Xinchen cloud security operation and maintenance method and device
By collecting and associating security data from multiple platforms in the domestic IT innovation cloud, the problem of data silos has been solved, enabling efficient data retrieval, display, and protection for security operations and maintenance, and reducing the frequency of security incidents.
Patent Information
- Application Number
- CN202411777342.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-05
- Publication Date
- 2025-10-24
- Estimated Expiration
- 2044-12-05
AI Technical Summary
The data between various platforms in the Xinchuang Cloud are not interoperable, which results in security operations and maintenance having to constantly switch between multiple platforms to view, collect, and analyze data, reducing operation and maintenance efficiency and causing frequent security incidents.
Based on the characteristics of different types of data in the domestic cloud platform, security data from multiple platforms is collected in an adaptive manner, integrated into a data warehouse, and cross-platform association is performed based on organizational fields to achieve data interoperability and perform security operations and maintenance, including data retrieval, display, protection, alarm notification, and operation.
By sharing data, we can improve operational efficiency, reduce the frequency of security incidents, and enable one-click retrieval, holographic display, and automated security protection, thereby enhancing the data acquisition efficiency and security for operations and maintenance personnel.
Smart Images

Figure CN119561770B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of operation and maintenance, in particular to a cloud security operation and maintenance method and device. BACKGROUND
[0002] The cloud is a cloud platform independently developed based on CPU and operating system in the context of information technology application innovation. It coordinates the use of computing, storage, network, security, application support, information resources and other hardware and software resources, and provides trusted computing, network and storage capabilities by taking advantage of cloud computing virtualization, high reliability, high universality, high scalability and fast, elastic, on-demand self-service and other features.
[0003] Since the cloud includes the operation and maintenance platform of each security device and the management and control platform of different cloud service providers, the data between the platforms are not interconnected, forming a data island, which leads to the need to constantly switch between multiple platforms to view, collect and analyze data for the security operation and maintenance of the cloud, reducing the operation and maintenance efficiency and leading to frequent security incidents. SUMMARY
[0004] The embodiments of the present application provide a cloud security operation and maintenance method and device to solve the technical problem that the data between the platforms in the cloud are not interconnected, forming a data island, which leads to the need to constantly switch between multiple platforms to view, collect and analyze data for the security operation and maintenance of the cloud, reducing the operation and maintenance efficiency and leading to frequent security incidents.
[0005] In a first aspect, the embodiments of the present application provide a cloud security operation and maintenance method, comprising:
[0006] Based on the characteristics of different types of data in the cloud, the multi-platform security data in the cloud is collected in an adaptive manner;
[0007] The multi-platform security data is integrated into a data warehouse, and the security data in the data warehouse is cross-platform associated based on an organization field to obtain associated data;
[0008] Based on the associated data, security operation and maintenance is performed; the security operation and maintenance includes data retrieval, data display, security protection, alarm notification and security operation.
[0009] In one embodiment, the multi-platform security data in the cloud is collected in an adaptive manner based on the characteristics of different types of data in the cloud, comprising:
[0010] The log data and monitoring data of the hardware devices in the cloud are collected by using a search engine; the hardware devices include cloud security devices;
[0011] The attribute data and instance data of the cloud resource products in the cloud are collected by using an API interface;
[0012] Collecting attribute data and instance data of the cloud security product in the cloud through a crawler.
[0013] In one embodiment, the security data in the data warehouse is cross-platform associated based on the organization field to obtain associated data, including:
[0014] The attribute data and instance data of the cloud resource product in the data warehouse are cross-platform associated based on the organization field to obtain cloud resource product associated data corresponding to each organization field;
[0015] The attribute data and instance data of the cloud security product in the data warehouse are cross-cloud host IP associated based on the organization field to obtain cloud security product associated data corresponding to each organization field.
[0016] In one embodiment, data retrieval is performed based on the associated data, including:
[0017] The associated data is created into a first data model through an MVC mode;
[0018] The first data model is called based on a search keyword input by a user, the relevant associated data of the search keyword is linked by using the first data model, and the relevant associated data is pushed to the user.
[0019] In one embodiment, data display is performed based on the associated data, including:
[0020] The cloud security device includes a vulnerability scanning device and a situation awareness device;
[0021] First log data of the vulnerability scanning device and second log data of the situation awareness device are obtained from the associated data;
[0022] Based on an IP field in the first log data, a vulnerability scanning network segment in the first log data is divided into a government network network segment and an Internet network segment;
[0023] The number of high-risk ports in the first log data is divided into the corresponding government network network segment and the Internet network segment to obtain the number of high-risk ports corresponding to the government network network segment and the number of high-risk ports corresponding to the Internet network segment;
[0024] Based on a time field in the first log data, the number of high-risk ports corresponding to the government network network segment and the number of high-risk ports corresponding to the Internet network segment are grouped and aggregated by day as a dimension to obtain high-risk port data formed by the number of high-risk ports of the government network network segment and the number of high-risk ports of the Internet network segment every day in the past week;
[0025] group and aggregate target attack events in the second log data by day based on a time field in the second log data, to obtain high-risk event data formed by attack event names with higher attack times and attacked IPs in the past 24 hours; the target attack events include attack success events and attack failure events;
[0026] create a second data model by the MVC mode based on the high-risk port data and the high-risk event data;
[0027] call the second data model, link the high-risk port data and the high-risk event data by the second data model, and render the high-risk port data and the high-risk event data into a chart for display.
