computing data. If only one device meets the priority requirements, that device is responsible for all functions, i.e., a single-device detection mode is used. If multiple devices meet the priority requirements, a distributed detection mode is used. Each server used for distributed detection determines the data type to be detected by each device and sends the corresponding type of probe data to each device. Figure 6 The initialization process for different functional services is shown.
[0076] Furthermore, the step of determining the detection server used for data transfer based on the sorting results includes:
[0077] Obtain the status data corresponding to each device that meets the priority requirements; wherein, the status data includes at least one of computing resources and reliability.
[0078] The detection server used for data relay is determined based on the sorting results of the network numbers and the status data of all devices.
[0079] Specifically, in addition to comparing network numbers, the status data of all devices that meet the priority requirements can also be compared, such as comparing indicators such as computing resources, reliability, and service priority, and finally a suitable device can be selected as the detection server for data relay.
[0080] For example, a pre-defined function election algorithm is used to: when the device status data contains multiple data types, pre-determine the weight value corresponding to each data type, and determine the vote value for each device by weighting the weight values and the status data. Finally, based on the vote values of each device, select one device to serve as the detection server.
[0081] In one implementation, obtaining the collected data from each device through the detection server includes:
[0082] The detection server issues operation instructions to the other devices according to the calculation task, and obtains the reported data generated by the other devices in response to the operation instructions.
[0083] Based on the reported data, update operation instructions are issued to the remaining devices, and update reporting data generated by the remaining devices in response to the update operation instructions is obtained;
[0084] Determine whether each of the reported update data meets the computing requirements corresponding to the computing task. If not, use the reported update data as the reported data and continue to execute the step of issuing update operation instructions to the remaining devices based on each of the reported data until the computing requirements corresponding to the computing task are met.
[0085] Specifically, the operation instructions for each device can include acquisition instructions. Based on these instructions, each device can execute a corresponding data acquisition task or a local computation task. Acquisition instructions can specify the data probes used by each device. Different data probes can collect different types of data. For example, system information probes are used to collect information about the current system operating environment; performance probes are used to collect information related to system resource utilization, such as CPU, memory, and disk information; and network probes are used to collect network packet information. Since each device may have a different operating system, the data probes that each device can support may also differ. In practical applications, the detection server receives computation tasks, decomposes these tasks through an orchestration module, orchestrates several basic operation instructions based on the decomposition results, and issues acquisition instructions to each device. Each operation instruction includes several instructions and their processing order. After receiving the operation instructions, if the instruction is an acquisition instruction, each device parses it to obtain data probes, collects local or system data through these probes, and reports the collected data to the detection server. In this embodiment, the detection server will orchestrate the acquisition capabilities of each device, judge the integrity and quality of the current acquisition data based on the data reported by each device, and dynamically re-arrange the instructions, issuing new acquisition instructions to the other devices, thereby realizing complex acquisition logic and ensuring that the final collected data can meet the computing needs of specific computing tasks.
[0086] For example, Figure 7The four arithmetic operations in the detection module represent a complex calculation instruction received by the server, essentially a computational task. When the server receives this instruction, the orchestration module breaks it down into several sub-instructions. These sub-instructions are then re-arranged based on the decomposition results, and this process is repeated multiple times to generate multiple instructions. The final operation instruction is generated based on the orchestrated instructions and their processing order and distributed to the corresponding device. The device can then understand the rules for data processing and / or data acquisition based on the received operation instruction, thus correctly completing the corresponding task. Furthermore, the detection server orchestrates and analyzes formulas based on the four arithmetic operations. These operations themselves can reflect pre-defined calculation rules, which can be specifically formulated by security administrators or operations personnel. In practical applications, each device possesses multiple detection capabilities; therefore, the detection server needs to orchestrate and issue instructions to specify which detection capability is currently being used and the order in which these capabilities are used.
[0087] In one implementation, the decomposition method for the computational task includes:
[0088] Based on the computation task, obtain the operator and the priority of each operator;
[0089] The computation task is decomposed according to each of the operators and their priorities to obtain several sub-computation tasks and a task processing order.
