A network security alarm rule description method and system
By evaluating the matching degree and correlation coefficient of preset network rules, combining network traffic monitoring data, and dynamically adjusting the rule base to identify network attacks, the problem of time-consuming updates and high false alarm rates of traditional systems is solved, and accurate network security alerts are achieved.
Patent Information
- Application Number
- CN202411818863.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-11
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2044-12-11
AI Technical Summary
Traditional network security warning systems are time-consuming to update and prone to missed and false alarms when facing new network attacks, and are unable to effectively describe complex attack scenarios.
By matching the types and times of historical attack behaviors, the matching degree and correlation coefficient of preset network rules are determined, access risks are assessed in combination with network traffic monitoring data, and the rule base is dynamically adjusted to identify attack behaviors.
It achieves accurate identification and risk assessment of network access behavior, reduces missed and false alarm rates, and improves the flexibility and adaptability of the system.
Smart Images

Figure CN119583315B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application belongs to the technical field of network security, and particularly relates to a network security alarm rule description method and system. BACKGROUND
[0002] At present, a network security alarm system uses fixed rules to identify network security threats, and has the following deficiencies:
[0003] 1. The traditional rule mode does not have sufficient flexibility, and when a new network security attack appears, the system needs to update the rule library frequently, which is very time-consuming and may miss some new network attacks.
[0004] 2. Attack behaviors often have multiple feature combinations, and the traditional fixed rule mode cannot effectively describe complex attack scenarios, and has a high false negative rate and false positive rate.
[0005] Therefore, it is necessary to improve the prior art, and provide an alarm rule expression method capable of accurate, flexible and adaptive expression, and an analysis engine for real-time discovery of attack behaviors.
[0006] In view of the above technical problems, the present application provides a network security alarm rule description method and system. SUMMARY
[0007] To achieve the object of the present application, the present application adopts the following technical solutions:
[0008] According to one aspect of the present application, a network security alarm rule description method is provided.
[0009] A network security alarm rule description method, characterized in that it specifically comprises:
[0010] S1 determines the matching degree of different preset network rules and the determination of the concerned network rule by the type of historical attack behaviors matched by different preset network rules and the attack times of different types of historical attack behaviors;
[0011] S2 determines the correlation coefficient of the preset network rule and other preset network rules by the type of historical attack behaviors matched by the preset network rule and other preset network rules at the same time and the attack times of different types of historical attack behaviors, and determines the associated network rule of the concerned network rule based on the correlation coefficient;
[0012] S3 determines the network rules that match the network access behavior based on the network traffic monitoring data, and uses them as the matching network rules. The initial access risk is determined based on the number of matches, the degree of abnormality, and the matching data of the associated network rules of different matching associated network rules. If the initial access risk does not meet the requirements, proceed to the next step.
[0013] S4 obtains the preset network rule that matches the network access behavior, and uses it as the matching network rule, and determines the access risk of the network access behavior based on the matching degrees of different matching network rules and the correlation coefficients between different matching network rules.
[0014] A further technical solution is that the preset network rule is determined according to the network rules of a preset network rule library.
[0015] A further technical solution is that the matching degree of the preset network rule ranges from 0 to 1, wherein the greater the matching degree of the preset network rule, the more the preset network rule matches the historical attack behavior.
[0016] A further technical solution is that the method for determining the initial access risk is:
[0017] Determining the number of matches of the associated network rules of the different matching network rules of interest based on the matching data of the associated network rules of the matching network rules of interest, and determining the matching risk level values of the different matching network rules of interest in combination with the abnormality levels of the different matching network rules of interest;
[0018] The initial access risk is determined by using different matching risk degree values and matching quantities of the matching attention network rules.
[0019] On the other hand, the present invention provides a computer system comprising: a memory and a processor in communication connection, and a computer program stored in the memory and capable of running on the processor, characterized in that: the processor executes the above-mentioned network security alarm rule description method when running the computer program.
[0020] The beneficial effects of the present invention are:
[0021] 1. By matching the types of historical attack behaviors and the number of attacks of different types of historical attack behaviors, the correlation coefficient between the preset network rules and other preset network rules is determined. This enables the correlation coefficient to be evaluated based on the correlation relationship between the preset network rules under different historical attack behaviors, avoiding the technical problem of slow update speed of the original reliance on a single preset combination of network rules for access risk identification.