[0028] In one embodiment, the security protection based on the association data comprises:
[0029] detect abnormal data in the association data;
[0030] generate alarm information based on the abnormal data;
[0031] analyze the alarm information to obtain key information of the alarm information; the key information includes an alarm level of the alarm information and an abnormal category of the abnormal data;
[0032] generate a protection measure according to a preset rule based on the alarm level and the abnormal category;
[0033] perform security protection based on the protection measure.
[0034] In one embodiment, the alarm notification based on the association data comprises:
[0035] send the alarm information to a 5G message terminal through a chat robot, a message gateway and a 5G message center in sequence to alarm and notify users of the 5G message terminal.
[0036] In one embodiment, the security operation based on the association data comprises:
[0037] the organization field includes county, city, district, department and project;
[0038] create a three-level directory of county-city-district-department-project based on the organization field;
[0039] input the association data into a security risk identification model to obtain security risk data output by the security risk identification model; the security risk identification model is obtained by training historical association data based on a random forest model;
[0040] The security risk data is labeled to obtain labeled data;
[0041] The labeled data, security service optimization suggestions for the labeled data, and vulnerability scanning reports are added to a third-level catalog to form a project file;
[0042] The project file is sent to a corresponding project leader.
[0043] In a second aspect, an embodiment of the present application provides a cloud security operation and maintenance device, comprising:
[0044] A data collection module is configured to collect multi-platform security data in the cloud in an adaptive manner based on characteristics of different types of data in the cloud.
[0045] A data correlation module is configured to integrate the multi-platform security data into a data warehouse and correlate security data in the data warehouse across platforms based on an organization field to obtain correlated data.
[0046] A security operation and maintenance module is configured to perform security operation and maintenance based on the correlated data, wherein the security operation and maintenance includes data retrieval, data display, security protection, alarm notification, and security operation.
[0047] In one embodiment, the security operation and maintenance module comprises:
[0048] A data retrieval module is configured to perform data retrieval based on the correlated data.
[0049] A data display module is configured to perform data display based on the correlated data.
[0050] A security protection module is configured to perform security protection based on the correlated data.
[0051] An alarm notification module is configured to perform alarm notification based on the correlated data.
[0052] A security operation module is configured to perform security operation based on the correlated data.
[0053] In a third aspect, an embodiment of the present application provides an electronic device comprising a processor and a memory storing a computer program, wherein the processor implements the steps of the cloud security operation and maintenance method of the first aspect when executing the program.
[0054] In a fourth aspect, an embodiment of the present application provides a computer program product comprising a computer program, wherein the computer program implements the steps of the cloud security operation and maintenance method of the first aspect when executed by a processor.
[0055] In a fifth aspect, the embodiments of the present application provide a non-transitory computer-readable storage medium comprising a computer program, which, when executed by a processor, implements the steps of the cloud security operation and maintenance method of the first aspect.
[0056] The cloud security operation and maintenance method and device provided by the present application collect multi-platform security data in the cloud in an adaptive manner based on the characteristics of different types of data in the cloud, integrate the multi-platform security data into a data warehouse, associate the security data in the data warehouse across platforms based on organization fields to obtain associated data, and perform security operation and maintenance based on the associated data, which includes data retrieval, data display, security protection, alarm notification and security operation. The present application collects multi-platform data in the cloud in a targeted manner and integrates them into the same data warehouse, associates the data of different platforms in the warehouse based on organization fields, realizes the intercommunication of multi-platform data under any organization field and the intercommunication of multi-platform data between organization fields, breaks the data silos, and when performing various security operation and maintenance based on the intercommunicated associated data, there is no need to switch between multiple platforms to view, collect and analyze data, thereby improving the operation and maintenance efficiency and reducing the frequency of security incidents. BRIEF DESCRIPTION OF DRAWINGS
[0057] In order to more clearly illustrate the technical solutions of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are some embodiments of the present application, and other drawings can also be obtained by those skilled in the art without creative labor.
[0058] Figure 1 is one of the flowcharts of the cloud security operation and maintenance method provided by the embodiments of the present application;
[0059] Figure 2 is an ECS product associated data schematic diagram in the cloud security operation and maintenance method provided by the embodiments of the present application;
[0060] Figure 3 is the second flowchart of the cloud security operation and maintenance method provided by the embodiments of the present application;
[0061] Figure 4 is the third flowchart of the cloud security operation and maintenance method provided by the embodiments of the present application;
[0062] Figure 5 is an alarm notification model architecture diagram in the cloud security operation and maintenance method provided by the embodiments of the present application;
[0063] Figure 6 is an alarm notification interaction diagram in the cloud security operation and maintenance method provided by the embodiments of the present application;
[0064] Figure 7 is a short message alarm notification schematic diagram in the signal creation cloud security operation and maintenance method provided by the embodiment of the application;
[0065] Figure 8 is a fourth flow schematic diagram of the signal creation cloud security operation and maintenance method provided by the embodiment of the application;
[0066] Figure 9 is a mail sending schematic diagram in the signal creation cloud security operation and maintenance method provided by the embodiment of the application;
[0067] Figure 10 is a structural schematic diagram of the signal creation cloud security operation and maintenance device provided by the embodiment of the application;
[0068] Figure 11 is a structural schematic diagram of the electronic device provided by the embodiment of the application. DETAILED DESCRIPTION
[0069] To make the objectives, technical solutions and advantages of the present application clearer, the technical solutions in the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without any creative work fall within the scope of protection of the present application.
