A safety alarm classification outbound calling method, device, electronic equipment and medium
By configuring the alarm levels of detection points and equipment in the credit reporting service system, and making correlation judgments on multiple alarm behaviors, generating outbound call information for target intrusion behavior, the problems of repeated alarms, difficulty in distinguishing importance, and insufficient concurrency mechanism in the prior art are solved, and security defense performance is improved.
Patent Information
- Application Number
- CN202510387438.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-31
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2045-03-31
AI Technical Summary
The existing alarm outbound call platforms have a large number of repeated alarms, inability to distinguish the importance of alarms, and insufficient outbound call concurrency mechanism, which makes it difficult for security operation and maintenance personnel to effectively handle important alarms.
By configuring the point alarm levels of different detection points of the credit reporting service system and the behavioral alarm levels of the equipment, the correlation judgment is made for multiple alarm behaviors received within the preset time period, and the associated alarm behavior is associated with a target intrusion behavior, and outbound call information is generated based on the level of the intrusion behavior.
It effectively reduces the number of alarms, accurately evaluates the harm of intrusion behavior, and ensures that intrusion behaviors with great harm are given priority, thereby improving the defense performance of the credit reporting service intranet.
Smart Images

Figure CN119892593B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology, and in particular to a security alarm classification outbound calling method, device, electronic equipment and medium. Background Art
[0002] The credit reporting system intranet is based on the principle of in-depth defense system construction and is divided into multiple logical areas based on the request from the entrance to the internal production, including the Internet area, DMZ area, dedicated line access area, joint debugging and testing area, core production area, etc. Each logical area carries different functional modules of the credit reporting business, and the core business system is deployed in the innermost core production area. The security monitoring system consists of firewalls, traffic monitoring equipment, web application firewalls, intrusion prevention systems, apt high-sustainability threat monitoring systems, host security systems and other equipment deployed in various areas. The monitoring points cover all logical areas of the credit reporting business intranet.
[0003] The existing monitoring devices are independent of each other, and each device has a customized alarm level. The devices send alarms to the alarm outbound calling platform, which defines different outbound calling methods based on the alarm levels of the respective devices.
[0004] The existing alarm outbound call platform has the following problems when making outbound calls: 1. There are a large number of duplicate alarms: a security event of a successful intrusion may break through multiple areas, which will involve triggering multiple device alarms. Multiple devices will issue alarms, causing security operation and maintenance personnel to receive multiple device alarms, but the alarms are all triggered by one event, resulting in a large number of duplicate alarms; 2. Alarms cannot distinguish the importance: the credit reporting business intranet adopts the in-depth defense design concept. Even if the boundary is breached, it will not affect the core production environment; from the perspective of the importance of logical areas, the core production area is higher than the boundary area. Therefore, the same level of alarms occurring in the core production area have a higher priority than the boundary alarm priority; the existing technology will only send based on the level of the alarm itself, which cannot reflect the importance of the monitoring point, and there will be frequent high-level alarm outbound calls in non-important areas; 3. Insufficient outbound call concurrency mechanism: when multiple events occur simultaneously in the credit reporting business intranet, there will be a busy situation at the same time, which may cause important alarms to fail to be effectively called out. Summary of the invention
[0005] In view of this, the purpose of the present application is to provide a security alarm classification outbound call method, device, electronic equipment and medium, which can avoid a large number of alarm duplications, accurately evaluate the alarm level, and solve the problem of outbound call busy.
[0006] An embodiment of the present application provides a security alarm classification outbound calling method, the method comprising:
[0007] Configure the point alarm level of different detection points of the credit reporting business system and the behavior alarm level of the alarm behavior of a single device at each detection point;
[0008] For multiple alarm behaviors of at least one monitoring point received within a preset time period, determine whether the multiple alarm behaviors are related; the alarm behavior corresponds to the point alarm level of the monitoring point and the behavior alarm level of the alarm behavior;
[0009] If so, associating the multiple warning behaviors into one target intrusion behavior;
[0010] Determine the security event alarm level information of the target intrusion behavior based on the point alarm level and behavior alarm level corresponding to the alarm behavior associated with the target intrusion behavior;
[0011] An outbound call information of the target intrusion behavior is generated based on the security event alarm level information of the target intrusion behavior, and the outbound call information is sent to a terminal device corresponding to the security operation and maintenance personnel.
[0012] In some embodiments, in the security alarm classification outbound calling method, the security event alarm level information of the target intrusion behavior is determined based on the point alarm level and behavior alarm level corresponding to the alarm behavior associated with the target intrusion behavior; including:
[0013] Based on a plurality of different tactical phases of the intrusion behavior divided in advance, determining a target tactical phase of the target intrusion behavior; wherein different tactical phases represent different degrees of harm of the intrusion behavior;
[0014] The target tactical phase of the target intrusion behavior, the point alarm level and the behavior alarm level corresponding to the alarm behavior associated with the target intrusion behavior are integrated to determine the security event alarm level information of the target intrusion behavior.
[0015] In some embodiments, in the security alarm classification outbound call method, the target tactical phase of the target intrusion behavior, the point alarm level and the behavior alarm level corresponding to the alarm behavior associated with the target intrusion behavior are integrated to determine the security event alarm level information of the target intrusion behavior, including:
[0016] Obtain the first target weight of the target tactical phase, the second target weight corresponding to the point warning level of each warning behavior, and the third target weight corresponding to the behavior warning level of each warning behavior;
[0017] The security event alarm score of the target intrusion behavior is determined by integrating the first target weight of the target tactical phase of the target intrusion behavior, the second target weight corresponding to the point alarm level of each alarm behavior of the target intrusion behavior, and the third target weight corresponding to the behavior alarm level of each alarm behavior of the target intrusion behavior;
[0018] Based on the corresponding relationship between the security incident warning score of the target intrusion behavior and different security levels, the security incident warning level of the target intrusion behavior is determined.
