An alarm data reduction method, apparatus, device, medium and product

By calculating the danger score of the device and analyzing the attack path based on the network topology, alarm data unrelated to the attack path is reduced, which solves the problems of poor false alarm reduction and high operational pressure in the existing technology, and improves the accuracy and efficiency of alarm data.

CN119766624BActive Publication Date: 2025-11-21SANGFOR TECH INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411998800.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-31
Publication Date
2025-11-21
Estimated Expiration
2044-12-31

AI Technical Summary

Technical Problem

Existing technologies are ineffective in reducing false alarms and face significant operational challenges in large-scale scenarios, lacking a dynamic and global perspective for analysis.

Method used

By acquiring alarm data and device information, a risk score is calculated, and attack paths are determined based on the network topology map, thus reducing alarm data that is irrelevant to the attack paths.

Benefits of technology

It has achieved precise reduction of alarm data, reduced the possibility of false alarms, and improved the accuracy of alarm data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119766624B_ABST
    Figure CN119766624B_ABST
Patent Text Reader

Abstract

The application relates to the field of network security, and in particular to an alarm data reduction method and device, equipment, medium and product. The method comprises the following steps: acquiring alarm data and device information corresponding to a plurality of devices in a current time window; performing a danger score on each device according to the alarm data and the device information, which can quantitatively evaluate the potential risk of the device; based on the danger score, screening a plurality of target attack paths from a plurality of possible attack paths determined according to a target device network topology diagram; and reducing the alarm data corresponding to the devices irrelevant to the target attack paths according to the node devices corresponding to each target attack path. The application determines a quantitative value of the device by combining the alarm data and the device information, dynamically evaluates the risk path and the key node from a whole perspective, predicts a maximum probability attack path, reduces the alarm data, greatly reduces the possibility of false positives, and makes the final alarm data more accurate.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of network security, and in particular, to an alarm data reduction method, device, equipment, medium and product. BACKGROUND

[0002] With the rapid development of information technology, various monitoring systems play an increasingly important role in various industries. These systems can monitor various indicators in real time and issue alarms when abnormalities occur, thereby helping operation and maintenance personnel to discover and handle problems in a timely manner.

[0003] Through research on existing technologies in the industry, it is found that current false alarm reduction mainly relies on time series anomaly analysis and simple rule merging. Time series anomaly analysis identifies abnormal points that deviate from the normal mode through analysis of time series data, thereby reducing false alarms. Simple rule merging merges multiple alarm rules to reduce repeated alarms. The above-mentioned technologies only reduce alarms from time series anomaly analysis or rely heavily on expert rules, resulting in poor false alarm reduction effect. SUMMARY

[0004] The purpose of the present application is to provide an alarm data reduction method, device, equipment, medium and product, which can improve the false alarm reduction effect.

[0005] In a first aspect, an alarm data reduction method is provided, comprising:

[0006] Obtaining a plurality of alarm data corresponding to a plurality of devices in a current time window and device information corresponding to the plurality of devices;

[0007] Determining a danger score corresponding to each of the plurality of devices according to the plurality of alarm data corresponding to each of the plurality of devices and the device information corresponding to each of the plurality of devices;

[0008] Determining a plurality of target attack paths from a plurality of attack paths according to the danger score corresponding to each of the plurality of devices, wherein the plurality of attack paths are a plurality of attack paths that an attacker can reach according to a target device network topology graph, and each attack path includes a plurality of node devices;

[0009] Reducing alarm data corresponding to other devices in the plurality of alarm data according to the node devices corresponding to each target attack path, wherein the other devices are devices other than the node devices corresponding to the target attack path in the plurality of devices.

[0010] In a preferred example, the present application can be further configured to obtain a plurality of alarm data corresponding to a plurality of devices in a current time window, comprising:

[0011] obtain a plurality of initial alarm data corresponding to each of a plurality of devices in a current time window;

[0012] perform category division on the plurality of initial alarm data corresponding to a target device to obtain a plurality of alarm categories, wherein the target device is any one of the plurality of devices, and each alarm category includes at least one initial alarm data;

[0013] determine feature information corresponding to each of the plurality of alarm categories, and perform filtering processing on the plurality of initial alarm data corresponding to the target device according to the feature information corresponding to each of the plurality of alarm categories to obtain a plurality of alarm data corresponding to the target device.

[0014] In a preferred example, the feature information includes frequency, time, and periodicity.

[0015] The filtering processing on the plurality of initial alarm data corresponding to the target device according to the feature information corresponding to each of the plurality of alarm categories to obtain a plurality of alarm data corresponding to the target device includes:

[0016] When a target alarm category meets a first condition, determine first initial alarm data corresponding to the target alarm category, wherein the target alarm category is any one of the plurality of alarm categories, and the first condition is that the time of the target alarm category exceeds a time threshold, or the target alarm category has periodicity.

[0017] When the frequency of the target alarm category is greater than a preset frequency threshold, determine second initial alarm data of the target alarm category.

[0018] Process the plurality of initial alarm data corresponding to the target device to delete the first initial alarm data in the plurality of initial alarm data corresponding to the target device and compress the second initial alarm data to obtain a plurality of alarm data corresponding to the target device.

[0019] In a preferred example, the determination of the danger score corresponding to each of the plurality of devices according to the plurality of alarm data corresponding to each of the plurality of devices and the device information corresponding to each of the plurality of devices includes:

[0020] Perform anomaly detection on the plurality of alarm data corresponding to each of the plurality of devices to determine an alarm score corresponding to each of the plurality of devices.

[0021] Perform vulnerability analysis on the device information corresponding to each of the plurality of devices to determine a vulnerability score corresponding to each of the plurality of devices.

[0022] According to the alarm score corresponding to each of the plurality of devices and the vulnerability score corresponding to each of the plurality of devices, a danger score corresponding to each of the plurality of devices is determined.

[0023] In a preferred example, the application can be further configured to: perform anomaly detection on the plurality of alarm data corresponding to each of the plurality of devices to determine an alarm score corresponding to each of the plurality of devices, including:

[0024] According to the current time window, the plurality of alarm data corresponding to the target device is cut to obtain a plurality of groups of alarm data;

[0025] The plurality of groups of alarm data corresponding to the target device are input into an anomaly detection model to perform anomaly detection to obtain an alarm score corresponding to the target device; the target device is any device in the plurality of devices;

[0026] According to the alarm score corresponding to each device, an alarm score corresponding to each of the plurality of devices is obtained.

[0027] In a preferred example, the application can be further configured to: the vulnerability analysis according to the device information corresponding to each of the plurality of devices to determine the vulnerability score corresponding to each of the plurality of devices, including:

[0028] According to the device information corresponding to the target device, multi-dimensional security factor calculation is performed to determine a score corresponding to each of the multi-dimensional security factors; the target device is any device in the plurality of devices; the multi-dimensional security factors include at least two of the following: vulnerability exploitability factor, asset importance factor, and network topology factor;

[0029] According to the score corresponding to each of the multi-dimensional security factors, a weighted calculation is performed to obtain a vulnerability score corresponding to the target device.

[0030] In a preferred example, the application can be further configured to: according to the device information corresponding to the target device, multi-dimensional security factor calculation is performed to determine a score corresponding to each of the multi-dimensional security factors, including:

[0031] According to the device information of the target device, the number of high-risk vulnerabilities, the number of weak passwords, and the asset type of the target device are determined;

[0032] According to the number of high-risk vulnerabilities and the number of weak passwords corresponding to the target device, a weighted calculation is performed to obtain a score corresponding to the vulnerability exploitability factor;

[0033] According to the asset type of the target device, a score corresponding to the asset type is determined according to the importance score mapping relationship, and the score represents the score corresponding to the asset importance factor; the importance score mapping relationship includes a corresponding relationship between a plurality of asset types and a plurality of importance scores.