[0070] Figure 1 is a first flow schematic diagram of the signal creation cloud security operation and maintenance method provided by the embodiment of the application. With reference to Figure 1 the embodiment of the present application provides a signal creation cloud security operation and maintenance method, which can include the following steps:
[0071] 101. Based on the characteristics of different types of data in the signal creation cloud, the multi-platform security data in the signal creation cloud is collected in an adaptive manner.
[0072] 102. The multi-platform security data is integrated into a data warehouse, the security data in the data warehouse is cross-platform associated based on an organization field, and associated data is obtained.
[0073] 103. The security operation and maintenance is performed based on the associated data.
[0074] The security operation and maintenance includes data retrieval, data display, security protection, alarm notification and security operation.
[0075] In step 101, the multi-platform security data is not necessarily obtained directly in the corresponding platform, but can be obtained at any location where the data exists.
[0076] In step 102, the multi-platform data can be uniformly collected into a fast and fully managed TB / PB level data warehouse such as MaxCompute.
[0077] The cloud security operation and maintenance method provided in the embodiment is based on the characteristics of different types of data in the cloud, collects multi-platform security data in the cloud in an adaptive manner, integrates the multi-platform security data into a data warehouse, correlates the security data in the data warehouse across platforms based on organization fields, obtains correlated data, and performs security operation and maintenance based on the correlated data. The security operation and maintenance includes data retrieval, data display, security protection, alarm notification, and security operation. The embodiment collects multi-platform data in the cloud in a targeted manner, integrates the data into the same data warehouse, correlates the data of different platforms in the warehouse based on organization fields, realizes multi-platform data intercommunication under any organization field and multi-platform data intercommunication between organization fields, breaks data silos, and when performing various security operation and maintenance based on the correlated data, there is no need to switch between multiple platforms to view, collect, and analyze data, which improves operation and maintenance efficiency and reduces the frequency of security incidents.
[0078] In one embodiment, based on the characteristics of different types of data in the cloud, the multi-platform security data in the cloud can be collected in an adaptive manner, which can include:
[0079] The log data and monitoring data of the hardware devices in the cloud are collected by using a search engine; the hardware devices include cloud security devices;
[0080] The attribute data and instance data of the cloud resource products in the cloud are collected by using an API interface;
[0081] The attribute data and instance data of the cloud security products in the cloud are collected by using a crawler.
[0082] The hardware devices in the cloud include physical servers, switches, routers, and various cloud security devices, such as APT (Advanced Persistent Threat) defense devices, WAF (Web Application Firewall) devices, IPS (Intrusion Prevention System) devices, RSAS (Risk and Security Analytics System) devices, EDR (Endpoint Detection and Response), bastion host devices, situation awareness devices, and vulnerability scanning devices.
[0083] The log data and monitoring data of these hardware devices will be transmitted to the monitoring server and log server for storage through the SNMP (Simple Network Management Protocol) and Syslog (System Log) protocols respectively. Among them, the monitoring server mainly stores the performance monitoring data of the CPU, memory, and disk of the hardware devices, as well as the status data of the fan, power supply, temperature sensor, etc.
[0084] Cloud resource products include cloud hosts, cloud load balancing, cloud databases, cloud object storage, cloud hard disks, cloud private networks, etc.
[0085] Cloud security products are security products supported by cloud security devices, and can include APT defense, WAF, IPS, RSAS, EDR, bastion host, situational awareness, vulnerability scanning, etc.
[0086] For log data and monitoring data of hardware devices, you can use search engines such as Elasticsearch to collect them in the corresponding servers;
[0087] For the attribute data and instance data of cloud resource products, we can use the Restful API interface of Xinchuang Cloud, use Python program development and high-concurrency multi-threading technology to collect them;
[0088] The attribute data and instance data of cloud security products can be collected on the Xinchuang Cloud website using crawlers.
[0089] This embodiment collects different types of data at different locations through various adaptation methods, and can collect security data of various platforms as completely as possible.
[0090] In one embodiment, cross-platform association of security data in a data warehouse based on organization fields to obtain associated data may include:
[0091] Based on the organization field, the attribute data and instance data of the cloud resource products in the data warehouse are cross-platform associated to obtain the cloud resource product association data corresponding to each organization field;
[0092] Based on the organization field, the attribute data and instance data of the cloud security product in the data warehouse are associated across cloud host IPs to obtain cloud security product association data corresponding to each organization field.
[0093] The cloud resource products can include four categories of ECS (Elastic Compute Service), OSS (Object Storage Service), RDS (Relational Database Service), and SLB (Server Load Balancer).
