Network Security Data Tracing Method, Device, Medium and Program Product

Through the cascading parent-child lock mechanism and thread pool concurrent execution, the problem of inefficient traceability of multi-level network security data is solved, and efficient resource utilization and fast signal notification are achieved.

CN119922021BActive Publication Date: 2025-06-27BEIJING THREATBOOK TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510413825.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-03
Publication Date
2025-06-27
Estimated Expiration
2045-04-03

AI Technical Summary

Technical Problem

Existing network security data traceability technologies are difficult to effectively deal with multi-level and cross-platform complex network attacks, resulting in low traceability efficiency and low resource utilization.

Method used

By designing a cascaded parent-child lock mechanism, state transfer and thread control are performed on multi-level traceability tasks, avoiding the waiting problem of the upper thread during the execution of the lower thread, and performing data pull tasks concurrently through the preset thread pool.

Benefits of technology

The efficiency and resource utilization of the overall data traceability process are improved, and the signal notification of the traceability end can be obtained in a timely manner, taking into account the balance between data integrity and traceability efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119922021B_ABST
    Figure CN119922021B_ABST
Patent Text Reader

Abstract

An embodiment of the present application provides a network security data traceability method, device, medium and program product, relating to the technical field of data traceability. The method includes: responding to a traceability request for a target IOC entity; determining a set of traceability edges corresponding to the IOC entity to be traced, and constructing corresponding edge locks based on the set; constructing data pulling tasks for each traceability edge respectively, and executing each data pulling task based on a preset thread pool to obtain an initial data set corresponding to each traceability edge; screening out a list of valid IOC entities that meet preset conditions based on the initial data set corresponding to each traceability edge, constructing corresponding entity locks respectively, and using each valid IOC entity as the IOC entity to be traced in the next round. By designing cascaded parent-child locks to perform status transfer and thread control on multi-level traceability tasks, the embodiment of the present application can avoid the waiting problem of upper-layer threads during the execution of lower-layer threads, thereby effectively improving the efficiency and resource utilization rate of the overall traceability process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of data traceability, and in particular, to a network security data traceability method, device, medium, and program product. Background Art

[0002] Network attack traceability refers to, after a network attack occurs, through a series of technical means and analysis methods, tracking information such as the source of the attack, the identity of the attacker, and the attack path, in order to implement network security management measures such as defense and accountability. With the development of technology, the means of network attacks have become increasingly complex, with more and more covering-up techniques. Attackers use multi-level and cross-platform complex means to hide their tracks, making threat traceability face severe challenges.

[0003] In the field of network security, Indicators of Compromise (IOCs) are key elements for identifying and tracking attack behaviors. The entity types corresponding to these indicators include IP addresses, domain names, file hashes, etc. How to find effective associated IOCs in a large amount of data has become a difficulty in traceability. For example, an IP may have been resolved by multiple domain names in history, each domain name has multiple DNS resolution (Domain Name System Resolution) IPs, each domain name may have multiple sub-domains, and at the same time, a domain name may be associated with multiple certificates, registrant information, and filing information. The same registrant may register multiple domain names, etc.

[0004] Currently, the traceability analysis technology based on IOCs mainly targets entities directly associated with IOCs, and usually lacks cross-level extended data traceability. This is because the data volume at multiple levels is huge and the data is scattered in different systems (DNS records, threat intelligence platforms, etc.), resulting in difficult data integration. And during the cascading traceability process, as the traceability level deepens, the upper-level threads need to wait for all the lower-level query tasks to complete before releasing the thread resources, resulting in low overall traceability efficiency and low resource utilization. Summary of the Invention

[0005] The purpose of the embodiments of this application is to provide a network security data traceability method, device, medium, and program product, which can improve the efficiency and resource utilization of the overall traceability process in the scenario of multi-level data traceability.

[0006] In a first aspect, the embodiments of this application provide a network security data traceability method, including:

[0007] In response to a traceability request for a target IOC entity, use the target IOC entity as the current IOC entity to be traced;

[0008] Create a tracing task for the IOC entity to be traced, determine the set of tracing edges corresponding to the IOC entity to be traced, and construct an edge lock corresponding to the IOC entity to be traced based on the set of tracing edges; wherein, the initial semaphore of the edge lock is equal to the number of edges in the set of tracing edges, and the edge lock is used to control whether to release the tracing task corresponding to the IOC entity to be traced according to its own semaphore;

[0009] Construct data pulling tasks for each tracing edge in the set of tracing edges respectively, and call tracing threads based on a preset thread pool to execute each data pulling task to obtain an initial data set corresponding to each tracing edge;

[0010] Based on the initial data sets corresponding to each tracing edge, filter out a list of valid IOC entities that meet the preset conditions respectively, construct an entity lock corresponding to each list of valid IOC entities respectively, and use the IOC entities in each list of valid IOC entities as the IOC entities to be traced in the next round; wherein, the parent lock of each entity lock is the edge lock constructed in the previous round, the initial semaphore of each entity lock is equal to the number of IOC entities in the corresponding list of valid IOC entities, and when the semaphore of each entity lock decreases to zero, the semaphore of its parent lock is decreased by one respectively.

[0011] In the embodiments of the present application, by designing cascaded parent-child locks for state transfer and thread control of multi-level tracing tasks, the waiting problem of upper-layer threads during the execution of lower-layer threads can be avoided, thereby effectively improving the overall efficiency and resource utilization rate of data tracing.