[0034] According to the device network topology graph, a score corresponding to a network topology factor of the target device is determined.

[0035] In a preferred example, the application can be further configured to, before the score corresponding to the vulnerability exploitability factor is calculated by weighting according to the number of high-risk vulnerabilities and weak passwords of the target device, further comprising:

[0036] Obtaining weight information corresponding to a current time window, wherein the weight information is obtained by adjusting historical weight information according to feedback information of historical time windows.

[0037] Accordingly, the score corresponding to the vulnerability exploitability factor is calculated by weighting according to the number of high-risk vulnerabilities and weak passwords of the target device, comprising:

[0038] The score corresponding to the vulnerability exploitability factor is calculated by weighting according to the number of high-risk vulnerabilities and weak passwords of the target device according to the weight information.

[0039] In a preferred example, the application can be further configured to, according to the device network topology graph, determine the score corresponding to the network topology factor of the target device, comprising:

[0040] According to the network level, in-degree information and out-degree information of the target device in the device network topology graph, a level score corresponding to the target device is determined.

[0041] According to the centrality score corresponding to the target device and the level score corresponding to the target device, a centrality score corresponding to the target device is determined.

[0042] In a preferred example, the application can be further configured to, according to the dangerous score corresponding to each of the plurality of devices, determine a plurality of target attack paths from a plurality of attack paths, comprising:

[0043] Determine the number of node devices corresponding to each of the plurality of attack paths.

[0044] According to the dangerous score corresponding to each of the plurality of attack paths and the number of node devices corresponding to each of the plurality of attack paths, a path score corresponding to each of the plurality of attack paths is determined.

[0045] According to the path score corresponding to each of the plurality of attack paths, a predetermined number of target attack paths with high scores are determined from the plurality of attack paths.

[0046] In a second aspect, a false alarm data reduction device is provided, comprising:

[0047] obtain a plurality of alarm data corresponding to a plurality of devices respectively and device information corresponding to the plurality of devices respectively in a current time window;

[0048] determine a plurality of risk scores corresponding to the plurality of devices respectively according to the plurality of alarm data corresponding to the plurality of devices respectively and the device information corresponding to the plurality of devices respectively;

[0049] determine a plurality of target attack paths from a plurality of attack paths according to the plurality of risk scores corresponding to the plurality of devices respectively, wherein the plurality of attack paths are a plurality of attack paths that an attacker can reach according to a target device network topology graph, each attack path including a plurality of node devices; and eliminate alarm data corresponding to other devices from the plurality of alarm data according to node devices corresponding to each target attack path, the other devices being devices other than the node devices corresponding to the target attack path in the plurality of devices.

[0050] In a third aspect, an electronic device is provided, comprising:

[0051] one or more processors;

[0052] a memory;

[0053] one or more application programs, wherein the one or more application programs are stored in the memory and configured to be executed by the one or more processors, and the one or more programs are configured to perform operations corresponding to the alarm data reduction method according to any possible implementation of the first aspect.

[0054] In a fourth aspect, a computer-readable storage medium is provided, and the storage medium stores at least one instruction, at least one program, a code set, or an instruction set, and the at least one instruction, at least one program, code set, or instruction set is loaded and executed by a processor to perform steps of the alarm data reduction method according to any possible implementation of the first aspect.

[0055] In a fifth aspect, a computer program product is provided, and the computer program product includes a computer program, and the computer program is executed by a processor to perform operations corresponding to the alarm data reduction method according to any possible implementation of the first aspect.

[0056] In summary, the method provided by the present application has the following beneficial technical effects:

[0057] Obtain a plurality of alarm data and device information corresponding to a plurality of devices in a current time window; according to the alarm data and the device information, a danger score of each device is determined, which can quantitatively evaluate the potential risk of the device; based on the danger score, a plurality of target attack paths are screened from a plurality of possible attack paths determined according to a target device network topology diagram; according to the node devices corresponding to each target attack path, the alarm data corresponding to the devices irrelevant to the target attack path is reduced, and the quantitative value of the device is determined by combining the alarm data and the device information, so as to dynamically evaluate the risk path and the key node from the overall perspective, realize the prediction of the maximum probability attack path, reduce the possibility of false alarm, and make the alarm data presented to the user more accurate.

[0058] In addition, the application also provides an alarm data reduction device, equipment, medium and product, which have the above beneficial technical effects. BRIEF DESCRIPTION OF DRAWINGS

[0059] In order to more clearly illustrate the technical solutions of the embodiments of the application or the prior art, the drawings needed in the embodiment or the prior art description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the application, and those skilled in the art can obtain other drawings according to these drawings without creative labor.

[0060] Figure 1 The application provides an application scenario of an alarm data reduction method;

[0061] Figure 2 The application provides a flowchart of an alarm data reduction method;

[0062] Figure 3 The application provides a flowchart of a plurality of alarm data acquisition;

[0063] Figure 4 The application provides a flowchart of a danger score determination;

[0064] Figure 5 The application provides a flowchart of a plurality of alarm data acquisition;

[0065] Figure 6 The application provides a flowchart of a target attack path determination;

[0066] Figure 7 The application provides a flowchart of a target attack path determination;

[0067] Figure 8A timing exception alarm reduction process schematic diagram provided by an embodiment of the present application;

[0068] Figure 9 A vulnerability analysis process schematic diagram provided by an embodiment of the present application;

[0069] Figure 10 An attack path alarm reduction process schematic diagram provided by an embodiment of the present application;

[0070] Figure 11 A false alarm data reduction device structure schematic diagram provided by an embodiment of the present application;

[0071] Figure 12 An electronic device structure schematic diagram provided by an embodiment of the present application. DETAILED DESCRIPTION

[0072] The specific embodiments are only an explanation of the present application, and are not a limitation of the present application, and those skilled in the art can make modifications to the embodiments without creative contribution after reading the present specification, and the modifications are protected by the patent law as long as they are within the scope of the present application.

[0073] It should be noted that in the optional embodiments of the present application, the object information and other related data involved in the embodiments of the present application when applied to specific products or technologies need to obtain the permission or consent of the object, and the collection, use and processing of the related data need to comply with the relevant laws, regulations and standards of the country and region. That is, if the embodiments of the present application involve data related to the object, the data needs to be obtained with the authorization and consent of the object, the authorization and consent of the relevant department, and in compliance with the relevant laws, regulations and standards of the country and region. If personal information is involved in the embodiments, the consent of the individual needs to be obtained for the acquisition of all personal information, and the separate consent of the information subject needs to be obtained for sensitive information, and the embodiments also need to be implemented with the authorization and consent of the object.

[0074] To make the purpose, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be described clearly and completely below in combination with the drawings in the embodiments of the present application. Obviously, the described embodiments are some of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.

[0075] In addition, the term "and / or" in this document is only a description of the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B can represent the existence of A alone, the existence of A and B at the same time, and the existence of B alone. In addition, the character " / " in this document generally represents an "or" relationship between the associated objects unless otherwise specified. In order to better understand and illustrate the scheme of the embodiments of the present application, the following will briefly describe some technical terms involved in the embodiments of the present application.

[0076] APM (Attack Path Management): Attack path management is a solution idea that stands in the perspective of an attacker to realize attack path mapping, key blocking point discovery, risk mitigation and elimination. By analyzing device vulnerability and real-time attack alarm and other multi-dimensional information, APM can identify and predict potential risk points in the system environment, and its security capabilities include but are not limited to: key node identification, attack path prediction and attack matrix mapping. Security personnel can focus on key nodes of the system, and cut off the attack path at the bottleneck to mitigate and eliminate security threats at the minimum cost.

