A network security alarm event false alarm removal method, device, equipment and medium
By employing cluster statistics, autocorrelation coefficient calculation, and time-frequency domain transformation, the problems of cumbersome and inaccurate false alarm handling in network security devices have been solved, achieving efficient and widely applicable false alarm removal.
Patent Information
- Application Number
- CN202411995565.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-31
- Publication Date
- 2026-02-06
- Estimated Expiration
- 2044-12-31
AI Technical Summary
Existing technologies for handling false alarms in network security devices are cumbersome, have low accuracy, and poor applicability, making it difficult to effectively eliminate false alarms.
By acquiring false alarm events, setting autocorrelation coefficient thresholds and processing intervals, cluster statistics and sequence recombination are performed to calculate autocorrelation coefficients and perform time-frequency domain transformation to remove non-zero target periodic event sequences.
It improves the accuracy and ease of false alarm removal, enhances the wide applicability of false alarm removal, and simplifies the false alarm handling process.
Smart Images

Figure CN119892592B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of network security intelligence analysis, and particularly relates to a network security alarm event false alarm removal method, device, equipment and medium. BACKGROUND
[0002] False alarms are often contained in the alarms generated by various security products, and false alarms have become an inevitable problem in network security devices. These false alarms seriously interfere with network security analysts. For example, some normal devices generate a large number of security events due to configuration or operation errors, causing false alarms. By statistically analyzing real scene alarm data, it is found that false alarms are often of a large data volume, and the same IP has a high proportion, the corresponding source or destination IP distribution is relatively uniform, and the duration is relatively long, etc., making it difficult to accurately remove false alarms.
[0003] The prior art is a statistical analysis method that can find that many false alarms have some characteristics compared with real alarms on the basis of analyzing large-scale and large-number alarms. Statistical analysis mainly finds alarm sets that meet false alarm characteristics, and then extracts filtering rules. The rules are based on the specific characteristics of the alarm set, thereby reducing the false alarm rate. This method needs to compare and analyze real alarms and false alarms, extract features, and needs a large amount of expert knowledge support. In addition, the alarm rules of various security devices are the same, and it is difficult to truly solve the actual problem, so a new false alarm removal method is needed to improve the simplicity, accuracy and wide applicability of false alarm removal. SUMMARY
[0004] Therefore, the present application provides a network security alarm event false alarm removal method, device, equipment and medium to solve the problems of false alarm removal complexity, low accuracy and poor applicability.
[0005] In a first aspect, the present application provides a network security alarm event false alarm removal method, which comprises:
[0006] obtaining a false alarm event, a preset autocorrelation coefficient threshold, a trend false alarm processing interval and a periodic false alarm processing interval;
[0007] Based on the trend false alarm processing interval, the false alarm events are clustered and counted to obtain a plurality of trend event sequences;
[0008] Based on the periodic false alarm processing interval, the plurality of trend event sequences are reorganized to obtain a plurality of periodic event sequences;
[0009] The autocorrelation coefficients of the plurality of periodic event sequences are calculated, and the autocorrelation coefficients are compared with the preset autocorrelation coefficient threshold to determine a plurality of target periodic event sequences;
[0010] time-frequency domain conversion is performed on the plurality of target periodic event sequences to obtain target periodic values, and target periodic event sequences with a non-zero target periodic value are removed.
[0011] The false alarm removal method provided by the embodiment of the present application improves the accuracy of determining the plurality of periodic event sequences, and further improves the accuracy of false alarm removal. In addition, the false alarm removal method provided by the embodiment of the present application improves the simplicity and wide applicability of false alarm removal through multiple sequence clustering statistics and combination of time-frequency domain conversion.
[0012] In an optional implementation, the clustering and counting of the false alarm events based on the trend false alarm processing interval to obtain a plurality of trend event sequences comprises:
[0013] The address information and type information corresponding to the false alarm events are obtained.
[0014] The clustering and counting of the false alarm events based on the trend false alarm processing interval, the address information and the type information to obtain a plurality of interval event sequences.
[0015] When the number of events corresponding to the plurality of interval event sequences is the same, first-order difference is performed on each interval event sequence to obtain the plurality of trend event sequences.
[0016] The false alarm removal method provided by the embodiment of the present application improves the accuracy of determining the plurality of trend event sequences, and further improves the accuracy of false alarm removal.
[0017] In an optional implementation, the sequence reorganization of the plurality of trend event sequences based on the periodic false alarm processing interval to obtain a plurality of periodic event sequences comprises:
[0018] an acquisition period arrangement order;
[0019] Based on the period false alarm processing interval, the period arrangement order and the address information, the multiple trend event sequences are recombined to obtain the multiple period event sequences.