[0090] The task decomposition result is determined based on each of the sub-computation tasks and the order in which the tasks are processed.
[0091] Specifically, the computation task in this embodiment can be an expression containing multiple operators, such as a data expression or a logical expression. To correctly complete the computation task, the detection server first needs to identify all operators in the expression, such as addition, subtraction, multiplication, and division operators, and determine the priority of each operator based on learned operational rules; for example, multiplication and division usually have higher priority than addition and subtraction. Furthermore, the priority of each operator can be presented through preorder, inorder, and subsequent expressions.
[0092] In practical applications, the detection server decomposes the calculation task based on all identified operators and their priorities, thereby generating operation instructions for the remaining devices. The task decomposition process is as follows: First, the highest-priority operator in the expression is identified, and its corresponding local operation is extracted to obtain a subexpression. If all operators in the expression have the same priority, the local operation corresponding to the first operator is extracted based on its order, resulting in a subexpression. A new expression is then formed based on the remaining operators and the calculation results of the subexpressions. The process of identifying the highest-priority operator in the expression continues until the expression contains only a basic operation or a single number.
[0093] For example, such as Figure 7 As shown, assuming the calculation task is 4.5 + 1.43 ÷ 1.3 - 1.23, we can break it down according to operator precedence, resulting in "1.43 ÷ 1.3" as the first subexpression. The result of this first subexpression is 1.1, forming the new expression "4.5 + 1.1 - 1.23". Then, we can further break it down according to operator order, resulting in "4.5 + 1.1" as the second subexpression. The result of this second subexpression is 5.6, forming the new expression "5.6 - 1.23". This expression is a basic operation and does not require further breakdown. Based on this expression, the final calculation result is 4.37.
[0094] In one implementation, the classification of the collected data from each device to obtain several data groups includes:
[0095] Each piece of equipment is grouped according to its operating conditions and business functions, resulting in several equipment groups.
[0096] Then, for the data collected from each device group, the data is grouped according to data category and / or data attribute to obtain several data groups.
[0097] Specifically, in this embodiment, for the data collected by each device, devices with similar operating conditions and services can first be grouped together. The data collected by devices in the same group are highly comparable, making it easier to identify abnormal data. Then, the data collected by devices in the same group are further grouped according to data category and / or data attribute in order to identify abnormal data.
[0098] In one implementation, the step of determining several servers for distributed detection based on the priority requirements of each device, and sending each data component to each server for data analysis, includes:
[0099] Obtain the computing resources of each device that meets the priority requirements, and determine several servers for distributed detection based on the devices whose computing resources are higher than the preset resource requirements;
[0100] A data group distribution strategy is determined based on all the data groups and all the server's computing resources;
[0101] According to the data component distribution strategy, each data component is sent to the corresponding server for data analysis.
[0102] Specifically, such as Figure 8 and Figure 9 As shown, the system in this embodiment can adopt a distributed analysis architecture, which provides the capabilities of data integration and data distribution. Data integration refers to extracting the same type of data from various devices and putting them together for analysis, which can identify anomalies that deviate from the general data. Data distribution refers to the analysis service sending various types of data to different devices for analysis, which can reasonably allocate group resources and avoid overloading any one device. In general, the agent in this embodiment uses a simplified design, containing only data collection functions and simple logic. The order of detection and data collection calls is handled by the device executing the detection service, enabling the agent to be compatible with more devices. The detection service adopts a priority and distributed design. Priority allows high-performance devices to do more work, while distribution splits tasks, allowing devices with lower performance to also perform detection collaboratively, thus adapting to more application scenarios.
[0103] In one implementation, the method further includes:
[0104] If a single-device detection mode is currently used, the detection server performs horizontal and vertical analysis on the data collected from each device to obtain the final data analysis results. Abnormal devices are identified based on the final data analysis results. Horizontal analysis involves comparing and analyzing data from different devices in the same data group, while vertical analysis involves comparing and analyzing different data from the same device.