[0077] IDS (Intrusion Detection System): Intrusion detection system, which is used to monitor activities in computer systems or networks to detect and respond to potential security threats and attacks. According to the application scenario, IDS can be divided into host IDS and network IDS, wherein the host IDS is used to monitor terminal behavior anomalies, and the network IDS is used to monitor network traffic anomalies. IDS can detect intrusions by analyzing abnormal behavior, specific attack patterns or known attack signatures, and can take various response measures such as notifying administrators, blocking attack traffic or isolating systems.

[0078] RRCF (Randomized Random Cut Forest): Randomized random cut forest is an anomaly detection algorithm based on random matrix theory, which reduces the dimension of data by constructing a random matrix, and uses recursive partitioning and clustering refinement to detect outliers. RRCF algorithm has the advantages of high efficiency, strong scalability, good adaptability to high-dimensional data, and is widely used in the field of anomaly detection.

[0079] Through research on existing technologies in the industry, it is found that current false alarm reduction is mainly based on time series anomaly analysis and simple rule merging. However, the existing scheme only reduces alarms from a single dimension, and relies heavily on expert rules, resulting in poor false alarm reduction rate and positive alarm detection rate. In addition, due to the lack of real-time, dynamic and global analysis of system assets from a holistic perspective, the operation pressure of root cause positioning and traceability analysis in large-scale scenarios is still large.

[0080] In view of the existing problems of the alarm fatigue solution in the industry, the alarm data reduction method based on attack path management is designed to overcome the problems of low false alarm reduction rate and positive alarm detection rate, and high operation pressure in large-scale scenarios.

[0081] In order to better understand the scheme provided by the embodiments of the present application, the scheme will be described below in combination with a specific application scenario.

[0082] Please refer to Figure 1 , Figure 1 The application scenario diagram of the alarm data reduction method provided by the embodiments of the present application is shown in the figure. The alarm data reduction method can be applied to a false alarm reduction system.

[0083] In some embodiments, the false alarm reduction system includes a terminal side device 100 and / or a network side device 200, and an electronic device 300. The electronic device 300 can be a server, which can be a physical server, a server cluster composed of multiple physical servers or a distributed system, or a cloud server providing cloud computing services. The electronic device 300 can also be a terminal device, which can be a smart phone, a tablet computer, a notebook computer, a desktop computer, etc., but is not limited to this, and the embodiments of the present application do not limit this here.

[0084] In one possible case, the electronic device 300 and the terminal side device 100 and the network side device 200 are directly or indirectly connected through wired or wireless communication, and the electronic device can collect alarm data and device information of the terminal side device 100 and the network side device 200, and then realize false alarm reduction through analysis.

[0085] In another possible case, the false alarm reduction system further includes a third party device, wherein the electronic device 300 and the third party device are directly or indirectly connected through wired or wireless communication, and the third party device and the terminal side device 100 and the network side device 200 are directly or indirectly connected through wired or wireless communication, and the third party device can collect alarm data and device information of the terminal side device 100 and the network side device 200, and then the electronic device 300 obtains the alarm data and the device information through the third party device, and realizes false alarm reduction through analysis.

[0086] It can be understood that the above is only an example, and the embodiments of the present application do not limit this here.

[0087] The embodiments of the present application provide an alarm data reduction method, as shown in Figure 2 The method provided in the embodiments of the present application can be executed by an electronic device, and the method includes:

[0088] S101, acquire a plurality of alarm data corresponding to each of a plurality of devices in a current time window and device information corresponding to each of the plurality of devices;

[0089] The time size of the current time window can be user-defined, such as the past 10 hours, or the past 20 hours. The plurality of devices refers to devices running in a network system, including but not limited to network-side devices and client devices, such as servers, routers, switches, IDS (Intrusion Detection System) engines, EDR (Endpoint Detection and Response), etc. The alarm data represents warning information generated when the device operating state is abnormal, wherein the alarm data includes but is not limited to alarm type, alarm level, and occurrence time. The device information represents various asset data related to the device, including asset type, device model, location, vulnerability information, etc.

[0090] In some embodiments, this step can be implemented in various ways: alternatively, by database query, according to the current time window and the identification information of the plurality of devices, all related alarm records and device information of the devices are retrieved from the information database. Alternatively, the electronic device interacts with the API interface of the third-party device to obtain the alarm data and device information of the device in real time or periodically. Of course, there are other ways, and the present embodiment is not limited, and the user can set it according to the actual demand.

[0091] S102, according to a plurality of alarm data corresponding to each of a plurality of devices and device information corresponding to each of the plurality of devices, determine a plurality of dangerous scores corresponding to each of the plurality of devices;

[0092] The dangerous score represents the risk level of the device.

[0093] In some possible embodiments, the dangerous score corresponding to each of the plurality of devices can be calculated according to a dangerous score model with a preset calculation rule through the alarm data and device information of the device; or, based on historical alarm data and device information, a trained model is obtained by training the relationship between the dangerous score of the device and the alarm data and device information; then the plurality of alarm data corresponding to each of the plurality of devices and the device information corresponding to each of the plurality of devices are input into the trained model to predict the dangerous score corresponding to each of the plurality of devices.

[0094] It can be understood that other ways can also be used to determine the dangerous score, which can be selected according to specific needs, which is not limited here.

[0095] S103, determining a plurality of target attack paths from the plurality of attack paths according to the respective dangerous scores of the plurality of devices, wherein the plurality of attack paths are a plurality of attack paths that an attacker can reach according to a target device network topology graph, and each attack path includes a plurality of node devices;

[0096] The attack path represents a path formed by a series of node devices that an attacker reaches from a starting attack device to a final device in a network attack according to a target device network topology graph. The target device network topology graph is a diagram of connection relationships between all devices in the network, or a topology graph obtained by connecting exposed devices in the device network topology graph to external entities, which are obtained by abstracting external attackers.

[0097] In some embodiments, the dangerous scores of the node devices on each path are added to obtain a total score of each path, and the first N paths are selected as the target attack paths according to the total scores. Further, since some paths are longer and have higher scores, the predicted score divided by the average of the path length can be used as a basis for selecting the first N paths as the target attack paths.

[0098] This step identifies dangerous target attack paths by comprehensively considering the dangerous scores of the devices and the attack paths in a complex network environment. Further, by determining the target attack paths, technical personnel can also improve the security capabilities of the devices and reduce potential security risks.

[0099] Further, before determining the target attack paths from the plurality of attack paths according to the respective dangerous scores of the plurality of attack paths, the method further includes: connecting exposed devices in the device network topology graph to external entities to obtain a target device network topology graph; the external entities are obtained by abstracting external attackers; and determining the plurality of attack paths according to the target device network topology graph. Specifically, the external attackers are all abstracted into an external entity external, and are connected to the externally exposed devices to update the network topology. Then, the external entity external starts to traverse all attack paths reachable by the attacker.

[0100] S104, according to the node devices corresponding to each target attack path, reducing alarm data corresponding to other devices in the plurality of alarm data, the other devices being devices other than the node devices corresponding to the target attack paths in the plurality of devices.

[0101] The node device list appearing in the target attack path is counted, and the alarms are filtered based on the list. Each node device on the target attack path is a device with low security, and thus the corresponding alarm data is valid alarm data. The alarm data corresponding to other devices is removed from the multiple alarm data, and only the alarm data corresponding to each node device on the target attack path is retained, so that accurate elimination of alarm data is achieved.

[0102] It can be seen that in the embodiment of the present application, the multiple alarm data and device information corresponding to each of the multiple devices in the current time window are obtained; the risk score of each device is calculated based on the alarm data and the device information, so that the potential risk of the device can be quantitatively evaluated; based on the risk score, the multiple target attack paths are selected from the multiple possible attack paths determined based on the target device network topology diagram; and the alarm data corresponding to the devices irrelevant to the target attack path is eliminated according to the node devices corresponding to each target attack path. The present application scheme determines the quantitative value of the device by combining the alarm data and the device information, dynamically evaluates the risk path and the key node from the overall perspective, realizes the prediction of the maximum probability attack path, and eliminates the alarm data, which greatly reduces the possibility of false positives and makes the alarm data presented to the user more accurate.

