A secure operation system, method, device, medium and product

CN119811039BActive Publication Date: 2026-09-08CHINA TELECOM CLOUD TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411705831.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-26
Publication Date
2026-09-08
Estimated Expiration
2044-11-26

AI Technical Summary

Technical Problem

然而,使用自动化扫描器、监控器,误报率过高,由于规则更新的滞后以及内部员工安全意识低,现有方式会产生大量误报;例如,误报一般有两种原因,一是内部员工未报备而进行安全风险极高的操作;二是规则匹配条件的误判

Benefits of technology

[0018] The fifth aspect of the present invention provides a computer program product, including a computer program/instruction, which, when executed by a processor, implements the secure operation method as described in the first aspect of the present invention.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119811039B_ABST
    Figure CN119811039B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a kind of safe operation system, method, equipment, medium and product, it is related to safe operation technical field.The system includes: alarm collection module, for collecting the alarm record generated by each security platform and sending alarm record to false alarm research module;False alarm research module is used to identify alarm record using false alarm research model to determine whether alarm record is false alarm;In the case of non-false alarm, alarm record is sent to report generation module;Report generation module is used to generate alarm event analysis report based on alarm record using report generation big model and show, in response to the research of user, determine whether alarm record is false alarm;In the case of non-false alarm, alarm record is sent to traceability notification module;Traceability notification module is used to determine corresponding involved personnel according to alarm record, and sends alarm record to involved personnel, to reduce the human input of security operation team, improve the execution efficiency of security operation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the field of security operation technology, and in particular to a security operation system, method, device, medium and product. Background Technology

[0002] In internal security operations scenarios, the large number and high frequency of use of internal assets can easily lead to security issues. Security operations refer to enterprises taking proactive measures to fully identify, combat, defend against, and resolve technical security risks, proposing reasonable and effective overall security solutions to protect the enterprise's data, systems, applications, and infrastructure, prevent external attacks and intrusions, ensure effective business operations, and improve the enterprise's data security protection capabilities. In the current environment, security teams rely on asset security scanners and monitors to reduce manpower investment and improve the efficiency of automated security operations.

[0003] Currently, most automated scanners and monitors detect suspicious attack behavior through rule matching and condition matching. However, the false positive rate of automated scanners and monitors is too high. Due to the lag in rule updates and the low security awareness of internal employees, existing methods generate a large number of false positives. For example, false positives generally have two causes: first, internal employees perform highly risky operations without reporting them; second, the rules are misjudged. The internal security operations team invests a lot of manpower in investigating false positives, resulting in a high manpower input for the security operations team, which naturally runs counter to the original intention of automating security operations.

[0004] Therefore, the current need for automated internal security operations is for a security operations system, method, and / or strategy to optimize security operations processes, reduce manpower, and improve the efficiency of security operations execution. Summary of the Invention

[0005] This invention provides a security operations system, method, device, medium, and product to reduce the manpower required by the security operations team and improve the execution efficiency of security operations.

[0006] The first aspect of this invention provides a security operation system, which includes at least: an alarm collection module, a false alarm analysis module, a report generation module, and a source tracing notification module;

[0007] The alarm collection module is used to collect alarm records generated by various security platforms and send the alarm records to the false alarm analysis module;

[0008] The false alarm analysis module is used to identify the alarm record using a false alarm analysis model to determine whether the alarm record is a false alarm; if the alarm record is not a false alarm, the alarm record is sent to the report generation module.

[0009] The report generation module is used to generate and display an alarm event analysis report based on the alarm record using a large report generation model, and respond to the user's judgment based on the alarm event analysis report to determine whether the alarm record is a false alarm; if the alarm record is not a false alarm, the alarm record is sent to the source tracing notification module.

[0010] The source tracing notification module is used to determine the corresponding involved personnel based on the alarm records and send the alarm records to the involved personnel.

[0011] A second aspect of this invention provides a secure operation method applied to the secure operation system provided in the first aspect of this invention, the method comprising:

[0012] The alarm collection module collects alarm records generated by various security platforms and sends the alarm records to the false alarm analysis module.

[0013] The false alarm analysis module uses a false alarm analysis model to identify the alarm record and determine whether the alarm record is a false alarm; if the alarm record is not a false alarm, the alarm record is sent to the report generation module.

