A method, device, equipment and storage medium for reducing noise of safety alarm data
By judging the target table entries in the dynamic table in the network security device and combining with the big model analysis, the problem of numerous alarm information and bypassing attacks is solved, the coverage and accuracy of alarms are improved, and the workload of security operation personnel is reduced.
Patent Information
- Application Number
- CN202510159028.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-12
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2045-02-12
AI Technical Summary
Existing network security equipment has a large number of false alarms when processing alarm information, which causes security operators to spend a lot of time screening and analyzing. A single alarm matching mechanism cannot accurately judge security behavior, which is one-sided, and attacks are easily bypassed.
By judging whether there are matching target table items in the dynamic table, if they exist, engineering judgment is carried out; if they do not exist, a preset big model is used to analyze and judge the target alarm data, and a target table item is generated in the dynamic table to determine the current judgment result of the alarm data and eliminate it.
It improves the coverage and accuracy of analysis and judgment alarms, identify important and real and effective alarms, reduces the workload of security operation personnel, and overcomes the problems of numerous alarm information and low large model coverage.
Smart Images

Figure CN119628971B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a security alarm data noise reduction method, device, equipment and storage medium. Background Art
[0002] There are many alarm messages generated by network security devices, including a large number of false alarms. Security operators need to spend a lot of time and energy to screen and analyze alarm messages to determine the real threats. At present, the alarms of existing research and judgment plans are automatically processed and noise-reduced through rule matching to reduce the workload of security operators and automatically generate noise reduction rules. However, when matching security alarms from the perspective of rule matching, many attacks are easily bypassed and the real attacks cannot be discovered more flexibly and accurately, resulting in the value of the alarm not being fully utilized. Therefore, a single alarm matching mechanism cannot accurately judge comprehensive security behaviors and is somewhat one-sided.
[0003] From the above, it can be seen that how to prevent attacks from being bypassed in order to improve the coverage of analysis and warning is an urgent problem to be solved. Summary of the invention
[0004] In view of this, the purpose of the present invention is to provide a security warning data noise reduction method, device, equipment and storage medium, which can prevent attacks from being bypassed to improve the coverage of judgment warnings. The specific scheme is as follows:
[0005] In a first aspect, the present application provides a method for reducing noise of security alarm data, comprising:
[0006] Determine whether there is a target table entry matching the currently acquired target alarm data in the locally pre-created dynamic table;
[0007] If a target table entry matching the target alarm data already exists in the dynamic table, the target alarm data is subjected to engineering analysis using the target table entry, so as to determine a current analysis result corresponding to the target alarm data based on the alarm data analysis result pre-recorded in the target table entry;
[0008] If there is no target table entry matching the target alarm data in the dynamic table, the target alarm data is analyzed and judged by using a preset large model to obtain a current judgment result corresponding to the target alarm data, and a target table entry corresponding to the target alarm data is generated in the dynamic table based on the current judgment result corresponding to the target alarm data;
[0009] Based on the current analysis result corresponding to the target alarm data, it is determined whether the target alarm data reaches a preset security threat level. If not, the target alarm data is eliminated.
[0010] Optionally, if there is no target table entry matching the target alarm data in the dynamic table, the target alarm data is analyzed and judged using a preset large model to obtain a current judgment result corresponding to the target alarm data, including:
[0011] If there is no target table entry matching the target alarm data in the dynamic table, feature extraction is performed on the target alarm data satisfying the first preset analysis condition to obtain first feature information;
[0012] Analyze and judge whether the target warning data is warning information corresponding to an active attack by using the first preset large model and the first characteristic information, so as to obtain a current judgment result corresponding to the target warning data;
[0013] Among them, the first preset analysis and judgment condition is that the alarm type corresponding to the target alarm data is one of network attack, vulnerability exploitation, and scanning behavior, and the target alarm data meets the preset application protocol condition.
[0014] Optionally, if there is no target table entry matching the target alarm data in the dynamic table, the target alarm data is analyzed and judged using a preset large model to obtain a current judgment result corresponding to the target alarm data, including:
[0015] If there is no target table entry matching the target alarm data in the dynamic table, the target alarm data meeting the second preset judgment condition is grouped based on the first preset grouping condition, and the response code corresponding to the target alarm data in each group, the IP address returned by the domain name server, and the alarm occurrence time are aggregated to obtain the second characteristic information;
[0016] Analyze and judge whether the target alarm data is alarm information corresponding to threat intelligence by using the second preset large model and the second characteristic information, so as to obtain a current judgment result corresponding to the target alarm data;
[0017] Among them, the first preset grouping condition is a condition for grouping based on the alarm type, application protocol, compromise indicator, source IP address and destination IP address of the target alarm data; the second preset analysis and judgment condition is that the alarm type corresponding to the target alarm data is one of malicious program and suspicious communication and the data flow direction of the target alarm data is the data flow direction corresponding to when any node inside the device accesses other nodes inside the device or the data flow direction corresponding to when a node inside the device accesses a node outside the device.