[0022] 2. By determining the initial access risk based on the matching number of the matching focus network rules, the degree of abnormality, and the matching data of the associated network rules of different matching associated network rules, the initial access risk of the network access behavior is evaluated from the perspective of matching focus network rules, fully considering the differences in the number of matching network rules and the degree of abnormality when the network access behavior is abnormal, and also considering the association relationship between the matching network rules when the network access behavior is abnormal.
[0023] 3. By determining the access risk of network access behavior based on the matching degree of different matching network rules and the correlation coefficient between different matching network rules, access risk assessment is achieved from the perspective of matching network rules matching network access behavior. The differences in the matching degree between different matching network rules and abnormal access behaviors under different access risks and the differences in the correlation coefficients between matching network rules under different abnormal access behaviors are fully considered, thus achieving accurate identification of network access risks.
[0024] Other features and advantages will be described in the following description, and in part will become apparent from the description, or understood by practicing the invention. The purpose and other advantages of the invention are realized and obtained by the structures particularly pointed out in the description and the drawings.
[0025] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, preferred embodiments are given below and described in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] The above and other features and advantages of the present invention will become more apparent by describing in detail exemplary embodiments thereof with reference to the accompanying drawings.
[0027] Figure 1 It is a flow chart of a method for describing network security alarm rules;
[0028] Figure 2 is a flow chart of a method for determining a matching degree of a preset network rule;
[0029] Figure 3 It is a framework diagram of a computer system. DETAILED DESCRIPTION
[0030] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be embodied in many forms and should not be construed as limited to the embodiments set forth herein; rather, these embodiments are provided so that this disclosure will be thorough and complete and will fully convey the concepts of the example embodiments to those skilled in the art. Like reference numerals in the figures represent like or similar structures, and thus their detailed description will be omitted.
[0031] The terms "a", "an", "the", and "said" are used to indicate the presence of one or more elements / components / etc.; the terms "including" and "having" are used to express an open-ended inclusive meaning and mean that additional elements / components / etc. may be present in addition to the listed elements / components / etc.
[0032] Example 1
[0033] To solve the above problems, according to one aspect of the present invention, Figure 1 According to one aspect of the present invention, a method for describing network security alarm rules is provided, which is characterized by specifically comprising:
[0034] S1 determines the matching degree of different preset network rules and focuses on the determination of network rules based on the types of historical attack behaviors matched by different preset network rules and the number of attacks of different types of historical attack behaviors;
[0035] Furthermore, the preset network rule is determined according to the network rules of a preset network rule library.
[0036] Specific examples, such as Figure 2 As shown, the method for determining the matching degree of the preset network rule is:
[0037] S11 determines the matching duration of the preset network rule based on historical network data, and uses the duration of historical attack behaviors in the matching duration as the matching attack duration.
[0038] S12: dividing the matching duration into a general matching duration and a complete matching duration according to the degree of matching of the preset network rules of different matching durations in the matching duration, obtaining the matching attack duration in the complete matching duration, the type of historical attack behavior in the matching attack duration, and the number of attacks of different types of historical attack behaviors, and determining the matching degree of the preset network rules in the complete matching duration in combination with the type of historical attack behavior matched by the preset network rules in the matching attack duration in the complete matching duration and the number of attacks of different types of historical attack behaviors;
[0039] S13 obtains the matching attack duration in the general matching duration, the type of historical attack behavior in the matching attack duration, and the attack times of different types of historical attack behavior, and determines the matching degree of the preset network rule in the general matching duration by combining the type of historical attack behavior matched by the preset network rule in the matching attack duration in the general matching duration and the attack times of different types of historical attack behavior, and determines the matching degree of the preset network rule by the matching degree of the preset network rule in the general matching duration and the matching degree of the preset network rule in the complete matching duration.
[0040] Optionally, the step S11 includes the following content:
[0041] S111 determines the matching duration of the preset network rule based on historical network data, and takes the duration with historical attack behavior in the matching duration as the matching attack duration, and judges whether the proportion of the matching attack duration is greater than the preset duration proportion, if yes, the next step is entered, if not, step S12 is entered;
[0042] S112 judges whether the historical attack behavior in the matching market matches the preset network rule, if yes, the preset network rule is taken as the concerned network rule, and the matching degree of the preset network rule is determined by the preset matching degree, if not, step S12 is entered.
[0043] It can be understood that the value range of the matching degree of the preset network rule is between 0 and 1, wherein the greater the matching degree of the preset network rule is, the more the preset network rule matches the historical attack behavior.