[0014] The report generation module utilizes a large-scale report generation model to generate and display an alarm event analysis report based on the alarm records. In response to the user's judgment based on the alarm event analysis report, it determines whether the alarm record is a false alarm. If the alarm record is not a false alarm, the alarm record is sent to the source tracing notification module.

[0015] The source tracing and notification module identifies the relevant personnel based on the alarm records and sends the alarm records to the relevant personnel.

[0016] A third aspect of the present invention provides an electronic device, the electronic device comprising: a memory, a processor, and a computer program stored in the memory and running on the processor, wherein the computer program, when executed by the processor, implements the secure operation method as described in the first aspect of the present invention.

[0017] A fourth aspect of the present invention provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the secure operation method of the first aspect of the present invention.

[0018] The fifth aspect of the present invention provides a computer program product, including a computer program / instruction, which, when executed by a processor, implements the secure operation method as described in the first aspect of the present invention.

[0019] In the security operation system provided in this embodiment of the invention, the alarm collection module collects alarm records generated by various security platforms and sends the alarm records to the false alarm analysis module; the false alarm analysis module uses a false alarm analysis model to identify the alarm records and determine whether the alarm records are false alarms; if the alarm records are not false alarms, the alarm records are sent to the report generation module; the report generation module uses a report generation model to generate and display an alarm event analysis report based on the alarm records, responding to the user's analysis based on the alarm event analysis report to determine whether the alarm records are false alarms; if the alarm records are not false alarms, the alarm records are sent to the source tracing notification module; the source tracing notification module determines the corresponding involved personnel based on the alarm records and sends the alarm records to the involved personnel. Thus, this embodiment reduces the false alarm generation rate by using a pre-trained false alarm analysis model, blocking a large number of false alarms before manual investigation, thereby reducing the manpower input of the security operations team. At the same time, it adds at least a report generation module and a source tracing notification module to realize automated processes, allowing security operations personnel to greatly reduce mechanical and repetitive operations and only need to focus on process approval, which greatly improves the execution efficiency of internal security operations of the enterprise. Attached Figure Description

[0020] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the description of the embodiments of the present invention will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0021] Figure 1 This is a structural block diagram of a safe operation system according to an embodiment of the present invention;

[0022] Figure 2 This is a flowchart of a safe operation method provided in an embodiment of the present invention;

[0023] Figure 3 This is an overall flowchart of an automated internal security operation method based on a large security model proposed in an embodiment of the present invention;

[0024] Figure 4 This is a schematic diagram of an electronic device according to an embodiment of the present invention. Detailed Implementation

[0025] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0026] refer to Figure 1 , Figure 1 This is a structural block diagram of a secure operation system according to an embodiment of the present invention. Figure 1 As shown, the security operation system in this embodiment includes at least: an alarm collection module, a false alarm analysis module, a report generation module, and a source tracing notification module.

[0027] The alarm collection module is used to collect alarm records generated by various security platforms and send the alarm records to the false alarm analysis module.

[0028] In this embodiment, the alarm collection module is communicatively connected to multiple security platforms. The alarm collection module can collect alarm records generated by each security platform and send the collected alarm records to the false alarm analysis module. Here, each security platform can refer to a platform set up within an enterprise for security monitoring, such as a scanner or monitor that can monitor attack behavior, record alarm information, and generate corresponding alarm records.

[0029] The false alarm analysis module is used to identify the alarm record using a false alarm analysis model to determine whether the alarm record is a false alarm; if the alarm record is not a false alarm, the alarm record is sent to the report generation module.

[0030] In this embodiment, after receiving alarm records from the alarm collection module, the false alarm analysis module can use a pre-trained false alarm analysis model to identify whether the alarm record is a false alarm and output the identification result. The identification result includes: the alarm record is not a false alarm, and the alarm record is a false alarm. The false alarm analysis model in this embodiment is a false alarm identification model built based on machine learning methods. During training, binary classification training is performed until the model's success rate in identifying false alarms reaches a preset threshold (e.g., 90%). The trained false alarm analysis model is used to identify false alarms in alarm records generated by various security platforms.

[0031] In this embodiment, if the false alarm judgment module determines that the alarm record is not a false alarm, it needs to send the non-false alarm record to the report generation module for subsequent processing.

[0032] The report generation module is used to generate and display an alarm event analysis report based on the alarm record using a large report generation model. In response to the user's judgment based on the alarm event analysis report, the module determines whether the alarm record is a false alarm. If the alarm record is not a false alarm, the module sends the alarm record to the source tracing notification module.