[0020] The false alarm removal method provided by the embodiment of the application combines the period false alarm processing interval, the period arrangement order and the address information to recombine the multiple trend event sequences, and then obtains the multiple period event sequences, thereby improving the rigor of the recombination process and the rigor and accuracy of the multiple period event sequences.
[0021] In an optional implementation, the calculating the autocorrelation coefficients of the multiple period event sequences comprises:
[0022] acquiring a lag sequence number;
[0023] Based on the lag sequence number, multiple lag period event sequences in the multiple period event sequences are determined.
[0024] Based on a coefficient calculation formula, autocorrelation coefficients of the multiple lag period event sequences are calculated to determine the autocorrelation coefficient corresponding to each lag period event sequence.
[0025] The false alarm removal method provided by the embodiment of the application determines multiple lag period event sequences through the lag sequence number, calculates autocorrelation coefficients of the multiple lag period event sequences based on a coefficient calculation formula, and then determines the autocorrelation coefficient corresponding to each lag period event sequence, thereby improving the accuracy of the autocorrelation coefficient calculation and providing more comprehensive and accurate information for subsequent false alarm removal period event sequence determination based on the autocorrelation coefficient calculation, and further improving the accuracy of the false alarm removal.
[0026] In an optional implementation, the comparing the autocorrelation coefficients with a preset autocorrelation coefficient threshold to determine multiple target period event sequences comprises:
[0027] Based on the comparison of the autocorrelation coefficients and the preset autocorrelation coefficient threshold, a coefficient comparison result is obtained.
[0028] The coefficient comparison result indicates that the period event sequence in the multiple period event sequences, in which the autocorrelation coefficient is greater than the preset autocorrelation coefficient threshold, is determined as the multiple target period event sequences.
[0029] The false report removal method provided by the embodiment of the present application compares the calculated autocorrelation coefficient with the preset autocorrelation coefficient threshold, and determines the period event sequence in which the autocorrelation coefficient is greater than the preset autocorrelation coefficient threshold in the plurality of period event sequences as the plurality of target period event sequences in the coefficient comparison result, thereby improving the accuracy and authenticity of determining the target period event sequence, and further providing effective data support for removing false reports in a mass of events.
[0030] In some optional embodiments, the time-frequency domain conversion of the plurality of target period event sequences to determine the target period value comprises:
[0031] The plurality of target period event sequences are subjected to Fourier processing to obtain a plurality of frequency values;
[0032] The plurality of frequency values are sorted to determine a target frequency value;
[0033] The target period value is determined based on the target frequency value and a period calculation formula.
[0034] The false report removal method provided by the embodiment of the present application determines a plurality of frequency values by Fourier processing the plurality of period event sequences, sorts the plurality of frequency values, and further determines the maximum frequency value as the target frequency value, and further applies the target frequency value to the period calculation formula to determine the target period value, thereby improving the rationality, rigor and calculation simplicity of determining the target period value.
[0035] In some optional embodiments, before the clustering and counting of the false report events based on the trend false report processing interval to obtain the plurality of interval event sequences, the method further comprises:
[0036] Obtaining a preset event format;
[0037] Based on the preset event format and the false report event, performing format processing to obtain a format false report event;
[0038] Based on the trend false report processing interval, clustering and counting the format false report event to obtain a plurality of interval event sequences.
[0039] The false report removal method provided by the embodiment of the present application performs format processing on the false report event based on the preset event format, and further clusters and counts the obtained format false report event based on the trend false report processing interval to obtain a plurality of interval event sequences, thereby improving the simplicity of false report event analysis and the simplicity of determining the interval event sequence.
[0040] In a second aspect, the present application provides a false report removal device, the device comprising:
[0041] The acquisition module is configured to acquire a false alarm event, a preset autocorrelation coefficient threshold, a trend false alarm processing interval, and a periodic false alarm processing interval.
[0042] The statistical module is configured to perform cluster statistics on the false alarm event based on the trend false alarm processing interval to obtain a plurality of trend event sequences.
[0043] The reorganization module is configured to perform sequence reorganization on the plurality of trend event sequences based on the periodic false alarm processing interval to obtain a plurality of periodic event sequences.
[0044] The calculation module is configured to calculate autocorrelation coefficients of the plurality of periodic event sequences, and compare the autocorrelation coefficients with the preset autocorrelation coefficient threshold to determine a plurality of target periodic event sequences.
[0045] The removal module is configured to perform time-frequency domain conversion on the plurality of target periodic event sequences to obtain target periodic values, and remove target periodic event sequences with non-zero target periodic values.