[0103] It should be noted that in the alarm data generated by the device (such as the IDS engine, EDR), many of them are caused by the benign behavior of the system. Through analysis of a large number of alarms, it is found that high-risk alarms caused by real attacks are rare, and most of them are low-risk system false positives, and the false positives are usually repetitive, such as alarms of the same behavior repeatedly appearing in a period of time, false positives related to benign behaviors triggered by semantically similar commands, etc. Therefore, in the embodiment of the present application, the preliminary elimination of alarm data can be performed in combination with the attribute to improve the elimination efficiency. Specifically, one possible implementation manner of the embodiment of the present application is shown in Figure 3 , S101, obtaining multiple alarm data corresponding to each of multiple devices in a current time window, comprising:

[0104] S1011, obtaining multiple initial alarm data corresponding to each of multiple devices in a current time window;

[0105] In the embodiment of the present application, the initial alarm data is the original alarm data corresponding to each of the multiple devices.

[0106] S1012, classifying the multiple initial alarm data corresponding to the target device to obtain multiple alarm categories; the target device is any device in the multiple devices, and each alarm category includes at least one initial alarm data;

[0107] The initial alarm data is classified to classify alarm data of the same type together to form multiple alarm categories. All alarm data of the same device in the current time window is aggregated, distinguished according to the alarm type and the process involved in the alarm, and the frequency and time (in hours) of each type of alarm are counted. Key information of the alarm is recorded for subsequent tracing and judgment.

[0108] S1013, determine the feature information corresponding to each of the multiple alarm categories, and filter the multiple initial alarm data corresponding to the target device according to the feature information corresponding to each of the multiple alarm categories to obtain multiple alarm data corresponding to the target device.

[0109] The feature information includes frequency, time, and periodicity. In the embodiments of the present application, the timing, frequency, and periodicity of the alarm can be analyzed according to the initial alarm data corresponding to each alarm category after classification, so as to filter false alarms from the original alarm data. The frequency refers to the number of times the alarm category occurs in a unit of time or in the current time window. The time refers to the duration of the alarm category, and the unit is hour. For example, if an alarm category occurs at 10:00-12:00, the time is 2 hours. In the embodiments of the present application, the determination method of the time is not set, and the actual duration can be used. The periodicity refers to the periodicity of the alarm category in time, such as occurring at intervals of a preset duration.

[0110] As can be seen, in the embodiments of the present application, the multiple initial alarm data corresponding to each device is classified, and the multiple initial alarm data corresponding to the device is filtered by the feature information corresponding to each of the multiple alarm categories. The multiple alarm data corresponding to the device can be obtained to achieve preliminary reduction of the alarm data and improve the reduction efficiency.

[0111] In one possible implementation of the embodiments of the present application, the feature information includes frequency, time, and periodicity. S1013, filtering the multiple initial alarm data corresponding to the target device according to the feature information corresponding to each of the multiple alarm categories to obtain multiple alarm data corresponding to the target device, includes: when the target alarm category meets the first condition, determining the first initial alarm data corresponding to the target alarm category, the target alarm category being any of the multiple alarm categories, the first condition being that the time of the target alarm category exceeds a time threshold, or the target alarm category having periodicity; when the frequency of the target alarm category is greater than a preset frequency threshold, determining the second initial alarm data of the target alarm category; processing the multiple initial alarm data corresponding to the target device to delete the first initial alarm data in the multiple initial alarm data corresponding to the target device and compress the second initial alarm data to obtain the multiple alarm data corresponding to the target device.

[0112] Specifically, in the embodiments of the present application, filtering processing is performed according to each category of initial alarm data of each device. For an alarm category, according to the time sequence statistical feature information, the following is sequentially judged: 1) whether the time (hour number) of alarm occurrence exceeds a time threshold Th; 2) whether the alarm occurrence has periodicity; 3) whether the frequency of the same alarm occurrence exceeds a preset frequency threshold Ts; wherein the time threshold and the preset frequency threshold are set by technicians according to experience. If any one of the above 1) and 2) is met, it is considered to be a false alarm, and the preset frequency threshold is filtered; if condition 3) is met, the alarm is compressed to below the preset frequency threshold Ts to reduce redundancy.

[0113] In one possible implementation manner of the embodiments of the present application, referring to Figure 4 S102, determining the danger score corresponding to each of the plurality of devices according to the plurality of alarm data corresponding to each of the plurality of devices and the device information corresponding to each of the plurality of devices, comprising:

[0114] S1021, performing anomaly detection on the plurality of alarm data corresponding to each of the plurality of devices to determine the alarm score corresponding to each of the plurality of devices;

[0115] In one possible implementation manner, the plurality of alarm data corresponding to the target device is cut according to a current time window to obtain a plurality of groups of alarm data; the plurality of groups of alarm data corresponding to the target device are input into an anomaly detection model to perform anomaly detection to obtain the alarm score corresponding to the target device; the target device is any one of the plurality of devices; the alarm score corresponding to each of the plurality of devices is obtained according to the alarm score corresponding to each device.

[0116] In the embodiments of the present application, the alarm sequence in the time window is cut, and the anomaly detection model is used for anomaly detection, and finally the alarm scores of all devices are output. The anomaly detection model can be an RRCF (Robust Random Cut Forest, robust random cut forest) model, which is an algorithm model for anomaly detection and is an unsupervised learning algorithm, which is used for anomaly detection of large-scale data sets and can effectively identify abnormal points or abnormal patterns in data. Through the RRCF model, the alarm score corresponding to each device can be output.

[0117] In an implementable manner, the alarm data is cut according to time sequence to obtain alarm data groups of multiple time periods, the cutting manner can be a fixed time interval, such as every hour, or can be dynamic, adjusted according to the density or quantity of alarm data; the multiple groups of alarm data cut are input into the RRCF model for abnormality detection, and the alarm score corresponding to the device is output. In another implementable manner, the alarm data of the target device is cut according to a time window and a preset sliding step to obtain multiple overlapping alarm data groups; each alarm data group is input into the RRCF model for abnormality detection to obtain an alarm score corresponding to each alarm data group; all alarm scores of each device are weighted and averaged or the like to obtain an alarm score corresponding to each device.

[0118] Further, the alarm score can also be displayed on a user interface for an administrator to view and handle.

[0119] In the embodiments of the present application, the multiple alarm data corresponding to the target device are cut according to the current time window, each group of alarm data contains the state information of the device in the time period, the multiple groups of alarm data cut are input into the abnormality detection model for abnormality detection, so that the abnormality detection model can comprehensively analyze the multiple groups of alarm data, thereby more accurately judging the abnormality degree of the device, and calculating an alarm score for each target device.

[0120] S1022, vulnerability analysis is performed according to the device information corresponding to each of the multiple devices to determine a vulnerability score corresponding to each of the multiple devices;

[0121] Different devices in the same system will have great differences in their own vulnerability due to different business environments and network topology locations. In the embodiments of the present application, multi-dimensional security factors can be comprehensively considered to analyze the vulnerability of a device to external attackers.

[0122] S1023, a danger score corresponding to each of the multiple devices is determined according to the alarm score corresponding to each of the multiple devices and the vulnerability score corresponding to each of the multiple devices.

[0123] Specifically, for each device, the sum of the alarm score and the vulnerability score of the device can be taken as the danger score of the device; or the value obtained by weighted calculation of the alarm score and the vulnerability score of the device can be taken as the danger score of the device. It can be seen that, in the embodiments of the present application, the abnormality detection is performed on multiple alarm data to obtain an alarm score corresponding to a device; the vulnerability analysis is performed according to the device information corresponding to the device to calculate a vulnerability score for each device; the security risk of the device is reflected from two aspects, and then the danger score is determined by combining the two scores, which can more comprehensively evaluate the security status of the device.