[0019] In some embodiments, in the security alarm classification outbound calling method, outbound calling information of the target intrusion behavior is generated based on the security event alarm level information of the target intrusion behavior, and the outbound calling information is sent to the terminal device corresponding to the security operation and maintenance personnel, including:
[0020] Determine the target outbound call mechanism corresponding to the security event alarm level information of the target intrusion behavior based on the association relationship between the security event alarm level and the outbound call mechanism in the pre-configured security event alarm level information;
[0021] Based on the target outbound call mechanism, the outbound call information is sent to the terminal device corresponding to the security operation and maintenance personnel.
[0022] In some embodiments, in the security alarm classification outbound calling method, sending the outbound calling information to the terminal device corresponding to the security operation and maintenance personnel includes:
[0023] For multiple outbound call information, queuing is performed based on the security event alarm level information of the target intrusion behavior corresponding to the outbound call information, and queuing information of the multiple outbound call information is determined;
[0024] The queuing information of the multiple outbound call messages is used to send the multiple outbound call messages to the terminal devices corresponding to the security operation and maintenance personnel.
[0025] In some embodiments, in the security alarm classification outbound calling method, sending the outbound calling information to the terminal device corresponding to the security operation and maintenance personnel includes:
[0026] Based on the security event alarm level information of the target intrusion behavior corresponding to the multiple outbound call information, determine the target outbound call information that meets the polling mechanism from the multiple outbound call information;
[0027] The target outbound call information is polled and sent based on a polling mechanism until a processing response result for the target outbound call information is received.
[0028] In some embodiments, in the security alarm classification outbound calling method, for multiple alarm behaviors of at least one monitoring point received within a preset time period, determining whether the multiple alarm behaviors are related includes:
[0029] For multiple alarm behaviors of at least one monitoring point received within a preset time period, determine whether the multiple alarm behaviors meet a preset association rule; the preset association rule is determined based on the correlation characteristics of the multiple alarm behaviors, or based on the device action characteristics of different devices at different monitoring points under the attack of the same intrusion behavior;
[0030] If so, it is determined that the multiple alarm behaviors are associated.
[0031] In some embodiments, a security alarm classification outbound call device is also provided, the device comprising:
[0032] A configuration module, used to configure the point alarm levels of different detection points of the credit reporting business system and the behavior alarm level of the alarm behavior of a single device at each detection point;
[0033] A judgment module, for judging whether the multiple alarm behaviors received from at least one monitoring point within a preset time period are related; the alarm behavior corresponds to the point alarm level of the monitoring point and the behavior alarm level of the alarm behavior;
[0034] An association module, configured to associate the multiple alarm behaviors into a target intrusion behavior when determining that the multiple alarm behaviors are associated;
[0035] A determination module, configured to determine the security event alarm level information of the target intrusion behavior based on the point alarm level and the behavior alarm level corresponding to the alarm behavior associated with the target intrusion behavior;
[0036] A generation module is used to generate outbound call information of the target intrusion behavior based on the security event alarm level information of the target intrusion behavior, and send the outbound call information to the terminal device corresponding to the security operation and maintenance personnel.
[0037] In some embodiments, an electronic device is also provided, including: a processor, a memory and a bus, wherein the memory stores machine-readable instructions executable by the processor, and when the electronic device is running, the processor and the memory communicate through the bus, and when the machine-readable instructions are executed by the processor, the steps of the security alarm classification outbound call method are performed.
[0038] In some embodiments, a computer-readable storage medium is also provided, on which a computer program is stored. When the computer program is executed by a processor, the steps of the security alarm classification outbound call method are executed.
[0039] The embodiment of the present application provides a security alarm classification outbound call method, device, electronic device and medium; the method configures the point alarm level of different detection points of the credit reporting business system and the behavior alarm level of the alarm behavior of a single device at each detection point; for multiple alarm behaviors received at at least one monitoring point within a preset time period, it is determined whether the multiple alarm behaviors are associated; the alarm behavior corresponds to the point alarm level of the monitoring point and the behavior alarm level of the alarm behavior; if so, the multiple alarm behaviors are associated as a target intrusion behavior; the target intrusion behavior is determined based on the point alarm level and the behavior alarm level corresponding to the alarm behavior associated with the target intrusion behavior The security event alarm level information of the target intrusion behavior is generated; based on the security event alarm level information of the target intrusion behavior, the outbound call information of the target intrusion behavior is generated, and the outbound call information is sent to the terminal device corresponding to the security operation and maintenance personnel. In this way, when the monitoring system detects a network attack behavior, it can perform intelligent correlation analysis based on a large number of alarms from various scattered independent devices to form a small number of intrusion behavior events, effectively reduce the number of alarms, and solve the problem of busy outbound calls to a certain extent; at the same time, the alarm levels of both monitoring points and single devices are taken into account, and the hazards of intrusion behaviors are assessed more accurately, ensuring that intrusion behaviors with greater hazards are given priority for outbound calls, thereby improving the defense performance of the credit reporting business intranet. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.
[0041] Figure 1 A flow chart of the security alarm classification outbound calling method according to an embodiment of the present application is shown;
[0042] Figure 2 A flow chart of a method for determining whether the multiple alarm behaviors are associated according to an embodiment of the present application is shown;
[0043] Figure 3 A flow chart of a method for determining the security event alarm level information of the target intrusion behavior according to an embodiment of the present application is shown;
[0044] Figure 4 The outbound call information for generating the target intrusion behavior according to the embodiment of the present application is shown;
[0045] Figure 5 A schematic diagram of the structure of the security alarm classification outbound call device according to an embodiment of the present application is shown;
[0046] Figure 6 A schematic structural diagram of an electronic device described in an embodiment of the present application is shown. DETAILED DESCRIPTION
[0047] To make the purpose, technical scheme and advantages of the embodiments of the present application clearer, the technical scheme in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. It should be understood that the drawings in the present application only serve the purpose of explanation and description and are not used to limit the scope of protection of the present application. In addition, it should be understood that the schematic drawings are not drawn in real proportion. The flowchart used in this application shows the operations implemented according to some embodiments of the present application. It should be understood that the operations of the flowchart can be implemented out of sequence, and the steps without logical context can be reversed in order or implemented simultaneously. In addition, those skilled in the art can add one or more other operations to the flowchart under the guidance of the content of the present application, or remove one or more operations from the flowchart.