[0046] In a third aspect, the present application provides a computer device, comprising a memory and a processor, the memory and the processor are communicatively connected with each other, the memory stores computer instructions, and the processor executes the computer instructions to perform the false alarm removal method of the first aspect or any of the corresponding embodiments thereof.
[0047] In a fourth aspect, the present application provides a computer readable storage medium, which stores computer instructions, and the computer instructions are used to make a computer execute the false alarm removal method of the first aspect or any of the corresponding embodiments thereof.
[0048] In a fifth aspect, the present application provides a computer program product, which comprises computer instructions, and the computer instructions are used to make a computer execute the false alarm removal method of the first aspect or any of the corresponding embodiments thereof. BRIEF DESCRIPTION OF DRAWINGS
[0049] In order to more clearly illustrate the specific embodiments of the present application or the technical solutions in the prior art, the drawings needed in the specific embodiments or prior art description will be briefly introduced as follows. Obviously, the drawings in the following description are some embodiments of the present application, and those skilled in the art can obtain other drawings according to these drawings without creative labor.
[0050] Figure 1 is a flowchart of the false alarm removal method according to the embodiments of the present application;
[0051] Figure 2 is a schematic diagram of the false alarm removal device according to the embodiments of the present application;
[0052] Figure 3 This is a schematic diagram of the structure of a computer device provided in an optional embodiment of the present invention. Detailed Implementation
[0053] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0054] Network security devices often contain numerous alarm errors. The existence of these alarm errors makes it difficult for security analysts to conduct effective security analysis, causing considerable trouble. In particular, a large number of false alarms caused by configuration errors or operational mistakes increase the difficulty of false alarm analysis. Furthermore, statistical analysis of alarm data in real-world scenarios often reveals that false alarms are characterized by a huge volume of data, a high proportion of the same IP address, a relatively even distribution of the corresponding source or destination IP addresses, and a long duration, making it difficult to accurately remove false alarms.
[0055] Existing false alarm removal technologies typically rely on statistical analysis to remove false alarms based on the analysis of large-scale and numerous alarms. This approach requires comparative analysis of real alarms and false alarms to extract features, necessitates extensive expert knowledge, and faces challenges in truly solving practical problems due to the different alarm rules of various security devices in real-world scenarios.
[0056] The volume of cybersecurity incidents in the big data environment is enormous, and the types of incidents are complex and intertwined. Analysis of numerous real alerts from multiple regulated enterprises revealed the following patterns:
[0057] 1. Individual security incidents account for the vast majority of all alarm events.
[0058] 2. A few individual IPs account for the vast majority of all alarm IPs, and this number is constantly increasing.
[0059] 3. The number of certain alarms remains almost constant within a unit of time.
[0060] 4. The number of alarms may vary per unit of time, but the number of alarms may be almost the same over a period of time.
[0061] The first two points indicate that the false alarm events have certain trend, and the last two points indicate that the number of false alarm events meets certain periodicity. Therefore, it is assumed that the false alarm events have certain regular behavior, such as meeting certain trend or periodicity. Therefore, a new false alarm removal method is provided.
[0062] According to the embodiment of the present application, a network security alarm event false alarm removal method is provided. It should be noted that the steps shown in the flowchart can be executed in a computer system such as a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0063] In this embodiment, a network security alarm event false alarm removal method is provided, which can be used in a system or program for false alarm removal, Figure 1 is a flowchart of the false alarm removal method according to the embodiment of the present application, as Figure 1 shown, the flow includes the following steps:
[0064] Step S101, obtaining false alarm events, a preset autocorrelation coefficient threshold, a trend false alarm processing interval and a periodic false alarm processing interval.
[0065] In one specific embodiment, the false alarm events can be security events collected by the system for false alarm; the preset autocorrelation coefficient threshold can be a standard value for determining whether a periodic event sequence is an attack sequence; the trend false alarm processing interval can be a time interval set for the false alarm events as a trend event sequence; and the periodic false alarm processing interval can be a time interval set for the false alarm events as a periodic event sequence.
[0066] Specifically, in the case of needing to remove false alarms, the false alarm security events existing in the security events, i.e. false alarm events, are obtained. Specifically, when each false alarm event is uploaded to the system, the false alarm event is stored, and further, the target user sets the preset autocorrelation coefficient threshold, the trend false alarm processing interval and the periodic false alarm processing interval based on the actual user demand. Optionally, the preset autocorrelation coefficient can be set based on the actual experience of the target user, and the trend false alarm processing interval and the periodic false alarm processing interval can be set by the target user based on the observation results of the false alarm events.
[0067] Step S102, clustering and counting the false alarm events based on the trend false alarm processing interval to obtain a plurality of trend event sequences.