[0012] In some possible embodiments, the determining the set of tracing edges corresponding to the IOC entity to be traced includes:

[0013] Determine a number of tracing paths corresponding to the IOC entity to be traced based on the entity type of the IOC entity to be traced;

[0014] Respectively use the combination of the IOC entity to be traced and each tracing path as a tracing edge to obtain the set of tracing edges corresponding to the IOC entity to be traced.

[0015] In the embodiments of the present application, by setting different tracing paths according to different IOC entity types, the flexibility and comprehensiveness of data tracing are further improved.

[0016] In some possible embodiments, the network security data tracing method further includes:

[0017] In the case that the waiting duration of the top-level edge lock exceeds a preset duration threshold, a chain release event starting from the top-level edge lock and going from top to bottom is triggered to end the tracing tasks of each level for the target IOC entity.

[0018] In the embodiment of the present application, by setting a timeout threshold for the topmost edge lock and releasing the traceability tasks at all levels in the case of waiting timeout, the balance between data integrity and traceability efficiency can be taken into account, and the flexibility of data traceability is further improved.

[0019] In some possible embodiments, the network security data traceability method further includes:

[0020] Construct a global traced data list corresponding to the target IOC entity, and record the information of the traced tasks that have been completed in real time;

[0021] The step of calling the traceability thread based on a preset thread pool to execute each of the data pulling tasks further includes:

[0022] Judge whether the traced task information corresponding to the current data pulling task is recorded in the global traced data list;

[0023] If so, end the current data pulling task, and decrement the semaphore of the current edge lock by one;

[0024] If not, call the traceability thread based on a preset thread pool to execute the current data pulling task.

[0025] In the embodiment of the present application, by constructing a global traced data list and recording the information of the traced tasks that have been completed in real time, the repeated execution of the same traced task can be avoided, thereby further improving the overall efficiency of data traceability.

[0026] In some possible embodiments, the step of respectively constructing an entity lock corresponding to each of the valid IOC entity lists and using the IOC entities in each of the valid IOC entity lists as the IOC entities to be traced in the next round includes:

[0027] Judge whether the current traceability level reaches a preset level upper limit;

[0028] If so, end the traceability task for the valid IOC entity list, and decrement the semaphore of the parent lock corresponding to the valid IOC entity by one;

[0029] If not, respectively construct an entity lock corresponding to each of the valid IOC entity lists, and use the IOC entities in each of the valid IOC entity lists as the IOC entities to be traced in the next round.

[0030] In the embodiment of the present application, by setting a maximum traceability level to limit the infinite splitting of traceability tasks, the overall efficiency and flexibility of data traceability are further improved.

[0031] In some possible embodiments, constructing a data pulling task for each traceability edge in the traceability edge set includes:

[0032] Determining data pulling rules corresponding to each traceability edge based on the types of the traceability edges in the traceability edge set, and respectively constructing data pulling tasks for each traceability edge according to the corresponding data pulling rules;

[0033] The screening out valid IOC entity lists that meet preset conditions based on the initial data sets corresponding to the respective traceability edges includes:

[0034] Determining entity screening rules corresponding to each traceability edge according to the types of the traceability edges, and respectively screening out valid IOC entity lists that meet preset conditions based on the initial data sets corresponding to the respective traceability edges according to the corresponding entity screening rules.

[0035] In the embodiments of the present application, by configuring different data pulling rules and entity screening rules for different traceability edges, valid IOC entities under different traceability paths can be obtained according to requirements, which is beneficial to further improving the efficiency and flexibility of data traceability.

[0036] In some possible embodiments, the network security data traceability method further includes:

[0037] Recording traceability basic information for all entity data in the initial data sets corresponding to the respective traceability edges; wherein, the traceability basic information includes traceability path information and parent entity information to which each entity data belongs;

[0038] In the case where the waiting duration of the top-level edge lock exceeds a preset duration threshold, or in the case where all traceability tasks are executed and completed, generating a final traceability result corresponding to the traceability request based on the valid IOC entities in all the valid IOC entity lists and their corresponding traceability basic information.

[0039] In the embodiments of the present application, by recording basic information for entity data traced at different levels, a final data traceability result can be generated according to the identified valid IOC entities and their corresponding traceability basic information, thereby further improving the efficiency and flexibility of data traceability.

[0040] In some possible embodiments, the network security data traceability method further includes:

[0041] After creating a traceability task for the IOC entities to be traced in the next round, releasing the traceability thread corresponding to the traceability task at the current level to the thread pool.

[0042] In the embodiments of the present application, by releasing the traceability thread of the previous round in a timely manner after creating the next round of traceability tasks, the resource utilization rate of the data traceability process is further improved.

[0043] In some possible embodiments, the entity type of the IOC entity to be traced includes at least one of IP address, domain name, sample hash, email, digital certificate, sub-domain name, filing information, and registrant.

[0044] In the embodiments of the present application, by providing multiple types of traceability IOC entities, the richness of the traceability path can be effectively improved, thereby further enhancing the comprehensiveness of data traceability.