[0124] For vulnerability scoring, one possible implementation of the embodiments of the present application, S1022, performing vulnerability analysis according to the device information corresponding to each of the plurality of devices to determine the vulnerability score corresponding to each of the plurality of devices, includes: performing multi-dimensional security factor calculation according to the device information corresponding to the target device to determine the score corresponding to each of the multi-dimensional security factors, the target device being any device in the plurality of devices; the dimension security factors including at least two of the following: vulnerability exploitability factor, asset importance factor, and network topology factor; and performing weighted calculation according to the score corresponding to each of the multi-dimensional security factors to obtain the vulnerability score corresponding to the target device.

[0125] For vulnerability scoring, the embodiments of the present application focus on three aspects: vulnerability exploitability, asset importance, and network topology. Of course, other security factors can also be used as indicators for vulnerability analysis, and the present embodiments are not limited thereto.

[0126] After calculating at least two of the vulnerability exploitability score, the asset importance score, and the network topology score, weighted calculation is performed to obtain the vulnerability score of each device.

[0127] One possible implementation of the embodiments of the present application is described with reference to Figure 5 , performing multi-dimensional security factor calculation according to the device information corresponding to the target device to determine the score corresponding to each of the multi-dimensional security factors, including:

[0128] Sa1, determining the number of high-risk vulnerabilities, the number of weak passwords, and the asset type of the target device according to the device information of the target device;

[0129] The device information refers to various data and attributes related to the target device, which is used to evaluate the security status of the device. High-risk vulnerabilities refer to vulnerabilities that can cause serious security risks. The number of weak passwords refers to the number of passwords set on the target device that are not strong enough to be easily guessed or cracked. The asset type refers to the classification of the target device, such as a database server, a web server, or middleware, a gateway, a firewall, or an open port.

[0130] Sa2, performing weighted calculation according to the number of high-risk vulnerabilities and the number of weak passwords of the target device to obtain the score corresponding to the vulnerability exploitability factor;

[0131] Generally speaking, the more security vulnerabilities a device contains, the greater the probability that it will be successfully attacked by an attacker and then fall. Among them, the problems of high-risk vulnerabilities (such as CVE) and weak passwords are particularly prominent, and they often become an important means for attackers to implement boundary breakthrough. High-risk vulnerabilities can be scored by cvss Common Vulnerability Scoring System, Common Vulnerability Scoring System) to measure the vulnerability value, which gives a score between 0 and 10 to quantify the severity of the vulnerability. The score between 9.0 and 10.0 indicates that the vulnerability can cause the system to completely fail or be completely controlled; the score between 7.0 and 8.9 indicates that the vulnerability can cause partial failure of the system or data leakage and other security problems; the score between 4.0 and 6.9 indicates that the vulnerability can cause partial failure of the system or data leakage and other security problems, but the impact is relatively small; the score between 0.1 and 3.9 indicates that the vulnerability has a small impact on the system, which may only be some restrictions on system functions or data leakage and other problems.

[0132] The embodiments of the present application simultaneously consider these two security problems, and respectively count the vulnerability values corresponding to the high-risk vulnerabilities and the number of weak passwords on each device, and then perform weighted score calculation to obtain the vulnerability exploitability score of each device. The higher the score, the higher the risk.

[0133] In some possible cases, the weight of high-risk vulnerabilities and the weight of weak passwords can be fixed, such as the weight of high-risk vulnerabilities being 0.05 and the weight of weak passwords being 1.

[0134] In other possible cases, the initial weight can be used to reduce false alarms first, and then user feedback information is received to dynamically adjust the weight, so that the result is more accurate.

[0135] Specifically, before the weighted calculation of the vulnerability exploitability factor corresponding score according to the number of high-risk vulnerabilities and weak passwords of the target device, it further includes: obtaining weight information corresponding to the current time window, wherein the weight information is obtained by adjusting the historical weight information weight according to the feedback information of the historical time window false alarm reduction; accordingly, the weighted calculation of the vulnerability exploitability factor corresponding score according to the number of high-risk vulnerabilities and weak passwords of the target device includes: weighted calculation of the vulnerability exploitability factor corresponding score according to the weight information target device The number of high-risk vulnerabilities and weak passwords.

[0136] The historical time window is a historical time window corresponding to the current time window. The historical weight information represents the weight information used by the historical time window. The feedback information refers to information used to evaluate the reduction effect after the false alarm reduction is over. Specifically, it can be feedback information of technical personnel. The level of reduction effect of high-risk vulnerabilities and weak passwords in the reduced alarm data is determined through user feedback. Different levels correspond to different adjustment values, and then the weight information is dynamically adjusted as the weight of the next time window, i.e., the current time window. This process is dynamic and continuous, aiming to continuously optimize the performance and accuracy of the system.

[0137] It can be seen that the weight information is dynamically adjusted as the weight information of the current time window according to the feedback information of the false alarm reduction of the historical time window. By continuously updating and optimizing the weight information, the data can be more accurately evaluated and processed, and the alarm reduction effect can be improved.

[0138] Sa3, determining a score corresponding to the asset type of the target device according to the importance score mapping relationship, the score representing the score corresponding to the asset importance factor; the importance score mapping relationship includes the correspondence relationship between a plurality of asset types and a plurality of importance scores;

[0139] For asset importance, assets (such as middleware, databases, etc.) existing on the device will be different due to business, but devices containing different assets will cause different harm to users after being compromised. For example, the importance of assets such as database servers and web servers is generally much greater than that of other asset categories. The present application embodiment can define a common asset list according to security experience, and specify the importance score mapping corresponding to each asset. For example: the scores corresponding to {{database server, web server} are 10.0, the scores corresponding to {middleware, gateway} are 5.0, and the scores corresponding to {firewall, open port} are 2.0}. In this way, the importance score of each device containing assets can be calculated.

[0140] Sa4, determining the score corresponding to the network topology nature factor of the target device according to the device network topology graph.

[0141] When determining the score corresponding to the network topology nature factor, the hierarchical score and / or the hierarchical score determined by the hierarchical score can be used.

[0142] In one possible implementation of the present application embodiment, the centrality score corresponding to the target device is determined according to the device network topology graph; the hierarchical score corresponding to the target device is determined according to the network level, the in-degree information and the out-degree information of the target device in the device network topology graph; and the score corresponding to the network topology nature factor of the target device is determined according to the centrality score corresponding to the target device and the hierarchical score corresponding to the target device.

[0143] Specifically, for the network topology, the different network topology positions of the device will have different effects on the attacks of the attacker, mainly including the following two aspects: i) network hierarchy, the difficulty of the attack of the attacker will increase significantly with the increase of the attack hop number, wherein the attack hop number is the number of intermediate nodes or steps required for the attacker to reach the target system (such as a certain specific server or database) from the initial attack point (such as an infected computer or network node); ii) network centrality, the explosion radius caused by the attack of the attacker will be different with the central position of the current device.

[0144] Based on this, the embodiment of the present application first acquires the network topology graph of the current system, and correctly labels which devices are included in the external exposure surface; the closeness_centrality function is used to calculate the centrality score of each node in the graph, wherein the closeness centrality index in graph theory is used to calculate the importance of the node in the network; the breadth-first search algorithm is used to obtain the network level, in-degree information and out-degree information of each device in turn from the root node, and then the hierarchy score is calculated, wherein the hierarchy score = 1 / network level + first factor*in-degree information + second factor*out-degree information, wherein the first factor and the second factor can be set according to the empirical value; the sum of the network hierarchy score and the network centrality score is integrated to obtain the network topology score of all the current devices.