[0105] If a distributed detection mode is currently adopted, several servers used for distributed detection perform horizontal analysis based on their respective received data sets; the detection servers perform vertical analysis based on the data collected by each server, and the final data analysis result is obtained by combining the horizontal analysis results returned by each server; abnormal devices are identified based on the final data analysis result; among them, horizontal analysis involves comparing and analyzing the data of different devices in the same data set; vertical analysis involves comparing and analyzing different data of the same device.
[0106] Specifically, the detection server can identify abnormal data through horizontal and vertical analysis. Horizontal analysis refers to the device performing the analysis service analyzing data within a group to identify abnormal data within the same group, thereby identifying abnormal devices. Vertical analysis refers to comprehensively analyzing all types of collected data from a particular device to identify abnormal data and determine whether the device is abnormal.
[0107] In one implementation, the detection server first performs single-device detection after receiving a certain type of data; then it checks whether there is a valid group. If so, the data or information is stored for subsequent data analysis.
[0108] In one implementation, such as Figure 10 As shown, in distributed detection mode, the device used for data analysis receives and stores data of the corresponding type; it determines whether it is the first piece of data of that type; if so, it starts timing. After receiving data from all devices or reaching a predetermined time, it detects all data according to groups, identifies data with significant differences based on different data types, and thus obtains abnormal data. Finally, it broadcasts the results and clears the data.
[0109] In one implementation, in addition to performing horizontal and vertical analysis on the data, the single-device detection mode and / or distributed detection mode can also perform one or more of the following detection methods: persistent detection, privilege escalation detection, lateral movement detection, and abnormal state detection.
[0110] Persistent detection is used to compare newly received data with previously cached data, identify data changes based on the comparison results, and identify abnormal data based on these changes. For example, in single-device detection mode, it is necessary to cache the previous user, user group, environment variable, and scheduled task data, and compare the new data with the previous cached data to calculate whether there are any additions; in distributed detection mode, it is necessary to compare the scheduled tasks, privileged users, etc. of this group of devices to calculate whether there are any duplicates.
[0111] Privilege escalation detection is used to determine whether there are abnormal permission changes and / or abnormal processes based on newly received data (including permission data and / or process data), and to identify abnormal data based on the judgment results. For example, in single-device detection mode, it is necessary to detect system calls (syscalls) related to permission changes in real time to determine whether they are abnormal permission changes. Detection points include: inconsistent permissions before and after the process, child process having higher permissions than parent process, and low-privilege process modifying privileged file permissions. In distributed detection mode, it is necessary to compare the permissions of the same processes in this group of devices, calculate whether a privileged process appears in a low-privilege process, and perform normalization processing when there are multiple instances of the same process in the process information.
[0112] Lateral movement detection is used to examine process data based on process blacklists and whitelists to detect the presence of illegal processes and identify abnormal data based on the detection results. For example, in single-device detection mode, it is necessary to examine process data based on process blacklists and whitelists to detect the presence of illegal processes.
[0113] Anomaly detection: This is used to detect non-system processes with abnormal permissions based on process data, and / or to detect abnormal resource usage based on system performance data, and / or to check the consistency of network connections within the same group, and to identify abnormal data based on the detection results. For example, in single-device detection mode, it is necessary to detect non-system processes with abnormal permissions based on process data, and to detect prolonged high CPU (computation data), I / O (read / write data), memory, network, and hard drive usage based on system performance data; in distributed detection mode, it is necessary to check the consistency of network connections within the same group, and if they are inconsistent, to identify whether an anomaly exists.
[0114] In one implementation, the method further includes:
[0115] The difficulty of data analysis is determined based on all the data sets described.
[0116] Based on the difficulty of the data analysis, determine whether to activate the backup data analysis node; wherein, the backup data analysis node is a super device and / or the cloud.
[0117] Specifically, in order to ensure timely response to various computing tasks, this embodiment can also add backup data analysis nodes when it is necessary to process complex and time-consuming tasks, and forward the data group to the edge device or the cloud to provide the system's scalability.