[0045] In a second aspect, embodiments of the present application provide a network security data traceability device, including:

[0046] A request response module, configured to respond to a traceability request for a target IOC entity and use the target IOC entity as the current IOC entity to be traced;

[0047] An edge lock construction module, configured to create a traceability task for the IOC entity to be traced, determine a set of traceability edges corresponding to the IOC entity to be traced, and construct an edge lock corresponding to the IOC entity to be traced based on the set of traceability edges; wherein, the initial semaphore of the edge lock is equal to the number of edges in the set of traceability edges, and the edge lock is used to control whether to release the traceability task corresponding to the IOC entity to be traced according to its own semaphore;

[0048] A data pulling module, configured to respectively construct data pulling tasks for each traceability edge in the set of traceability edges, and call traceability threads based on a preset thread pool to execute each data pulling task to obtain an initial data set corresponding to each traceability edge;

[0049] An entity screening module, configured to respectively screen out a list of valid IOC entities that meet preset conditions based on the initial data sets corresponding to each traceability edge, respectively construct an entity lock corresponding to each list of valid IOC entities, and use the IOC entities in each list of valid IOC entities as the IOC entities to be traced in the next round; wherein, the parent lock of each entity lock is the edge lock constructed in the previous round, the initial semaphore of each entity lock is equal to the number of IOC entities in the corresponding list of valid IOC entities, and when the semaphore of each entity lock decreases to zero, the semaphore of its parent lock is decreased by one.

[0050] In a third aspect, embodiments of the present application provide an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein when the processor executes the program, the method described in any embodiment of the first aspect can be implemented.

[0051] Fourthly, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is run by a processor, the method described in any embodiment of the first aspect can be implemented.

[0052] Fifthly, an embodiment of the present application provides a computer program product, which includes a computer program, and when the computer program is executed by a processor, the method described in any embodiment of the first aspect can be implemented. Description of the Drawings

[0053] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required to be used in the embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.

[0054] Figure 1 It is a schematic flowchart of a network security data traceability method provided by an embodiment of the present application;

[0055] Figure 2 It is an overall flowchart of a network security data traceability method provided by an embodiment of the present application;

[0056] Figure 3 It is a schematic architecture diagram of a parent-child lock mechanism provided by an embodiment of the present application;

[0057] Figure 4 It is a schematic structural diagram of a network security data traceability device provided by an embodiment of the present application;

[0058] Figure 5 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application. Detailed Embodiments

[0059] Next, the technical solutions in the embodiments of the present application will be described with reference to the drawings in the embodiments of the present application.

[0060] It should be noted that similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present application, terms such as "first" and "second" are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.

[0061] It should be noted that, at present, in the process of cross-level traceability query, a serial layer-by-layer analysis process is adopted (first check the IP-associated domain name, then check the domain name-associated certificate, and so on). The data expanded at each layer increases exponentially, and the query time of each layer also increases exponentially. In this real-time traceability scenario, the same-level query mostly adopts thread pool concurrent query technology. In order to obtain the signal that the query is completed, the upper-level traceability query thread needs to wait for the completion of the lower-level traceability task before releasing the thread resources. During this process, the upper-level thread is always in a waiting state. As the traceability level deepens, the number of threads in a waiting state will increase, resulting in a large amount of resource waste.

[0062] In view of the problems existing in the above-mentioned prior art, an embodiment of the present application provides a network security data tracing method, which integrates IOC-related resources allocated in different systems by designing an engineering architecture solution for cascade tracing, and retains the tracing path in the tracing process; in addition, the cascaded parent-child lock is redesigned through CountDownLatch (lock, a synchronization tool class in Java concurrent programming, mainly used to coordinate synchronization between multiple threads) based on the Java language, and the signal transmission of the parent-child lock is used to avoid the waiting problem of the upper-level thread during the query process of the lower-level thread, thereby improving resource utilization, and at the same time, the signal notification of the end of tracing can be obtained in time.

[0063] like Figure 1 As shown, the embodiment of the present application provides a network security data tracing method, which may include the steps of:

[0064] S1. In response to a traceability request for a target IOC entity, the target IOC entity is used as the current IOC entity to be traced.

[0065] Specifically, when a suspicious IOC entity is discovered and a traceability query is required for further analysis, the network security detection system can initiate a traceability request based on the currently identified suspicious IOC entity (target IOC entity). The present application scheme can serve as a deep traceability system associated with the network security detection system, responding to the traceability request for the target IOC entity and returning the final data traceability result to the network security detection system, so that the network security detection system can conduct further attack traceability analysis based on the data traceability result.

[0066] Exemplarily, step S1 starts the tracing task corresponding to the tracing request based on the target IOC entity as the current IOC entity to be traced. The IOC entity can be a specific entity information such as an IP address, domain name, etc., and the IOC entity is used as the starting point to efficiently mine its associated cross-level entities (IP, domain name, sample hash, email, digital certificate, subdomain, filing information, registrant, etc.) through concurrent technology.

[0067] S2. Create a tracing task for the IOC entity to be traced, determine the set of tracing edges corresponding to the IOC entity to be traced, and construct an edge lock corresponding to the IOC entity to be traced based on the set of tracing edges. Among them, the initial semaphore of the edge lock is equal to the number of edges in the set of tracing edges, and the edge lock is used to control whether to release the tracing task corresponding to the IOC entity to be traced according to its own semaphore.

[0068] Specifically, first create a tracing task for the current IOC entity to be traced. According to the preset rules, the set of tracing edges corresponding to the current IOC entity to be traced can be determined. Each tracing edge in the set of tracing edges represents a tracing path. Exemplarily, for an IOC entity to be traced that is an IP address, its corresponding tracing edges may include: IP -> domain name, IP -> certificate, etc.