[0048] In addition, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. The components of the embodiments of the present application described and shown in the drawings here can be arranged and designed in various configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the application claimed for protection, but merely represents the selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without making creative work belong to the scope of protection of the present application.
[0049] It should be noted that the term "comprising" will be used in the embodiments of the present application to indicate the existence of the features declared thereafter, but does not exclude the addition of other features.
[0050] The credit reporting system intranet is based on the principle of in-depth defense system construction and is divided into multiple logical areas based on the request from the entrance to the internal production, including the Internet area, DMZ area, dedicated line access area, joint debugging and testing area, core production area, etc. Each logical area carries different functional modules of the credit reporting business, and the core business system is deployed in the innermost core production area. The security monitoring system consists of firewalls, traffic monitoring equipment, web application firewalls, intrusion prevention systems, apt high-sustainability threat monitoring systems, host security systems and other equipment deployed in various areas. The monitoring points cover all logical areas of the credit reporting business intranet.
[0051] The existing monitoring devices are independent of each other, and each device has a customized alarm level. The devices send alarms to the alarm outbound calling platform, which defines different outbound calling methods based on the alarm levels of the respective devices.
[0052] The existing alarm outbound call platform has the following problems when making outbound calls: 1. There are a large number of duplicate alarms: a security event of a successful intrusion may break through multiple areas, which will involve triggering multiple device alarms. Multiple devices will issue alarms, causing security operation and maintenance personnel to receive multiple device alarms, but the alarms are all triggered by one event, resulting in a large number of duplicate alarms; 2. Alarms cannot distinguish the importance: the credit reporting business intranet adopts the in-depth defense design concept. Even if the boundary is breached, it will not affect the core production environment; from the perspective of the importance of logical areas, the core production area is higher than the boundary area. Therefore, the same level of alarms occurring in the core production area have a higher priority than the boundary alarm priority; the existing technology will only send based on the level of the alarm itself, which cannot reflect the importance of the monitoring point, and there will be frequent high-level alarm outbound calls in non-important areas; 3. Insufficient outbound call concurrency mechanism: when multiple events occur simultaneously in the credit reporting business intranet, there will be a busy situation at the same time, which may cause important alarms to fail to be effectively called out.
[0053] Based on this, the embodiment of the present application provides a security alarm classification outbound call method, device, electronic device and medium; the method configures the point alarm level of different detection points of the credit reporting business system and the behavior alarm level of the alarm behavior of a single device at each detection point; for multiple alarm behaviors of at least one monitoring point received within a preset time period, it is determined whether the multiple alarm behaviors are related; the alarm behavior corresponds to the point alarm level of the monitoring point and the behavior alarm level of the alarm behavior; if so, the multiple alarm behaviors are associated as a target intrusion behavior; based on the point alarm level and the behavior alarm level corresponding to the alarm behavior associated with the target intrusion behavior, the target intrusion behavior is determined. The security event alarm level information of the target intrusion behavior; based on the security event alarm level information of the target intrusion behavior, the outbound call information of the target intrusion behavior is generated, and the outbound call information is sent to the terminal device corresponding to the security operation and maintenance personnel. In this way, when the monitoring system detects a network attack behavior, it can perform intelligent correlation analysis based on a large number of alarms from various scattered independent devices to form a small number of intrusion behavior events, effectively reduce the number of alarms, and solve the problem of busy outbound calls to a certain extent; at the same time, the alarm levels of both monitoring points and individual devices are taken into account, and the harm of intrusion behaviors is assessed more accurately, ensuring that intrusion behaviors with greater harm are given priority for outbound calls, thereby improving the defense performance of the credit reporting business intranet.
[0054] Please refer to Figure 1 , Figure 1 A flow chart of the security alarm classification outbound calling method according to an embodiment of the present application is shown; Figure 1 As shown, the security alarm classification outbound calling method includes the following steps S101-S105:
[0055] S101, configuring the point alarm level of different detection points of the credit reporting business system and the behavior alarm level of the alarm behavior of a single device at each detection point;
[0056] S102, for multiple alarm behaviors of at least one monitoring point received within a preset time period, determining whether the multiple alarm behaviors are associated; the alarm behavior corresponds to the point alarm level of the monitoring point and the behavior alarm level of the alarm behavior;
[0057] S103: If yes, associate the multiple warning behaviors into one target intrusion behavior;
[0058] S104, determining the security event alarm level information of the target intrusion behavior based on the point alarm level and the behavior alarm level corresponding to the alarm behavior associated with the target intrusion behavior;
[0059] S105: Generate outbound call information of the target intrusion behavior based on the security event alarm level information of the target intrusion behavior, and send the outbound call information to a terminal device corresponding to the security operation and maintenance personnel.
[0060] The security alarm classification outbound calling method is applied to an alarm outbound calling system.
[0061] In step S101, the point alarm levels of different detection points of the credit reporting business system and the behavior alarm levels of the alarm behaviors of individual devices at each detection point are configured.
[0062] The different detection points are determined based on the business modules carried by different areas of the credit reporting business intranet.
[0063] The detection points include core production areas, joint debugging and testing areas, DMZ areas, Internet areas, dedicated line areas, etc.
[0064] Based on the importance of the service modules carried by the detection points, the point alarm levels of the different detection points are determined.
[0065] For example, the point alarm levels are ranked as follows: core production area > joint debugging test area > DMZ area > Internet area = dedicated line area.
[0066] The behavior alarm level of the alarm behavior of a single device may be, for example, four levels: low, medium, high, and emergency.
[0067] The point alarm levels of different detection points and the behavior alarm level of the alarm behavior of a single device at each detection point are used to comprehensively weigh the monitoring point to which the alarm behavior belongs and the importance of the alarm behavior to recalculate the alarm level of the alarm behavior.