[0118] In one implementation, the method further includes:
[0119] The business processes of malfunctioning devices are transferred to other normal devices, thereby ensuring the safe operation of the devices' business processes.
[0120] Specifically, abnormal devices (also known as risky devices) need to report abnormal device data and send this data to all devices in the subnet. Each device will mark the abnormal device (i.e., add it to the abnormal device group) and respond accordingly. To ensure uninterrupted service response, risk management of abnormal devices is required, transferring services from the abnormal device to other normal devices to ensure the safe and uninterrupted operation of services. After the risk is eliminated, the original service can be restored to the original device for processing. In practical applications, when anomalies are repeatedly triggered, only abnormal device data is reported, and abnormal device data is no longer sent to all devices in the subnet.
[0121] In one implementation, the response to a faulty device includes:
[0122] Operations such as degrading, restoring, and restricting specific execution functions of abnormal devices;
[0123] Business flows from malfunctioning devices are transferred to trusted devices.
[0124] A faulty device is prohibited from performing distributed task scheduling on other devices.
[0125] Abnormal devices are prohibited from initiating IPC (Inter-Process Communication) with other devices;
[0126] Abnormal device recovery: Remove restrictions on the abnormal device. The device sends recovery data to all devices in the subnet. The devices in the subnet remove the device from the abnormal device group and add it as a new device, executing the add process.
[0127] Possible future technology optimizations:
[0128] Improved distributed capabilities; improved function election algorithm to prevent elected devices from failing to meet minimum resource requirements; improved task allocation algorithm to better utilize group resources; improved device grouping algorithm to enhance the accuracy of distributed detection; improved response module capabilities to ensure the secure operation of device services.
[0129] Functionality Enhancement: Building a unified system on the existing foundation requires not only improving existing functions but also enhancing functionality across all aspects—prevention, response, and post-incident tracing—to create a comprehensive defense system that adheres to the PDCA (Total Quality Management) cycle and achieves a closed-loop security solution. Simultaneously, machine learning and artificial intelligence are integrated to assist data analysis and improve the ability to defend against unknown risks. Regarding the unified system construction, all product functions are designed based on the OpenSCAP (an open-source project) framework, encompassing standards and tools such as SCAP, CVE, CPE, and OVAL. This provides capabilities such as data collection, security baselines, and vulnerability patch checking, and has been extensively practiced with Red Hat (a professional certification in system administration and maintenance), ensuring abundant community resources. A unified system avoids the current situation where most security platforms use separate products for each function, minimizing resource consumption and maximizing functionality utilization.
[0130] Possible future technological variations:
[0131] Ecosystem co-construction includes, but is not limited to, knowledge base co-construction and capability co-construction. Regarding knowledge base co-construction, based on OpenSCAP specifications such as OVAL, CVE, and CPE, the community can expand the definition of security baselines and vulnerability patches, write security check items, and modify and adapt existing definition files on Linux systems. Regarding capability co-construction, based on the orchestration module's vertical orchestration of instructions and horizontal orchestration of devices, the community can extend existing threat detection and tracing capabilities by writing orchestration rules and adding data collection methods. It can also leverage the flexibility of the orchestration module to develop and design new situational awareness capabilities or systems.
[0132] Based on the above embodiments, the present invention also provides a situational awareness system with multiple detection modes, such as... Figure 11 As shown, the system includes:
[0133] The detection server identifies devices that meet priority requirements from the group of devices to be detected and uses them for data transfer.
[0134] The data collection server is used to collect data from devices in the device group to be sensed that do not meet the priority requirements.
[0135] The detection server is also used to acquire the collected data from all devices, classify the collected data from each device to obtain several data groups, and determine the current detection mode based on at least one of the following: the number of devices that meet the priority requirements, the total number of devices, and the number of data groups.
[0136] If a distributed detection mode is currently adopted, several servers are determined for distributed detection based on the priority requirements of each device, and each data component is sent to each server for data analysis.
[0137] All data analysis results are obtained through the detection server, and abnormal devices are identified based on all data analysis results to obtain situational awareness results.