[0033] In this embodiment, the report generation module deploys a large-scale report generation model, which is trained based on a large-scale security model and is used to automatically generate alarm event analysis reports based on alarm records. In one example, the alarm event analysis report may include: original alarm information (i.e., alarm records), relevant threat intelligence, and historical similar alarms. The large-scale security model is a large language model developed for the security vertical domain. It is trained with massive amounts of professional security knowledge, endowing the machine with language intelligence similar to that of security experts, enabling it to process massive amounts of security data and perform security-specific tasks. The large-scale security model is of great significance in protecting organizational and personal information security and improving security protection efficiency. A large-scale model refers to a machine learning model with a large number of parameters and complex computational structures. These models are typically built from deep neural networks and have billions or even hundreds of billions of parameters. The design purpose of large-scale models is to improve the expressive power and predictive performance of the model, enabling it to handle more complex tasks and data. Large-scale models have wide applications in various fields, including natural language processing, computer vision, speech recognition, and recommendation systems. Large models learn complex patterns and features by training on massive amounts of data, and have a stronger generalization ability, enabling them to make accurate predictions on unseen data.

[0034] The report generation module utilizes a large-scale report generation model to generate and display alarm event analysis reports based on received alarm records. Each alarm record corresponds to one alarm event analysis report. The alarm event analysis report includes at least the alarm record (i.e., the original alarm records generated by each security platform). In this embodiment, the alarm event analysis report is automatically generated through the large-scale report generation model, eliminating the need for manual document review; instead, it is displayed to operations personnel along with the original alarm information.

[0035] This embodiment generates a large model through report generation. Based on the alarm content, it automatically retrieves historical similar alarm information and related threat intelligence, and then organizes them into a report format. Operations personnel no longer need to manually search for information; instead, the information is presented to them along with the original alarm information, greatly improving operational efficiency. Furthermore, after an incident, it can also help operations personnel compile a final incident report based on multi-dimensional descriptions, significantly reducing the operational burden.

[0036] Users can perform manual analysis based on the displayed alarm event analysis report. For example, security experts can manually analyze the report based on information from the previous step to ensure the accuracy of alarm handling, determine whether the alarm record corresponding to the alarm event analysis report is a false alarm, and take appropriate action in the security operations system. The report generation module responds to the user's analysis based on the alarm event analysis report, determines whether the alarm record is a false alarm, and obtains the manual analysis result, including: the alarm record is not a false alarm, or the alarm record is a false alarm. If the manual analysis result indicates that the alarm record is not a false alarm, the report generation module needs to send the notified alarm record to the source tracing notification module for further processing.

[0037] The source tracing notification module is used to determine the corresponding involved personnel based on the alarm records and send the alarm records to the involved personnel.

[0038] In this embodiment, the source tracing notification module receives alarm records that are determined to be genuine alarms by both the false alarm analysis module and the report generation module. Through dual verification using a false alarm analysis model and manual analysis, the alarm record can be accurately identified as a genuine alarm record. At this point, the source tracing notification module can determine the relevant personnel corresponding to the received alarm record and send the alarm record to the relevant personnel, generating an alarm. For example, a notification mechanism can be automatically triggered based on the security event level of the alarm record to promptly notify the relevant personnel to respond. The relevant personnel can refer to those involved in the critical operations corresponding to the alarm record, such as those involved in critical operations on the asset for which the alarm record is located.

[0039] In this embodiment, a pre-trained false alarm analysis model reduces the false alarm generation rate, blocking a large number of false alarms before manual investigation, thus reducing the manpower required by the security operations team. At the same time, at least a report generation module and a source tracing notification module are included to automate the process. This allows security operations personnel to significantly reduce repetitive tasks and focus solely on process approval, greatly improving the efficiency of internal security operations. Thus, from alarm generation to event resolution, the only area requiring manual intervention by operations personnel is the manual analysis of false alarms: operator tracing, information synchronization, report generation, and other operations are all handled automatically by the intelligent security operations system, eliminating the need for significant human intervention.

[0040] In conjunction with the above embodiments, in one implementation, the present invention also provides a security operation system. Specifically, in this embodiment, the false alarm analysis module is further configured to send the alarm record to a false alarm dataset when the alarm record is a false alarm.