[0018] Optionally, if there is no target table entry matching the target alarm data in the dynamic table, the target alarm data is analyzed and judged using a preset large model to obtain a current judgment result corresponding to the target alarm data, including:
[0019] If there is no target table entry matching the target alarm data in the dynamic table, the target alarm data satisfying the third preset judgment condition is grouped based on the second preset grouping condition, and the response code corresponding to the target alarm data in each group, the IP address returned by the domain name server, the source IP address, and the alarm occurrence time are aggregated to obtain the third characteristic information;
[0020] Analyze and judge the access traffic type of the attacker corresponding to the target alarm data by using the third preset large model and the third characteristic information to obtain the current judgment result corresponding to the target alarm data; the access traffic type includes real attack traffic, harmless traffic and unknown traffic;
[0021] Among them, the second preset grouping condition is a condition for grouping based on the source IP address and data flow direction of the target alarm data; the third preset analysis condition is that the data flow direction of the target alarm data is the corresponding data flow direction when any node inside the device accesses other nodes inside the device or the corresponding data flow direction when a node outside the device accesses a node inside the device.
[0022] Optionally, after analyzing and judging the target warning data by using a preset large model to obtain a current judgment result corresponding to the target warning data, the method further includes:
[0023] If the current analysis result indicates that the access traffic type of the attacker corresponding to the target alarm data is unknown traffic, jump to the step of grouping the target alarm data that meets the third preset analysis condition based on the second preset grouping condition, and aggregating the response code corresponding to the target alarm data in each group, the IP address returned by the domain name server, the source IP address and the alarm occurrence time.
[0024] Optionally, if there is no target table entry matching the target alarm data in the dynamic table, the target alarm data is analyzed and judged by using a preset large model to obtain a current judgment result corresponding to the target alarm data, further comprising:
[0025] If the current analysis result characterizes that the access traffic type corresponding to the target alarm data is real attack traffic or harmless traffic, then the target alarm data corresponding to the current analysis result is obtained, and the process jumps to the step of performing engineering analysis on the target alarm data using the target table item, so as to determine the current analysis result corresponding to the target alarm data based on the alarm data analysis result pre-recorded in the target table item.
[0026] Optionally, generating a target table entry corresponding to the target alarm data based on a current analysis result corresponding to the target alarm data in the dynamic table includes:
[0027] If the current judgment result indicates that the access traffic type corresponding to the target alarm data is real attack traffic, the attack source IP address, data flow direction and the current judgment result of the target alarm data are extracted to generate a target table entry corresponding to the target alarm data in the dynamic table;
[0028] If the current analysis result indicates that the access traffic type corresponding to the target alarm data is harmless traffic, the alarm name, alarm type, application protocol, compromise indicator, source IP address and current analysis result of the target alarm data are extracted to generate a target table entry corresponding to the target alarm data in the dynamic table.
[0029] In a second aspect, the present application provides a security warning data noise reduction device, comprising:
[0030] An alarm data judgment module is used to judge whether there is a target table entry matching the currently acquired target alarm data in the locally pre-created dynamic table;
[0031] An alarm data analysis module, used for, if a target table entry matching the target alarm data already exists in the dynamic table, using the target table entry to perform engineering analysis on the target alarm data, so as to determine a current analysis result corresponding to the target alarm data based on the alarm data analysis result pre-recorded in the target table entry;
[0032] A target table item generation module is used for analyzing and judging the target alarm data using a preset large model to obtain a current judgment result corresponding to the target alarm data if there is no target table item matching the target alarm data in the dynamic table, and generating a target table item corresponding to the target alarm data in the dynamic table based on the current judgment result corresponding to the target alarm data;
[0033] The alarm data elimination module is used to determine whether the target alarm data reaches a preset security threat level based on the current analysis result corresponding to the target alarm data. If not, the target alarm data is eliminated.
[0034] In a third aspect, the present application provides an electronic device, including:
[0035] Memory, used to store computer programs;
[0036] The processor is used to execute the computer program to implement the aforementioned safety warning data noise reduction method.
[0037] In a fourth aspect, the present application provides a computer-readable storage medium for storing a computer program, wherein the computer program implements the aforementioned security alarm data noise reduction method when executed by a processor.
[0038] The present application determines whether there is a target table entry that matches the currently acquired target alarm data in a locally pre-created dynamic table; if there is a target table entry that matches the target alarm data in the dynamic table, the target table entry is used to perform engineering analysis on the target alarm data, so as to determine the current analysis result corresponding to the target alarm data based on the alarm data analysis result pre-recorded in the target table entry; if there is no target table entry that matches the target alarm data in the dynamic table, the target alarm data is analyzed and judged using a preset large model to obtain the current analysis result corresponding to the target alarm data, and a target table entry corresponding to the target alarm data is generated in the dynamic table based on the current analysis result corresponding to the target alarm data; based on the current analysis result corresponding to the target alarm data, it is determined whether the target alarm data reaches a preset security threat level, and if not, the target alarm data is eliminated.
[0039] As can be seen from the above, the present application performs engineering analysis on the target alarm data for the target table items corresponding to the target alarm data in the dynamic table. If there is no target table item matching the target alarm data in the dynamic table, the target alarm data is analyzed and judged using a preset large model. In this way, the alarm is judged through the large model analysis results combined with engineering analysis, which not only overcomes the problem of too much alarm information and low coverage of the large model, but also improves the accuracy and coverage of alarm analysis, and implements noise reduction on alarms to identify important and real and effective alarms, thereby reducing the workload of security operators. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying creative work.