[0094] For each organization field, the attribute data and instance data of each cloud resource product under the organization field are obtained in the data warehouse, the attribute data of each cloud resource product is associated, and the instance data of each cloud resource product is associated. Since the attribute data and instance data are originally data in different platforms, the association process realizes cross-platform association of the attribute data and cross-platform association of the instance data, thereby obtaining the associated data of each cloud resource product corresponding to the organization field. Figure 2 Two ECS product association data examples are shown, each of which includes multiple attribute data and instance data.
[0095] For each organization field, the attribute data and instance data of each cloud security product under the organization field are obtained in the data warehouse, the attribute data of each cloud security product is associated, and the instance data of each cloud security product is associated. Since the attribute data and instance data are originally data of cloud security products deployed on different cloud host IPs, the association process realizes cross-cloud host IP association of the attribute data and cross-cloud host IP association of the instance data, thereby obtaining the associated data of each cloud security product corresponding to the organization field. Different cloud host IPs include private IP, NAT IP (Network Address Translation IP), SLB IP (Server Load Balancer public IP), and EIP (Elastic IP).
[0096] Further, for each organization field, the security product subscription data and security product deployment data under the organization field can be associated, thereby forming multi-dimensional data under the organization field. Based on any dimensional data, data of other dimensions under the organization field can be obtained.
[0097] The embodiment can realize cross-platform and cross-host IP linkage of each data based on the organization field to associate cloud resource product data across platforms and associate cloud security product data across cloud host IPs, thereby improving subsequent operation and maintenance efficiency.
[0098] In one embodiment, the data retrieval based on the association data can include:
[0099] The association data is used to create a first data model through an MVC (Model-View-Controller) mode, the first data model is invoked based on a retrieval keyword input by a user, the relevant association data of the retrieval keyword is linked by using the first data model, and the relevant association data is pushed to the user.
[0100] Referring to Figure 2 The data retrieval webpage can be built by using a Python language and a Flask framework to ensure the safety of the data, access permissions are set on the webpage according to the sensitivity and importance of the data, a user needs to register an account and pass an administrator's approval to access the webpage, and an account invalidation time is set to further ensure the safety of the data.
[0101] In the webpage, the retrievable content includes user, type, specification, network, security and other information of a cloud resource product, and the status and performance of the cloud resource product are supported to be viewed, and the cloud security product deployment information is supported to be queried through multiple dimensions such as a user, a project and an instance, so that an operation and maintenance personnel does not need to log in to multiple platforms to obtain related data.
[0102] The embodiment can implement one-key retrieval of cloud resource product data and cloud security product data based on the association data to build a webpage and a data model, improve data acquisition efficiency and integrity, set access permissions and an account invalidation time for the retrieval webpage, and ensure the safety of the data.
[0103] Figure 3 FIG. 2 is a flowchart of a cloud security operation and maintenance method provided by an embodiment of the application. Referring to Figure 3 In one embodiment, the data display based on the association data can include:
[0104] The cloud security device includes a vulnerability scanning device and a situation awareness device;
[0105] 301, first log data of the vulnerability scanning device and second log data of the situation awareness device are obtained from the association data;
[0106] 302, the vulnerability scanning network segment in the first log data is divided into a government network network segment and an Internet network segment based on an IP field in the first log data;
[0107] 303, the number of high-risk ports in the first log data is divided into the corresponding government network network segment and the Internet network segment to obtain the number of high-risk ports corresponding to the government network network segment and the number of high-risk ports corresponding to the Internet network segment;
[0108] 304. Based on the time field in the first log data, group and aggregate the number of high-risk ports corresponding to the government network segment and the number of high-risk ports corresponding to the Internet segment by day, to obtain high-risk port data formed by the number of high-risk ports on the government network segment and the number of high-risk ports on the Internet segment every day in the past week;
[0109] 305. Based on the time field in the second log data, group and aggregate the target attack events in the second log data by day, and obtain the names of the attack events with the highest number of attacks within the past 24 hours and the high-risk event data formed by the attacked IP addresses;
[0110] Target attack events include successful attack events and failed attack events;
[0111] 306. Create a second data model using the high-risk port data and the high-risk event data through the MVC model;
[0112] 307 : Call the second data model, use the second data model to link the high-risk port data and the high-risk event data, and render the high-risk port data and the high-risk event data into a chart for display.
[0113] In steps 302 to 304, the portion of the number of high-risk ports in the first log data that belongs to the government network segment is divided into the government network segment, and the portion that belongs to the Internet segment is divided into the Internet segment. Then, the portion of the number of high-risk ports in the government network segment that belongs to each day in the past week is divided into the corresponding day, and the portion of the number of high-end ports in the Internet segment that belongs to each day in the past week is divided into the corresponding day. The daily data is integrated to obtain comparative data on the number of high-risk ports of the government network segment and the Internet network corresponding to each day in the past week.
[0114] In step 305, the target attack events in the second log data that belong to the daily part are divided into the corresponding days, so as to obtain all attack events within the past 24 hours, count the number of attacks of the same attack event, and arrange the corresponding attack event names and attacked IP addresses in descending order according to the number of attacks.