[0069] At the same time, construct an edge lock corresponding to the IOC entity to be traced, that is, an edge lock used to control whether to release the tracing task corresponding to the current IOC entity to be traced. Among them, the initial semaphore of this edge lock is equal to the number of tracing edges in the set of tracing edges. When the data pulling task of a tracing edge is completed, the semaphore of this edge lock is decremented by one, and so on until the semaphore of this edge lock is decremented to zero. When the semaphore of the edge lock is decremented to zero, the tracing task corresponding to the IOC entity to be traced is released. If this edge lock is the top-level edge lock, when the semaphore of this edge lock is decremented to zero, it indicates that all tracing tasks of the target IOC entity have been completed, and the final data tracing result is returned.

[0070] S3. Construct data pulling tasks for each tracing edge in the set of tracing edges respectively, and call tracing threads based on a preset thread pool to execute each data pulling task to obtain the initial data set corresponding to each tracing edge.

[0071] Specifically, for the set of tracing edges corresponding to the IOC entity to be traced, construct data pulling tasks for each tracing edge in it (one tracing edge corresponds to one data pulling task). Then, submit the constructed data pulling tasks to the waiting queue, and the preset thread pool calls the tracing threads to execute the data pulling tasks in the queue concurrently. When a certain data pulling task is completed, its corresponding tracing thread is recycled to the thread pool and called to process other data pulling tasks waiting in the queue. Every time a data pulling task is completed, the semaphore of the edge lock corresponding to the set of tracing edges is decremented by one until all the data pulling tasks of all the tracing edges corresponding to the set of tracing edges are completed.

[0072] It should be noted that different data pulling tasks may need to build requests through the adaptation layer to pull the data of the corresponding traceability edge from different systems (DNS records, threat intelligence platforms, etc.), and the data pulled by different data pulling tasks may have inconsistent formats. Therefore, the data adaptation layer can be used to normalize the data pulled by each system into a unified data structure. At this point, when each data pulling task is completed, the initial data set corresponding to the corresponding traceability edge will be obtained. The data in the initial data set can retain the detailed information of the current traceability edge and its parent traceability entity.

[0073] S4. Based on the initial data set corresponding to each traceability edge, the valid IOC entity lists that meet the preset conditions are screened out respectively, and the entity locks corresponding to each valid IOC entity list are constructed respectively, and the IOC entities in each valid IOC entity list are used as the IOC entities to be traced in the next round; wherein, the parent lock of each entity lock is the edge lock constructed in the previous round, and the initial semaphore of each entity lock is equal to the number of IOC entities in the corresponding valid IOC entity list. When the semaphore of each entity lock decreases to zero, the semaphore of its parent lock is reduced by one.

[0074] Specifically, the same initial data set contains different entity data under the same traceability edge. For example, for the data pulling task of the "IP->domain name" traceability edge, its initial data set contains different domain name entity data. For each initial data set, data can be filtered according to preset conditions to obtain a valid IOC entity list (a collection of valid IOC entities). Exemplarily, for the initial data set of the "IP->domain name" traceability edge, IOC entities that do not need to be processed can be filtered by setting preset conditions such as a whitelist, thereby filtering out a valid IOC entity list.

[0075] Then, an entity lock is constructed for each valid IOC entity list respectively. For each valid IOC entity list, each IOC entity therein is used as the IOC entity to be traced in the next round. The tracing process for these IOC entities to be traced is the same as the process of steps S2 to S4, and so on.

[0076] Specifically, the initial semaphore of the entity lock is equal to the number of valid IOC entities in the valid IOC entity list, and each valid IOC entity will serve as the IOC entity to be traced in the next round, that is, the valid IOC entity will build the edge lock of the next level based on its traceability edge set. When the edge lock semaphore is reduced to zero, the current entity lock semaphore is reduced by one until the current entity lock semaphore is reduced to zero. At this time, it means that all IOC entities in the current valid IOC entity list have completed the next round of data pulling tasks, and the semaphore of its parent lock (the parent lock of the entity lock is the edge lock of the previous level) is reduced by one, and so on.

[0077] In the embodiments of the present application, by designing cascaded parent-child locks for state transfer and thread control of multi-level traceability tasks, starting from an IOC entity as an entry point, multi-level traceability is performed through concurrent cascaded scheduling, and finally valid IOCs are output and the traceability paths of each level are retained, which can avoid the waiting problem of upper-level threads during the execution of lower-level threads, thereby effectively improving the overall efficiency and resource utilization rate of data traceability.

[0078] In some possible embodiments, in step S2, determining the set of traceability edges corresponding to the IOC entity to be traced may include:

[0079] S201. Determine a number of traceability paths corresponding to the IOC entity to be traced based on the entity type of the IOC entity to be traced;

[0080] S202. Respectively use the combination of the IOC entity to be traced and each traceability path as a traceability edge to obtain the set of traceability edges corresponding to the IOC entity to be traced.

[0081] It should be noted that different sets of traceability paths can be set for different entity types, so that a corresponding number of traceability paths can be determined according to the entity type of the current IOC entity to be traced. Then, the current IOC entity to be traced is respectively combined with these traceability paths as a traceability edge to obtain the set of traceability edges corresponding to the IOC entity to be traced.

[0082] Exemplarily, the IOC entity to be traced that needs to be processed currently is a certain IP address. For the entity type of IP address, its preset traceability paths include domain name and certificate. Then, the set of traceability edges corresponding to the IOC entity to be traced is {IP -> domain name, IP -> certificate}.