[0041] Figure 1 A flow chart of a method for reducing noise of safety warning data disclosed in this application;
[0042] Figure 2 A flow chart of a specific method for reducing noise of safety warning data disclosed in this application;
[0043] Figure 3 A schematic diagram of matching a dynamic table and target warning data disclosed in this application;
[0044] Figure 4 A schematic diagram of a large model analysis and judgment disclosed in this application;
[0045] Figure 5 This is a schematic diagram of an engineering research and judgment disclosed in this application;
[0046] Figure 6 A schematic diagram of a security alarm processing disclosed in this application;
[0047] Figure 7 This is a schematic diagram of the structure of a safety warning data noise reduction device disclosed in this application;
[0048] Figure 8 This is a structural diagram of an electronic device disclosed in this application. DETAILED DESCRIPTION
[0049] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0050] At present, the alarms of existing analysis and judgment schemes are automatically handled and noise-reduced through rule matching. By reducing the workload of security operators, noise reduction rules can be automatically generated. However, many attacks are easily bypassed and it is impossible to discover real attacks more flexibly and accurately, resulting in the value of alarms not being fully utilized. Therefore, a single alarm matching mechanism cannot accurately judge comprehensive security behaviors and has a certain one-sidedness. To this end, the present application provides a method for reducing the noise of security alarm data, which uses the results of large model analysis and combined with engineering analysis to judge alarms. It not only overcomes the problems of numerous alarm information and low coverage of large models, but also improves the accuracy and coverage of alarm analysis, and reduces the noise of alarms to identify important and real and effective alarms, thereby reducing the workload of security operators.
[0051] See also Figure 1 As shown, an embodiment of the present invention discloses a method for reducing noise of security alarm data, comprising:
[0052] Step S11: determine whether there is a target table entry matching the currently acquired target alarm data in the locally pre-created dynamic table.
[0053] In this embodiment, a preset monitoring device is used to collect target alarm data of a target device. After the target alarm data is obtained, a locally pre-created dynamic table is used to determine whether there is a target table entry in the dynamic table that matches the target alarm data. The dynamic table is a dynamic table corresponding to the target alarm data generated by analyzing and judging the target alarm data using a preset large model to obtain a current judgment result, and the dynamic table includes a plurality of target table entries corresponding to the target alarm data.
[0054] Step S12: If a target table entry matching the target alarm data already exists in the dynamic table, the target table entry is used to perform engineering analysis on the target alarm data so as to determine the current analysis result corresponding to the target alarm data based on the alarm data analysis result pre-recorded in the target table entry.
[0055] In this embodiment, if a target table entry matching the target alarm data already exists in the dynamic table, the target table entry matching the target alarm data is queried from the dynamic table, and the alarm data analysis result corresponding to the preset target alarm data pre-recorded in the target table entry is read, so as to perform engineering analysis on the target alarm data based on the alarm data analysis result, so as to obtain the current analysis result corresponding to the target alarm data.
[0056] Step S13: If there is no target table entry matching the target alarm data in the dynamic table, the target alarm data is analyzed and judged using a preset large model to obtain a current judgment result corresponding to the target alarm data, and a target table entry corresponding to the target alarm data is generated in the dynamic table based on the current judgment result corresponding to the target alarm data.
[0057] In this embodiment, if there is no target table entry matching the target alarm data in the dynamic table, different preset large models are used to analyze and judge the target alarm data that meets the corresponding preset judgment conditions to obtain the current judgment result corresponding to the target alarm data. After obtaining the current judgment result, a target table entry corresponding to the target alarm data is generated in the dynamic table based on the current judgment result.
[0058] In a first specific implementation manner, if there is no target table entry matching the target alarm data in the dynamic table, then the target alarm data whose alarm type is Web (World Wide Web) attack, vulnerability exploitation, scanning behavior, etc., and which complies with the application protocol of HTTP (Hypertext Transfer Protocol) or HTTPS (Hypertext Transfer Protocol Secure) or HTTP2 (Hypertext Transfer Protocol version 2), and which has not been engineered or the current judgment result indicates that the access traffic type corresponding to the target alarm data is real attack traffic, is subjected to feature extraction to obtain first feature information, and then a first preset large model and the first feature information are used to analyze and judge whether the target alarm data is alarm information corresponding to an active attack to obtain the current judgment result. Specifically, if there is no target table entry matching the target alarm data in the dynamic table, the target alarm data is analyzed and judged using a preset large model to obtain a current judgment result corresponding to the target alarm data, including: if there is no target table entry matching the target alarm data in the dynamic table, feature extraction is performed on the target alarm data that meets the first preset judgment condition to obtain first feature information, and the first preset large model and the first feature information are used to analyze and judge whether the target alarm data is the alarm information corresponding to an active attack to obtain the current judgment result corresponding to the target alarm data; wherein, the first preset judgment condition is that the alarm type corresponding to the target alarm data is one of network attack, vulnerability exploitation, and scanning behavior, and the target alarm data meets the preset application protocol condition.