[0041] In this embodiment, the false alarm judgment model is trained based on false alarm alarm records and real attack data. For example, it learns from previously accumulated false alarm data and malicious attack data through binary classification training. This allows the trained false alarm judgment module to automatically determine whether an alarm record is a false alarm. If the false alarm judgment module determines that the alarm record is a false alarm, it sends the false alarm record (i.e., false alarm data) to the false alarm dataset, thus blocking the alarm and preventing false alarms from interfering with system security. In this embodiment, the false alarm dataset is used to train, validate, and update the false alarm judgment model in the false alarm judgment module.

[0042] The report generation module is also used to send the alarm record to the false alarm dataset if the alarm record is a false alarm.

[0043] In this embodiment, if the obtained manual assessment result is that the alarm record is a false alarm, the report generation module can send the false alarm record to the false alarm dataset, and the alarm will be blocked to avoid the false alarm from interfering with the system security.

[0044] The false alarm analysis module is also used to update the false alarm analysis model based on the false alarm dataset.

[0045] In this embodiment, the false alarm analysis module can also update the false alarm analysis model based on the false alarm dataset collected after the false alarm analysis model is launched, thereby further improving the accuracy of the false alarm analysis model in identifying false alarms.

[0046] In conjunction with the above embodiments, in one implementation, the present invention also provides a security operation system. Specifically, in this embodiment, the source tracing notification module is further configured to create a group chat for the involved personnel and display the alarm event analysis report in the group chat.

[0047] In this embodiment, the report generation module sends an alarm record to the source tracing notification module along with the corresponding alarm event analysis report. After identifying the personnel involved in the alarm record, the source tracing notification module can create a group chat for those personnel and display the alarm event analysis report in the created group. Therefore, this embodiment eliminates the need for involved personnel to manually view the alarm event analysis report, thus providing a real-time communication platform between security teams and promoting information sharing and collaboration.

[0048] In one implementation, the personnel involved include at least: the personnel involved (such as the account user), the security officer, and the asset interface person.

[0049] The source tracing notification module is also used to respond to the judgment of the relevant personnel in the group chat to determine whether the alarm event corresponding to the alarm record is a human operation by internal personnel; if the alarm event is not a human operation by internal personnel, an emergency response is performed on the alarm record.

[0050] In this embodiment, within the created group chat, relevant personnel can analyze the alarm event report to determine whether the alarm event corresponding to the alarm record was caused by internal personnel's human intervention, and then respond accordingly in the security operations system. The source tracing notification module responds to the analysis conducted by relevant personnel in the group chat, determining whether the alarm event corresponding to the alarm record was caused by internal personnel's human intervention, and obtaining a human intervention analysis result. This human intervention analysis result includes: the alarm event was caused by internal personnel's human intervention, or the alarm event was not caused by internal personnel's human intervention.

[0051] If the source tracing and notification module determines that the alarm event is not caused by internal personnel (e.g., it cannot be determined that the alarm record is caused by internal personnel), the alarm event corresponding to the alarm record is determined to be a human attack. At this time, the source tracing and notification module immediately initiates an emergency response for the alarm record.

[0052] In conjunction with the above embodiments, in another implementation, the present invention also provides a security operation system. Specifically, in this embodiment, the security operation system further includes an automatic training module.

[0053] The source tracing notification module is also used to send the information of the actual operator and the safety manager among the personnel involved, as well as the alarm record, to the automatic training module when the alarm event is caused by human operation by internal personnel.

[0054] In this embodiment, when the source tracing notification module determines that the human operation analysis result is that the alarm event was caused by internal personnel, it can send the information of the actual operator and the safety manager among the personnel involved, as well as the alarm record corresponding to the alarm event, to the automatic training module.

[0055] The automatic training module is used to generate training content based on the alarm records and the information of the actual operator and the safety officer using an automatic training big data model, and to send the training content to the actual operator and the safety officer, and to monitor the training.

[0056] In this embodiment, the automatic training module deploys an automatic training model. This model allows the module to generate training content for operators and safety officers based on received alarm records and information about the operators and safety officers. This training content is customized and automated, provided automatically by the automatic training knowledge base to meet safety awareness training needs. The automatic training module can send the generated training content to the operators and safety officers, for example, by pushing links to the automatic training materials (including the training content), to train and monitor them. The alarm process ends only after the training is completed.