[0044] In another possible embodiment, the method for determining the matching degree of the preset network rule is:
[0045] The matching duration of the preset network rule is determined based on historical network data, and the duration with historical attack behavior in the matching duration is taken as the matching attack duration, and the matching duration is divided into the general matching duration and the complete matching duration according to the rule matching degree of the preset network rule in different matching durations in the matching duration;
[0046] The matching attack duration in the complete matching duration, the type of historical attack behavior in the matching attack duration, and the attack times of different types of historical attack behavior are obtained, and the matching degree of the preset network rule in the complete matching duration is determined by combining the type of historical attack behavior matched by the preset network rule in the matching attack duration in the complete matching duration and the attack times of different types of historical attack behavior;
[0047] Obtaining the matching attack duration in the general matching duration, the type of historical attack behavior in the matching attack duration, and the number of attacks of different types of historical attack behaviors, and determining the matching degree of the preset network rule in the general matching duration in combination with the type of historical attack behavior matching the preset network rule in the matching attack duration in the general matching duration and the number of attacks of different types of historical attack behaviors;
[0048] The matching degree of the preset network rule is determined by the matching degree of the preset network rule in the general matching duration and the matching degree of the preset network rule in the complete matching duration.
[0049] S2: determining a correlation coefficient between the preset network rule and other preset network rules based on the types of historical attack behaviors that are matched simultaneously with the preset network rule and the number of attacks of different types of historical attack behaviors, and determining an associated network rule of the focused network rule based on the correlation coefficient;
[0050] Specifically, for example, the method of calculating the correlation coefficient between the preset network rule and other preset network rules is as follows:
[0051] S21 determines a historical duration of simultaneous matching of the preset network rule and other preset network rules based on historical network traffic data, and uses the duration as a historical association duration of the preset network rule and other preset network rules;
[0052] S22: obtaining the duration of historical attack behaviors that are matched simultaneously with the preset network rule and other preset network rules in the historical association duration, and using the duration as the associated attack behavior duration, and determining the basic association coefficient between the preset network rule and other preset network rules based on the duration ratio;
[0053] S23 uses the historical attack behaviors that match the preset network rule and other preset network rules at the same time as the filtered historical attack behaviors, and determines the weight values of different types of filtered historical attack behaviors according to the attack duration and number of attacks of different types of filtered historical attack behaviors, and determines the correlation coefficient between the preset network rule and other preset network rules according to the number and the basic correlation coefficient of the weight values of different types of filtered historical attack behaviors.
[0054] Optionally, the above step S22 includes the following contents:
[0055] S221 acquire the time length of the historical attack behaviors that match the preset network rule and other preset network rules simultaneously in the historical association time length, and take it as the association attack behavior time length, determine whether the time length of the association attack behavior time length accounts for more than a preset time length ratio, if yes, determine the association coefficient of the preset network rule and other preset network rules through the time length ratio, if no, go to the next step;
[0056] S222 determine the basic association coefficient of the preset network rule and other preset network rules through the time length ratio, and determine whether the historical attack behaviors in the association attack behavior time length all match the preset network rule and other preset network rules, if yes, determine the association coefficient of the preset network rule and other preset network rules through the time length ratio, if no, go to the next step.
[0057] It should be noted that the preset time length ratio is determined according to the size of the association attack behavior time length, wherein the larger the association attack behavior time length is, the smaller the preset time length ratio is.
[0058] Specifically, the method for determining the association coefficient of the preset network rule and other preset network rules is:
[0059] Determine the historical time length of the preset network rule and other preset network rules that match simultaneously based on historical network traffic data, and take it as the historical association time length of the preset network rule and other preset network rules;
[0060] When the time length of the historical attack behaviors in the historical association time length accounts for less than a preset attack time length ratio, determine the association coefficient of the preset network rule and other preset network rules through a preset association coefficient;
[0061] When the time length of the historical attack behaviors in the historical association time length accounts for no less than a preset attack time length ratio, acquire the time length of the historical attack behaviors that match the preset network rule and other preset network rules simultaneously in the historical association time length, and take it as the association attack behavior time length, and when the association attack behavior time length is greater than a preset time length, determine the association coefficient of the preset network rule and other preset network rules through the time length ratio;
[0062] When the association attack behavior time length is not greater than a preset time length:
[0063] The historical attack behaviors that match the preset network rules and other preset network rules at the same time are used as the filtered historical attack behaviors, and the weight values of different types of filtered historical attack behaviors are determined by the attack duration and number of attacks of different types of filtered historical attack behaviors. The correlation coefficient between the preset network rules and other preset network rules is determined by the sum of the number of weight values of different types of filtered historical attack behaviors and the basic correlation coefficient.