[0059] In a second specific implementation, if there is no target table entry matching the target alarm data in the dynamic table, based on the alarm type, application protocol, compromise indicator, source IP address (Internet Protocol Address) and destination IP address of the target alarm data, the target alarm data whose alarm type is malicious program, suspicious communication type and whose data flow direction is the data flow direction corresponding to when any node inside the device accesses other nodes inside the device or the data flow direction corresponding to when a node inside the device accesses a node outside the device is grouped, and based on the first preset periodic condition, the response code corresponding to the target alarm data in each group, the IP address returned by the domain name server and the alarm occurrence time are aggregated to obtain second feature information, and then the second preset large model and the second feature information are used to analyze and judge whether the target alarm data is the alarm information corresponding to the threat intelligence to obtain the current judgment result.
[0060] Specifically, if there is no target table item matching the target alarm data in the dynamic table, the target alarm data is analyzed and judged by using a preset large model to obtain a current judgment result corresponding to the target alarm data, including: if there is no target table item matching the target alarm data in the dynamic table, the target alarm data that meets the second preset judgment condition is grouped based on a first preset grouping condition, and the response code corresponding to the target alarm data in each group, the IP address returned by the domain name server, and the alarm occurrence time are aggregated to obtain the second feature information; the second preset large model and the second feature information are used to group the target alarm data; The target alarm data is analyzed and judged whether it is the alarm information corresponding to the threat intelligence, so as to obtain the current judgment result corresponding to the target alarm data; wherein, the first preset grouping condition is a condition for grouping based on the alarm type, application protocol, compromise indicator, source IP address and destination IP address of the target alarm data; the second preset judgment condition is that the alarm type corresponding to the target alarm data is one of malicious program and suspicious communication and the data flow direction of the target alarm data is the data flow direction corresponding to the access of any node inside the device to other nodes inside the device or the data flow direction corresponding to the access of the node inside the device to the node outside the device.
[0061] In a third specific implementation, if there is no target table entry matching the target alarm data in the dynamic table, then based on the source IP address and data flow direction of the target alarm data, the target alarm data whose data flow direction is the corresponding data flow direction when any node inside the device accesses other nodes inside the device or the corresponding data flow direction when a node outside the device accesses a node inside the device is grouped, and based on the second preset periodic condition, the response code corresponding to the target alarm data in each group, the response IP returned by the DNS (Domain Name Server, i.e., domain name server), the source IP address, and the alarm occurrence time are aggregated to obtain the third characteristic information, and the third preset large model and the third characteristic information are used to analyze and judge the access traffic type of the attacker corresponding to the target alarm data to obtain the current judgment interception. It should be pointed out that the first preset periodic condition and the second preset periodic condition can be configured as 30 minutes, and can also be adjusted accordingly according to the actual situation, which is not specifically limited here.
[0062] Specifically, if there is no target table entry matching the target alarm data in the dynamic table, the target alarm data is analyzed and judged using the preset large model to obtain the current judgment result corresponding to the target alarm data, including: if there is no target table entry matching the target alarm data in the dynamic table, the target alarm data that meets the third preset judgment condition is grouped based on the second preset grouping condition, and the response code corresponding to the target alarm data in each group, the IP address returned by the domain name server, the source IP address and the alarm occurrence time are aggregated to obtain the third characteristic information; using the third preset The large model and the third characteristic information analyze and judge the access traffic type of the attacker corresponding to the target alarm data to obtain the current judgment result corresponding to the target alarm data; the access traffic type includes real attack traffic, harmless traffic and unknown traffic; wherein, the second preset grouping condition is a condition for grouping based on the source IP address and data flow direction of the target alarm data; the third preset judgment condition is that the data flow direction of the target alarm data is the data flow direction corresponding to when any node inside the device accesses other nodes inside the device or the data flow direction corresponding to when a node outside the device accesses a node inside the device.
[0063] In this embodiment, when analyzing and judging the access traffic type of the attacker corresponding to the target alarm data using the third preset large model and the third characteristic information, if the current judgment result corresponding to the target alarm data indicates that the access traffic type of the attacker corresponding to the target alarm data is unknown traffic, the target alarm data corresponding to the unknown traffic is analyzed and judged again in a loop until the current judgment result indicates that the access traffic type corresponding to the target alarm data is real attack traffic or harmless traffic. Specifically, after analyzing and judging the target alarm data using the preset large model to obtain the current judgment result corresponding to the target alarm data, it also includes: if the current judgment result indicates that the access traffic type of the attacker corresponding to the target alarm data is unknown traffic, jump to the step of grouping the target alarm data that meets the third preset judgment condition based on the second preset grouping condition, and aggregating the response code corresponding to the target alarm data in each group, the IP address returned by the domain name server, the source IP address, and the alarm occurrence time.
[0064] It can be understood that when the access traffic type of the attacker corresponding to the target alarm data is analyzed and judged using the third preset large model and the third characteristic information, if the current judgment result corresponding to the target alarm data obtained characterizes that the access traffic type of the attacker corresponding to the target alarm data is real attack traffic or harmless traffic, then the corresponding target alarm data is obtained, and the target alarm data is passed to the engineering judgment. Specifically, if there is no target table item matching the target alarm data in the dynamic table, then the target alarm data is analyzed and judged using the preset large model to obtain the current judgment result corresponding to the target alarm data, and it also includes: if the current judgment result characterizes that the access traffic type corresponding to the target alarm data is real attack traffic or harmless traffic, then the target alarm data corresponding to the current judgment result is obtained, and jumps to the step of using the target table item to perform engineering judgment on the target alarm data, so as to determine the current judgment result corresponding to the target alarm data based on the alarm data judgment result pre-recorded in the target table item.
