Automated Attack Disposal Method Implemented by SOAR Technology through a Security Resource Pool

By introducing a security resource pool in SOAR technology, dynamically matching and calling security components, the problems of insufficient design flexibility of protection rules and difficulty in large-scale scenario management in the existing technology are solved, and efficient automated security incident handling is achieved.

CN119906590BActive Publication Date: 2025-06-13LIAONING BRANCH OF CHINA UNITED NETWORK COMM CO LTD

Patent Information

Application Number
CN202510398697.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-01
Publication Date
2025-06-13
Estimated Expiration
2045-04-01

AI Technical Summary

Technical Problem

The existing SOAR technology is not flexible enough in the design of preset protection rules and cannot adapt to dynamic security threats. In large-scale and complex scenarios, there are problems such as high difficulty in unified management and coordination of multiple lines and difficulty in adapting multiple devices.

Method used

Through the security resource pool combined with SOAR technology, the security operation platform is used to identify attack events, match preset protection rules, and dynamically call security components for automated handling, achieving flexible responses to different attack events.

Benefits of technology

It improves the efficiency of network security incident handling, realizes rapid response and automated handling of dynamic security threats, and avoids the limitations of fixed security components in the security resource pool.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119906590B_ABST
    Figure CN119906590B_ABST
Patent Text Reader

Abstract

An embodiment of the present invention discloses a method for automatically disposing of attacks implemented by SOAR technology through a security resource pool, which relates to the field of network service security technology. The method includes: identifying attack events based on a security operation platform and determining the attack categories of the attack events; matching the attack categories with preset protection rules orchestrated by SOAR technology, and taking the preset protection policies corresponding to the attack categories in the preset protection rules as target protection policies; calling security components in the security resource pool according to the target protection policies to complete the automatic disposal of the attack events. By combining SOAR technology with the security resource pool and leveraging the dynamic allocation ability of security components in the security resource pool and the advantage of security capability collaboration between different security resource pools through the security operation platform, automatic security operation can be achieved, which can improve the efficiency of network security event disposal.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and particularly to an automated attack disposal method implemented by SOAR technology through a security resource pool. Background Art

[0002] SOAR (Security Orchestration, Automation and Response) is a technology that improves the efficiency of security incident response by integrating security tools, automated processes, and standardized workflows. Currently, SOAR technology requires preset protection rules, which need to be written and designed in advance by security experts, lacking flexibility and unable to adapt to dynamic security threats; the security devices and other hardware integrated by SOAR technology are suitable for static allocation of security resources and cannot dynamically respond to sudden attacks; in large-scale complex scenarios (scenarios with multiple security resource pools), SOAR technology has problems such as high difficulty in unified management and coordination of multiple lines and difficulty in adapting multiple devices. Summary of the Invention

[0003] In view of this, the present invention provides an automated attack disposal method implemented by SOAR technology through a security resource pool, which is used to solve the problems that existing SOAR technology requires preset protection rules, which need to be written and designed in advance by security experts, lacking flexibility and unable to adapt to dynamic security threats; the security devices and other hardware integrated by SOAR technology are suitable for static allocation of security resources and cannot dynamically respond to sudden attacks; in large-scale complex scenarios (scenarios with multiple security resource pools), SOAR technology has problems such as high difficulty in unified management and coordination of multiple lines and difficulty in adapting multiple devices.

[0004] In a first aspect, an embodiment of the present invention provides an automated attack disposal method implemented by SOAR technology through a security resource pool, and the method includes:

[0005] Identifying an attack event based on a security operation platform and determining the attack category of the attack event;

[0006] Matching the attack category with preset protection rules orchestrated by SOAR technology, and taking the preset protection strategy corresponding to the attack category in the preset protection rules as the target protection strategy;

[0007] Invoking security components in the security resource pool according to the target protection strategy to complete the automated disposal of the attack event.

[0008] Optionally, the step of identifying an attack event based on a security operation platform and determining the attack category of the attack event includes:

[0009] Obtain the alarm information of the security resource pool and the system where the security resource pool is located based on the security operation platform, and use the event corresponding to the alarm information as the attack event;

[0010] Obtain the feature data of the attack event, and determine the attack category of the attack event based on the feature data.