[0068] In this way, if an alarm of the same level occurs at two detection points, the detection point with a higher alarm level has a higher priority. When an alarm call is made, both the level of the alarm itself and the importance of the monitoring point can be considered, which can prevent frequent high-level alarm calls in non-important areas to a certain extent.
[0069] In the steps S102 and S103, for multiple alarm behaviors of at least one monitoring point received within a preset time period, it is determined whether the multiple alarm behaviors are associated; the alarm behavior corresponds to the point alarm level of the monitoring point and the behavior alarm level of the alarm behavior;
[0070] If yes, the multiple alarm behaviors are associated into one target intrusion behavior.
[0071] A security incident of a successful intrusion may break through multiple areas and trigger multiple device alarms. Multiple devices will issue alarms, causing security operation and maintenance personnel to receive multiple device alarms, but the alarms are all triggered by one event, and there are a large number of duplicate alarms. This will also cause concurrent busy lines, resulting in some important alarms being unable to be effectively dialed out. However, associating the multiple alarm behaviors that are related to each other into one target intrusion behavior can greatly reduce duplicate alarms and concurrent busy lines.
[0072] Please refer to Figure 2 , for multiple alarm behaviors of at least one monitoring point received within a preset time period, determining whether the multiple alarm behaviors are related, including the following steps S201-S202:
[0073] S201, for multiple alarm behaviors of at least one monitoring point received within a preset time period, determine whether the multiple alarm behaviors meet a preset association rule; the preset association rule is determined based on the correlation characteristics of the multiple alarm behaviors, or based on the device action characteristics of different devices at different monitoring points under the attack of the same intrusion behavior;
[0074] S202: If yes, determine that the multiple alarm behaviors are associated.
[0075] The correlation feature of the multiple alarm behaviors, that is, if the multiple alarm behaviors are triggered by one or continuous attack, there is some common information between the attributes of the multiple alarm behaviors, and the common information can be used as the correlation feature.
[0076] Exemplarily, the correlation features include: the same attack source, the same destination address, etc.
[0077] Based on the device action characteristics of different devices at different monitoring points under the attack of the same intrusion behavior, when the same intrusion behavior attacks different devices at different monitoring points, different devices will trigger similar actions and changes. Therefore, it is possible to analyze whether multiple alarm behaviors are related based on the device.
[0078] Here, whether the multiple alarm behaviors are associated means that the multiple alarm behaviors are regarded as one intrusion behavior or multiple intrusion behaviors of the same type.
[0079] The device action characteristics include: the same intranet host launching the same type of attack multiple times, the same intranet host launching a network scan after being attacked, database privilege escalation after a SQL injection attack, and webshell injection after abnormal web backend login.
[0080] In other words, the alarm behaviors triggered simultaneously at multiple points are correlated and analyzed, and multiple alarms are connected in series through intelligent analysis to form an intrusion behavior.
[0081] Specifically, according to the network attack model, a preset association rule corresponding to the associated alarm analysis scenario is constructed to realize that multiple alarms are associated to form one intrusion behavior.
[0082] Exemplarily, some associated alarm analysis scenarios are listed below.
[0083] Scenario 1: The number of specific alarms from the same attack source is superimposed, indicating that the attack may be continuous;
[0084] Scenario description: Determine whether the source address launches continuous security attacks based on the number of security attack alarms of the same type;
[0085] Analysis method: Within a specific period of time (such as 5 minutes), the same source address launches a specific attack (such as log4j vulnerability exploitation attack) more than a certain number (such as 10 times).
[0086] Scenario 2: The same destination address is attacked multiple times by the same type of attack;
[0087] Scenario description: Determine whether the destination address is under continuous security attack by counting the number of security attack alarms of the same type;
[0088] Analysis method: Within a specific period of time (such as 5 minutes), the same destination address is attacked by a specific attack (such as log4j vulnerability exploitation attack) more than a certain number (such as 10 times).
[0089] Scenario 3: The same intranet host launches the same type of attack multiple times;
[0090] Scenario description: Determine whether the intranet host has been compromised by counting the number of security attack alarms initiated by the intranet host;
[0091] Analysis method: Within a specific period of time (such as 10 minutes), the number of specific attacks (such as remote vulnerability exploitation attacks) launched by the intranet host with the same source address exceeds a certain number (such as 20 times).
[0092] Scenario 4: A network scan is initiated after the same intranet host is attacked;
[0093] Scenario description: After the intranet host is attacked, a network scan is initiated to determine whether the intranet host has been compromised;
[0094] Analysis method: Within a specific period of time (e.g. 60 minutes), a webshell is implanted into an intranet host with the same source address and a network scan is initiated.
[0095] Scenario 5: Database privilege escalation occurs after a SQL injection attack;
[0096] Scenario description: After a SQL injection attack, a database privilege escalation alarm occurs, indicating that the SQL injection attack has been successful;
[0097] Analysis method: After the web server generates an SQL injection attack alert, a database privilege escalation event occurs within a specific period of time (e.g., 5 minutes);
[0098] Scenario 6: Webshell is injected after abnormal web backend login;
[0099] Scenario description: After the web backend login is abnormal, a webshell is injected, and it is determined that the web attack has been successful;
[0100] Analysis method: Within a specific period of time (such as 10 minutes), the same source address logged into the same web service backend abnormally, and a webshell was implanted.
[0101] The analysis method here is to preset association rules.
[0102] In the step S104, the security event alarm level information of the target intrusion behavior is determined based on the point alarm level and the behavior alarm level corresponding to the alarm behavior associated with the target intrusion behavior.