[0065] Furthermore, if the current analysis and judgment result indicates that the access traffic type corresponding to the target alarm data is real attack traffic, the attack source IP address, data flow direction and the current analysis and judgment result of the target alarm data are extracted to form a target table entry corresponding to the target alarm data in the dynamic table; if the current analysis and judgment result indicates that the access traffic type corresponding to the target alarm data is harmless traffic, the alarm name, alarm type, application protocol, compromise indicator, source IP address and the current analysis and judgment result of the target alarm data are extracted to form a target table entry corresponding to the target alarm data in the dynamic table. Specifically, the target table entry corresponding to the target alarm data is generated in the dynamic table based on the current analysis result corresponding to the target alarm data, including: if the current analysis result indicates that the access traffic type corresponding to the target alarm data is real attack traffic, the attack source IP address, data flow direction and the current analysis result of the target alarm data are extracted to generate a target table entry corresponding to the target alarm data in the dynamic table; if the current analysis result indicates that the access traffic type corresponding to the target alarm data is harmless traffic, the alarm name, alarm type, application protocol, compromise indicator, source IP address and the current analysis result of the target alarm data are extracted to generate a target table entry corresponding to the target alarm data in the dynamic table.
[0066] Step S14: determine whether the target alarm data reaches a preset security threat level based on the current analysis result corresponding to the target alarm data; if not, remove the target alarm data.
[0067] In this embodiment, if the current analysis result corresponding to the target alarm data determines whether the target alarm data reaches a preset security threat level, if the target alarm data reaches the preset security threat level, the target alarm data is automatically disposed of using a third-party device or SOAR (Security Orchestration, Automation and Response), and the traffic information corresponding to the actual attack traffic corresponding to the target alarm data can be logged, or a blocking strategy can be formulated according to the attack nature and severity of the target alarm data. For example, for IP addresses that frequently launch attacks, a permanent ban can be implemented or the blocking status can be re-evaluated regularly; if the target alarm data does not reach the preset security threat level, the target alarm data is eliminated, a preset whitelist database can be created, and the target alarm data that does not reach the preset security threat level can be stored, and the preset whitelist database can be updated regularly according to actual business needs.
[0068] As can be seen from the above, the present application performs engineering analysis on the target alarm data for the target table items corresponding to the target alarm data in the dynamic table. If there is no target table item matching the target alarm data in the dynamic table, the target alarm data is analyzed and judged using a preset large model. In this way, the alarm is judged through the large model analysis results combined with engineering analysis, which not only overcomes the problem of too much alarm information and low coverage of the large model, but also improves the accuracy and coverage of alarm analysis, and implements noise reduction on alarms to identify important and real and effective alarms, thereby reducing the workload of security operators.
[0069] It can be seen from the above embodiments that the present application analyzes and issues alarms based on the results of large model analysis and combines them with engineering analysis to improve the accuracy and coverage of alarm analysis. Therefore, the process of analyzing and issuing alarms based on the results of large model analysis and combines them with engineering analysis is described.
[0070] See also Figure 2 As shown, the embodiment of the present invention discloses a specific method for reducing noise of security alarm data, including:
[0071] In this embodiment, the target alarm data is first obtained, and it is determined whether there is a target table entry matching the target alarm data in the locally pre-created dynamic table. Figure 3 A schematic diagram of matching a dynamic table and target alarm data provided for this embodiment. If there is a target table item matching the target alarm data in the dynamic table, the target alarm data is subjected to engineering analysis using the target table item, so as to determine the current analysis result corresponding to the target alarm data based on the analysis result of the alarm data corresponding to the target table item; if there is no target table item matching the target alarm data in the dynamic table, the target alarm data is analyzed and judged using a preset large model.
[0072] Figure 4 A schematic diagram of a large model analysis and judgment provided for this embodiment, using a preset large model to analyze and judge the target alarm data, including analyzing and judging whether the target alarm data is alarm information corresponding to an active attack, analyzing and judging whether the target alarm data is alarm information corresponding to threat intelligence, and analyzing and judging the access traffic type of the attacker corresponding to the target alarm data, so as to obtain a current judgment result corresponding to the target alarm data.
[0073] Figure 5An engineering analysis schematic diagram is provided for this embodiment. If the current analysis result characterizes that the access traffic type corresponding to the target alarm data is real attack traffic or harmless traffic, the target alarm data corresponding to the current analysis result is passed to the engineering analysis, so as to extract the attack source IP address, data flow direction and the current analysis result of the target alarm data based on the current analysis result characterizing that the access traffic type corresponding to the target alarm data is real attack traffic, so as to generate a target table entry corresponding to the target alarm data in the dynamic table; or based on the current analysis result characterizing that the access traffic type corresponding to the target alarm data is harmless traffic, the alarm name, alarm type, application protocol, compromise indicator, source IP address and the current analysis result of the target alarm data are extracted to generate a target table entry corresponding to the target alarm data in the dynamic table. Figure 6 A schematic diagram of security alarm processing is provided for this embodiment, which extracts the target alarm data based on the current analysis result to form an alarm to be processed, and uses a third-party device or SOAR to automatically handle the alarm.