[0011] Optionally, the step of identifying the attack event based on the security operation platform and determining the attack category of the attack event further includes:

[0012] Invoke the attack event recognition model through the security operation platform;

[0013] Obtain the first operation data of the security resource pool and the second operation data of the system where the security resource pool is located based on the security operation platform;

[0014] Substitute the first operation data and the second operation data into the attack event recognition model respectively to obtain the recognition result;

[0015] When the recognition result indicates the existence of an attack event, determine the attack category of the attack event according to the recognition result.

[0016] Optionally, the method further includes:

[0017] Determine the disposal plan for the attack category through the first disposal plan prediction model and the attack category;

[0018] Match the disposal plan with the target protection policy;

[0019] If the disposal plan is inconsistent with the target protection policy, generate a modification suggestion for updating the preset protection rule based on the disposal plan, and display the modification suggestion.

[0020] Optionally, the step of matching the attack category with the preset protection rules orchestrated by SOAR technology and using the preset protection policy corresponding to the attack category in the preset protection rules as the target protection policy further includes:

[0021] Match the attack category with the preset protection rules orchestrated by SOAR technology. If there is no preset protection rule corresponding to the attack category in the preset protection rules;

[0022] Then obtain the context information of the attack event;

[0023] Input the context information into the second disposal plan prediction model to obtain the first target disposal plan corresponding to the attack event;

[0024] Generate a preset protection rule corresponding to the attack event according to the first target handling solution through the SOAR technology, obtain a preset protection rule corresponding to the attack category, and use the preset protection strategy corresponding to the attack category in the preset protection rule as the target protection strategy.

[0025] Optionally, the step of matching the attack category with a preset protection rule orchestrated by the SOAR technology and using the preset protection strategy corresponding to the attack category in the preset protection rule as the target protection strategy further includes:

[0026] Match the attack category with a preset protection rule orchestrated by the SOAR technology. If there is no preset protection rule corresponding to the attack category in the preset protection rule;

[0027] Then obtain the context information of the attack event;

[0028] Match the context information with the preset protection data to obtain a second target handling solution corresponding to the attack event;

[0029] Generate a preset protection rule corresponding to the attack event according to the second target handling solution through the SOAR technology, obtain a preset protection rule corresponding to the attack category, and use the preset protection strategy corresponding to the attack category in the preset protection rule as the target protection strategy.

[0030] Optionally, the step of invoking security components in the security resource pool according to the target protection strategy to complete the automated handling of the attack event includes:

[0031] Generate a control instruction according to the target protection strategy and send the control instruction to the security resource pool, so that the security resource pool responds to the control instruction to invoke security components and complete the automated handling of the attack event.

[0032] Optionally, the step of invoking security components in the security resource pool according to the target protection strategy to complete the automated handling of the attack event further includes:

[0033] Generate a control instruction according to the target protection strategy and send the control instruction to the security operation platform;

[0034] Based on the security operation platform, obtain the occurrence point of the attack event, determine the security resource pool corresponding to the occurrence point, and use the security resource pool corresponding to the occurrence point as the target security resource pool;

[0035] Send the control instruction to the target security resource pool through the security operation platform, so that the target security resource pool responds to the control instruction to call security components and complete the automated handling of the attack event.

[0036] Optionally, the step of calling security components in the security resource pool according to the target protection policy to complete the automated handling of the attack event further includes:

[0037] Obtain the protection function parameters of each security component in the security resource pool through the security operation platform, and determine whether the security components in the security resource pool can meet the target protection policy based on the protection function parameters;

[0038] When the security components in the security resource pool cannot meet the target protection policy, update the security resource pool based on the target protection policy, and complete the automated handling of the attack event based on the updated security resource pool.

[0039] Optionally, the method further includes:

[0040] Obtain the process data of the attack event;

[0041] When the process data indicates the end of the attack event, restore the updated security resource pool to release the resources occupied when updating the security resource pool.