[0103] For details, please refer to Figure 3 , determining the security event alarm level information of the target intrusion behavior based on the point alarm level and the behavior alarm level corresponding to the alarm behavior associated with the target intrusion behavior; comprising the following steps S301-S302:
[0104] S301, based on a plurality of different tactical phases of the intrusion behavior divided in advance, determining a target tactical phase of the target intrusion behavior; wherein different tactical phases represent different degrees of harm of the intrusion behavior;
[0105] S302: The target tactical phase of the target intrusion behavior, the point alarm level and the behavior alarm level corresponding to the alarm behavior associated with the target intrusion behavior are integrated to determine the security event alarm level information of the target intrusion behavior.
[0106] That is to say, in addition to the two dimensions of point alarm level and behavior alarm level, the present application further considers the target tactical stage of the target intrusion behavior, so as to more accurately assess the security event alarm level of the target intrusion behavior.
[0107] Specifically, based on a plurality of different tactical phases of the pre-divided intrusion behaviors, determining the target tactical phase of the target intrusion behavior includes: associating an ATT&CK model, and determining the target tactical phase of the target intrusion behavior based on the ATT&CK model.
[0108] Based on the ATT&CK model, attack techniques are divided into 14 different tactical stages, including reconnaissance, resource development, initial access, execution, persistence, privilege escalation, defense bypass, credential access, discovery, lateral movement, collection, command and control, data theft, and compromise.
[0109] Different tactical stages represent different degrees of intrusion behavior. Therefore, the tactics used in association with an attack behavior can be used to redefine the impact of the attack behavior. The alarms generated by the security monitoring system are associated with the ATT&CK model to determine the degree of development of the intrusion behavior. Therefore, redefining the security incident alarm level based on the ATT&CK model can achieve more accurate alarm classification.
[0110] In some embodiments, specifically, the target tactical phase of the target intrusion behavior, the point alarm level and the behavior alarm level corresponding to the alarm behavior associated with the target intrusion behavior are integrated to determine the security event alarm level information of the target intrusion behavior, including:
[0111] Obtain the first target weight of the target tactical phase, the second target weight corresponding to the point warning level of each warning behavior, and the third target weight corresponding to the behavior warning level of each warning behavior;
[0112] The security event alarm score of the target intrusion behavior is determined by integrating the first target weight of the target tactical phase of the target intrusion behavior, the second target weight corresponding to the point alarm level of each alarm behavior of the target intrusion behavior, and the third target weight corresponding to the behavior alarm level of each alarm behavior of the target intrusion behavior;
[0113] Based on the corresponding relationship between the security incident warning score of the target intrusion behavior and different security levels, the security incident warning level of the target intrusion behavior is determined.
[0114] The first target weight represents the importance of the target tactical stage in the overall security incident assessment; the weight value is usually between 0 and 1, and the sum of the weights of all tactical stages should be equal to 1.
[0115] The second target weight represents the importance of the point alarm level of each alarm behavior in the overall security incident assessment;
[0116] For each alarm behavior, there is a corresponding point alarm level weight.
[0117] The third target weight represents the importance of the behavior warning level of each warning behavior in the overall security incident assessment.
[0118] Similar to the second target weight, for each alarm behavior, there is a corresponding behavior alarm level weight.
[0119] Exemplarily, when calculating the security event alarm score, the score is first initialized to set an initial value for the security event alarm score of the target intrusion behavior.
[0120] A basic score is calculated based on the target tactical phase and the corresponding first target weight.
[0121] For example, if the target tactical phase is "attack attempt phase" and its weight is 0.6, then a base score can be given based on this weight (which can be an arbitrarily set base value multiplied by the weight).
[0122] For each alarm behavior, the point alarm level score of the alarm behavior is calculated according to its point alarm level and the corresponding second target weight; here, the point alarm level (which may be a value or a level) is converted into a score and multiplied by the corresponding weight.
[0123] Similar to the calculation of the point alarm level score, for each alarm behavior, the behavior alarm level score of the alarm behavior is calculated according to its behavior alarm level and the corresponding third target weight.
[0124] The tactical phase score, the point alarm level scores of all alarm behaviors, and the behavior alarm level scores are weighted and summed to obtain the final security event alarm score.
[0125] For example, assume that the target tactical stage of the target intrusion behavior is "attack attempt stage", and its weight is 0.6; the target intrusion behavior is associated with two alarm behaviors: Alarm behavior 1: the point alarm level is "high", the weight is 0.7; the behavior alarm level is "serious", the weight is 0.8; Alarm behavior 2: the point alarm level is "medium", the weight is 0.3; the behavior alarm level is "general", the weight is 0.2;
[0126] Then, the calculation result of the security incident alert score is as follows:
[0127] Tactical phase score: base value * 0.6 (assuming the base value is 100, the tactical phase score is 60).
[0128] The point alarm level score of alarm behavior 1 is: high level score * 0.7 (assuming the high level score is 50, the point alarm level score is 35).
[0129] The behavior alarm level score of alarm behavior 1 is: severity level score * 0.8 (assuming the severity level score is 70, the behavior alarm level score is 56).
[0130] The point alarm level score of alarm behavior 2 is: medium level score * 0.3 (assuming the medium level score is 30, the point alarm level score is 9).
[0131] The behavioral warning level score of warning behavior 2 is: general level score * 0.2 (assuming the general level score is 40, the behavioral warning level score is 8).
[0132] The final security incident alert score is: 60 (tactical stage score) + 35 (point alert level score of alert behavior 1) + 56 (behavior alert level score of alert behavior 1) + 9 (point alert level score of alert behavior 2) + 8 (behavior alert level score of alert behavior 2) = 178.
[0133] It can be seen that the security incident alarm score of the target intrusion behavior obtained here also takes into account the number of alarm behaviors associated with the target intrusion behavior. Generally speaking, the more alarm behaviors there are, the more serious the intrusion behavior is to a certain extent.
[0134] After the security incident warning score is determined, the security incident warning level of the target intrusion behavior is determined based on the corresponding relationship between the security incident warning score of the target intrusion behavior and different security levels.
[0135] The security incident warning score can quantitatively analyze the degree of harm of the target intrusion behavior, and the security incident warning level can qualitatively describe the degree of harm of the target intrusion behavior.