[0057] The automated training model in this embodiment can automatically generate training content for the actual operator and safety manager (such as the person who made the mistake) based on the alarm record corresponding to the alarm event and the information of the actual operator and the safety manager. This can improve the safety awareness of internal personnel in a timely manner, and the operation personnel no longer need to spend time and effort to promote safety, but the automated training module will complete the task.

[0058] In conjunction with the above embodiments, in another implementation, this embodiment of the invention also provides a secure operation system. In this embodiment, the automatic training module is further configured to send the training results to the report generation module after monitoring the completion of training.

[0059] In this embodiment, the automatic training module obtains the training results after monitoring the completion of the training and sends the training results to the report generation module.

[0060] The source tracing notification module is also used to generate a source tracing report based on the personnel involved and send it to the report generation module.

[0061] In this embodiment, the source tracing notification module also generates a source tracing report based on the personnel involved and sends it to the report generation module. The source tracing report includes the complete process steps, node information, and personnel information corresponding to the alarm event.

[0062] The report generation module is also used to generate and display a security operation event report based at least on the training results, the source tracing report, and the alarm event analysis report.

[0063] In this embodiment, after receiving the training results and the source tracing report, the report generation module will generate and display a security operation event report based on at least the training results, the source tracing report, and the alarm event analysis report. Furthermore, in one embodiment, the report generation module can generate and display a security operation event report based on the training results, the source tracing report, the alarm event analysis report, and a description of the account user (i.e., a description of the actual operator's work regarding the alarm event).

[0064] In conjunction with the above embodiments, in one implementation, the present invention also provides a security operation system. Specifically, in this embodiment, the alarm collection module is specifically used for:

[0065] Collect alarm records generated by various security platforms, and the alarm records shall include at least one of the following: local privilege escalation, system backdoor monitoring, web backdoor detection, and password brute-force.

[0066] The alarm records are organized by category using a Kafka cluster to generate a consumption queue;

[0067] By subscribing to the data stream of the Kafka cluster, the alarm records are pulled from the message queue and transferred to the false alarm analysis module.

[0068] In this embodiment, the alarm collection module collects alarm records generated by various security platforms. These alarm records include at least one of the following: local privilege escalation, system backdoor monitoring, web backdoor detection, and password brute-force attacks. All these alarm records are then produced to the Kafka cluster. Next, the alarm collection module uses the Kafka cluster to categorize and organize the collected alarm records, generating a consumption queue for consumption, which is then used for security analysis and troubleshooting. Finally, the alarm collection module subscribes to the data stream of the Kafka cluster, pulls alarm records from the message queue, and forwards the pulled alarm records to the false alarm analysis module. Specifically, when a security platform generates a new alarm shortcut, it can consume data from the message queue one by one and forward it to the false alarm analysis model of the false alarm analysis module.

[0069] Based on the same inventive concept, one embodiment of the present invention provides a safe operation method. (See reference...) Figure 2 , Figure 2 This is a flowchart of a security operation method provided by an embodiment of the present invention. The security operation method of this embodiment is applied to the security operation system described in any of the above embodiments, which includes at least: an alarm collection module, a false alarm analysis module, a report generation module, and a source tracing notification module. Figure 2 As shown, this security operation method includes at least the following steps:

[0070] Step S11: Collect alarm records generated by each security platform through the alarm collection module, and send the alarm records to the false alarm analysis module;

[0071] Step S12: The false alarm judgment module uses a false alarm judgment model to identify the alarm record and determine whether the alarm record is a false alarm; if the alarm record is not a false alarm, the alarm record is sent to the report generation module.

[0072] Step S13: Using the report generation module and the large model for report generation, generate and display an alarm event analysis report based on the alarm record. In response to the user's judgment based on the alarm event analysis report, determine whether the alarm record is a false alarm. If the alarm record is not a false alarm, send the alarm record to the source tracing notification module.

[0073] Step S14: Through the source tracing notification module, determine the corresponding involved personnel based on the alarm record, and send the alarm record to the involved personnel.

[0074] Optionally, in one embodiment, a security operation method is provided, wherein the false alarm judgment model is trained based on false alarm alarm records and real attack data; the method further includes:

[0075] The false alarm analysis module sends the alarm record to the false alarm dataset when the alarm record is a false alarm.

[0076] In the event that the alarm record is a false alarm, the alarm record is sent to the false alarm dataset via the report generation module.