[0115] A successful attack event typically refers to an event in which the attacker has been able to penetrate or compromise the security measures of the target system, achieving their attack objectives. For example, an attacker may have successfully gained unauthorized access to the system. A compromised attack event typically refers to an event in which the attacker has taken control of the system or caused severe damage to the system. In this case, the attacker may have established a persistent presence in the system, remotely controlling the affected system and conducting malicious activities such as data theft, encryption ransomware, and distributed denial of service attacks.
[0116] In step 307, the chart can be displayed in various forms such as a column chart, a line chart, a pie chart, a list, etc. For example, the high-risk port data is displayed in a column chart to compare the number of high-risk ports of the government network segment and the Internet network per day, and the high-risk event data is displayed in a list to show the top ten attack event names and attacked IPs in descending order of attack times within 24 hours in the past day.
[0117] The embodiment captures high-risk port data and attack event data, groups and aggregates these data, and displays the data in a holographic form to improve the readability of the data, provide one-stop information of key security indicators for operation and maintenance personnel, and meet the management and analysis needs of different levels.
[0118] Figure 4 FIG. 3 is a flowchart of a method for cloud security operation and maintenance provided by the embodiment of the application. Referring to FIG. 3, the method includes the following steps. Figure 4 In one embodiment, the security protection based on the correlation data can include the following steps.
[0119] 401, detecting abnormal data in the correlation data;
[0120] 402, generating an alarm information based on the abnormal data;
[0121] 403, parsing the alarm information to obtain key information of the alarm information;
[0122] The key information includes an alarm level of the alarm information and an abnormal category of the abnormal data;
[0123] 404, generating a protection measure according to a preset rule based on the alarm level and the abnormal category;
[0124] 405, performing security protection based on the protection measure.
[0125] In step 401, the abnormal data can be obtained from log data and monitoring data of a security device, cloud security product instance data, etc.
[0126] In step 403, the abnormal category can be login failure, access rejection, high-risk vulnerability, etc. If the data is attack data, the key information further includes a source IP and a target IP of the attack.
[0127] In step 405, the protection measure can include blocking the source IP of the attack, blocking and repairing the high-risk vulnerability, reinforcing the protection of the high-risk vulnerability, etc.
[0128] The embodiment can automatically respond to the detected abnormal data and quickly take corresponding security measures, reducing the dependence on manual operation, improving the network security protection capability of the cloud environment, effectively reducing the security risk, and protecting the business continuity and data security of the user.
[0129] In one embodiment, the alarm notification based on the correlation data can include:
[0130] The alarm information is sent to the message terminal via the chat robot, the message gateway and the message center in sequence to alarm the user of the message terminal.
[0131] A B / S framework platform and a 5G message machine can be constructed on the server side, and a 5G message notification program is developed, which respectively interfaces with an ODPS (Open Data Processing Service) platform alarm data interface and a 5G message machine API to realize a mode of pushing alarm information by the 5G message.
[0132] Referring to Figure 5 , the 5G message program sends the alarm information to the chat robot, the chat robot encapsulates the alarm information and sends it to the Maap (Messaging as a Platform) message gateway, the message gateway sends the encapsulated alarm information to the 5G message center, the 5G message center converts the encapsulated alarm information into a SIP (Session Initiation Protocol) message format, and finally sends it to the 5G message terminal via the IMS (IP Multimedia Subsystem), 5GC (5G Core Network) and base station.
[0133] Referring to Figure 6 , the interaction process between the chat robot, the Maap message gateway, the 5G message center and the 5G message terminal is as follows, wherein the 5G message center includes a message AS (Application Server) and an access module, and the IMS, 5GC and base station are omitted in the interaction:
[0134] 1. The chat robot encapsulates the alarm information as an A2P (Application to Person) message and sends it to the Maap message gateway;
[0135] 2. The Maap message gateway sends a response with an OK state to the chat robot;
[0136] 3. The Maap message gateway sends the A2P message to the message AS based on the Hypertext Transfer Protocol (HTTP);
[0137] 4. The message AS sends a response with an OK state to the Maap message gateway;
[0138] 5. The message AS encapsulates the A2P message as a SIP message and sends it to the access module;
[0139] 6、The access module forwards the SIP message to the 5G message terminal;
[0140] 7、The 5G message terminal sends a response of 200 OK state to the access module;
[0141] 8、The access module forwards the response of 200 OK state to the message AS;
[0142] 9、The 5G message terminal sends a SIP message receipt to the access module;
[0143] 10、The access module forwards the SIP message receipt to the message AS;
[0144] 11、The message AS sends a response of 202 ACCEPTED state to the access module;
[0145] 12、The access module forwards the response of 202 ACCEPTED state to the 5G message terminal;
[0146] 13、The message AS sends a delivery receipt of A2P message to the Maap message gateway;
[0147] 14、The Maap message gateway sends a response of OK state to the message AS;
[0148] 15、The Maap message gateway forwards the delivery receipt to the chat robot;
[0149] 16、The chat robot sends a response of OK state to the Maap message gateway.
[0150] Referring to Figure 7 Through the above interaction, the 5G message terminal, such as a mobile phone, can receive relevant short message alarm notifications.