[0138] Specifically, in this embodiment, the system framework layer is divided into two parts: a data acquisition server and a detection server. The data acquisition server is an agent solely responsible for collecting system data. The detection server is responsible for orchestrating the acquisition commands from the agent and managing and detecting the collected data. The agent and the detection server communicate via IPC (inter-process communication), while the detection servers communicate with each other via a distributed soft bus. The detection server carries a basic detection module, enabling real-time threat detection and providing collected data externally through an orchestration module, thus achieving richer situational awareness capabilities.
[0139] Figure 12This demonstrates a data acquisition and analysis separation architecture. The device performing the data acquisition service only has multiple acquisition capabilities, is context-free and stateless, and has low resource consumption. How to acquire and analyze data is handled by the device performing the analysis service. The detection server can orchestrate acquisition capabilities to implement complex acquisition logic.
[0140] Furthermore, the functional design goals of the system's framework layer include:
[0141] Data acquisition refers to the collection and analysis of data generated during system operation. Data acquisition can be implemented in several ways, including collecting and reporting system information, receiving and executing commands, and proactively responding to threats. Examples include collecting system information, monitoring file changes, monitoring network probes (syscall calls), and actively responding to threats.
[0142] Threat identification involves discovering threats within the system and issuing alerts. This is achieved through methods such as analyzing reported data for potential risks and issuing alerts. Examples include generating data collection rules and issuing collection commands, analyzing data from single devices, performing joint analysis of data from multiple devices, managing collected data, coordinating data detection across multiple devices, and issuing alerts and responses to detected threats.
[0143] In one implementation, the overall threat detection and response framework is developed using C / C++ based on OpenHarmony, and the service process starts automatically at system boot. It utilizes the OpenScap standard, integrating widely used security tools and knowledge bases such as CVE, CPE, OVAL, and CIS. The agent's collection probes are implemented using the open-source OVAL project, with modifications and cross-compilation by the ovaldi collector. Performance data and network probe calls are implemented using HiPerf (a performance sampling and analysis tool). The agent and detection server interact via inter-process communication, and the detection services communicate with each other via a distributed soft bus.
[0144] In one implementation, the agent's function is to collect and report system data from the device and receive and execute instructions from the detection server. The reported data can be self-reported or reported based on service instructions; instructions can be collection instructions or response instructions. Data collection methods are divided into periodic collection and real-time collection. Periodic collection involves the detection service periodically sending fixed collection instructions, while real-time collection involves the probe actively reporting data. Figure 13 As shown, the agent includes, but is not limited to: a communication module, a management module, a data acquisition probe module, a command module, and a response module.
[0145] Communication module: mainly communicates with the detection service, including receiving instructions and reporting data.
[0146] Management module: This module mainly manages the functions and resource usage of the agent, including configuration management, function activation management, and resource restrictions.
[0147] The acquisition probe module is mainly used to collect information from the device, including system information probes, performance probes, and network probes. It collects information such as processes, ports, users (groups), scheduled tasks, environment variables, file attributes, system resource usage, and network data from the device.
[0148] Instruction module: mainly responsible for instruction parsing, instruction distribution and execution, including instruction acquisition and instruction response.
[0149] The response module mainly executes various response actions based on the instructions, including degrading privileges, blocking the network, restricting resources, and switching services.
[0150] like Figure 14 As shown, after the agent starts, it initializes and loads the acquisition module according to the configuration. After establishing a connection with the detection server, it enters a waiting loop, waiting for instructions from the detection server and acquiring data.
[0151] In one implementation, when the detection server runs, it first performs single-device detection on the received data, and then performs distributed device detection. For example... Figure 15 As shown, the detection server includes a communication module, a data management module, an instruction management module, an orchestration module, and a detection module. Regarding the generation process of periodic acquisition instructions, the orchestration module loads the periodic acquisition instruction flow and calls the interface of the instruction management module to generate instructions. For example... Figure 16 As shown, both the detection server and the proxy need to be initialized during the initial application phase.