[0074] As can be seen from the above, this embodiment uses a preset large model to analyze and judge the target alarm data, and forms an engineering judgment capability by combining the judgment results of the large model, thereby reducing the performance load on the large model, so that the large model can be used to judge more data, so as to identify important and real and effective alarms, reduce the workload of security operations personnel, and improve the accuracy and coverage of alarm judgment.
[0075] Accordingly, see Figure 7 As shown, the present application also provides a safety warning data noise reduction device, comprising:
[0076] An alarm data determination module 11 is used to determine whether there is a target table entry matching the currently acquired target alarm data in a locally pre-created dynamic table;
[0077] The alarm data analysis module 12 is used to perform engineering analysis on the target alarm data using the target table item if a target table item matching the target alarm data already exists in the dynamic table, so as to determine the current analysis result corresponding to the target alarm data based on the alarm data analysis result pre-recorded in the target table item;
[0078] A target table item generating module 13 is used for analyzing and judging the target alarm data by using a preset large model to obtain a current judgment result corresponding to the target alarm data if there is no target table item matching the target alarm data in the dynamic table, and generating a target table item corresponding to the target alarm data in the dynamic table based on the current judgment result corresponding to the target alarm data;
[0079] The alarm data elimination module 14 is used to determine whether the target alarm data reaches a preset security threat level based on the current analysis result corresponding to the target alarm data, and if not, eliminate the target alarm data.
[0080] As can be seen from the above, the present application performs engineering analysis on the target alarm data for the target table items corresponding to the target alarm data in the dynamic table. If there is no target table item matching the target alarm data in the dynamic table, the target alarm data is analyzed and judged using a preset large model. In this way, the alarm is judged through the large model analysis results combined with engineering analysis, which not only overcomes the problem of too much alarm information and low coverage of the large model, but also improves the accuracy and coverage of alarm analysis, and implements noise reduction on alarms to identify important and real and effective alarms, thereby reducing the workload of security operators.
[0081] In some specific implementations, the target entry generation module 13 may specifically include:
[0082] A first feature information acquisition unit, configured to extract features of the target warning data that meets a first preset judgment condition to obtain first feature information if there is no target table entry matching the target warning data in the dynamic table;
[0083] The first analysis and judgment unit is used to analyze and judge whether the target warning data is warning information corresponding to an active attack by using a first preset large model and the first characteristic information, so as to obtain a current judgment result corresponding to the target warning data.
[0084] In some specific implementations, the target entry generation module 13 may specifically include:
[0085] A second characteristic information acquisition unit is used for grouping the target alarm data that meets the second preset judgment condition based on the first preset grouping condition if there is no target table entry matching the target alarm data in the dynamic table, and aggregating the response code corresponding to the target alarm data in each group, the IP address returned by the domain name server, and the alarm occurrence time to obtain the second characteristic information;
[0086] The second analysis and judgment unit is used to analyze and judge whether the target alarm data is the alarm information corresponding to the threat intelligence by using the second preset large model and the second characteristic information, so as to obtain the current judgment result corresponding to the target alarm data.
[0087] In some specific implementations, the target entry generation module 13 may specifically include:
[0088] A third characteristic information acquisition unit is used for grouping the target alarm data that meets the third preset judgment condition based on the second preset grouping condition if there is no target table entry matching the target alarm data in the dynamic table, and aggregating the response code corresponding to the target alarm data in each group, the IP address returned by the domain name server, the source IP address, and the alarm occurrence time to obtain the third characteristic information;
[0089] The third analysis and judgment unit is used to analyze and judge the access traffic type of the attacker corresponding to the target alarm data using the third preset large model and the third characteristic information to obtain the current judgment result corresponding to the target alarm data; the access traffic type includes real attack traffic, harmless traffic and unknown traffic.
[0090] In some specific implementations, the security warning data noise reduction device may further include:
[0091] The first traffic type determination unit is used to jump to the step of grouping the target alarm data that meets the third preset analysis condition based on the second preset grouping condition if the current analysis result indicates that the access traffic type of the attacker corresponding to the target alarm data is unknown traffic, and aggregating the response code corresponding to the target alarm data in each group, the IP address returned by the domain name server, the source IP address and the alarm occurrence time.
[0092] In some specific implementations, the security warning data noise reduction device may further include:
[0093] The second traffic type determination unit is used to obtain the target alarm data corresponding to the current analysis result if the current analysis result characterizes that the access traffic type corresponding to the target alarm data is real attack traffic or harmless traffic, and jump to the step of using the target table item to perform engineering analysis on the target alarm data, so as to determine the current analysis result corresponding to the target alarm data based on the alarm data analysis result pre-recorded in the target table item.