[0077] The false alarm analysis module updates the false alarm analysis model based on the false alarm dataset.

[0078] Optionally, in one embodiment, a security operation method is provided, the method further comprising:

[0079] The source tracing and notification module creates a group chat for the relevant personnel and displays the alarm event analysis report in the group chat.

[0080] Through the source tracing notification module, in response to the judgment of the relevant personnel in the group chat, it is determined whether the alarm event corresponding to the alarm record is a human operation by internal personnel; if the alarm event is not a human operation by internal personnel, an emergency response is carried out on the alarm record.

[0081] Optionally, in one embodiment, a safe operation method is provided, wherein the system further includes: an automatic training module; the method further includes:

[0082] In the event that the alarm event is caused by human intervention by internal personnel, the traceability notification module sends the information of the actual operator and the safety manager among the personnel involved, as well as the alarm record, to the automatic training module.

[0083] The automatic training module utilizes an automatic training model to generate training content based on alarm records and the information of the actual operator and the safety officer. The training content is then sent to the actual operator and the safety officer, and training monitoring is performed.

[0084] Optionally, in one embodiment, a security operation method is provided, the method further comprising:

[0085] The automatic training module sends the training results to the report generation module after monitoring the completion of the training.

[0086] The source tracing notification module generates a source tracing report based on the personnel involved and sends it to the report generation module.

[0087] The report generation module generates and displays a security operation event report based at least on the training results, the source tracing report, and the alarm event analysis report.

[0088] Optionally, in one embodiment, a secure operation method is provided, in which step S11 specifically includes the following steps:

[0089] The alarm collection module collects alarm records generated by various security platforms. The alarm records include at least one of the following: local privilege escalation, system backdoor monitoring, web backdoor detection, and password brute-force.

[0090] The alarm collection module organizes the alarm records by category through the Kafka cluster and generates a consumption queue.

[0091] The alarm collection module retrieves alarm records from the message queue by subscribing to the data stream of the Kafka cluster and then forwards them to the false alarm analysis module.

[0092] like Figure 3 As shown, Figure 3 This is an overall flowchart of an automated internal security operation method based on a large security model, proposed in one embodiment of the present invention. Figure 3In this process, each security platform generates security platform logs based on alarm information recorded by its scanners, monitors, etc., and produces them all to the Kafka cluster. The Kafka cluster then categorizes and organizes these alarm logs, awaiting consumption by the alarm collection module and for use in security analysis and troubleshooting. The alarm collection module subscribes to the Kafka cluster's data stream, and when a new alarm is generated by the platform, it consumes the data one by one from the message queue and transfers it to the false alarm analysis model (i.e., the false alarm analysis model in the aforementioned embodiment). This false alarm analysis model is a false alarm identification model built using machine learning algorithms. It learns from previously accumulated false alarm data and malicious attack data, performing binary classification training until the false alarm analysis model achieves a 90% success rate in identifying false alarms.

[0093] In the false alarm analysis mini-model, an automatic mechanism determines whether an alarm is a false alarm: if it is determined to be a valid alarm (potentially an attack), the alarm data is transmitted to the report generation module for further processing; if it is a false alarm, the alarm is transmitted to the false alarm dataset, and the alarm is blocked to prevent false alarms from interfering with system security. The false alarm dataset collects new false alarm data generated after the mini-model goes live, and is used for training, updating, and validating the false alarm analysis mini-model.

[0094] The report generation module integrates a large-scale report generation model, which can automatically generate alarm event analysis reports based on this model. These reports include the following: original alarm information, relevant threat intelligence, and historical similar alarms. This eliminates the need for manual data review; the information is presented to operations personnel along with the original alarm information. If the false alarm analysis model cannot determine that an alarm record is a genuine false alarm, security experts can manually assess the alarm based on the information in the report generated by the module, ensuring the accuracy of alarm handling. If the manual assessment determines it is not a false alarm (potentially an attack), the alarm data is transmitted to the operation tracing module for further steps. If the manual assessment determines it is a false alarm, the alarm data is transmitted to the false alarm dataset for model updates, and the alarm is blocked.