[0042] On the other hand, an embodiment of the present invention provides an attack automated handling device implemented by a SOAR technology through a security resource pool. The device includes:

[0043] An identification module, configured to identify an attack event based on a security operation platform and determine the attack category of the attack event;

[0044] A matching module, configured to match the attack category with a preset protection rule orchestrated by the SOAR technology, and use the preset protection policy corresponding to the attack category in the preset protection rule as the target protection policy;

[0045] An execution module, configured to call security components in the security resource pool according to the target protection policy to complete the automated handling of the attack event.

[0046] In a third aspect, an embodiment of the present invention further provides an electronic device, and the electronic device includes:

[0047] One or more processors;

[0048] A storage device, configured to store one or more programs;

[0049] When the one or more programs are executed by the one or more processors, the one or more processors implement the attack automated handling method implemented by the SOAR technology through the security resource pool in any of the embodiments of the present invention.

[0050] In a fourth aspect, an embodiment of the present invention further provides a storage medium containing computer-executable instructions, and the computer-executable instructions are used to execute the attack automated handling method implemented by the SOAR technology through the security resource pool in any of the embodiments of the present invention when executed by a computer processor.

[0051] The technical solution of the embodiment of the present invention identifies attack events based on a security operation platform and determines the attack categories of the attack events; matches the attack categories with preset protection rules orchestrated by the SOAR technology, and uses the preset protection policies corresponding to the attack categories in the preset protection rules as target protection policies; calls security components in the security resource pool according to the target protection policies to complete the automated handling of the attack events. By combining the SOAR technology with the security resource pool, through the dynamic allocation ability of the security components in the security resource pool by the security operation platform and the advantages of security capability collaboration between different security resource pools, the limitations of the fixed security components in the security resource pool are avoided. Dynamically updating the preset protection rules orchestrated by the SOAR technology can protect against different attack events, realize automated security event handling, and improve the handling efficiency of network security events. It can achieve rapid response and handling of security risks and threat intrusion behaviors. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings without creative efforts based on these drawings.

[0053] Among them:

[0054] Figure 1 is a schematic flow chart of an attack automated handling method implemented by the SOAR technology through the security resource pool in an embodiment of the present invention;

[0055] Figure 2 is a schematic structural diagram of an attack automated handling device implemented by the SOAR technology through the security resource pool in an embodiment of the present invention;

[0056] Figure 3 is a schematic structural diagram of an electronic device provided by an embodiment of the present invention;

[0057] Figure 4 It is a schematic structural diagram of a computer-readable storage medium provided by an embodiment of the present invention. Specific implementation manners

[0058] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0059] An embodiment of the present invention provides a method for automatically disposing of attacks implemented by SOAR technology through a security resource pool. The SOAR technology is used to implement automatic response and disposal of attacks through the security resource pool. The capabilities of security components in the security resource pool are utilized to collect information such as traffic, logs, and alarms, and summarize them to the security operation platform. The security operation platform processes and analyzes the above information by invoking an attack event recognition model, and sends the result (the attack category of the attack event) to the SOAR platform. The SOAR platform, according to the preset protection rules, through the orchestrator, sends the disposal strategy to the corresponding security components in the security resource pool, and completes the automatic response and disposal of security events through the strategies of the security components.

[0060] In one embodiment, an embodiment of the present invention provides a method for automatically disposing of attacks implemented by SOAR technology through a security resource pool. The method for automatically disposing of attacks implemented by SOAR technology through a security resource pool in the embodiment of the present invention can be executed by an apparatus for automatically disposing of attacks implemented by SOAR technology through a security resource pool. The apparatus for automatically disposing of attacks implemented by SOAR technology through a security resource pool can be implemented by software and / or hardware.

[0061] As Figure 1 shown, the method for automatically disposing of attacks implemented by SOAR technology through a security resource pool in the embodiment of the present invention specifically includes the following steps:

[0062] S110. Identify attack events based on the security operation platform and determine the attack categories of the attack events;

[0063] In a possible implementation manner, the step of identifying attack events based on the security operation platform and determining the attack categories of the attack events includes:

[0064] Obtain the alarm information of the security resource pool and the system where the security resource pool is located based on the security operation platform, and use the event corresponding to the alarm information as the attack event;

[0065] Obtain the feature data of the attack event, and determine the attack category of the attack event based on the feature data.