[0094] In some specific implementations, the target entry generation module 13 may specifically include:
[0095] A first data extraction unit is used to extract the attack source IP address, data flow direction and the current judgment result of the target alarm data if the current judgment result indicates that the access traffic type corresponding to the target alarm data is real attack traffic, so as to generate a target table entry corresponding to the target alarm data in the dynamic table;
[0096] The second data extraction unit is used to extract the alarm name, alarm type, application protocol, compromise indicator, source IP address and current judgment result of the target alarm data if the current judgment result indicates that the access traffic type corresponding to the target alarm data is harmless traffic, so as to generate a target table entry corresponding to the target alarm data in the dynamic table.
[0097] Furthermore, the present application also discloses an electronic device. Figure 8 It is a structural diagram of an electronic device 20 shown according to an exemplary embodiment, and the content in the figure cannot be regarded as any limitation on the scope of use of this application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input and output interface 25 and a communication bus 26. Among them, the memory 22 is used to store a computer program, and the computer program is loaded and executed by the processor 21 to implement the relevant steps in the safety warning data denoising method disclosed in any of the aforementioned embodiments. In addition, the electronic device 20 in this embodiment may specifically be an electronic computer.
[0098] In this embodiment, the power supply 23 is used to provide working voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and the external device, and the communication protocol it follows is any communication protocol that can be applied to the technical solution of the present application, and is not specifically limited here; the input and output interface 25 is used to obtain external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs and is not specifically limited here.
[0099] In addition, the memory 22, as a carrier for storing resources, can be a read-only memory, a random access memory, a disk or an optical disk, etc. The resources stored thereon can include an operating system 221, a computer program 222, etc., and the storage method can be temporary storage or permanent storage.
[0100] The operating system 221 is used to manage and control the hardware devices and computer program 222 on the electronic device 20, which can be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program that can be used to complete the security warning data noise reduction method performed by the electronic device 20 disclosed in any of the aforementioned embodiments, the computer program 222 can further include a computer program that can be used to complete other specific tasks.
[0101] Furthermore, the present application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the aforementioned disclosed safety warning data noise reduction method is implemented. The specific steps of the method can refer to the corresponding contents disclosed in the aforementioned embodiments, and will not be repeated here.
[0102] In this specification, each embodiment is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part.
[0103] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in the above description according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0104] The steps of the method or algorithm described in conjunction with the embodiments disclosed herein may be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.
[0105] Finally, it should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the presence of other identical elements in the process, method, article or device including the elements.
[0106] The technical solution provided by the present application is introduced in detail above. Specific examples are used in this article to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea. At the same time, for general technicians in this field, according to the idea of the present application, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.
Claims
1. A method for reducing noise of security alarm data, characterized in that: include: Determine whether there is a target table entry matching the currently acquired target alarm data in the locally pre-created dynamic table; If a target table entry matching the target alarm data already exists in the dynamic table, the target alarm data is subjected to engineering analysis using the target table entry, so as to determine a current analysis result corresponding to the target alarm data based on the alarm data analysis result pre-recorded in the target table entry; If there is no target table entry matching the target alarm data in the dynamic table, the target alarm data is analyzed and judged by using a preset large model to obtain a current judgment result corresponding to the target alarm data, and a target table entry corresponding to the target alarm data is generated in the dynamic table based on the current judgment result corresponding to the target alarm data; Determine whether the target warning data reaches a preset security threat level based on the current analysis result corresponding to the target warning data, and if not, remove the target warning data; Wherein, if there is no target table item matching the target alarm data in the dynamic table, the target alarm data is analyzed and judged by using the preset large model to obtain the current judgment result corresponding to the target alarm data, including: if there is no target table item matching the target alarm data in the dynamic table, the target alarm data satisfying the second preset judgment condition is grouped based on the first preset grouping condition, and the response code corresponding to the target alarm data in each group, the IP address returned by the domain name server, and the alarm occurrence time are aggregated to obtain the second characteristic information; the target alarm data is grouped by using the second preset large model and the second characteristic information; The target alarm data is analyzed and judged whether it is the alarm information corresponding to the threat intelligence, so as to obtain the current judgment result corresponding to the target alarm data; wherein the first preset grouping condition is a condition for grouping based on the alarm type, application protocol, compromise indicator, source IP address and destination IP address of the target alarm data; the second preset judgment condition is that the alarm type corresponding to the target alarm data is one of malicious program and suspicious communication and the data flow direction of the target alarm data is the data flow direction corresponding to when any node inside the device accesses other nodes inside the device or the data flow direction corresponding to when a node inside the device accesses a node outside the device; Or, if there is no target table entry matching the target alarm data in the dynamic table, the target alarm data that meets the third preset judgment condition is grouped based on the second preset grouping condition, and the response code corresponding to the target alarm data in each group, the IP address returned by the domain name server, the source IP address and the alarm occurrence time are aggregated to obtain the third characteristic information; the access traffic type of the attacker corresponding to the target alarm data is analyzed and judged using the third preset large model and the third characteristic information to obtain the current judgment result corresponding to the target alarm data; the access traffic type includes real attack traffic, harmless traffic and unknown traffic; wherein the second preset grouping condition is a condition for grouping based on the source IP address and data flow direction of the target alarm data; the third preset judgment condition is that the data flow direction of the target alarm data is the corresponding data flow direction when any node inside the device accesses other nodes inside the device or the corresponding data flow direction when a node outside the device accesses a node inside the device.