[0083] Based on this, by setting different traceability paths according to different IOC entity types, selective traceability of massive data can be performed according to requirements, thereby further improving the flexibility and comprehensiveness of data traceability.

[0084] In some possible embodiments, the network security data traceability method may further include:

[0085] In the case where the waiting duration of the top-level edge lock exceeds the preset duration threshold, a chain release event starting from the top-level edge lock and going from top to bottom is triggered to end the traceability tasks of each level for the target IOC entity.

[0086] It should be noted that in addition to waiting for all traceability tasks to be executed to obtain the final data traceability result, an external traceability request can also be controlled for timeout by setting a maximum waiting time limit.

[0087] Specifically, when starting to time the creation of the traceability task for the target IOC entity, that is, starting to time when creating the top-level edge lock, when the cumulative waiting duration of the top-level edge lock exceeds the pre-set duration threshold, the traceability tasks at all levels are immediately ended, and at the same time, starting from the top-level edge lock, the chain release is triggered to the sub-locks at the lower levels in sequence, so as to recycle all the traceability threads that are executing tasks.

[0088] It can be understood that before the event of timeout recovery is triggered, a certain number of data traceability tasks have been completed at all levels. At this time, the traceability results can be generated based on the entity data that has completed traceability and its corresponding traceability basic information (such as the paths and entity details at all levels), and used as the results to feedback to the external traceability request.

[0089] Based on this, by setting the timeout threshold at the top-level edge lock and releasing the traceability tasks at all levels in the case of waiting timeout, in this way, when the traceability level is relatively deep or the data is massive, the traceability results can be generated based on appropriate traceability data without waiting for all the traceability tasks to be completed, so as to be able to balance between data integrity and traceability efficiency, and further improve the flexibility of data traceability.

[0090] In some possible embodiments, the network security data traceability method may further include:

[0091] Construct a global list of traced data corresponding to the target IOC entity, and record the information of the traced tasks that have been executed in real time;

[0092] In step S3, when calling the traceability thread based on the preset thread pool to execute each data pulling task, it may further include:

[0093] Judge whether the traceability task information corresponding to the current data pulling task is recorded in the global list of traced data;

[0094] If so, end the current data pulling task, and decrement the semaphore of the current edge lock by one;

[0095] If not, call the traceability thread based on the preset thread pool to execute the current data pulling task.

[0096] It should be noted that during the traceability process, the situation where the same traceability edge or different traceability edges generate the same valid IOC entity may occur at the same level or different levels (for example, the resolved IP of a domain name is the same as a certain IP associated with a certificate).

[0097] In order to avoid loop tracing or repeated tracing, you can keep a global list of traced entities (you can use IOC entity + traceability edge as the unique query primary key). Before the traceability tasks at each level pull specific data, first determine whether the corresponding traceability task information (current IOC entity + traceability edge) already exists in the global list (global traced data list).

[0098] If it exists, it means that the same valid IOC entity has been expanded in the traceability tasks of other levels or other traceability edges at the same level, and the corresponding traceability tasks have been created. In this case, there is no need to continue the current task. The current traceability task (data pulling task) can be ended and the edge lock semaphore is notified to decrease by one (one data pulling task corresponds to one semaphore of the edge lock).

[0099] On the contrary, if there is no tracing task information corresponding to the current data pulling task in the global list (global traced data list), the thread is called to process the data pulling task according to the normal process.

[0100] Based on this, by building a global traceable data list to record the information of completed traceability tasks in real time, and judging whether to end the traceability task based on the traced situation before executing the data pulling task, unnecessary task duplication can be avoided, thereby further improving the overall efficiency of data traceability.

[0101] In some possible embodiments, in step S4, constructing entity locks corresponding to each valid IOC entity list respectively, and using the IOC entities in each valid IOC entity list as the IOC entities to be traced in the next round, may include:

[0102] Determine whether the current traceability level has reached the preset level upper limit;

[0103] If yes, the traceability task for the valid IOC entity list is terminated, and the parent lock semaphore corresponding to the valid IOC entity is reduced by one;

[0104] If not, construct entity locks corresponding to each valid IOC entity list respectively, and use the IOC entities in each valid IOC entity list as the IOC entities to be traced in the next round.

[0105] It should be noted that the number of traceability tasks will increase exponentially with the increase of traceability levels, and since the types of entities are limited, the types of traceability edges (tracing paths) are also limited. Therefore, when the number of data traceability levels exceeds a certain number, the probability of repeated traceability tasks (the same traceability path for the same entity) will increase greatly. Therefore, a suitable maximum traceability level can be set according to needs to control the overall traceability level depth.

[0106] Based on a pre-set hierarchy limit, before filtering out the valid IOC entity list and constructing the corresponding entity locks each time, first determine whether the current tracing hierarchy has reached the limit. If so, the tracing task will not be extended further, and it is considered that the tracing task at the current level has been completed, and the semaphore of the parent lock is decremented by one. Otherwise, create the entity locks corresponding to each valid IOC entity list normally, and continue to create the next round of data pulling tasks, and so on until the tracing hierarchy reaches the pre-set hierarchy limit.

[0107] Based on this, by setting the maximum tracing hierarchy to limit the infinite splitting of the tracing task, the overall tracing task is executed within a suitable hierarchy range, thereby further improving the efficiency and flexibility of the overall data tracing.