[0068] In a specific embodiment, the plurality of trend event sequences can be event sequences with trends; specifically, the false alarm events in each trend false alarm processing interval are counted as a plurality of trend event sequences based on the trend false alarm processing interval.
[0069] Step S103, reorganize the plurality of trend event sequences into a plurality of period event sequences based on the period false alarm processing interval.
[0070] In a specific embodiment, the plurality of period event sequences can be event sequences with periodicity; specifically, the plurality of trend event sequences obtained above are re-dispersed, and the false alarm events in each period false alarm processing interval are counted as a plurality of period event sequences based on the period false alarm processing interval.
[0071] Step S104, calculate the autocorrelation coefficients of the plurality of period event sequences, and compare the autocorrelation coefficients with a preset autocorrelation coefficient threshold to determine a plurality of target period event sequences.
[0072] In a specific embodiment, the autocorrelation coefficient can be an autocorrelation coefficient between the plurality of period event sequences; specifically, the autocorrelation coefficients corresponding to the plurality of period event sequences are calculated when the plurality of period event sequences are obtained, and then the calculated autocorrelation coefficients are compared with the stored preset autocorrelation coefficient threshold to determine the target period event sequences.
[0073] Step S105, time-frequency domain conversion is performed on the plurality of target period event sequences to obtain a target period value, and target period event sequences with a target period value of 0 are removed.
[0074] In a specific embodiment, the target period value can be a value in which the period event sequence in the plurality of period event sequences exhibits periodicity; specifically, time domain to frequency domain conversion is performed on the plurality of target period event sequences, and then the target period value is calculated after the conversion is completed. Further, it is identified whether the target period value is 0. The period event sequence with a target period value of 0 is removed as a target period event sequence that needs to be removed, and the target period event that needs to be removed is removed.
[0075] In an optional embodiment, before step S101, the method further comprises:
[0076] Step a1, obtaining a preset event format;
[0077] Step a2, based on the preset event format and the false alarm event, performing format processing to obtain a format false alarm event;
[0078] Step a3, based on the trend false alarm processing interval, the format false alarm events are clustered and counted to obtain a plurality of interval event sequences.
[0079] In one specific embodiment, the preset event format can be an event format that can be recognized by the system or program; the trend false alarm processing interval can be a time interval in which false alarm events are divided into trend event sequences; specifically, the formats of security event data such as alarms, logs, audits, etc. generated from different security products are not uniform, and they need to be uniformly processed by formatting. In order to reduce the storage amount, the false alarm events generated by various security events are formatted, that is, based on the preset event format, the false alarm events are format-converted, and accordingly, the false alarm events are formatted to obtain format false alarm events; specifically, the format false alarm events corresponding to the preset event format mainly include the following attributes: source address information (source_ip), destination address (dest_ip), source port number (source_port), target port (dest_port), protocol (app_protocol), event time (event_time), event name (event_name), event number (event_id), device type (device_type). These false alarm events can map the original events through the event number. The format false alarm event format is shown in Table 1 as follows:
[0080] Table 1
[0081] Field Chinese Name Field English Name Field Type Source IP source_ip IP Destination IP dest_ip IP Source Port Number source_port Numeric Type Destination Port dest_port Numeric Type Protocol app_protocol Text Type Event Time event_time Time Type Event Name event_name Text Type Event ID event_id Text Type Device Type device_type Text Type
[0082] Further, based on the preset event format, the false alarm events are format-processed accordingly, and based on the trend false alarm event interval, the format false alarm events are clustered and counted. Optionally, the trend false alarm event interval can be set according to actual conditions.
[0083] In one optional embodiment, the above step S102 includes:
[0084] Step S1021, obtaining address information and type information corresponding to the false alarm events;
[0085] Step S1022, based on the trend false alarm processing interval, the address information and the type information, the false alarm events are clustered and counted to obtain a plurality of interval event sequences;
[0086] Step S1023, when the number of events corresponding to the plurality of interval event sequences is the same, first-order difference is performed on each interval event sequence to obtain a plurality of trend event sequences.
[0087] In a specific embodiment, the address information can be the address of each false positive event obtained, and optionally, the address information includes IP address and other address information; the type information can be the type information of each false positive event obtained, and optionally, the type information can include operation false positive and other type information.