[0066] Exemplarily, establish a host anomaly detection rule based on the normal distribution method and a traffic anomaly detection rule based on the statistical method. For the host anomaly detection rule based on the normal distribution method, use the statistical method based on the normal distribution. In the learning stage, calculate the interval threshold of 24 measures for each protected host at each time period every day in the past 30 days, and establish a traffic rule according to the interval threshold. In the working stage, calculate the latest data of each port on each host on the current day, and compare the latest data with the historical mean. If the displayed activity difference exceeds the preset standard deviation, an alarm will be generated. To avoid false alarms for short-term port usage, one of the following two conditions must be met: there are at least 50 flow data in the current hour, or there are at least 50 flow data in the calculated baseline mean. For the traffic anomaly detection rule based on the statistical method, anomaly detection first uses the historical traffic data of the network traffic to establish a normal traffic rule, and evaluates the deviation degree of the current traffic through the traffic steady-state rule to determine whether the current traffic is abnormal. The establishment and update of the traditional detection rule estimate the features according to the central limit theorem and the hypothesis testing theorem, calculate the confidence interval of the detection rule for a period of time, and then compare whether the current traffic feature value is within this confidence interval. If it is satisfied, it means that the current traffic behavior is normal and the queue data is updated; otherwise, an anomaly has occurred, the historical queue data is not updated, and an anomaly error is reported. In addition to the above rules, the security operation platform customizes a variety of analysis rules for terminal logs, traffic logs, and alarm logs to realize the analysis and operation of the operation platform.

[0067] In a possible implementation manner, the step of identifying the attack event based on the security operation platform and determining the attack category of the attack event further includes:

[0068] Invoke the attack event recognition model through the security operation platform;

[0069] Obtain the first operation data of the security resource pool and the second operation data of the system where the security resource pool is located based on the security operation platform;

[0070] Substitute the first operation data and the second operation data into the attack event recognition model respectively to obtain the recognition result;

[0071] When the recognition result indicates that there is an attack event, determine the attack category of the attack event according to the recognition result.

[0072] Exemplarily, a trained large language model (such as a specific Qwen large model for classification) can be used as the attack recognition model, and then the trained Qwen large model can be deployed on the server for subsequent use.

[0073] Exemplarily, the training of the Qwen large model can use known attack types and the corresponding running data as the training set / validation set.

[0074] Exemplarily, the first running data includes but is not limited to the logs and event data of the security resource pool; the second running data includes but is not limited to the logs and event data of the system where the security resource pool is located.

[0075] By implementing the recognition of attack types in different ways, the method described in this application can be applicable to different scenarios.

[0076] S120. Match the attack category with the preset protection rules orchestrated by the SOAR technology, and use the preset protection strategy corresponding to the attack category in the preset protection rules as the target protection strategy;

[0077] S130. Invoke the security components in the security resource pool according to the target protection strategy to complete the automated handling of the attack event.

[0078] By identifying attack events based on the security operation platform and determining the attack category of the attack event; matching the attack category with the preset protection rules orchestrated by the SOAR technology, and using the preset protection strategy corresponding to the attack category in the preset protection rules as the target protection strategy; invoking the security components in the security resource pool according to the target protection strategy to complete the automated handling of the attack event. Combining the SOAR technology with the security resource pool, leveraging the dynamic allocation ability of the security components in the security resource pool and the advantages of security capability coordination between different security resource pools through the security operation platform, it avoids the limitations of the fixed security components in the security resource pool. Dynamically updating the preset protection rules orchestrated by the SOAR technology can protect against different attack events, achieve automated security event handling, and improve the handling efficiency of network security events. It enables rapid response and handling of security risks and threat intrusion behaviors.

[0079] In a possible implementation manner, the method further includes:

[0080] Determine the handling solution for the attack category through the first handling solution prediction model and the attack category;

[0081] Match the handling solution with the target protection strategy;

[0082] If the disposal plan is inconsistent with the target protection policy, a modification suggestion for updating the preset protection rule is generated based on the disposal plan, and the modification suggestion is displayed.

[0083] Exemplarily, the first disposal plan prediction model can be understood as a large language model for predicting the disposal plan for the attack category.