[0108] In some possible embodiments, in step S3, constructing data pulling tasks for each tracing edge in the tracing edge set may include:

[0109] Determine the data pulling rules corresponding to each tracing edge based on the types of the tracing edges in the tracing edge set, and construct the data pulling tasks for each tracing edge according to the corresponding data pulling rules respectively;

[0110] In step S4, filtering out the valid IOC entity lists that meet the preset conditions based on the initial data sets corresponding to the tracing edges respectively may include:

[0111] Determine the entity filtering rules corresponding to each tracing edge according to the types of the tracing edges, and filter out the valid IOC entity lists that meet the preset conditions based on the initial data sets corresponding to the tracing edges respectively according to the corresponding entity filtering rules.

[0112] It should be noted that different data pulling rules can be configured for different tracing edges. For example, for the tracing edge of IP -> domain name, it can be set to pull the domain name data resolved within a preset historical period (such as within the past 30 days).

[0113] In addition, for the initial data sets pulled for each tracing edge, different entity filtering rules can be configured for different tracing edges. For example, for the tracing edge of IP -> domain name, corresponding domain name whitelists and blacklists can be configured. Among them, the domain names in the whitelist are filtering rules, and the domain names in the whitelist are not included in the valid IOC entity list, and the blacklist is a screening rule, and the domain names in the blacklist are included in the valid IOC entity list; or it can be configured to filter and retain static type domain names and filter out dynamic type domain names.

[0114] Based on this, by configuring different data pulling rules and entity filtering rules for different tracing edges, the valid IOC entities under different tracing paths can be obtained according to requirements, which is beneficial to further improving the efficiency and flexibility of data tracing.

[0115] In some possible embodiments, the network security data traceability method further includes:

[0116] Recording traceability basic information for all entity data in the initial dataset corresponding to each traceability edge; wherein, the traceability basic information includes the traceability path information to which each entity data belongs and the parent entity information.

[0117] In the case where the waiting duration of the top-level edge lock exceeds a preset duration threshold, or in the case where all traceability tasks are executed and completed, based on the valid IOC entities in all valid IOC entity lists and their corresponding traceability basic information, a final traceability result corresponding to the traceability request is generated.

[0118] It should be noted that when the corresponding data is pulled by each traceability edge through a data pull task, relevant traceability basic information can be saved for these data, and the traceability basic information includes the traceability path information to which the entity itself belongs and the parent entity information. Exemplarily, for the domain name data pulled by the traceability edge of IP -> domain name, the corresponding traceability path information (IP -> domain name) and the detailed information of its parent entity (specific IP address) are saved for each domain name data.

[0119] When all traceability tasks are executed and completed or reach the timeout, based on the recorded traceability basic information, starting from the last node of the traceability chain, reverse lookup can be performed according to the parent traceability entity and the traceability edge, and the complete traceability link of the corresponding entity can be found, and finally the traceability results corresponding to all valid IOC entities are generated.

[0120] Based on this, by recording basic information for entity data obtained through traceability at different levels, the final data traceability result can be generated according to the identified valid IOC entities and their corresponding traceability basic information, thereby further improving the efficiency and flexibility of data traceability.

[0121] In some possible embodiments, the network security data traceability method may further include:

[0122] After creating a traceability task for the next round of IOC entities to be traced, release the traceability thread corresponding to the current level of traceability task to the thread pool.

[0123] It should be noted that after the parent traceability task is completed, only the traceability tasks of the next level need to be constructed and submitted to the thread pool, and the thread of the current task can end and return to the thread pool, thus avoiding waste of thread resources to the greatest extent. At the same time, the status of each traceability task can be obtained in a timely manner through the semaphore of the edge lock / entity lock.

[0124] In the embodiments of the present application, by releasing the traceability thread of the previous round in a timely manner after creating the next round of traceability tasks, the resource utilization rate of the data traceability process is further improved.

[0125] In some possible embodiments, the entity types of the IOC entities to be traced include at least one of IP address, domain name, sample hash, email, digital certificate, sub-domain name, filing information, and registrant.

[0126] It should be noted that the entity types of the IOC entities (including the IOC entities to be traced and valid IOC entities, etc.) in the embodiments of the present application can all include one or more of IP address, domain name, sample hash, email, digital certificate, sub-domain name, filing information, and registrant. According to the entity types of different entities, different traceability paths, data pulling rules, and entity screening rules can be configured respectively, so as to further improve the flexibility and comprehensiveness of data traceability.

[0127] Please refer to Figure 2 , and the main step processes of the embodiments of the present application are described as follows:

[0128] 1. Starting from an IOC entity (target IOC entity), enter the entity adaptation layer, and determine the traceability edge set of the current entity according to the entity type (IP address, domain name, certificate, etc.) of the IOC entity and the traceability path (for example, if the type is IP, the traceability edges may include IP -> domain name, IP -> certificate, etc.).

[0129] 2. Construct an edge lock according to the traceability edge set. If there are N edges in the traceability edge set, the edge lock semaphore is N, that is, the edge lock can be unlocked and released only when all N edges are completed. The parent lock of the top-level edge lock is a null value, and the business thread of the external request waits on the edge lock to obtain the completion status of the overall traceability task.

[0130] 3. Each edge constructs a request through the data pulling adaptation layer and concurrently sends it to each system to pull the data corresponding to the traceability edge. Each edge can set its own data pulling rules; after the data pulling tasks of each edge are constructed, they are submitted to the queue to be processed, and the data pulling is performed concurrently through the thread pool; the outer calling side can control the request timeout through the edge lock of the first layer or wait for all hierarchical traceability tasks to be completed to obtain the final traceability result. The traceability level at this time is 1.