[0095] The operation tracing module can record a list of relevant personnel involved in key operations on the corresponding assets based on received alarm information, generate a tracing report, and send it to the report generation module. Then, through the automatic notification module, a notification mechanism is automatically triggered according to the security incident level to promptly notify relevant personnel to respond. Specifically, a response group chat can be quickly created based on the list of relevant personnel (such as the list of involved personnel, security officers, and asset interface personnel), and the report information generated by the report generation module can be automatically synchronized, eliminating the need for manual viewing by relevant personnel. A real-time communication platform is provided between security teams to promote information sharing and collaboration. Furthermore, in the group chat, parties can determine whether the operation was performed by internal personnel: if it is determined to be an internal operation, an automatic training link is pushed to the actual operator and the security officer; the alarm process can only end after completing the automatic training system; if it cannot be determined that it was an internal operation, an emergency response should be initiated immediately.

[0096] In the automated training system (i.e., the automated training module in the aforementioned embodiments), customized automated training content and solutions can be automatically provided based on the deployed automated training model to meet security awareness training needs, relying on the security training knowledge base, and pushed to relevant personnel for training. After the relevant personnel complete the training, the training results are generated and sent to the report generation module. The report generation module generates the final event operation report based on the alarm report, the source tracing report, the training results, and the account user information, thereby completing the security operation of this alarm.

[0097] The automated internal security operations method based on a large security model proposed in this embodiment is applicable to enterprises that have already deployed various security platforms, scanners, and monitors and require the ability to train large security models. This embodiment fully utilizes model capabilities (large models and machine learning models), specifically combining them in three scenarios: First, a false alarm analysis model, which, through training, can significantly reduce the false alarm rate and decrease manual investigation; second, a report generation model, which can automatically retrieve historical similar alarm information and related threat intelligence based on the alarm content, and then organize it into a report format. Operations personnel no longer need to manually review materials; instead, the information is presented to them along with the original alarm information, greatly improving operational efficiency. Furthermore, after the incident, it can also help operations personnel compile a final incident report based on multi-dimensional descriptions, greatly reducing the operational burden; third, an automated training model, which can automatically generate training content for personnel who made mistakes based on the content of the alarm event, promptly improving the security awareness of internal personnel. Simultaneously, operations personnel no longer need to expend effort on security training; instead, the automated training system handles this.

[0098] Furthermore, the automated internal security operation method based on a large security model, as illustrated in this embodiment, proposes an automated event handling process: from alarm generation to event termination, the only point where operators need to manually intervene is the manual assessment of false alarms. All operations, such as operator attribution, group chat creation, information synchronization, report generation, and security dissemination, are handled automatically by the intelligent system, eliminating the need for significant human intervention.

[0099] It should be noted that, for the sake of simplicity, the method embodiments are all described as a series of actions. However, those skilled in the art should understand that the embodiments of the present invention are not limited to the described order of actions, because according to the embodiments of the present invention, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions involved are not necessarily essential to the embodiments of the present invention.

[0100] As the method embodiments are basically similar to the system embodiments, the description is relatively simple, and relevant parts can be found in the description of the system embodiments.

[0101] Based on the same inventive concept, another embodiment of the present invention provides an electronic device, such as... Figure 4 As shown. Figure 4 This is a schematic diagram of an electronic device according to an embodiment of the present invention. The electronic device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When executed by the processor, the program implements the steps of the secure operation method described in any of the above embodiments of the present invention.

[0102] Based on the same inventive concept, another embodiment of the present invention provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps in the secure operation method described in any of the above embodiments of the present invention.

[0103] Based on the same inventive concept, another embodiment of the present invention provides a computer program product, including a computer program / instruction, which, when executed by a processor, implements the steps in the secure operation method described in any of the above embodiments of the present invention.

[0104] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.

[0105] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, apparatus, or computer program products. Therefore, embodiments of the present invention can take the form of entirely hardware embodiments, entirely software embodiments, or embodiments combining software and hardware aspects. Furthermore, embodiments of the present invention can take the form of computer program products implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0106] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, terminal devices (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing terminal device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing terminal device, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0107] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing terminal device to operate in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0108] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal equipment, causing a series of operational steps to be performed on the computer or other programmable terminal equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable terminal equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0109] Although preferred embodiments of the present invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of the embodiments of the present invention.

[0110] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or terminal device. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or terminal device that includes said element.

[0111] The above provides a detailed description of the safe operation system, method, device, medium, and product provided by the present invention. Specific examples have been used to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only for the purpose of helping to understand the method and core ideas of the present invention. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.