[0084] Exemplarily, with the development of technology, in actual use, there are often better protection methods. For example, in the preset protection rules orchestrated by SOAR technology, the preset protection policy for attack type A needs to mobilize component X and component Y. However, due to the iterative update of security protection technology, a component Z with the same function as component Y and better performance appears. At this time, a modification suggestion (recommending component Z to technicians) is generated to ensure the optimal protection effect.

[0085] In a possible implementation manner, the step of matching the attack category with the preset protection rules orchestrated by SOAR technology and using the preset protection policy corresponding to the attack category in the preset protection rules as the target protection policy further includes:

[0086] Match the attack category with the preset protection rules orchestrated by SOAR technology. If there is no preset protection rule corresponding to the attack category in the preset protection rules;

[0087] Then obtain the context information of the attack event;

[0088] Input the context information into the second disposal plan prediction model to obtain the first target disposal plan corresponding to the attack event;

[0089] Generate a preset protection rule corresponding to the attack event according to the first target disposal plan through SOAR technology, obtain the preset protection rule corresponding to the attack category, and use the preset protection policy corresponding to the attack category in the preset protection rule as the target protection policy.

[0090] Exemplarily, the context information includes but is not limited to the severity of the event, the affected assets, the behavior pattern of the attacker, the current system state, etc. The second disposal plan prediction model is a large language model trained based on historical context information and historical disposal plans corresponding to the historical context information.

[0091] Exemplarily, the second disposal solution prediction model and SOAR technology dynamically generate protection strategies, which can automatically generate response strategies based on real-time security events, threat intelligence and environmental changes. The SOAR platform collects security events and threat data in real time through a variety of security tools (such as EDR, firewalls, etc.); threat data can be obtained through external threat intelligence (such as IP blacklists, malicious hash values, etc.); then the second disposal solution prediction model (a large language model trained based on historical context information and historical disposal solutions corresponding to historical context information) is used to analyze historical events (threat data) and response effects, and dynamically generate script content.

[0092] Exemplarily, the attack event recognition model, the first disposal solution prediction model and the second disposal solution prediction model may be three independent large language models, or may be a single large language model that simultaneously has the functions of attack recognition, determining the disposal solution for the attack category according to the attack category, and determining the first target disposal solution corresponding to the attack event according to the context information of the attack event.

[0093] In a possible implementation, the step of matching the attack category with a preset protection rule arranged by SOAR technology, and using a preset protection strategy corresponding to the attack category in the preset protection rule as a target protection strategy, further includes:

[0094] Matching the attack category with the preset protection rules compiled by SOAR technology, if there is no preset protection rule corresponding to the attack category in the preset protection rules;

[0095] Then obtaining context information of the attack event;

[0096] Matching the context information with the preset protection data to obtain a second target disposal solution corresponding to the attack event;

[0097] Through SOAR technology, a preset protection rule corresponding to the attack event is generated according to the second target disposal plan to obtain the preset protection rule corresponding to the attack category, and the preset protection strategy corresponding to the attack category in the preset protection rule is used as the target protection strategy.

[0098] For example, since the preset protection strategies corresponding to the attack categories obtained through the large language model often lack specificity, in specific scenarios (special security protection requirements), determining the second target handling plan corresponding to the attack event based on the preset protection data pre-set by the technical staff is more in line with actual needs, and can face different scenarios and meet different special needs in different scenarios.

[0099] Exemplarily, the preset protection data includes but is not limited to different attack types, protection strategies corresponding to different attack types, default playbooks, etc.

[0100] In a possible implementation manner, the step of invoking security components in the security resource pool according to the target protection strategy to complete the automated handling of the attack event includes:

[0101] Generate a control instruction according to the target protection strategy, and send the control instruction to the security resource pool, so that the security resource pool responds to the control instruction to invoke security components, and complete the automated handling of the attack event.

[0102] Exemplarily, sending the control instruction to the security resource pool avoids the data transmission process of the control instruction passing through the security operation platform, improves the response efficiency, and reduces resource occupancy.