[0131] 4. The data pulled from each system is normalized into a unified data structure through the data adaptation layer. The data sets pulled for each traceability edge may be different. The normalized data can retain information such as the current traceability relationship edge and the details of the parent-level traceability entity, etc., as the data basis for generating the final traceability result.

[0132] 5. The initial data set retrieved for each traceability edge is filtered through the data filtering layer. Different entity screening rules can be set for each traceability edge to screen out the entities that meet the conditions and enter the valid IOC entity list. Based on the parent entity and edge relationship retained in the entity, the traceability path and the details of the entities on each level of the path can be found by reverse cycling. It should be noted that the top-level IOC entity traced back from any traced entity is the target IOC entity that initially entered the traceability process. The traceability path of any IOC entity can be found through reverse cycling search.

[0133] 6. The data retrieved for each traceability edge enters the traceability filtering layer to determine whether there are IOC entities that meet the conditions for entering the next round of traceability (i.e., the valid IOC entity list). If none of them meet the conditions, the traceability task for this edge ends, and the parent lock semaphore is decremented by one. When the parent lock semaphore is reduced to 0, the parent lock is released. If the parent lock has a parent lock, when the parent lock semaphore is reduced to 0, the semaphore of the parent lock of the parent lock is decremented by one.

[0134] 7. If there are IOC entities that meet the conditions for the next round of traceability, an entity lock is constructed for the valid IOC entity list corresponding to the current edge that enters the next round of traceability. The semaphore is the number of valid IOC entities in each valid IOC entity list, and the parent lock is the edge lock constructed in the previous round. Then, a traceability task is constructed for each valid IOC entity separately and submitted to the thread pool. At this time, the level of the task is the parent level + 1, and the details of the entities and the upper-level traceability edge of the upper-level traceability are retained in each traceability task. After the task is submitted, the traceability thread of the current task returns to the thread pool and can be used by other traceability tasks.

[0135] 8. For the traceability tasks of each valid IOC entity in step 7, it will go back to step 1 to obtain the set of traceability edges, and then construct an edge lock based on the set of traceability edges. The parent lock of this layer of edge lock is the entity lock constructed in step 7, and so on.

[0136] 9. If the maximum level of traceability is set in the business thread, when the traceability level gradually increases and reaches the maximum level, the traceability task will no longer expand, and a cascade notification will be sent to the parent lock that the current task has ended.

[0137] It can be understood that during the entire process of gradually delving deeper layer by layer, without the existence of the parent-child lock mechanism, in order to obtain the completion status of the overall task at the top layer, the thread at the top layer must wait. For example, if the IOC entity at the Nth layer needs to expand three edges, the thread needs to wait for the completion of three traceability tasks. Each traceability task may expand m IOC entities, and these IOC entities will enter the next-level traceability task, that is, the traceability task at the N+1th layer. Then the edge traceability thread at the Nth layer needs to wait for the completion of all traceability tasks at the N+1th layer, and so on. As a result, a large amount of thread resources will be wasted during the overall traceability process.

[0138] In the embodiment of the present application, through the cascaded parent-child lock mechanism of "edge lock -> entity lock -> edge lock", only the business thread at the top layer needs to wait on the edge lock at the top layer to obtain the completion of the overall traceability task or reach the timeout. Except for this, there will be no situation where any parent thread needs to wait for the completion of the child thread task to obtain the completion signal. After the completion of the parent-level traceability task, only the traceability task of the next level needs to be constructed and then submitted to the thread pool. The traceability thread of the current traceability task can end and return to the thread pool, thus avoiding the waste of thread resources to the greatest extent. At the same time, based on the cascaded parent-child lock mechanism, the traceability thread at the top layer can timely obtain the status of tasks at each level. When the traceability task at the deep level ends, the semaphore of the parent lock is decremented by one. When the semaphore of the parent lock is 0, the parent lock is released. At the same time, if the parent lock still has a parent lock, the semaphore of the parent lock's parent lock is decremented by one, and so on, until the edge lock at the top layer is released. In addition, because the parent lock retains a reference to the child lock, when the overall task times out, the child lock can be notified hierarchically from top to bottom to release the current task.

[0139] The following lists specific examples to elaborate in detail on the solution of the embodiment of the present application:

[0140] Step A1: The target IOC entity (the current IOC entity to be traced) enters the entity adaptation layer, and obtains the traceability edge set according to the type and context of the target IOC entity.

[0141] In this step, the traceability edges of the IOC entity are obtained through the entity type. For example, if the entity type is IP, the traceability edges may include traceability edges such as the above IP -> domain name, IP -> certificate, etc. In the following steps, it is assumed that starting from the IP entity vertex1, m traceability edges are obtained.

[0142] Step A2: Build the traceability task (data pulling task) for each edge in a loop according to the traceability edge set, and build a traceability edge lock latch1 according to the number of traceability edges; query whether there is a unique primary key composed of the current entity and the traceability edge in the global traceability entity set. If it already exists, it means that the current entity and the current edge have entered or completed the traceability, so the current edge task ends. If not, add it to the global traceability entity set and submit the traceability task of this traceability edge to the traceability thread pool.

[0143] Step A3: Normalize the data pulled corresponding to the traceability edges, filter out valid IOC entities and filter out the traceability entities for the next round (either directly use all valid IOC entities as the entities to be traced in the next round, or further filter out the entities to be traced in the next round from the valid IOC entities).