[0064] S3 determines the network rules that match the network access behavior based on the network traffic monitoring data, and uses them as the matching network rules. The initial access risk is determined based on the number of matches, the degree of abnormality, and the matching data of the associated network rules of different matching associated network rules. If the initial access risk does not meet the requirements, proceed to the next step.
[0065] It should be noted that the method for determining the initial access risk is:
[0066] Determining the number of matches of the associated network rules of the different matching network rules of interest based on the matching data of the associated network rules of the matching network rules of interest, and determining the matching risk level values of the different matching network rules of interest in combination with the abnormality levels of the different matching network rules of interest;
[0067] The initial access risk is determined by using different matching risk degree values and matching quantities of the matching attention network rules.
[0068] Furthermore, the value range of the initial access risk is between 0 and 1, wherein the greater the initial access risk, the greater the risk of the network access behavior corresponding to the network traffic.
[0069] S4 obtains the preset network rule that matches the network access behavior, and uses it as the matching network rule, and determines the access risk of the network access behavior based on the matching degrees of different matching network rules and the correlation coefficients between different matching network rules.
[0070] To illustrate specifically, the method for determining the access risk of the network access behavior is as follows:
[0071] When it is determined that the network access behavior does not have risks through the matching degrees of different matching network rules and the number of matching network rules, the access risk of the network access behavior is determined through the matching degrees of the matching network rules and the number of matching network rules;
[0072] When the network access behavior is determined to be risky based on the matching degrees and number of matching network rules:
[0073] Determining the correlation coefficients between the network matching rule and the remaining network matching rules and the associated matching rules of the network matching rules through correlation coefficients between different network matching rules, and determining the risk assessment values of different network matching rules in combination with the matching degrees of the network matching rules;
[0074] When the sum of the risk assessment values of the network matching rules does not meet the requirement, determining the access risk of the network access behavior by the sum of the risk assessment values of the network matching rules;
[0075] When the number and risk assessment values of the network matching rules meet the requirements, the risk matching rules are determined based on the risk assessment values of the network matching rules, and the access risk of the network access behavior is determined based on the number of risk matching rules and the risk assessment values of different risk matching rules, the number of network matching rules and the number of risk assessment values.
[0076] Furthermore, when the access risk of the network access behavior does not meet the requirements, a network alarm signal is generated, and the combined risk rules of the network rule library are updated based on the identification result of the access risk of the network access behavior.
[0077] Example 2
[0078] On the other hand, Figure 3 As shown, the present invention provides a computer system, comprising: a memory and a processor connected in communication, and a computer program stored in the memory and capable of running on the processor, characterized in that: the processor executes the above-mentioned network security alarm rule description method when running the computer program.
[0079] Through the above embodiments, the present application achieves the following technical effects:
[0080] 1. By matching the types of historical attack behaviors and the number of attacks of different types of historical attack behaviors, the correlation coefficient between the preset network rules and other preset network rules is determined. This enables the correlation coefficient to be evaluated based on the correlation relationship between the preset network rules under different historical attack behaviors, avoiding the technical problem of slow update speed of the original reliance on a single preset combination of network rules for access risk identification.
[0081] 2. By determining the initial access risk based on the matching number of the matching focus network rules, the degree of abnormality, and the matching data of the associated network rules of different matching associated network rules, the initial access risk of the network access behavior is evaluated from the perspective of matching focus network rules, fully considering the differences in the number of matching network rules and the degree of abnormality when the network access behavior is abnormal, and also considering the association relationship between the matching network rules when the network access behavior is abnormal.
[0082] 3. By determining the access risk of network access behavior based on the matching degree of different matching network rules and the correlation coefficient between different matching network rules, access risk assessment is achieved from the perspective of matching network rules matching network access behavior. The differences in the matching degree between different matching network rules and abnormal access behaviors under different access risks and the differences in the correlation coefficients between matching network rules under different abnormal access behaviors are fully considered, thus achieving accurate identification of network access risks.
[0083] The various embodiments in this specification are described in a progressive manner. Similar portions between the various embodiments can be referenced to each other, and each embodiment focuses on the differences from the other embodiments. In particular, the device, apparatus, and non-volatile computer storage medium embodiments are generally similar to the method embodiments, so their descriptions are relatively simplified. For relevant details, refer to the descriptions of the method embodiments.