[0151] The embodiment alarms users through 5G messages, so that users can quickly obtain the security protection state of their own use of resources and products. Compared with platform viewing, it is more timely and reliable, effectively reduces fault duration, improves user safety awareness, drives the subscription of safety products, and finally makes the business system run safely and stably, and safety events gradually decrease.
[0152] Figure 8 is a fourth flowchart of a cloud security operation and maintenance method provided by the embodiment of the application. Referring to Figure 8 In an embodiment, the security operation based on the association data can include:
[0153] The organization field includes county, city, district, department, and project;
[0154] 801、Create a three-level directory of county-city-district-department-project based on the organization field;
[0155] 802. Input the associated data into the safety hazard identification model to obtain safety hazard data output by the safety hazard identification model;
[0156] The safety hazard identification model is trained using historical correlation data based on the random forest model;
[0157] 803. Label the safety hazard data to obtain labeled data;
[0158] 804. Add the annotated data, security service optimization suggestions for the annotated data, and vulnerability scanning reports to the adapted third-level directory to form a project file.
[0159] 805. Send the project files to the corresponding project leader.
[0160] In step 801, the organization field can be a three-level field of county, city, district, department, and project, so a corresponding three-level directory can be created accordingly.
[0161] In step 802, before training the random forest model, the historical correlation data may be cleaned, converted, standardized, etc. to eliminate noise in the data.
[0162] Additionally, the security risk identification model outputs security risk data, including cloud security product misconfiguration data, high-risk system vulnerabilities, high-risk application ports, and security group non-compliance data, without limitation here. The logic for determining security group non-compliance is based on the security group policy being fully open with no restrictions on the source IP address of incoming traffic, or restricting source IP addresses with a segment mask smaller than 24.
[0163] The use of safety hazard identification models can efficiently, accurately, real-timely and intelligently locate safety hazard data, solving the problem of easy errors in manual operation and maintenance.
[0164] In step 804, Python's docx module can be used to combine the annotated data and the standardized text suggestions, and a comprehensive evaluation can be performed based on the usage of cloud security products, such as the number of cloud security products, usage rate, coverage rate, compliance rate and other indicators, to output security service optimization suggestions for the annotated data.
[0165] In step 805, the project files can be packaged and compressed and then sent to the corresponding project leader in the form of an email, such as Figure 9 shown.
[0166] In this embodiment, not only can the cloud security product service status related to the Xinchuang Cloud user business system be flexibly integrated and summarized on demand and informed to users regularly, but also security protection can be provided to users based on cloud security best practices, such as baseline verification, vulnerability scanning, penetration testing, etc.
[0167] The cloud security operation and maintenance device provided by the embodiments of the present application is described below. The cloud security operation and maintenance device described below can be correspondingly referred to the cloud security operation and maintenance method described above.
[0168] Figure 10 FIG. 1 is a structural schematic diagram of the cloud security operation and maintenance device provided by the embodiments of the present application. Referring to FIG. 1, the cloud security operation and maintenance device provided by the embodiments of the present application can include: Figure 10 The cloud security operation and maintenance device provided by the embodiments of the present application can include:
[0169] The data collection module 1001 is configured to collect multi-platform security data in the cloud in an adaptive manner based on the characteristics of different types of data in the cloud.
[0170] The data correlation module 1002 is configured to integrate the multi-platform security data into a data warehouse, and correlate the security data in the data warehouse across platforms based on an organization field to obtain correlated data.
[0171] The security operation and maintenance module 1003 is configured to perform security operation and maintenance based on the correlated data. The security operation and maintenance includes data retrieval, data display, security protection, alarm notification, and security operation.
[0172] The security operation and maintenance module 1003 includes:
[0173] The data retrieval module is configured to perform data retrieval based on the correlated data.
[0174] The data display module is configured to perform data display based on the correlated data.
[0175] The security protection module is configured to perform security protection based on the correlated data.
[0176] The alarm notification module is configured to perform alarm notification based on the correlated data.
[0177] The security operation module is configured to perform security operation based on the correlated data.
[0178] The cloud security operation and maintenance device provided by the embodiment is based on the characteristics of different types of data in the cloud, collects multi-platform security data in the cloud in an adaptive manner, integrates the multi-platform security data into a data warehouse, cross-platform correlates the security data in the data warehouse based on organization fields to obtain correlated data, and performs security operation and maintenance based on the correlated data, which includes data retrieval, data display, security protection, alarm notification and security operation. The embodiment collects multi-platform data in the cloud in a targeted manner, integrates the data into the same data warehouse, correlates the data of different platforms in the warehouse based on organization fields, realizes multi-platform data intercommunication under any organization field and multi-platform data intercommunication between organization fields, breaks the data silos, and when performing various security operation and maintenance based on the correlated data, there is no need to switch multiple platforms to view, collect and analyze data, thereby improving the operation and maintenance efficiency and reducing the frequency of security incidents.
[0179] In one embodiment, the data collection module 1001 is specifically configured to:
[0180] collecting log data and monitoring data of the hardware devices in the cloud by using a search engine; the hardware devices include cloud security devices;
[0181] collecting attribute data and instance data of the cloud resource products in the cloud by using an API interface;
[0182] collecting attribute data and instance data of the cloud security products in the cloud by using a crawler.