[0145] In the embodiment of the present application, the network topology score of the target device is determined according to the network level, in-degree information and out-degree information of the target device in the device network topology graph; the network topology score of the target device is determined according to the centrality score of the target device and the hierarchy score of the target device, so that the result is more accurate.

[0146] As can be seen, in the embodiment of the present application, the high-risk vulnerability corresponding to the vulnerability value and the number of weak passwords are weighted and calculated to obtain the score corresponding to the vulnerability exploitability factor, which is used to represent the possibility of vulnerability exploitation; the score corresponding to the asset type of the target device is determined according to the importance score mapping relationship; the score corresponding to the network topology factor of the target device is determined according to the device network topology graph; the high-risk vulnerability, the number of weak passwords, the asset type and the network topology structure of the target device are comprehensively considered to quantitatively analyze the multi-dimensional security factors.

[0147] One possible implementation of the embodiment of the present application is shown in Figure 6 S103, determining a plurality of target attack paths from a plurality of attack paths according to the respective danger scores of the plurality of devices, comprising:

[0148] S1031, determining the number of node devices corresponding to each of the plurality of attack paths;

[0149] S1032, determine a path score corresponding to each of the plurality of attack paths according to the danger score corresponding to each of the plurality of attack paths and the number of node devices corresponding to each of the plurality of attack paths;

[0150] The threat scores of the plurality of attack paths are sequentially calculated.

[0151] In an implementable embodiment, the vulnerability score and the alarm anomaly score of all devices on a path are added to obtain a prediction score of the path. In addition, to balance the problem of high scores of long paths, the average value obtained by dividing the prediction score by the path length is taken as the path score.

[0152] In another implementable embodiment, the total score of the path can be logarithmically transformed by Formula I, and then divided by the number of devices; wherein Formula I is: .

[0153] In another implementable embodiment, a long path coefficient β can be introduced by Formula II. When β is greater than a preset value, β is less than 1, and the value size can be set by the user. Otherwise, β is 1; wherein Formula II is: .

[0154] It can be understood that other ways can be used to determine the path score to balance the problem of high scores of long paths, which are not limited here.

[0155] S1033, determine a preset number of target attack paths with high scores from the plurality of attack paths according to the path scores corresponding to each of the plurality of attack paths.

[0156] The risk paths are ranked in descending order according to the scores, and the top k (k is a preset number and can be set by the user) maximum probability attack paths are selected as the prediction result of the current time window.

[0157] It can be seen that in the embodiments of the present application, the path score corresponding to each of the plurality of attack paths is determined according to the danger score corresponding to each of the plurality of attack paths and the number of node devices corresponding to each of the plurality of attack paths. The problem of high scores of long paths is balanced, the overall threat level of each attack path can be more comprehensively evaluated, and then the preset number of target attack paths with high scores are determined from the plurality of attack paths according to the path scores corresponding to each of the plurality of attack paths, so that the obtained target attack paths are more accurate.

[0158] Based on any of the above embodiments, refer to Figure 7 , Figure 7 An overall flow architecture diagram is provided for the embodiments of the present application.

[0159] The attack path management-based alarm reduction method provided by the embodiments of the present application can be divided into three modules: timing exception alarm reduction, vulnerability analysis, and attack path alarm reduction. The results of the timing exception alarm reduction and the vulnerability analysis are used as inputs of the attack path alarm reduction to achieve false alarm reduction, attack detection, and attack path prediction of original alarms. Each module will be described in detail below.

[0160] The timing exception alarm reduction is described with reference to Figure 8 . Whether the current time window is reached is determined. If not, the step is slid. If yes, alarm data is obtained, the alarm data is classified and aggregated, and statistical information, i.e., feature information, is recorded. Then, whether the time of the alarm category exceeds a time threshold, whether the alarm category has periodicity, and whether the alarm frequency (i.e., the number of times) is greater than a preset frequency threshold are determined. If the time of the alarm category exceeds the time threshold, or the alarm category has periodicity, alarm consideration is performed. If the alarm frequency is greater than the preset frequency threshold, alarm compression is performed. Initial filtering is achieved. Then, RRCF abnormal score calculation is performed according to the filtered alarm data, and an abnormal score is obtained.

[0161] The vulnerability analysis is described with reference to Figure 9 . Device information is formatted to obtain vulnerability information, asset information, and a network topology diagram. Vulnerability availability is calculated according to the number of high-risk vulnerabilities and weak passwords of the vulnerability information. Asset information is clustered to obtain asset types and obtain a mapping relationship of importance scores for asset importance score calculation. A network topology diagram is constructed and an exposure surface is marked. Then, centrality and hierarchy are calculated according to the marked network topology diagram, and network topology score calculation is performed according to the calculation results. The scores obtained from the three factors are weighted to obtain a device vulnerability score.

[0162] The attack path alarm reduction is described with reference to Figure 10 . External attacks are abstracted to update the network topology diagram. Attack path traversal is performed based on the abstracted external attacks to obtain multiple attack paths. The scores of the devices in the timing exception alarm reduction and the scores of the devices in the vulnerability analysis are used to calculate the scores of the attack paths. Topk attack paths are selected. The alarm data corresponding to the list of devices involved in the topk attack paths is saved. For the alarms after the timing exception reduction, if the corresponding device is not in the list, the alarm is filtered. Otherwise, the alarm data is retained.

[0163] It can be seen that, in the embodiment of the application, the alarm data in the sliding time window is aggregated, filtered and compressed through the timing anomaly and periodicity information, efficient false alarm reduction and positive alarm detection are realized, the vulnerability of the current business system device is evaluated in multiple dimensions through vulnerability analysis, topology analysis and asset importance analysis, and the risk path and key node are dynamically evaluated from the overall perspective by associating the real-time attack alarm and vulnerability information, and the maximum probability attack path prediction is realized. In combination with the real-time attack alarm data and the device vulnerability information, the massive alarms generated by the terminal side and the network side in different scenarios can be generalized to reduce and efficiently detect positive alarms and predict attack paths. In addition, the embodiment of the application comprehensively evaluates the system threat from a global perspective in real time and dynamically, focuses on the key node and the maximum probability attack path, and significantly improves the efficiency of attack root cause positioning and traceability analysis in a large-scale scenario.

[0164] Next, an apparatus provided by an embodiment of the application is described. The apparatus described below can be referred to each other in the description of the method described above. The apparatus of the embodiment is arranged in an electronic device, and the apparatus is described with reference to Figure 11 , Figure 11 FIG. 1 is a structural block diagram of the apparatus of an embodiment of the application, which includes:

[0165] The acquisition module 10 is configured to acquire a plurality of alarm data corresponding to each of a plurality of devices and device information corresponding to each of the plurality of devices in a current time window.

[0166] The danger score module 20 is configured to determine a danger score corresponding to each of the plurality of devices according to the plurality of alarm data corresponding to each of the plurality of devices and the device information corresponding to each of the plurality of devices.

[0167] The attack path alarm reduction module 30 is configured to determine a plurality of target attack paths from a plurality of attack paths according to the danger score corresponding to each of the plurality of devices, wherein the plurality of attack paths are a plurality of attack paths that an attacker can reach according to a target device network topology graph, and each attack path includes a plurality of node devices; and the attack path alarm reduction module 30 is configured to reduce alarm data corresponding to other devices in the plurality of alarm data according to the node devices corresponding to each target attack path, wherein the other devices are devices other than the node devices corresponding to the target attack path in the plurality of devices.

[0168] In an implementable manner, the acquisition module 10 is specifically configured to:

[0169] acquire a plurality of initial alarm data corresponding to each of the plurality of devices in the current time window;

[0170] perform category division on the plurality of initial alarm data corresponding to the target device to obtain a plurality of alarm categories, wherein the target device is any device in the plurality of devices, and each alarm category includes at least one initial alarm data;

[0171] determining feature information corresponding to each of the plurality of alarm categories, and performing filtering processing on the plurality of initial alarm data corresponding to the target device according to the feature information corresponding to each of the plurality of alarm categories, to obtain a plurality of alarm data corresponding to the target device.