[0136] In subsequent steps, the security incident warning score may also be used directly; the security incident warning level of the target intrusion behavior can intuitively reflect the harm of the target intrusion behavior.
[0137] Based on this, the security event alarm level information includes: a security event alarm score and / or a security event alarm grade.
[0138] As an example only, the security incident warning levels include three levels: low risk, high risk and emergency.
[0139] In the step S105, outbound call information of the target intrusion behavior is generated based on the security event alarm level information of the target intrusion behavior, and the outbound call information is sent to a terminal device corresponding to the security operation and maintenance personnel.
[0140] For details, please refer to Figure 4 , generating outbound call information of the target intrusion behavior based on the security event alarm level information of the target intrusion behavior, and sending the outbound call information to the terminal device corresponding to the security operation and maintenance personnel, including the following steps S401-S402:
[0141] S401, determining a target outbound call mechanism corresponding to the security event alarm level information of the target intrusion behavior based on the association relationship between the security event alarm level and the outbound call mechanism in the pre-configured security event alarm level information;
[0142] S402: Based on the target outbound call mechanism, the outbound call information is sent to a terminal device corresponding to the security operation and maintenance personnel.
[0143] The target outbound calling mechanism includes: sending emails, sending instant messaging, mobile phone text messages, direct telephone outbound calls, etc.
[0144] Based on the alarm correlation analysis of multiple devices, intrusion behaviors are formed, and they are classified according to the attack tactics associated with the behaviors. At the same time, the alarm levels are divided according to the impact of the tactics. Different levels of alarms are sent using different external mechanisms.
[0145] For example, for low-risk behaviors, emails are sent; for high-risk behaviors, instant messaging and text messages are sent; and for emergency behaviors, direct phone calls are made.
[0146] Even though the security alarm classification outbound calling method described in the embodiment of the present application has reduced concurrent busy lines to a great extent, when multiple events occur simultaneously in the credit reporting business intranet, the alarm outbound calling system has no mechanism for distinguishing priority sequences and lacks an alarm pre-processing mechanism, and busy lines may still occur, which may result in the inability to effectively call out the most important alarms.
[0147] Based on this, in some embodiments, sending the outbound call information to the terminal device corresponding to the security operation and maintenance personnel includes:
[0148] For multiple outbound call information, queuing is performed based on the security event alarm level information of the target intrusion behavior corresponding to the outbound call information, and queuing information of the multiple outbound call information is determined;
[0149] The queuing information of the multiple outbound call messages is used to send the multiple outbound call messages to the terminal devices corresponding to the security operation and maintenance personnel.
[0150] When multiple events occur, they are queued based on their urgency and dispatched. The more urgent the target intrusion behavior, the higher the priority, thus ensuring that the most important alarms are effectively dispatched.
[0151] Specifically, queuing is performed based on the security incident alarm level information of the target intrusion behavior corresponding to the outbound call information. The queuing can be performed directly based on the security incident alarm level score in the security incident alarm level information, or based on the security incident alarm level in the security incident alarm level information. The same security incident alarm level is queued based on chronological order.
[0152] In some embodiments, the security alarm classification outbound calling method sends the outbound calling information to the terminal device corresponding to the security operation and maintenance personnel, including:
[0153] Based on the security event alarm level information of the target intrusion behavior corresponding to the multiple outbound call information, determine the target outbound call information that meets the polling mechanism from the multiple outbound call information;
[0154] The target outbound call information is polled and sent based on a polling mechanism until a processing response result for the target outbound call information is received.
[0155] Based on the security incident alarm level information of the target intrusion behavior corresponding to the multiple outbound call information, the target outbound call information that meets the polling mechanism is determined from the multiple outbound call information. Specifically, based on the security incident alarm level in the security incident alarm level information, the target outbound call information of the target level can be screened out; or based on the security incident alarm score in the security incident alarm level information, a preset number of target outbound call information with the highest score ranking can be screened out.
[0156] That is to say, for important target outbound call information, a polling mechanism is used to poll and send it to ensure that the processing response result is received.
[0157] Exemplarily, only the target outbound call information with an urgent security event alarm level is sent through a polling mechanism.
[0158] The polling mechanism is specific, for example, after an outbound call is triggered once, if no response is processed, the outbound call will continue after 5 minutes, and if still not processed after 30 minutes, the outbound call will be terminated after the processing is completed.
[0159] Based on this, in the security alarm classification outbound calling method described in the embodiment of the present application, when the monitoring system detects a network attack behavior, it can perform intelligent correlation analysis based on a large number of alarms from various scattered independent devices to form a small number of intrusion behavior events, effectively reducing the number of alarms; based on the level of the event, an outbound calling mechanism is defined to implement intelligent outbound calling for events of different types and levels, so that security operation and maintenance personnel can be notified immediately to handle the situation.
[0160] Based on the same inventive concept, the embodiment of the present application also provides a security alarm classification outbound call device corresponding to the security alarm classification outbound call method. Since the principle of solving the problem by the device in the embodiment of the present application is similar to the above-mentioned security alarm classification outbound call method in the embodiment of the present application, the implementation of the device can refer to the implementation of the method, and the repeated parts will not be repeated.
[0161] Please refer to Figure 5 , Figure 5 The structure diagram of the security alarm classification outbound call device according to the embodiment of the present application is shown as follows: Figure 5 As shown, the device comprises:
[0162] Configuration module 501, used to configure the point alarm level of different detection points of the credit reporting business system and the behavior alarm level of the alarm behavior of a single device at each detection point;
[0163] The judgment module 502 is used to judge whether the multiple alarm behaviors of at least one monitoring point received within a preset time period are related; the alarm behavior corresponds to the point alarm level of the monitoring point and the behavior alarm level of the alarm behavior;
[0164] The association module 503 is used to associate the multiple alarm behaviors into a target intrusion behavior when determining the association of the multiple alarm behaviors;
[0165] A determination module 504 is used to determine the security event alarm level information of the target intrusion behavior based on the point alarm level and the behavior alarm level corresponding to the alarm behavior associated with the target intrusion behavior;
[0166] The generating module 505 is used to generate outbound call information of the target intrusion behavior based on the security event alarm level information of the target intrusion behavior, and send the outbound call information to the terminal device corresponding to the security operation and maintenance personnel.