[0183] In one embodiment, the data correlation module 1002 is specifically configured to:
[0184] cross-platform correlating the attribute data and the instance data of the cloud resource products in the data warehouse based on the organization fields to obtain cloud resource product correlation data corresponding to each organization field;
[0185] cross-cloud host IP correlating the attribute data and the instance data of the cloud security products in the data warehouse based on the organization fields to obtain cloud security product correlation data corresponding to each organization field.
[0186] In one embodiment, the data retrieval module is specifically configured to:
[0187] creating a first data model by using the MVC mode based on the correlated data;
[0188] calling the first data model based on a retrieval keyword input by a user, linking relevant correlated data of the retrieval keyword by using the first data model, and pushing the relevant correlated data to the user.
[0189] In one embodiment, the data display module is specifically configured to:
[0190] The cloud security device comprises a vulnerability scanning device and a situation awareness device;
[0191] Obtain first log data of the vulnerability scanning device and second log data of the situation awareness device from the association data;
[0192] Divide the vulnerability scanning network segment in the first log data into a government network network segment and an Internet network segment based on the IP field in the first log data;
[0193] Divide the number of high-risk ports in the first log data to the corresponding government network network segment and Internet network segment to obtain the number of high-risk ports corresponding to the government network network segment and the number of high-risk ports corresponding to the Internet network segment;
[0194] Based on the time field in the first log data, the number of high-risk ports corresponding to the government network network segment and the number of high-risk ports corresponding to the Internet network segment are grouped and aggregated by day, to obtain high-risk port data formed by the number of high-risk ports of the government network network segment and the number of high-risk ports of the Internet network segment every day in the past week;
[0195] Based on the time field in the second log data, the target attack event in the second log data is grouped and aggregated by day to obtain high-risk event data formed by the attack event name and the attacked IP with high attack frequency in 24 hours in the past day; the target attack event includes attack success event and attack failure event;
[0196] Create a second data model by MVC mode based on the high-risk port data and the high-risk event data;
[0197] Call the second data model, link the high-risk port data and the high-risk event data by using the second data model, and render the high-risk port data and the high-risk event data into a chart for display.
[0198] In one embodiment, the security protection module, specifically for:
[0199] Detect abnormal data in the association data;
[0200] Generate alarm information based on the abnormal data;
[0201] Parse the alarm information to obtain key information of the alarm information; the key information includes alarm level of the alarm information and abnormal category of the abnormal data;
[0202] Based on the alarm level and the abnormal category, generate protection measures according to a preset rule;
[0203] Perform security protection based on the above protection measures.
[0204] In one embodiment, the alarm notification module is specifically configured to:
[0205] The alarm information is sent to the 5G message terminal via the chat robot, the message gateway and the 5G message center in sequence to provide an alarm notification to the user of the 5G message terminal.
[0206] In one embodiment, the security operation module is specifically configured to:
[0207] The organization fields include counties, cities, districts, departments, and projects;
[0208] Create a three-level directory of county, city, district, department, and project based on the organization field;
[0209] Inputting the associated data into a safety hazard identification model to obtain safety hazard data output by the safety hazard identification model; the safety hazard identification model is trained using historical associated data based on a random forest model;
[0210] Labeling the potential safety hazard data to obtain labeled data;
[0211] Add the annotated data, security service optimization suggestions for the annotated data, and vulnerability scanning reports to the adapted third-level directory to form a project file;
[0212] Send the project files to the corresponding project leader.
[0213] FIG11 is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. Figure 11 As shown, the electronic device may include: a processor 1110, a communication interface 1120, a memory 1130, and a communication bus 1140, wherein the processor 1110, the communication interface 1120, and the memory 1130 communicate with each other via the communication bus 1140. The processor 1110 may call a computer program in the memory 1130 to execute the steps of the secure operation and maintenance method of the trust-building cloud, for example, including:
[0214] Based on the characteristics of different types of data in the Xinchuang Cloud, multi-platform security data in the Xinchuang Cloud is collected in an adaptive manner;
[0215] Integrating the multi-platform security data into a data warehouse, and correlating the security data in the data warehouse across platforms based on an organization field to obtain correlated data;
[0216] Perform security operation based on the association data; the security operation includes data retrieval, data display, security protection, alarm notification and security operation.
[0217] In addition, the logical instructions in the memory 1130 described above can be implemented in the form of a software function unit and sold or used as an independent product, and can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application essentially or the parts that contribute to the prior art or parts of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various media that can store program codes.
[0218] On the other hand, the embodiments of the present application also provide a computer program product, which includes a computer program, the computer program can be stored on a non-transitory computer readable storage medium, and the computer program is executed by a processor, so that the computer can execute the steps of the cloud security operation method provided by the above-mentioned embodiments, for example, including:
[0219] Based on the characteristics of different types of data in the cloud, multi-platform security data in the cloud is collected in an adaptive manner;
[0220] The multi-platform security data is integrated into a data warehouse, and the security data in the data warehouse is cross-platform associated based on the organization field to obtain association data;
[0221] Perform security operation based on the association data; the security operation includes data retrieval, data display, security protection, alarm notification and security operation.