[0152] Communication module: mainly used for communication with other devices, including command sending and receiving, and data sending and receiving;
[0153] Data management module: mainly responsible for grouping distributed data and / or device grouping, as well as routing data.
[0154] Command Management Module: This module mainly handles command generation and issuance, including command acquisition and command response.
[0155] Orchestration module: mainly task decomposition, instruction orchestration, and instruction invocation, including but not limited to: task parsing, vertical orchestration, horizontal orchestration, and instruction invocation.
[0156] The detection module mainly detects whether there are anomalies based on different data and different rules, including single-device detection and distributed detection.
[0157] In one implementation, the orchestration module can interact with the security baseline module, vulnerability module, patch module, and weak password module. These four modules can be set up within the detection server or on an external device, thereby saving the computing resources of the detection server.
[0158] Furthermore, the security baseline module is defined using OVAL and generates a format readable by the orchestration module, which is then sent to the orchestration module. The orchestration module orchestrates and issues commands to the baseline, collecting data through the OVAL format acquisition probes provided by the agent. The agent then returns the collected data to the security baseline module for security baseline compliance checks.
[0159] Vulnerability Module: By leveraging the capabilities of the security baseline module, the data that needs to be collected and detected for vulnerabilities can be compiled into a baseline format, and then compliance checks can be performed through the security baseline. Based on the check results, it can be calculated whether the vulnerability exists.
[0160] Patch module: Patches and vulnerabilities are similar in scenario, only the checkpoints are different.
[0161] Weak password module: The collection command is sent to the agent through the orchestration module. After the agent obtains the collected data, it uses a weak password dictionary to brute-force the password. If the brute-force attack is successful, it means that a weak password exists.
[0162] Based on the above embodiments, the present invention also provides a terminal, the principle block diagram of which can be as follows: Figure 17 As shown, the terminal includes a processor, memory, network interface, and display screen connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides the environment for the operation of the operating system and computer programs in the non-volatile storage media. The network interface is used to communicate with external terminals via a network connection. When the computer program is executed by the processor, it implements a multi-detection mode situational awareness method. The display screen can be an LCD screen or an e-ink screen.
[0163] Those skilled in the art will understand that Figure 17 The schematic diagram shown is only a partial structural diagram related to the present invention and does not constitute a limitation on the terminal to which the present invention is applied. A specific terminal may include more or fewer components than shown in the figure, or combine certain components, or have different component arrangements.
[0164] In one implementation, the terminal's memory stores one or more programs, and these programs are configured to be executed by one or more processors, and the programs contain instructions for performing a situational awareness method with multiple detection modes.
[0165] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided by this invention can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and RAMbus dynamic RAM (RDRAM), etc.
[0166] In summary, this invention discloses a situational awareness method, system, terminal, and storage medium with multiple detection modes. By acquiring the priority of each device in the group of devices to be sensed, a detection server for data relay is determined from the devices that meet the priority requirements. The detection server acquires the collected data from each device, classifies the collected data into several data groups, and determines the current detection mode based on at least one of the following: the number of devices meeting the priority requirements, the total number of devices, and the number of data groups. If a distributed detection mode is currently used, several servers for distributed detection are determined based on the devices that meet the priority requirements, and each data group is sent to its respective server for data analysis. All data analysis results are acquired by the detection server, and abnormal devices are identified based on these results, yielding the situational awareness result. This invention dynamically selects one or more devices to perform analysis services within the system, eliminating the need for a dedicated additional detection server. This fully utilizes idle device resources in the system for situational awareness, improving system resource utilization. Furthermore, in the distributed detection mode, multiple devices collaborate to complete data analysis tasks, effectively improving response speed.
[0167] It should be understood that the application of the present invention is not limited to the examples above. Those skilled in the art can make improvements or modifications based on the above description, and all such improvements and modifications should fall within the protection scope of the appended claims.