[0167] In some embodiments, in the security alarm classification outbound call device, the determination module, when determining the security event alarm level information of the target intrusion behavior based on the point alarm level and the behavior alarm level corresponding to the alarm behavior associated with the target intrusion behavior, is specifically used to:
[0168] Based on a plurality of different tactical phases of the intrusion behavior divided in advance, determining a target tactical phase of the target intrusion behavior; wherein different tactical phases represent different degrees of harm of the intrusion behavior;
[0169] The target tactical phase of the target intrusion behavior, the point alarm level and the behavior alarm level corresponding to the alarm behavior associated with the target intrusion behavior are integrated to determine the security event alarm level information of the target intrusion behavior.
[0170] In some embodiments, in the security alarm classification outbound call device, the determination module, when fusing the target tactical phase of the target intrusion behavior, the point alarm level and the behavior alarm level corresponding to the alarm behavior associated with the target intrusion behavior, determines the security event alarm level information of the target intrusion behavior, is specifically used to:
[0171] Obtain the first target weight of the target tactical phase, the second target weight corresponding to the point warning level of each warning behavior, and the third target weight corresponding to the behavior warning level of each warning behavior;
[0172] The security event alarm score of the target intrusion behavior is determined by integrating the first target weight of the target tactical phase of the target intrusion behavior, the second target weight corresponding to the point alarm level of each alarm behavior of the target intrusion behavior, and the third target weight corresponding to the behavior alarm level of each alarm behavior of the target intrusion behavior;
[0173] Based on the corresponding relationship between the security incident warning score of the target intrusion behavior and different security levels, the security incident warning level of the target intrusion behavior is determined.
[0174] In some embodiments, in the security alarm classification outbound call device, the generation module, when generating outbound call information of the target intrusion behavior based on the security event alarm level information of the target intrusion behavior and sending the outbound call information to the terminal device corresponding to the security operation and maintenance personnel, is specifically used to:
[0175] Determine the target outbound call mechanism corresponding to the security event alarm level information of the target intrusion behavior based on the association relationship between the security event alarm level and the outbound call mechanism in the pre-configured security event alarm level information;
[0176] Based on the target outbound call mechanism, the outbound call information is sent to the terminal device corresponding to the security operation and maintenance personnel.
[0177] In some embodiments, in the security alarm classification outbound call device, the generation module, when sending the outbound call information to the terminal device corresponding to the security operation and maintenance personnel, is specifically used to:
[0178] For multiple outbound call information, queuing is performed based on the security event alarm level information of the target intrusion behavior corresponding to the outbound call information, and queuing information of the multiple outbound call information is determined;
[0179] The queuing information of the multiple outbound call messages is used to send the multiple outbound call messages to the terminal devices corresponding to the security operation and maintenance personnel.
[0180] In some embodiments, in the security alarm classification outbound call device, the generation module, when sending the outbound call information to the terminal device corresponding to the security operation and maintenance personnel, is specifically used to:
[0181] Based on the security event alarm level information of the target intrusion behavior corresponding to the multiple outbound call information, determine the target outbound call information that meets the polling mechanism from the multiple outbound call information;
[0182] The target outbound call information is polled and sent based on a polling mechanism until a processing response result for the target outbound call information is received.
[0183] In some embodiments, in the security alarm classification outbound call device, the judgment module, when judging whether multiple alarm behaviors of at least one monitoring point received within a preset time period are related, is specifically used to:
[0184] For multiple alarm behaviors of at least one monitoring point received within a preset time period, determine whether the multiple alarm behaviors meet a preset association rule; the preset association rule is determined based on the correlation characteristics of the multiple alarm behaviors, or based on the device action characteristics of different devices at different monitoring points under the attack of the same intrusion behavior;
[0185] If so, it is determined that the multiple alarm behaviors are associated.
[0186] Based on the same inventive concept, an electronic device corresponding to the security alarm classification outbound call method is also provided in the embodiment of the present application. Since the principle of solving the problem by the electronic device in the embodiment of the present application is similar to the above-mentioned security alarm classification outbound call method in the embodiment of the present application, the implementation of the electronic device can refer to the implementation of the method, and the repeated parts will not be repeated.
[0187] Please refer to Figure 6 , Figure 6 A schematic diagram of the structure of the electronic device described in an embodiment of the present application is shown; the electronic device 600 includes: a processor 602, a memory 601 and a bus, the memory 601 stores machine-readable instructions executable by the processor 602, and when the electronic device 600 is running, the processor 602 communicates with the memory 601 through the bus, and when the machine-readable instructions are executed by the processor 602, the steps of the security alarm classification outbound call method are executed.
[0188] Based on the same inventive concept, a computer-readable storage medium corresponding to the security alarm classification outbound calling method is also provided in the embodiment of the present application. Since the principle of solving the problem by the computer-readable storage medium in the embodiment of the present application is similar to the above-mentioned security alarm classification outbound calling method in the embodiment of the present application, the implementation of the computer-readable storage medium can refer to the implementation of the method, and the repeated parts will not be repeated.
[0189] A computer-readable storage medium stores a computer program, which executes the steps of the security alarm classification outbound call method when executed by a processor.
[0190] Those skilled in the art can clearly understand that, for the convenience and simplicity of description, the specific working process of the system and device described above can refer to the corresponding process in the method embodiment, and will not be repeated in this application. In the several embodiments provided in this application, it should be understood that the disclosed system, device and method can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the modules is only a logical function division. There may be other division methods in actual implementation. For example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some communication interfaces, indirect coupling or communication connection of devices or modules, which can be electrical, mechanical or other forms.
[0191] The modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0192] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0193] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a non-volatile computer-readable storage medium that is executable by a processor. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, a platform server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard drives, ROM, RAM, magnetic disks, or optical disks.