[0222] On the other hand, the embodiments of the present application also provide a non-transitory computer readable storage medium, which stores a computer program, the computer program is used to make the processor execute the steps of the cloud security operation method provided by the above-mentioned embodiments, for example, including:
[0223] Based on the characteristics of different types of data in the cloud, multi-platform security data in the cloud is collected in an adaptive manner;
[0224] The multi-platform security data is integrated into a data warehouse, and the security data in the data warehouse is cross-platform associated based on the organization field to obtain association data;
[0225] Based on the association data, security operation and maintenance is performed; the security operation and maintenance includes data retrieval, data display, security protection, alarm notification and security operation.
[0226] The non-transitory computer readable storage medium can be any available medium or data storage device that the processor can access, including but not limited to a magnetic memory (such as a floppy disk, a hard disk, a magnetic tape, a magneto-optical disk (MO), etc.), an optical memory (such as a CD, a DVD, a BD, a HVD, etc.), and a semiconductor memory (such as a ROM, an EPROM, an EEPROM, a non-volatile memory (NAND FLASH), a solid state disk (SSD)), etc.
[0227] The device embodiments described above are only illustrative, wherein the units illustrated as separate components can or can not be physically separated, and the components illustrated as units can or can not be physical units, i.e., they can be located in one place or distributed on multiple network units. Part or all of the modules can be selected to achieve the purposes of the embodiments according to actual needs. Those skilled in the art can understand and implement it without creative labor.
[0228] From the above description of the embodiments, those skilled in the art can clearly understand that the embodiments can be realized by means of software plus necessary universal hardware platforms, and of course, can also be realized by hardware. Based on such understanding, the above technical solutions, essentially or in other words, the part that contributes to the prior art, can be embodied in the form of a software product, which can be stored in a computer readable storage medium, such as a ROM / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute the methods described in each embodiment or some parts of the embodiments.
[0229] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacements for some technical features; and these modifications or replacements do not make the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A method for operating and maintaining cloud security of Xinxin, characterized in that, The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. 2.The method of claim 1, wherein, The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. 3.The method of claim 1, wherein, The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data collection and display method and device. The application relates to a cloud security data Call the second data model, link the high-risk port data and the high-risk event data by using the second data model, and render the high-risk port data and the high-risk event data into a chart for display.
4. The cloud security operation method of the Xinyi according to claim 1, characterized in that, Security protection based on the associated data includes: Detecting abnormal data in the associated data; Generating alarm information based on the abnormal data; Parsing the alarm information to obtain key information of the alarm information; the key information includes an alarm level of the alarm information and an abnormal category of the abnormal data; Generating a protection measure according to a preset rule based on the alarm level and the abnormal category; Security protection based on the protection measure.
5. The Xinyi cloud security operation and maintenance method according to claim 4, characterized in that, Alarm notification based on the associated data includes: Sending the alarm information to a message terminal via a chat robot, a message gateway and a message center in sequence to alarm the user of the message terminal.
6. The cloud security operation method of the Xinyi according to claim 1, characterized in that, Security operation based on the associated data includes: The organization field includes county, city, district, department and project; Creating a three-level directory of county-city-district-department-project based on the organization field; Inputting the associated data into a security risk identification model to obtain security risk data output by the security risk identification model; the security risk identification model is trained based on a random forest model using historical associated data; Labeling the security risk data to obtain labeled data; Adding the labeled data, security service optimization suggestions for the labeled data and a vulnerability scanning report to an adapted three-level directory to form a project file; Sending the project file to a corresponding project leader.
7. A Xinyi cloud security operation and maintenance device, characterized in that, The signal creation cloud security operation and maintenance method of claim 1 includes: A data collection module for collecting multi-platform security data in the signal creation cloud in an adaptive manner based on the characteristics of different types of data in the signal creation cloud; A data association module for associating the multi-platform security data into a data warehouse and associating the security data in the data warehouse across platforms based on an organization field to obtain associated data; A security operation and maintenance module for performing security operation and maintenance based on the associated data; the security operation and maintenance includes data retrieval, data display, security protection, alarm notification and security operation.
8. The signal creation cloud security operation and maintenance device of claim 7, wherein: The security operation and maintenance module includes: A data retrieval module for performing data retrieval based on the associated data; A data display module for performing data display based on the associated data; A security protection module for performing security protection based on the associated data; An alarm notification module for performing alarm notification based on the associated data; A security operation module for performing security operation based on the associated data.
9. An electronic device comprising a processor and a memory having a computer program stored therein, characterized in that, The processor executes the computer program to implement the steps of the signal creation cloud security operation and maintenance method of any one of claims 1 to 6.
10. A computer program product comprising a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the signal creation cloud security operation and maintenance method of any one of claims 1 to 6.
11. A non-transitory computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the signal creation cloud security operation and maintenance method of any one of claims 1 to 6.
Citation Information
Patent Citations
System and method for generating and refining cyber threat intelligence data
CA3108494A1
Information security event automatic association and rapid response method and system based on big data analysis
CN105847029A