Claims
1. A situational awareness method with multiple detection modes, characterized in that, The method includes: Obtain the priority of each device in the group of devices to be detected, and determine the detection server for data transfer from the devices that meet the priority requirements; The detection server acquires data from each device, categorizes the data into several data groups, and determines the current detection mode based on at least one of the following: the number of devices meeting the priority requirement, the total number of devices, and the number of data groups. Specifically: if the number of devices meeting the priority requirement is one, a single-device detection mode is used; if the total number of devices is less than a preset number, a single-device detection mode is used; if the number of data groups is less than a preset number, a single-device detection mode is used; if the number of devices meeting the priority requirement is greater than one, the total number of devices is greater than or equal to a preset number, and the number of data groups is greater than or equal to a preset number, a distributed detection mode is used. If a distributed detection mode is currently adopted, several servers are determined for distributed detection based on the priority requirements of each device, and each data component is sent to each server for data analysis. All data analysis results are obtained through the detection server, and abnormal devices are identified based on all data analysis results to obtain situational awareness results.
2. The situational awareness method with multiple detection modes according to claim 1, characterized in that, The step of determining the detection server for data relay from devices that meet priority requirements includes: If the number of devices that meet the priority requirements is greater than one, then sort all devices that meet the priority requirements according to their network number. The detection server used for data relay is determined based on the sorting results of the network numbers.
3. The situational awareness method with multiple detection modes according to claim 2, characterized in that, The step of determining the detection server for data transfer based on the sorting results includes: Obtain the status data corresponding to each device that meets the priority requirements; wherein, the status data includes at least one of computing resources and reliability. The detection server used for data relay is determined based on the sorting results of the network numbers and the status data of all devices.
4. The situational awareness method with multiple detection modes according to claim 1, characterized in that, The step of determining several servers for distributed detection based on the priority requirements of each device, and sending each data component to each server for data analysis, includes: Obtain the computing resources of each device that meets the priority requirements, and determine several servers for distributed detection based on the devices whose computing resources are higher than the preset resource requirements; A data group distribution strategy is determined based on all the data groups and all the server's computing resources; According to the data component distribution strategy, each data component is sent to the corresponding server for data analysis.
5. The situational awareness method with multiple detection modes according to claim 4, characterized in that, The method further includes: The difficulty of data analysis is determined based on all the data sets described. Based on the difficulty of the data analysis, determine whether to activate the backup data analysis node; wherein, the backup data analysis node is a super device and / or the cloud.
6. A situational awareness system with multiple detection modes, characterized in that, The system includes: The detection server identifies devices that meet priority requirements from the group of devices to be detected and uses them for data transfer. The data collection server is used to collect data from devices in the device group to be sensed that do not meet the priority requirements. The detection server is also used to acquire the collected data from all devices, classify the collected data from each device into several data groups, and determine the current detection mode based on at least one of the following: the number of devices that meet the priority requirements, the total number of devices, and the number of data groups. This includes: if the number of devices that meet the priority requirements is one, then a single-device detection mode is used; if the total number of devices is less than a preset number, then a single-device detection mode is used; if the number of data groups is less than a preset number of groups, then a single-device detection mode is used; if the number of devices that meet the priority requirements is greater than one, and the total number of devices is greater than or equal to a preset number, and the number of data groups is greater than or equal to a preset number of groups, then a distributed detection mode is used. If a distributed detection mode is currently adopted, several servers are determined for distributed detection based on the priority requirements of each device, and each data component is sent to each server for data analysis. All data analysis results are obtained through the detection server, and abnormal devices are identified based on all data analysis results to obtain situational awareness results.
7. A terminal, characterized in that, The terminal includes a memory and one or more processors; the memory stores one or more programs; the programs contain instructions for executing the situational awareness method with multiple detection modes as described in any one of claims 1-5; the processors are used to execute the programs.
8. A computer-readable storage medium storing a plurality of instructions, characterized in that, The instructions are applicable to be loaded and executed by a processor to implement the steps of the situational awareness method with multiple detection modes as described in any one of claims 1-5.
Citation Information
Patent Citations
Data acquisition method and system thereof
CN106936618A
Security protection method and system for power terminal
WO2023216641A1