[0172] In an implementable manner, the feature information includes frequency, time, and periodicity.

[0173] The obtaining module 10 is specifically configured to:

[0174] When the target alarm category meets the first condition, determining first initial alarm data corresponding to the target alarm category, the target alarm category being any one of the plurality of alarm categories, and the first condition being that the time of the target alarm category exceeds a time threshold, or the target alarm category having periodicity.

[0175] When the frequency of the target alarm category is greater than a preset frequency threshold, determining second initial alarm data of the target alarm category.

[0176] Processing the plurality of initial alarm data corresponding to the target device, so as to delete the first initial alarm data in the plurality of initial alarm data corresponding to the target device, and compress the second initial alarm data, to obtain the plurality of alarm data corresponding to the target device.

[0177] In an implementable manner, the danger score module 20 is specifically configured to:

[0178] Performing anomaly detection on the plurality of alarm data corresponding to each of the plurality of devices, to determine an alarm score corresponding to each of the plurality of devices.

[0179] Performing vulnerability analysis on device information corresponding to each of the plurality of devices, to determine a vulnerability score corresponding to each of the plurality of devices.

[0180] According to the alarm score corresponding to each of the plurality of devices and the vulnerability score corresponding to each of the plurality of devices, determining a danger score corresponding to each of the plurality of devices.

[0181] In an implementable manner, the danger score module 20 is specifically configured to cut the plurality of alarm data corresponding to the target device according to a current time window, to obtain a plurality of groups of alarm data.

[0182] Inputting the plurality of groups of alarm data corresponding to the target device into an anomaly detection model to perform anomaly detection, to obtain an alarm score corresponding to the target device; the target device being any one of the plurality of devices.

[0183] According to the alarm score corresponding to each device, obtaining the alarm score corresponding to each of the plurality of devices.

[0184] In an implementable manner, the danger scoring module 20 is specifically configured to calculate a plurality of dimension security factors according to the device information of the target device, and determine a score corresponding to each of the plurality of dimension security factors; the target device is any one of a plurality of devices; the dimension security factors include at least two of the following: a vulnerability exploitability factor, an asset importance factor, and a network topology factor.

[0185] The vulnerability score corresponding to the target device is obtained by weighted calculation according to the scores corresponding to the plurality of dimension security factors.

[0186] In an implementable manner, the danger scoring module 20 is specifically configured to determine, according to the device information of the target device, a vulnerability value corresponding to a high-risk vulnerability of the target device, a number of weak passwords, and an asset type of the target device.

[0187] The score corresponding to the vulnerability exploitability factor is obtained by weighted calculation according to the vulnerability value corresponding to the high-risk vulnerability of the target device and the number of weak passwords.

[0188] The score corresponding to the asset importance factor is determined according to an importance score mapping relationship corresponding to the asset type of the target device; the importance score mapping relationship includes a corresponding relationship between a plurality of asset types and a plurality of importance scores.

[0189] The score corresponding to the network topology factor of the target device is determined according to the device network topology graph.

[0190] In an implementable manner, the method further includes:

[0191] The weight obtaining module is configured to obtain weight information corresponding to a current time window, wherein the weight information is obtained by adjusting historical weight information according to feedback information of a historical time window.

[0192] Correspondingly, the danger scoring module 20 is specifically configured to:

[0193] The score corresponding to the vulnerability exploitability factor is obtained by weighted calculation according to the weight information, the high-risk vulnerability of the target device, and the number of weak passwords.

[0194] In an implementable manner, the danger scoring module 20 is specifically configured to:

[0195] The level score corresponding to the target device is determined according to the network level, the in-degree information, and the out-degree information of the target device in the device network topology graph.

[0196] The centrality score corresponding to the target device is determined according to the centrality score corresponding to the target device and the level score corresponding to the target device.

[0197] In an implementable manner, the attack path alarm reduction module 30 is specifically configured to determine the number of node devices corresponding to each of the plurality of attack paths.

[0198] According to the danger score corresponding to each of the plurality of attack paths and the number of node devices corresponding to each of the plurality of attack paths, a path score corresponding to each of the plurality of attack paths is determined.

[0199] According to the path score corresponding to each of the plurality of attack paths, a preset number of target attack paths with high scores are determined from the plurality of attack paths.

[0200] An electronic device is provided in the embodiments of the present application, as shown in Figure 12 Figure 12 The electronic device 300 shown in the embodiments of the present application includes a processor 301 and a memory 303. The processor 301 and the memory 303 are connected, for example, through a bus 302. Optionally, the electronic device 300 can further include a transceiver 304. It should be noted that the transceiver 304 is not limited to one in actual application, and the structure of the electronic device 300 does not constitute a limitation on the embodiments of the present application.

[0201] The processor 301 can be a CPU (Central Processing Unit, central processor), a general-purpose processor, a DSP (Digital Signal Processor, data signal processor), an ASIC (Application Specific Integrated Circuit, application specific integrated circuit), an FPGA (Field Programmable Gate Array, field programmable gate array) or other programmable logic devices, transistor logic devices, hardware components or any combination thereof. It can implement or execute various exemplary logical blocks, modules and circuits described in combination with the disclosure content of the present application. The processor 301 can also be a combination of computing functions, such as one or more microprocessor combinations, combinations of DSP and microprocessor, etc.

[0202] The bus 302 can include a channel for transmitting information between the above-mentioned components. The bus 302 can be a PCI (Peripheral Component Interconnect, peripheral component interconnect) bus or an EISA (Extended Industry Standard Architecture, extended industry standard architecture) bus, etc. The bus 302 can be divided into an address bus, a data bus, a control bus, etc. For the convenience of representation, Figure 12 In the embodiments of the present application, only one thick line is used to represent the bus, but it does not mean that there is only one bus or only one type of bus.

[0203] ​The memory 303 can be a ROM (Read Only Memory) or other type of static storage device that can store static information and instructions, a RAM (Random Access Memory) or other type of dynamic storage device that can store information and instructions, an EEPROM (Electrically Erasable Programmable Read Only Memory), a CD-ROM (Compact Disc Read Only Memory) or other optical disk storage, a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer, but is not limited thereto.

[0204] The memory 303 is configured to store application program codes for implementing the solutions of the present application, and the processor 301 is configured to control the execution of the application program codes. The processor 301 is configured to execute the application program codes stored in the memory 303 to implement the content shown in the foregoing method embodiments.

[0205] Figure 12 The electronic device shown is merely an example, and should not impose any limitation on the functions and use range of the embodiments of the present application.

[0206] The embodiments of the present application provide a computer readable storage medium, which stores a computer program. When the computer program is run on a computer, the computer can execute the corresponding content in the foregoing method embodiments.

[0207] The embodiments of the present application provide a computer program product, which includes a computer program. When the computer program is executed by a processor, the corresponding content in the foregoing method embodiments is implemented.

[0208] It should be understood that, although each step in the flowchart of the accompanying drawings is shown in sequence according to the direction of the arrow, these steps are not necessarily executed in sequence according to the direction of the arrow. Unless otherwise specified herein, the execution of these steps is not strictly limited in sequence, and they can be executed in other sequences. Moreover, at least part of the steps in the flowchart of the accompanying drawings can include multiple sub-steps or multiple stages, which are not necessarily executed at the same time, but can be executed at different times, and the execution sequence is not necessarily sequential, but can be executed in rotation or alternation with at least part of other steps or sub-steps or stages of other steps.