[0084] The foregoing description of this specification describes specific embodiments. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in an order different from that described in the embodiments and still achieve the desired results. Furthermore, the processes depicted in the accompanying drawings do not necessarily require the specific order shown or the sequential order to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0085] The foregoing description is merely one or more embodiments of this specification and is not intended to limit this specification. It will be apparent to those skilled in the art that various modifications and variations may be made to one or more embodiments of this specification. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of one or more embodiments of this specification are intended to be within the scope of the claims of this specification.
Claims
1. A method for describing network security alarm rules, characterized in that: Specifically include: Determine the matching degree of different preset network rules and focus on the determination of network rules by the types of historical attack behaviors matched by different preset network rules and the number of attacks of different types of historical attack behaviors; Determining a correlation coefficient between the preset network rule and other preset network rules by the types of historical attack behaviors that are simultaneously matched between the preset network rule and other preset network rules and the number of attacks of different types of historical attack behaviors, and determining the associated network rule of the focused network rule based on the correlation coefficient; Determine the network access behavior matching network rules based on the network traffic monitoring data, and use them as the matching network rules. Determine the initial access risk based on the number of matches, the degree of abnormality, and the matching data of the associated network rules of different matching associated network rules. If the initial access risk does not meet the requirements, proceed to the next step. A preset network rule matching the network access behavior is obtained and used as a matching network rule, and the access risk of the network access behavior is determined based on the matching degrees of different matching network rules and the correlation coefficients between different matching network rules.
2. The method for describing network security alarm rules according to claim 1, wherein: The preset network rules are determined according to the network rules of a preset network rule library.
3. The network security alarm rule description method according to claim 1, characterized in that: The matching degree of the preset network rule ranges from 0 to 1, wherein the greater the matching degree of the preset network rule, the more the preset network rule matches the historical attack behavior.
4. The method for describing network security alarm rules according to claim 1, wherein: The method for determining the correlation coefficient between the preset network rule and other preset network rules is: Determine a historical duration of simultaneous matching of the preset network rule and other preset network rules based on historical network traffic data, and use the duration as a historical association duration of the preset network rule and other preset network rules; When the proportion of the duration of historical attack behaviors in the historical association duration is less than the preset attack duration proportion, determining the correlation coefficient between the preset network rule and other preset network rules by using the preset correlation coefficient; When the proportion of the duration of historical attack behaviors in the historical association duration is not less than the preset attack duration proportion, the duration of historical attack behaviors that match the preset network rule and other preset network rules in the historical association duration is obtained and used as the associated attack behavior duration. When the associated attack behavior duration is greater than the preset duration, the association coefficient between the preset network rule and other preset network rules is determined based on the duration proportion. When the duration of the associated attack behavior is not greater than the preset duration: The historical attack behaviors that match the preset network rules and other preset network rules at the same time are used as the filtered historical attack behaviors, and the weight values of different types of filtered historical attack behaviors are determined by the attack duration and number of attacks of different types of filtered historical attack behaviors. The correlation coefficient between the preset network rules and other preset network rules is determined by the number and basic correlation coefficient of the weight values of different types of filtered historical attack behaviors.
5. The method for describing network security alarm rules according to claim 4, wherein: The preset duration ratio is determined according to the duration of the associated attack behavior, wherein the longer the duration of the associated attack behavior is, the smaller the preset duration ratio is.
6. The method for describing network security alarm rules according to claim 1, wherein: The method for determining the initial access risk is: Determining the number of matches of the associated network rules of the different matching network rules of interest based on the matching data of the associated network rules of the matching network rules of interest, and determining the matching risk level values of the different matching network rules of interest in combination with the abnormality levels of the different matching network rules of interest; The initial access risk is determined by using different matching risk degree values and matching quantities of the matching attention network rules.
7. The method for describing network security alarm rules according to claim 1, wherein: The value range of the initial access risk is between 0 and 1, wherein the greater the initial access risk, the greater the risk of the network access behavior corresponding to the network traffic.
8. A computer system comprising: A memory and a processor in communication connection, and a computer program stored in the memory and capable of running on the processor, characterized in that: when the processor runs the computer program, it executes a network security alarm rule description method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Network access management method, system and device and storage medium
CN110944007A
Network access control method and device, equipment and storage medium
CN117499148A