[0088] Specifically, while obtaining the false positive event, the address information and the type information corresponding to the false positive event are also obtained. Further, the false positive events in each trend false positive processing interval are clustered and counted according to the address information and the type information, to obtain a plurality of interval event sequences. Optionally, after the statistical grouping, the original false positive event sequence corresponding to each address information and type information is Ai (i = 1, 2, 3, 4, 5, …), and the interval event sequence in each trend false positive processing interval after aggregation is Xi (i = 1, 2, 3, 4, 5, …). Further, it is judged whether the number of events corresponding to the plurality of interval event sequences is the same. Correspondingly, when the number of events corresponding to the plurality of interval event sequences is the same, a first-order difference calculation is performed on each interval event sequence. Specifically, the interval event sequence value at time T corresponding to the trend false positive processing interval is X T, Then the sequence after the first-order difference calculation can be expressed as: X' T = X T -X T-1 (1). After the first-order difference calculation is performed on each interval event sequence, a plurality of trend event sequences are obtained.
[0089] In an optional embodiment, the above step S103 includes:
[0090] Step S1031, obtaining a periodic arrangement order;
[0091] Step S1032, based on the periodic false positive processing interval, the periodic arrangement order and the address information, recombining the plurality of trend event sequences to obtain the plurality of periodic event sequences.
[0092] In a specific embodiment, the periodic arrangement order can be a pre-set arrangement order of false positive event to determine the periodic event sequence, and optionally, the periodic arrangement order can be an arrangement order according to the ATT&CK attack chain. Specifically, based on each periodic false positive processing interval, the plurality of trend event sequences are separated, and further, based on the periodic arrangement order and the address information, the separated plurality of trend event sequences are recombined in sequence, and correspondingly, the plurality of periodic event sequences are obtained.
[0093] In an optional embodiment, the above step S104 includes:
[0094] Step b1, obtaining a lag sequence number;
[0095] Step b2, determining a plurality of lag period event sequences from the plurality of period event sequences based on the lag sequence number;
[0096] Step b3, calculating an autocorrelation coefficient of the plurality of lag period event sequences based on a coefficient calculation formula, to determine an autocorrelation coefficient corresponding to each lag period event sequence.
[0097] In a specific embodiment, the lag sequence number can be a pre-set lag number of the screened period event sequence, and optionally, the lag sequence number includes 1, 2, 3,..., 12. Specifically, based on the lag sequence number, a plurality of lag period event sequences are screened from the plurality of period event sequences. Further, a coefficient calculation formula for obtaining the autocorrelation coefficient is obtained. Specifically, the coefficient calculation formula can be The plurality of lag period sequences are brought into the formula, and then the autocorrelation coefficient corresponding to each lag period event sequence is calculated. Optionally, in the coefficient calculation formula, E(Y t ) represents the expected value of the current period event sequence, E(Y t+h ) represents the expected value of the period event sequence with the lag sequence number h, and p h represents the autocorrelation coefficient.
[0098] In an optional embodiment, the above step S104 further includes:
[0099] Step c1, comparing the autocorrelation coefficient with the preset autocorrelation coefficient threshold to obtain a coefficient comparison result;
[0100] Step c2, indicating the period event sequence with the autocorrelation coefficient greater than the preset autocorrelation coefficient threshold in the plurality of period event sequences as the plurality of target period event sequences based on the coefficient comparison result.
[0101] In a specific embodiment, the preset autocorrelation coefficient threshold can be a standard comparison value of the autocorrelation coefficient. Specifically, the autocorrelation coefficient obtained by the foregoing calculation is compared with the preset autocorrelation coefficient threshold. Optionally, each autocorrelation coefficient obtained by the calculation is compared with the preset autocorrelation coefficient threshold, respectively. Correspondingly, the coefficient comparison result is obtained. Further, the period event sequence with the autocorrelation coefficient greater than the preset autocorrelation coefficient threshold in the plurality of period event sequences is determined as the plurality of target period event sequences based on the coefficient comparison result.
[0102] In an optional embodiment, the above step S105 includes:
[0103] Step S1051, performing Fourier processing on the plurality of target period event sequences to obtain a plurality of frequency values;
[0104] Step S1052, the plurality of frequency values are sorted to determine a target frequency value;
[0105] Step S1053, based on the target frequency value and the period calculation formula, the target period value is determined.
[0106] In one specific embodiment, the plurality of period event sequences are subjected to fast Fourier transform to convert the time sequence diagram into a frequency diagram, specifically, the fast Fourier formula is Wherein xi represents the number of false alarm events corresponding to each period event processing interval, and the plurality of target period event sequences are converted from time domain to frequency domain based on the fast Fourier formula, specifically as shown in the figure, further, the plurality of calculated frequency values are sorted by size, and the sorting result is obtained, further, the maximum frequency value in the sorting is determined as the target frequency value, further, the target frequency value is brought into the period calculation formula to calculate and determine the target period value, optionally, the period calculation formula is p=1 / f, wherein p is the target period value and f is the target frequency value.
[0107] Further, if the target period value is non-0 is significant, it can be determined that the plurality of target period sequences have a certain periodicity, and then the target period sequence with the target period value of non-0 is removed.