Claims

1. A secure operation system, characterized in that, The system includes at least: an alarm collection module, a false alarm analysis module, a report generation module, and a source tracing and notification module; The alarm collection module is used to collect alarm records generated by various security platforms and send the alarm records to the false alarm analysis module; The false alarm analysis module is used to identify the alarm record using a false alarm analysis model to determine whether the alarm record is a false alarm; if the alarm record is not a false alarm, the alarm record is sent to the report generation module. The report generation module is used to generate and display an alarm event analysis report based on the alarm record using a large report generation model, and respond to the user's judgment based on the alarm event analysis report to determine whether the alarm record is a false alarm; if the alarm record is not a false alarm, the alarm record is sent to the source tracing notification module. The source tracing and notification module is used to identify the relevant personnel based on the alarm record and send the alarm record to the relevant personnel. It is also used to create a group chat for the relevant personnel, display the alarm event analysis report in the group chat, and respond to the judgment of the relevant personnel in the group chat to determine whether the alarm event corresponding to the alarm record is a human operation by internal personnel. If the alarm event is not a human operation by internal personnel, an emergency response is performed on the alarm record.

2. The secure operation system according to claim 1, characterized in that, The false alarm analysis model is trained based on false alarm alarm records and real attack data; The false alarm analysis module is also used to send the alarm record to the false alarm dataset when the alarm record is a false alarm; The report generation module is also used to send the alarm record to the false alarm dataset when the alarm record is a false alarm; The false alarm analysis module is also used to update the false alarm analysis model based on the false alarm dataset.

3. The secure operation system according to claim 1, characterized in that, The system also includes: an automatic training module; The source tracing notification module is also used to send the information of the actual operator and the safety manager among the personnel involved, as well as the alarm record, to the automatic training module when the alarm event is a human operation by internal personnel. The automatic training module is used to generate training content based on the alarm records and the information of the actual operator and the safety officer using an automatic training big data model, and to send the training content to the actual operator and the safety officer, and to monitor the training.

4. The safe operation system according to claim 3, characterized in that, The automatic training module is also used to send the training results to the report generation module after monitoring that the training has been completed; The source tracing notification module is also used to generate a source tracing report based on the personnel involved and send it to the report generation module; The report generation module is also used to generate and display a security operation event report based at least on the training results, the source tracing report, and the alarm event analysis report.

5. The secure operation system according to any one of claims 1 to 4, characterized in that, The alarm collection module is specifically used for: Collect alarm records generated by various security platforms, and the alarm records shall include at least one of the following: local privilege escalation, system backdoor monitoring, web backdoor detection, and password brute-force. The alarm records are organized by category using a Kafka cluster to generate a consumption queue; By subscribing to the data stream of the Kafka cluster, the alarm records are pulled from the consumer queue and transferred to the false alarm analysis module.

6. A safe operation method, characterized in that, Applied to the security operation system as described in any one of claims 1 to 5, the method comprises: The alarm collection module collects alarm records generated by various security platforms and sends the alarm records to the false alarm analysis module. The false alarm analysis module uses a false alarm analysis model to identify the alarm record and determine whether the alarm record is a false alarm; if the alarm record is not a false alarm, the alarm record is sent to the report generation module. The report generation module utilizes a large-scale report generation model to generate and display an alarm event analysis report based on the alarm records. In response to the user's judgment based on the alarm event analysis report, it determines whether the alarm record is a false alarm. If the alarm record is not a false alarm, the alarm record is sent to the source tracing notification module. The source tracing and notification module identifies the relevant personnel based on the alarm records and sends the alarm records to them. A group chat is created for the relevant personnel, and the alarm event analysis report is displayed in the group chat. Based on the judgment of the relevant personnel in the group chat, it is determined whether the alarm event corresponding to the alarm record is due to human intervention by internal personnel. If the alarm event is not due to human intervention by internal personnel, an emergency response is initiated for the alarm record.

7. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the computer program is executed by the processor, it implements the secure operation method as described in claim 6.

8. A computer-readable storage medium storing a computer program thereon, characterized in that, When the computer program is executed by the processor, it implements the secure operation method as described in claim 6.

9. A computer program product, comprising a computer program / instructions, characterized in that, When the computer program / instruction is executed by the processor, it implements the secure operation method of claim 6.

Citation Information

Patent Citations

  • System for affirming responsibility traceability

    CN113034028A

  • Possibility assessment of security event alerts

    CN117501658A