[0103] In a possible implementation manner, the step of invoking security components in the security resource pool according to the target protection strategy to complete the automated handling of the attack event further includes:

[0104] Generate a control instruction according to the target protection strategy, and send the control instruction to the security operation platform;

[0105] Based on the security operation platform, obtain the occurrence point of the attack event, determine the security resource pool corresponding to the occurrence point, and use the security resource pool corresponding to the occurrence point as the target security resource pool;

[0106] Send the control instruction to the target security resource pool through the security operation platform, so that the target security resource pool responds to the control instruction to invoke security components, and complete the automated handling of the attack event.

[0107] Exemplarily, when there are multiple security resource pools, the security operation platform is used to identify the occurrence point of the attack event, and then the control instruction is sent to the security resource pool corresponding to the occurrence point through the security operation platform, ensuring the pertinence of the protection and avoiding incorrect responses.

[0108] In a possible implementation manner, the step of invoking security components in the security resource pool according to the target protection strategy to complete the automated handling of the attack event further includes:

[0109] Obtain the protection function parameters of each security component in the security resource pool through the security operation platform, and judge whether the security components in the security resource pool can meet the target protection strategy based on the protection function parameters;

[0110] When the security components in the security resource pool cannot meet the target protection policy, the security resource pool is updated based on the target protection policy, and the automated handling of the attack event is completed based on the updated security resource pool.

[0111] Exemplarily, the security resource pool is dynamically updated so that the security components in the security resource pool are not fixed, thereby enabling the security resource pool to protect against different attack events, avoiding the limitations of fixed security components in the security resource pool, and improving the applicable scope of the solution described in this application.

[0112] In a possible implementation manner, the method further includes:

[0113] Obtain the process data of the attack event;

[0114] When the process data indicates the end of the attack event, the updated security resource pool is restored to release the resources occupied by updating the security resource pool.

[0115] Exemplarily, when the attack event ends, the resources of the temporarily occupied security components are released, that is, the security components used to update the security resource pool are no longer occupied, avoiding resource waste.

[0116] In a possible implementation manner, as Figure 2 shown, this application provides an attack automated handling device implemented by a SOAR technology through a security resource pool, and the device includes:

[0117] An identification module 201, configured to identify an attack event based on a security operation platform and determine the attack category of the attack event;

[0118] A matching module 202, configured to match the attack category with a preset protection rule orchestrated by the SOAR technology, and use the preset protection policy corresponding to the attack category in the preset protection rule as the target protection policy;

[0119] An execution module 203, configured to call the security components in the security resource pool according to the target protection policy to complete the automated handling of the attack event

[0120] It should be noted that the various modules included in the above device are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be realized; in addition, the specific names of the functional modules are only for the convenience of mutual distinction and do not limit the protection scope of the embodiments of the present invention.

[0121] In another embodiment of the present invention, an electronic device is further provided. Figure 3A block diagram of an exemplary electronic device 50 suitable for implementing the embodiments of the present invention is shown. Figure 3 The electronic device 50 shown is merely an example and should not impose any limitations on the functions and scope of use of the embodiments of the present invention.

[0122] As Figure 3 shown, the electronic device 50 is presented in the form of a general-purpose computing device. The components of the electronic device 50 may include, but are not limited to: one or more processors or processing units 501, a system memory 502, and a bus 503 connecting different system components (including the system memory 502 and the processing unit 501).

[0123] The bus 503 represents one or more of several types of bus architectures, including a memory bus or a memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any of the multiple bus architectures. By way of example, these architectures include, but are not limited to, Industry Standard Architecture (ISA) bus, Micro Channel Architecture (MAC) bus, Enhanced ISA bus, Video Electronics Standards Association (VESA) local bus, and Peripheral Component Interconnect (PCI) bus.

[0124] The electronic device 50 typically includes a variety of computer system-readable media. These media can be any available media accessible by the electronic device 50, including volatile and non-volatile media, removable and non-removable media.