[0108] The false alarm removal method provided by the embodiment of the application improves the accuracy of determining the plurality of period event sequences, and further calculates the autocorrelation coefficients of the plurality of period event sequences, compares the autocorrelation coefficients with the preset autocorrelation coefficient threshold, determines the target period event sequence, and improves the rigor and accuracy of determining the target period event sequence. Further, the plurality of target period event sequences are subjected to time-frequency domain conversion to obtain the target period value, and the target period event sequence with the target period value of non-0 is removed. Through time-frequency domain conversion, the accuracy of determining the target period value is improved, and the accuracy of false alarm removal is improved. In the present application, the sequence clustering statistics are performed multiple times, and the time-frequency domain conversion is combined to improve the simplicity and wide applicability of false alarm removal.
[0109] Also provided in the present embodiments is a false alarm removal device for implementing the above embodiments and preferred embodiments, which has been described above and will not be repeated. As used below, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the device described in the following embodiments is preferably implemented in software, implementation in hardware or a combination of software and hardware is also possible and contemplated.
[0110] The present embodiments provide a false alarm removal device, as shown in Figure 2 comprises:
[0111] The acquisition module 201 is configured to acquire false alarm events, a preset autocorrelation coefficient threshold, a trend false alarm processing interval, and a periodic false alarm processing interval.
[0112] The statistical module 202 is configured to perform cluster statistics on the false alarm events based on the trend false alarm processing interval to obtain a plurality of trend event sequences.
[0113] The reorganization module 203 is configured to perform sequence reorganization on the plurality of trend event sequences based on the periodic false alarm processing interval to obtain a plurality of periodic event sequences.
[0114] The calculation module 204 is configured to calculate autocorrelation coefficients of the plurality of periodic event sequences, and compare the autocorrelation coefficients with the preset autocorrelation coefficient threshold to determine a plurality of target periodic event sequences.
[0115] The removal module 205 is configured to perform time-frequency domain conversion on the plurality of target periodic event sequences to obtain target periodic values, and remove target periodic event sequences with non-zero target periodic values.
[0116] In an optional embodiment, the statistical module 202 includes:
[0117] The information acquisition unit is configured to acquire address information and type information corresponding to the false alarm events.
[0118] The interval statistical unit is configured to perform cluster statistics on the false alarm events based on the trend false alarm processing interval, the address information, and the type information to obtain a plurality of interval event sequences.
[0119] The trend determination unit is configured to perform first-order difference on each interval event sequence to obtain the plurality of trend event sequences when the number of events corresponding to the plurality of interval event sequences is the same.
[0120] In an optional embodiment, the reorganization module 203 includes:
[0121] The periodic order acquisition unit is configured to acquire a periodic arrangement order.
[0122] A period reorganization unit is configured to reorganize the plurality of trend event sequences based on the period false alarm processing interval, the period arrangement order and the address information, to obtain the plurality of period event sequences.
[0123] In some optional embodiments, the computing module 204 includes:
[0124] A lag obtaining unit is configured to obtain a lag sequence number.
[0125] A lag determining unit is configured to determine a plurality of lag period event sequences from the plurality of period event sequences based on the lag sequence number.
[0126] A coefficient calculating unit is configured to calculate an autocorrelation coefficient of each lag period event sequence based on a coefficient calculation formula, to determine the autocorrelation coefficient corresponding to each lag period event sequence.
[0127] In some optional embodiments, the computing module 204 further includes:
[0128] A coefficient comparing unit is configured to compare the autocorrelation coefficient with a preset autocorrelation coefficient threshold, to obtain a coefficient comparison result.
[0129] A coefficient greater than unit is configured to determine, as the plurality of target period event sequences, the period event sequences from the plurality of period event sequences, for which the autocorrelation coefficient is greater than the preset autocorrelation coefficient threshold, according to the coefficient comparison result.
[0130] In some optional embodiments, the removing module 205 includes:
[0131] A Fourier processing unit is configured to perform Fourier processing on the plurality of target period event sequences, to obtain a plurality of frequency values.
[0132] A sorting unit is configured to sort the plurality of frequency values, to determine a target frequency value.
[0133] A period calculating unit is configured to determine the target period value based on the target frequency value and a period calculation formula.
[0134] In some optional embodiments, the apparatus further includes:
[0135] A format obtaining unit is configured to obtain a preset event format.
[0136] A format processing unit is configured to perform format processing on the false alarm event based on the preset event format, to obtain a format false alarm event.
[0137] The trend statistics unit is used to perform cluster statistics on the formatted false alarm events based on the trend false alarm processing interval to obtain multiple interval event sequences.