[0194] The above are only specific implementations of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
Claims
1. A security alarm classification outbound calling method, characterized in that: The method comprises: Configure the point alarm level of different detection points of the credit reporting business system and the behavior alarm level of the alarm behavior of a single device at each detection point; For multiple alarm behaviors of at least one monitoring point received within a preset time period, determine whether the multiple alarm behaviors are related; the alarm behavior corresponds to the point alarm level of the monitoring point and the behavior alarm level of the alarm behavior; If so, associating the multiple warning behaviors into one target intrusion behavior; Determine the security event alarm level information of the target intrusion behavior based on the point alarm level and behavior alarm level corresponding to the alarm behavior associated with the target intrusion behavior; An outbound call information of the target intrusion behavior is generated based on the security event alarm level information of the target intrusion behavior, and the outbound call information is sent to a terminal device corresponding to the security operation and maintenance personnel.
2. The security alarm classification outbound calling method according to claim 1 is characterized in that: Determining the security event alarm level information of the target intrusion behavior based on the point alarm level and behavior alarm level corresponding to the alarm behavior associated with the target intrusion behavior; including: Based on a plurality of different tactical phases of the intrusion behavior divided in advance, determining a target tactical phase of the target intrusion behavior; wherein different tactical phases represent different degrees of harm of the intrusion behavior; The target tactical phase of the target intrusion behavior, the point alarm level and the behavior alarm level corresponding to the alarm behavior associated with the target intrusion behavior are integrated to determine the security event alarm level information of the target intrusion behavior.
3. The security alarm classification outbound calling method according to claim 2 is characterized in that: The target tactical phase of the target intrusion behavior, the point alarm level and the behavior alarm level corresponding to the alarm behavior associated with the target intrusion behavior are integrated to determine the security event alarm level information of the target intrusion behavior, including: Obtain the first target weight of the target tactical phase, the second target weight corresponding to the point warning level of each warning behavior, and the third target weight corresponding to the behavior warning level of each warning behavior; The security event alarm score of the target intrusion behavior is determined by integrating the first target weight of the target tactical phase of the target intrusion behavior, the second target weight corresponding to the point alarm level of each alarm behavior of the target intrusion behavior, and the third target weight corresponding to the behavior alarm level of each alarm behavior of the target intrusion behavior; Based on the corresponding relationship between the security incident warning score of the target intrusion behavior and different security levels, the security incident warning level of the target intrusion behavior is determined.
4. The security alarm classification outbound calling method according to claim 1, characterized in that: Generate outbound call information of the target intrusion behavior based on the security event alarm level information of the target intrusion behavior, and send the outbound call information to a terminal device corresponding to the security operation and maintenance personnel, including: Determine the target outbound call mechanism corresponding to the security event alarm level information of the target intrusion behavior based on the association relationship between the security event alarm level and the outbound call mechanism in the pre-configured security event alarm level information; Based on the target outbound call mechanism, the outbound call information is sent to the terminal device corresponding to the security operation and maintenance personnel.
5. The security alarm classification outbound calling method according to claim 1 or 4, characterized in that: Sending the outbound call information to the terminal device corresponding to the security operation and maintenance personnel includes: For multiple outbound call information, queuing is performed based on the security event alarm level information of the target intrusion behavior corresponding to the outbound call information, and queuing information of the multiple outbound call information is determined; The queuing information of the multiple outbound call messages is used to send the multiple outbound call messages to the terminal devices corresponding to the security operation and maintenance personnel.
6. The security alarm classification outbound calling method according to claim 5, characterized in that: Sending the outbound call information to the terminal device corresponding to the security operation and maintenance personnel includes: Based on the security event alarm level information of the target intrusion behavior corresponding to the multiple outbound call information, determine the target outbound call information that meets the polling mechanism from the multiple outbound call information; The target outbound call information is polled and sent based on a polling mechanism until a processing response result for the target outbound call information is received.
7. The security alarm classification outbound calling method according to claim 1, characterized in that: For multiple alarm behaviors of at least one monitoring point received within a preset time period, determining whether the multiple alarm behaviors are related includes: For multiple alarm behaviors of at least one monitoring point received within a preset time period, determine whether the multiple alarm behaviors meet a preset association rule; the preset association rule is determined based on the correlation characteristics of the multiple alarm behaviors, or based on the device action characteristics of different devices at different monitoring points under the attack of the same intrusion behavior; If so, it is determined that the multiple alarm behaviors are associated.
8. A security alarm classification outbound call device, characterized in that: The device comprises: A configuration module, used to configure the point alarm levels of different detection points of the credit reporting business system and the behavior alarm level of the alarm behavior of a single device at each detection point; A judgment module, for judging whether the multiple alarm behaviors received from at least one monitoring point within a preset time period are related; the alarm behavior corresponds to the point alarm level of the monitoring point and the behavior alarm level of the alarm behavior; An association module, configured to associate the multiple alarm behaviors into a target intrusion behavior when determining that the multiple alarm behaviors are associated; A determination module, configured to determine the security event alarm level information of the target intrusion behavior based on the point alarm level and the behavior alarm level corresponding to the alarm behavior associated with the target intrusion behavior; A generation module is used to generate outbound call information of the target intrusion behavior based on the security event alarm level information of the target intrusion behavior, and send the outbound call information to the terminal device corresponding to the security operation and maintenance personnel.
9. An electronic device, characterized in that: include: A processor, a memory and a bus, wherein the memory stores machine-readable instructions executable by the processor, and when the electronic device is running, the processor and the memory communicate via the bus, and when the machine-readable instructions are executed by the processor, the steps of the security alarm classification outbound call method as described in any one of claims 1 to 7 are performed.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the security alarm classification outbound call method according to any one of claims 1 to 7 are executed.
Citation Information
Patent Citations
Security event alarm association aggregation method and device and medium thereof
CN116032724A
Service alarm information processing method and device, electronic equipment and storage medium
CN116737765A