[0125] The system memory 502 may include computer system-readable media in the form of volatile memory, such as random access memory (RAM) 504 and / or cache memory 505. The electronic device 50 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, a storage system 506 may be used to read and write non-removable, non-volatile magnetic media ( Figure 3 not shown, typically referred to as a "hard disk drive"). Although Figure 3 not shown in the figure, a disk drive for reading and writing removable non-volatile disks (such as "floppy disks") and an optical disk drive for reading and writing removable non-volatile optical disks (such as CD-ROM, DVD-ROM, or other optical media) may be provided. In these cases, each drive may be connected to the bus 503 through one or more data media interfaces. The memory 502 may include at least one program product having a set of (e.g., at least one) program modules configured to perform the functions of the embodiments of the present invention.

[0126] A program / utilities 508 having a set (at least one) of program modules 507 can be stored, for example, in a memory 502. Such program modules 507 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment. The program modules 507 generally execute the functions and / or methods in the embodiments described in the present invention.

[0127] The electronic device 50 can also communicate with one or more external devices 509 (such as a keyboard, a pointing device, a display 510, etc.), and can also communicate with one or more devices that enable a user to interact with the electronic device 50, and / or communicate with any device that enables the electronic device 50 to communicate with one or more other computing devices (such as a network card, a modem, etc.). Such communication can be carried out through an input / output (I / O) interface 511. Moreover, the electronic device 50 can also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through a network adapter 512. As shown in the figure, the network adapter 512 communicates with other modules of the electronic device 50 through a bus 503. It should be understood that although Figure 3 not shown in the figure, other hardware and / or software modules can be used in combination with the electronic device 50, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.

[0128] The processing unit 501 executes various functional applications and data processing by running programs stored in the system memory 502, such as implementing the attack automated handling method provided by the SOAR technology through a security resource pool in the embodiments of the present invention.

[0129] In another embodiment of the present invention, as Figure 4 shown, there is also provided a storage medium 400 containing a computer program 411, and the computer program 411 is used to execute an attack automated handling method implemented by the SOAR technology through a security resource pool when executed by a computer processor. The method includes:

[0130] Identifying an attack event based on a security operation platform and determining the attack category of the attack event;

[0131] Matching the attack category with a preset protection rule choreographed by the SOAR technology, and taking the preset protection strategy corresponding to the attack category in the preset protection rule as the target protection strategy;

[0132] Invoke the security components in the security resource pool according to the target protection policy to complete the automated handling of the attack event.

[0133] The computer storage medium of the embodiments of the present invention may adopt any combination of one or more computer-readable media. The computer-readable media may be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (non-exhaustive list) of the computer-readable storage medium include: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this document, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.

[0134] The computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries the computer-readable program code. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium may also be any computer-readable medium other than the computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0135] The program code contained on the computer-readable medium can be transmitted by any suitable medium, including - but not limited to - wireless, wire, optical cable, RF, etc., or any suitable combination of the above.

[0136] Computer program code for performing the operations of the embodiments of the present invention may be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).

[0137] The above disclosure is only for the preferred embodiments of the present invention, and of course cannot be used to limit the scope of the rights of the present invention. Therefore, equivalent changes made according to the claims of the present invention still fall within the scope covered by the present invention.

Claims

1. A method for automatically handling attacks using SOAR technology through a security resource pool, characterized in that: include: Identify attack events based on the security operation platform and determine the attack category of the attack events; Matching the attack category with the preset protection rules compiled by SOAR technology, and using the preset protection strategy corresponding to the attack category in the preset protection rule as the target protection strategy; The step of matching the attack category with the preset protection rule arranged by the SOAR technology, and taking the preset protection strategy corresponding to the attack category in the preset protection rule as the target protection strategy, further includes: Matching the attack category with the preset protection rules compiled by SOAR technology, if there is no preset protection rule corresponding to the attack category in the preset protection rules; Then obtaining context information of the attack event; Inputting the context information into a second disposal solution prediction model to obtain a first target disposal solution corresponding to the attack event; Generate a preset protection rule corresponding to the attack event according to the first target disposal scheme through SOAR technology, obtain a preset protection rule corresponding to the attack category, and use the preset protection strategy corresponding to the attack category in the preset protection rule as the target protection strategy; The step of matching the attack category with the preset protection rule arranged by the SOAR technology, and taking the preset protection strategy corresponding to the attack category in the preset protection rule as the target protection strategy, further includes: Matching the attack category with the preset protection rules compiled by SOAR technology, if there is no preset protection rule corresponding to the attack category in the preset protection rules; Then obtaining context information of the attack event; Matching the context information with the preset protection data to obtain a second target disposal solution corresponding to the attack event; Generate a preset protection rule corresponding to the attack event according to the second target disposal scheme through SOAR technology, obtain a preset protection rule corresponding to the attack category, and use the preset protection strategy corresponding to the attack category in the preset protection rule as the target protection strategy; The security components in the security resource pool are called according to the target protection strategy to complete the automatic handling of the attack event.