[0138] Further functional descriptions of the above modules and units are the same as those in the corresponding embodiments described above, and will not be repeated here.
[0139] In this embodiment, the false alarm removal device is presented in the form of a functional unit. Here, a unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that execute one or more software or fixed programs, and / or other devices that can provide the above functions.
[0140] This invention also provides a computer device having the above-described features. Figure 2 The false alarm removal device shown.
[0141] Please see Figure 3 , Figure 3 This is a schematic diagram of the structure of a computer device provided in an optional embodiment of the present invention, such as... Figure 3 As shown, the computer device includes one or more processors 10, memory 20, and interfaces for connecting the components, including high-speed interfaces and low-speed interfaces. The components communicate with each other via different buses and can be mounted on a common motherboard or otherwise installed as needed. The processors can process instructions executed within the computer device, including instructions stored in or on memory to display graphical information of a GUI on external input / output devices (such as display devices coupled to the interfaces). In some alternative implementations, multiple processors and / or multiple buses can be used with multiple memories and multiple memory modules, if desired. Similarly, multiple computer devices can be connected, each providing some of the necessary operations (e.g., as a server array, a group of blade servers, or a multiprocessor system). Figure 3 Take a processor 10 as an example.
[0142] Processor 10 may be a central processing unit, a network processor, or a combination thereof. Processor 10 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The programmable logic device may be a complex programmable logic device (CAMP), a field-programmable gate array (FPGA), a general-purpose array logic (GPA), or any combination thereof.
[0143] The memory 20 stores instructions executable by at least one processor 10 to cause the at least one processor 10 to perform the method shown in the above embodiments.
[0144] The memory 20 can include a program storage area and a data storage area, where the program storage area can store an operating system, application programs required for at least one function, and the data storage area can store data created according to the use of the computer device, etc. In addition, the memory 20 can include a high-speed random access memory, and can also include a non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state memory device. In some alternative embodiments, the memory 20 can optionally include a memory disposed remotely from the processor 10, which can be connected to the computer device through a network. Examples of the network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0145] The memory 20 can include a volatile memory, such as a random access memory, and can also include a non-volatile memory, such as a flash memory, a hard disk, or a solid state disk, and can also include a combination of the above-mentioned kinds of memories.
[0146] The computer device also includes an input device 30 and an output device 40. The processor 10, the memory 20, the input device 30, and the output device 40 can be connected by a bus or other means, Figure 3 For example, by a bus connection.
[0147] The input device 30 can receive input digital or character information, and generate key signal inputs related to the user settings and function controls of the computer device, such as a touch screen, a keypad, a mouse, a trackpad, a touchpad, a pointing stick, one or more mouse buttons, a trackball, a joystick, etc. The output device 40 can include a display device, an auxiliary lighting device (e.g., an LED), a tactile feedback device (e.g., a vibration motor), etc. The display device includes, but is not limited to, a liquid crystal display, a light-emitting diode, a display, and a plasma display. In some alternative embodiments, the display device can be a touch screen.
[0148] The embodiments of the present application further provide a computer readable storage medium, and the method according to the embodiments of the present application can be implemented in hardware, firmware, or recorded in a storage medium, or stored in a remote storage medium or a non-transitory machine readable storage medium and downloaded to a local storage medium through network, so that the method described herein can be processed by such software on a storage medium using a general purpose computer, a special purpose processor, or programmable or special hardware. The storage medium can be a magnetic disk, an optical disk, a read-only memory, a random access memory, a flash memory, a hard disk, or a solid state disk, etc. Further, the storage medium can also include a combination of the above-mentioned memories. It can be understood that the computer, the processor, the microprocessor controller, or the programmable hardware includes a storage component that can store or receive software or computer code, when the software or computer code is accessed and executed by the computer, the processor, or the hardware, the method shown in the above embodiments is implemented.
[0149] Part of the present application can be applied as a computer program product, for example, computer program instructions, when executed by a computer, the operation of the computer can invoke or provide the method and / or technical solutions according to the present application. Those skilled in the art should understand that the form of computer program instructions in computer readable medium includes but is not limited to source file, executable file, installation package file, etc. Correspondingly, the way of computer program instructions executed by computer includes but is not limited to: the computer directly executes the instructions, or the computer compiles the instructions and then executes the corresponding compiled program, or the computer reads and executes the instructions, or the computer reads and installs the instructions and then executes the corresponding installed program. Here, the computer readable medium can be any available computer readable storage medium or communication medium accessible to the computer.
[0150] Although the embodiments of the present application are described in conjunction with the accompanying drawings, various modifications and changes can be made by those skilled in the art without departing from the spirit and scope of the present application, and such modifications and changes fall within the scope defined by the appended claims.