2. The method for reducing noise of security alarm data according to claim 1, characterized in that: After analyzing and judging the target warning data by using the preset large model to obtain the current judgment result corresponding to the target warning data, the method further includes: If the current analysis result indicates that the access traffic type of the attacker corresponding to the target alarm data is unknown traffic, jump to the step of grouping the target alarm data that meets the third preset analysis condition based on the second preset grouping condition, and aggregating the response code corresponding to the target alarm data in each group, the IP address returned by the domain name server, the source IP address and the alarm occurrence time.
3. The method for reducing noise of security alarm data according to claim 1, characterized in that: If there is no target table entry matching the target alarm data in the dynamic table, the target alarm data is analyzed and judged by using a preset large model to obtain a current judgment result corresponding to the target alarm data, and further includes: If the current analysis result characterizes that the access traffic type corresponding to the target alarm data is real attack traffic or harmless traffic, then the target alarm data corresponding to the current analysis result is obtained, and the process jumps to the step of performing engineering analysis on the target alarm data using the target table item, so as to determine the current analysis result corresponding to the target alarm data based on the alarm data analysis result pre-recorded in the target table item.
4. The method for reducing noise of security warning data according to any one of claims 1 to 3, characterized in that: The generating of a target table entry corresponding to the target alarm data based on the current analysis result corresponding to the target alarm data in the dynamic table includes: If the current judgment result indicates that the access traffic type corresponding to the target alarm data is real attack traffic, the attack source IP address, data flow direction and the current judgment result of the target alarm data are extracted to generate a target table entry corresponding to the target alarm data in the dynamic table; If the current analysis result indicates that the access traffic type corresponding to the target alarm data is harmless traffic, the alarm name, alarm type, application protocol, compromise indicator, source IP address and current analysis result of the target alarm data are extracted to generate a target table entry corresponding to the target alarm data in the dynamic table.
5. A safety warning data noise reduction device, characterized in that: include: An alarm data judgment module is used to judge whether there is a target table entry matching the currently acquired target alarm data in the locally pre-created dynamic table; An alarm data analysis module, used for, if a target table entry matching the target alarm data already exists in the dynamic table, using the target table entry to perform engineering analysis on the target alarm data, so as to determine a current analysis result corresponding to the target alarm data based on the alarm data analysis result pre-recorded in the target table entry; A target table item generation module is used for analyzing and judging the target alarm data using a preset large model to obtain a current judgment result corresponding to the target alarm data if there is no target table item matching the target alarm data in the dynamic table, and generating a target table item corresponding to the target alarm data in the dynamic table based on the current judgment result corresponding to the target alarm data; An alarm data elimination module is used to determine whether the target alarm data reaches a preset security threat level based on the current analysis result corresponding to the target alarm data, and if not, eliminate the target alarm data; Among them, the target table entry generation module is specifically used to group the target alarm data that meets the second preset judgment condition based on the first preset grouping condition if there is no target table entry matching the target alarm data in the dynamic table, and obtain the second characteristic information by aggregating the response code corresponding to the target alarm data in each group, the IP address returned by the domain name server, and the alarm occurrence time; use the second preset large model and the second characteristic information to analyze and judge whether the target alarm data is the alarm information corresponding to the threat intelligence, so as to obtain the current judgment result corresponding to the target alarm data; wherein, the first preset grouping condition is a condition for grouping based on the alarm type, application protocol, compromise indicator, source IP address and destination IP address of the target alarm data; the second preset judgment condition is that the alarm type corresponding to the target alarm data is one of malicious program and suspicious communication and the data flow direction of the target alarm data is the corresponding data flow direction when any node inside the device accesses other nodes inside the device or the internal node of the device accesses the external node of the device. The data flow direction corresponding to the row access; or, specifically used for grouping the target alarm data that meets the third preset judgment condition based on the second preset grouping condition if there is no target table entry matching the target alarm data in the dynamic table, and aggregating the response code corresponding to the target alarm data in each group, the IP address returned by the domain name server, the source IP address and the alarm occurrence time to obtain the third characteristic information; using the third preset large model and the third characteristic information to analyze and judge the access traffic type of the attacker corresponding to the target alarm data to obtain the current judgment result corresponding to the target alarm data; the access traffic type includes real attack traffic, harmless traffic and unknown traffic; wherein, the second preset grouping condition is a condition for grouping based on the source IP address and data flow direction of the target alarm data; the third preset judgment condition is that the data flow direction of the target alarm data is the data flow direction corresponding to the access of any node inside the device to other nodes inside the device or the data flow direction corresponding to the access of a node outside the device to a node inside the device.
6. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor is used to execute the computer program to implement the security warning data denoising method as described in any one of claims 1 to 4.
7. A computer-readable storage medium, characterized in that: Used to store a computer program, wherein when the computer program is executed by a processor, the safety warning data denoising method according to any one of claims 1 to 4 is implemented.
Citation Information
Patent Citations
Log noise reduction method and electronic equipment
CN116991680A
Network security alarm automatic studying and judging method, device, equipment and medium
CN119402282A
Alarm data processing method and device, electronic equipment and storage medium
CN119416267A