2. The method for automatically handling attacks using the SOAR technology through a security resource pool as claimed in claim 1, characterized in that: The step of identifying the attack event based on the security operation platform and determining the attack category of the attack event includes: Acquiring alarm information of a security resource pool and a system where the security resource pool is located based on the security operation platform, and taking an event corresponding to the alarm information as the attack event; Acquire characteristic data of the attack event, and determine the attack category of the attack event based on the characteristic data.

3. The method for automatically handling attacks using the SOAR technology through a security resource pool as claimed in claim 1, characterized in that: The step of identifying the attack event based on the security operation platform and determining the attack category of the attack event also includes: Invoking the attack event identification model through the security operation platform; Acquire first operation data of a security resource pool and second operation data of a system where the security resource pool is located based on the security operation platform; Substituting the first operation data and the second operation data into the attack event recognition model respectively to obtain a recognition result; When the recognition result indicates that an attack event exists, the attack category of the attack event is determined according to the recognition result.

4. The method for automatically handling attacks using the SOAR technology through a security resource pool as claimed in claim 1, characterized in that: The method further comprises: Determine a treatment plan for the attack category by using a first treatment plan prediction model and the attack category; Matching the treatment plan with the target protection strategy; If the disposal plan is inconsistent with the target protection strategy, a modification suggestion for updating the preset protection rule is generated based on the disposal plan, and the modification suggestion is displayed.

5. The method for automatically handling attacks using the SOAR technology through a security resource pool as claimed in claim 1, characterized in that: The step of calling the security components in the security resource pool according to the target protection strategy to complete the automatic handling of the attack event includes: A control instruction is generated according to the target protection strategy, and the control instruction is sent to the security resource pool, so that the security resource pool responds to the control instruction to call the security component and completes the automatic handling of the attack event.

6. The method for automatically handling attacks using the SOAR technology through a security resource pool as claimed in claim 1, characterized in that: The step of calling the security components in the security resource pool according to the target protection strategy to complete the automatic handling of the attack event also includes: Generate a control instruction according to the target protection strategy, and send the control instruction to the security operation platform; Acquire the occurrence point of the attack event based on the security operation platform, determine the security resource pool corresponding to the occurrence point, and use the security resource pool corresponding to the occurrence point as the target security resource pool; The control instruction is sent to the target security resource pool through the security operation platform, so that the target security resource pool responds to the control instruction to call the security component and completes the automated handling of the attack event.

7. The method for automatically handling attacks using the SOAR technology through a security resource pool as claimed in claim 1, characterized in that: The step of calling the security components in the security resource pool according to the target protection strategy to complete the automatic handling of the attack event also includes: Obtaining protection function parameters of each security component in the security resource pool through the security operation platform, and judging whether the security components in the security resource pool can meet the target protection strategy based on the protection function parameters; When the security components in the security resource pool cannot meet the target protection strategy, the security resource pool is updated based on the target protection strategy, and the automatic handling of the attack event is completed based on the updated security resource pool.

8. The method for automatically handling attacks using the SOAR technology through a security resource pool as claimed in claim 7, characterized in that: The method further comprises: Obtaining process data of the attack event; When the process data indicates that the attack event is over, the updated security resource pool is restored to release the resources occupied by updating the security resource pool.

Citation Information

Patent Citations

  • SOAR-based defense automation process arrangement method

    CN115442133A

  • SOAR-based attack behavior response method, SOAR-based attack behavior response device and SOAR-based processing equipment

    CN116015819A

Cited By

  • Intelligent studying, judging and automatic processing system for network security alarm

    CN122204403A