Claims
1. A network security alert event false positive removal method, characterized in that, The method comprises: obtaining a false alarm event, a preset autocorrelation coefficient threshold, a trend false alarm processing interval and a periodic false alarm processing interval; based on the trend false alarm processing interval, the false alarm event is clustered and counted to obtain a plurality of trend event sequences; based on the periodic false alarm processing interval, the plurality of trend event sequences are reorganized to obtain a plurality of periodic event sequences; calculate the autocorrelation coefficient of the plurality of periodic event sequences, and compare the autocorrelation coefficient with the preset autocorrelation coefficient threshold to determine a plurality of target periodic event sequences, the preset autocorrelation coefficient threshold is a standard value for determining whether the periodic event sequence is an attack sequence; the time-frequency domain conversion of the plurality of target periodic event sequences is carried out to obtain a target periodic value, and the target periodic event sequence with the target periodic value is removed; the method further comprises: obtaining the address information and type information corresponding to the false alarm event; based on the trend false alarm processing interval, the address information and the type information, the false alarm event is clustered and counted to obtain a plurality of interval event sequences; when the number of events corresponding to the plurality of interval event sequences is the same, first-order difference is carried out on each interval event sequence to obtain the plurality of trend event sequences.
2. The method of claim 1, wherein, the method further comprises: obtaining a periodic arrangement sequence; based on the periodic false alarm processing interval, the periodic arrangement sequence and the address information, the plurality of trend event sequences are reorganized to obtain the plurality of periodic event sequences.
3. The method of claim 1, wherein, the method further comprises: obtaining a lag sequence number; based on the lag sequence number, a plurality of lag periodic event sequences in the plurality of periodic event sequences are determined; based on a coefficient calculation formula, the autocorrelation coefficients of the plurality of lag periodic event sequences are calculated to determine the autocorrelation coefficient corresponding to each lag periodic event sequence.
4. The method of claim 1, wherein, the method further comprises: based on the autocorrelation coefficient and the preset autocorrelation coefficient threshold, a coefficient comparison result is obtained; the coefficient comparison result indicates that the autocorrelation coefficient of the periodic event sequence in the plurality of periodic event sequences is greater than the preset autocorrelation coefficient threshold, and the periodic event sequence is determined as the plurality of target periodic event sequences.
5. The method of claim 1, wherein, the method further comprises: the plurality of target periodic event sequences are subjected to Fourier processing to obtain a plurality of frequency values; the plurality of frequency values are sorted to determine a target frequency value; based on the target frequency value and a period calculation formula, the target periodic value is determined.
6. The method of claim 1, wherein, before the method further comprises: obtaining a preset event format; Based on the preset event format and the false positive event, a formatting process is performed to obtain a formatted false positive event; Based on the trend false positive processing interval, the formatted false positive event is clustered and counted to obtain a plurality of interval event sequences.
7. A network security alert event false positive removal apparatus characterized by comprising: The apparatus comprises: An acquisition module configured to acquire a false positive event, a preset autocorrelation coefficient threshold, a trend false positive processing interval, and a periodic false positive processing interval; A statistical module configured to cluster and count the false positive event based on the trend false positive processing interval to obtain a plurality of trend event sequences; A reorganization module configured to reorganize the plurality of trend event sequences based on the periodic false positive processing interval to obtain a plurality of periodic event sequences; A calculation module configured to calculate autocorrelation coefficients of the plurality of periodic event sequences, and compare the autocorrelation coefficients with a preset autocorrelation coefficient threshold to determine a plurality of target periodic event sequences, the preset autocorrelation coefficient threshold being a standard value for determining whether the periodic event sequence is an attack sequence; A removal module configured to convert the plurality of target periodic event sequences into a time-frequency domain to obtain target periodic values, and remove target periodic event sequences with non-zero target periodic values. The clustering and counting of the false positive event based on the trend false positive processing interval to obtain a plurality of trend event sequences comprises: acquiring address information and type information corresponding to the false positive event; clustering and counting the false positive event based on the trend false positive processing interval, the address information, and the type information to obtain a plurality of interval event sequences; and performing first-order difference on each interval event sequence when the number of events corresponding to the plurality of interval event sequences is the same, to obtain the plurality of trend event sequences.
8. A computer device, comprising: It comprises: A memory and a processor, which are communicatively connected, the memory stores computer instructions, and the processor executes the computer instructions to perform the network security alarm event false positive removal method of any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer instructions, which are used to make a computer execute the network security alarm event false positive removal method of any one of claims 1 to 6.
Citation Information
Patent Citations
False alarm removing method and device for alarm event
CN112769612A