[0209] The above merely describes some embodiments of the present application, and it should be pointed out that, for those skilled in the art, some improvements and refinements can be made without departing from the principles of the present application, and these improvements and refinements should also be considered as the protection scope of the present application.

Claims

1. A method for reducing alarm data, characterized in that, include: Retrieve multiple alarm data and device information corresponding to multiple devices within the current time window; Based on the multiple alarm data corresponding to each of the multiple devices and the device information corresponding to each of the multiple devices, determine the risk score corresponding to each of the multiple devices; Based on the risk scores corresponding to each of the multiple devices, multiple target attack paths are determined from multiple attack paths. The multiple attack paths are determined based on the network topology of the target devices and are multiple attack paths that the attacker can reach. Each attack path includes multiple node devices. According to the node device corresponding to each target attack path, reduce the alarm data corresponding to other devices in the multiple alarm data, where the other devices are devices other than the node device corresponding to the target attack path among the multiple devices.

2. The alarm data reduction method according to claim 1, characterized in that, Retrieve multiple alarm data corresponding to multiple devices within the current time window, including: Retrieve initial alarm data for each of the multiple devices within the current time window; Multiple initial alarm data corresponding to the target device are categorized to obtain multiple alarm categories; the target device is any one of the multiple devices, and each alarm category includes at least one initial alarm data. The characteristic information corresponding to each of the multiple alarm categories is determined, and the multiple initial alarm data corresponding to the target device are filtered according to the characteristic information corresponding to each of the multiple alarm categories to obtain the multiple alarm data corresponding to the target device.

3. The alarm data reduction method according to claim 2, characterized in that, The feature information includes: frequency, time, and periodicity; The step involves filtering multiple initial alarm data corresponding to the target device based on the feature information corresponding to each of the multiple alarm categories, to obtain multiple alarm data corresponding to the target device, including: When the target alarm category meets the first condition, the first initial alarm data corresponding to the target alarm category is determined. The target alarm category is any one of multiple alarm categories. The first condition is that the time of the target alarm category exceeds a time threshold, or that the target alarm category has periodicity. If the frequency of the target alarm category is greater than a preset frequency threshold, then the second initial alarm data for the target alarm category is determined; The multiple initial alarm data corresponding to the target device are processed to delete the first initial alarm data from the multiple initial alarm data corresponding to the target device and compress the second initial alarm data to obtain multiple alarm data corresponding to the target device.

4. The alarm data reduction method according to claim 1 or 2, characterized in that, The step of determining the risk score corresponding to each of the multiple devices based on the multiple alarm data and the device information corresponding to each of the multiple devices includes: Anomaly detection is performed based on the multiple alarm data corresponding to each of the multiple devices, and the alarm score corresponding to each of the multiple devices is determined. Vulnerability analysis is performed based on the device information corresponding to each of the multiple devices to determine the vulnerability score corresponding to each of the multiple devices; Based on the alarm scores and vulnerability scores of each of the multiple devices, a risk score is determined for each of the multiple devices.

5. The alarm data reduction method according to claim 4, characterized in that, Anomaly detection is performed based on multiple alarm data corresponding to each of the multiple devices to determine the alarm score corresponding to each of the multiple devices, including: Based on the current time window, the multiple alarm data corresponding to the target device are segmented to obtain multiple sets of alarm data; Multiple sets of alarm data corresponding to the target device are input into the anomaly detection model for anomaly detection to obtain the alarm score corresponding to the target device; the target device can be any one of multiple devices. Based on the alarm score corresponding to each device, the alarm scores corresponding to each of the multiple devices are obtained.

6. The alarm data reduction method according to claim 4, characterized in that, The vulnerability analysis, performed based on the device information corresponding to each of the multiple devices, to determine the vulnerability score for each of the multiple devices includes: Based on the device information corresponding to the target device, multi-dimensional security factors are calculated to determine the score corresponding to each of the multi-dimensional security factors; the target device is any one of multiple devices; the multi-dimensional security factors include at least two of the following: vulnerability exploitability factors, asset importance factors, and network topology factors; The vulnerability score of the target device is obtained by weighting the scores corresponding to each of the multi-dimensional security factors.

7. The alarm data reduction method according to claim 6, characterized in that, Based on the device information corresponding to the target device, multi-dimensional security factors are calculated to determine the score corresponding to each of the multi-dimensional security factors, including: Based on the device information of the target device, determine the vulnerability value, number of weak passwords, and asset type corresponding to the high-risk vulnerabilities of the target device; The score corresponding to the vulnerability exploitability factor is obtained by weighted calculation based on the vulnerability value and the number of weak passwords corresponding to the high-risk vulnerability of the target device. The score corresponding to the asset type of the target device is determined based on the importance score mapping relationship, and the score represents the score corresponding to the asset importance factor; the importance score mapping relationship includes the correspondence between multiple asset types and multiple importance scores; Based on the device network topology diagram, determine the score corresponding to the network topology factor of the target device.

8. The alarm data reduction method according to claim 7, characterized in that, Before calculating the score corresponding to the vulnerability exploitability factor by weighting the number of high-risk vulnerabilities and weak passwords of the target device, the method further includes: Obtain the weight information corresponding to the current time window, wherein the weight information is obtained by adjusting the weight of historical weight information based on the feedback information of false alarm reduction in historical time windows; Accordingly, the weighted calculation of the vulnerability exploitability factor based on the number of high-risk vulnerabilities and weak passwords of the target device includes: Based on the weighted information, the number of high-risk vulnerabilities and weak passwords in the target device is used to calculate a weighted score for the vulnerability exploitability factor.

9. The alarm data reduction method according to claim 7, characterized in that, The step of determining the score corresponding to the network topology factor of the target device based on the device network topology diagram includes: Based on the network level, in-degree information, and out-degree information of the target device in the device network topology diagram, determine the hierarchical score corresponding to the target device; The centrality score of the target device is determined based on the centrality score and the hierarchical score of the target device.

10. The alarm data reduction method according to claim 1, characterized in that, Based on the risk scores corresponding to each of the multiple devices, multiple target attack paths are determined from multiple attack paths, including: Determine the number of node devices corresponding to each of the multiple attack paths; The path score for each of the multiple attack paths is determined based on the risk score corresponding to each of the multiple attack paths and the number of node devices corresponding to each of the multiple attack paths. Based on the path scores corresponding to each of the multiple attack paths, a preset number of target attack paths with high scores are determined from the multiple attack paths.

11. A false alarm data reduction device, characterized in that, include: The acquisition module is used to acquire multiple alarm data and device information corresponding to multiple devices within the current time window. The hazard rating module is used to determine the hazard rating of each of the multiple devices based on the multiple alarm data corresponding to each of the multiple devices and the device information corresponding to each of the multiple devices. The attack path alarm reduction module is used to determine multiple target attack paths from multiple attack paths based on the risk scores corresponding to the multiple devices. The multiple attack paths are determined based on the network topology of the target devices, and each attack path includes multiple node devices. The module reduces the alarm data corresponding to other devices in the multiple alarm data according to the node devices corresponding to each target attack path. The other devices are devices other than the node devices corresponding to the target attack path.

12. An electronic device, characterized in that, include: One or more processors; Memory; One or more applications, wherein the one or more applications are stored in the memory and configured to be executed by the one or more processors, the one or more applications being configured to perform the steps of the method according to any one of claims 1 to 10.

13. A computer-readable storage medium, characterized in that, The storage medium stores at least one instruction, at least one program, code set, or instruction set, and the at least one instruction, at least one program, code set, or instruction set is loaded by a processor and executed according to the steps of the method according to any one of claims 1 to 10.

14. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the steps of the method as described in any one of claims 1 to 10.

Citation Information

Patent Citations

  • Wireless multi-step attack mode excavation method for WLAN

    CN103944919A

  • Power security event association analysis method and device facing attack monitoring scene

    CN117692188A