[0144] This step includes three sub-steps:

[0145] Step A31: Normalize the pulled data. The normalized data includes extended entities, entity types, and specific data for subsequent filtering of valid ioc entities and building the traceability task for the next round.

[0146] Step A32: According to the initial data set pulled for each traceability edge, filter out valid IOC entities. Different entity filtering rules can be customized for each traceability edge. For example, for the domain name resolution IP edge, it can be filtered according to the resolution time, IP intelligence, etc. If valid IOC entities are filtered out, they will enter the valid ioc entity list corresponding to this traceability edge.

[0147] Step A33: Build the traceability entity set for the next round according to the list of valid IOC entities traced. Each entity can include information such as entities, entity types, data details, and parent traceability entities. During the process of filtering the traceability entity set for the next round, different entity filtering conditions can be customized for each edge and each type of entity. For example, it doesn't make much sense to continue tracing dynamic domain names, so they don't enter the next round.

[0148] It should be noted that according to the field definition of the traceability entity, starting from the last node of the traceability chain, the complete traceability link of this entity can be found by reverse searching according to the parent traceability entity and the traceability edge. The top-level entities of the traceability chain are all entity vertex1.

[0149] Step A4: Determine the set of traced entities (valid IOC entity list) that enter the next round filtered for each edge. If the set is empty, it indicates that the tracing task for this edge is completed, notify the edge lock Latch1, and decrement the semaphore of Latch1 by one. If the set is not empty, construct an entity lock Latch2 for this edge. The semaphore of the entity lock is the number of valid IOC entities in the traced edge's corresponding set. The parent lock of the entity lock Latch2 is the edge lock Latch1, and at the same time, add Latch2 to the set of child locks of Latch1.

[0150] Step A5: Construct tracing tasks (data pulling tasks) for each entity in the current valid IOC entity list respectively. Increment the level of the tracing task by 1 and submit them to the tracing thread pool. Each task then repeats and enters Step A1 for the next round of tracing.

[0151] It should be noted that the overall tracing process is a process of exponential task inflation. Starting from the initial few edge tasks, as the tracing level deepens, the number of expanded entities increases, and the number of tasks expands rapidly. If the common way of using the thread pool is adopted, the upper-layer tasks need to wait for all the lower-layer tasks to complete before obtaining the task status, which will result in the problem of chained thread waiting. For example, the task execution thread for the edge IP -> domain name is thread1. Thread1 expands N domain names, and these N domain names enter the next round of tracing process. Thread1 needs to wait for the tracing of these N domain names to complete before ending the task and returning it to the thread pool. Assuming that each of the N domain names has three traced edges, 3N threads are required to execute the tracing tasks. These 3N threads need to wait for all the sub-tasks of the next round to complete, and so on. This will cause a large number of threads not to be immediately recycled to the thread pool to execute new tasks after completing their own tracing tasks, but to be in a waiting state. The embodiment of the present application effectively solves the problem of resource waste caused by thread waiting through the mechanism of cascading parent-child locks.

[0152] Please refer to Figure 3 , and the lock mechanism of the embodiment of the present application is briefly described as follows:

[0153] 1. If the ioc entity entering the tracing process passes through the entity adaptation layer to obtain m traced edges, the semaphore of the edge lock is m, that is, after m sub-tasks are completed and this edge lock is notified, this edge lock will be released.

[0154] 2. Construct m tracing sub-tasks and submit them to the tracing thread pool. The top-level tracing service thread (external service request) waits on the edge lock.

[0155] 3. Taking one of the traced edges as an example, N valid ioc entities are expanded from the traced edge and enter the next round of tracing. Construct an entity lock. The semaphore of the entity lock is the number N of valid ioc entities, and associate the parent-child relationship between the edge lock and the entity lock;

[0156] 4. Build the traceability tasks for each valid IOC entity, jump to step 1 to obtain the edge locks corresponding to each valid IOC entity, and build the parent-child relationship between the entity locks in step 3 and the edge locks in this round, finally forming a cascaded parent-child chain of edge lock -> entity lock -> edge lock.

[0157] 5. When the deepest task is completed, notify the parent lock and decrement the parent lock semaphore by one; when the semaphore of itself is 0, release the lock and at the same time notify the held parent lock to decrement the semaphore by one, and so on until the topmost edge lock is released.

[0158] The following lists specific examples to elaborate on the lock mechanism of the embodiments of the present application in detail:

[0159] Step L1. The IOC entity to be traced enters the tracing process. Suppose there are three tracing edges, then create an edge lock latch1 with a semaphore of 3 for the edge lock. The tracing service thread can wait on the edge lock Latch1 to obtain the tracing status in a timely manner.

[0160] Step L2. Build the tracing tasks for each tracing edge and make concurrent requests to pull data. The threads used are T1, T2, and T3 respectively; if N1, N2, and N3 valid IOC entities enter the next round respectively, then build entity locks Latch11, Latch12, and Latch13 in threads T1, T2, and T3 respectively, with semaphores of N1, N2, and N3 respectively. The parent locks of the three entity locks are all the edge lock Latch1. At the same time, add the three entity locks Latch11, Latch12, and Latch13 to the child lock set of Latch1.

[0161] Step L3. Build N1, N2, and N3 entity tracing tasks concurrently in threads T1, T2, and T3 respectively and submit them to the thread pool.

[0162] It should be noted that after step L3 is completed (after submitting the entity tracing tasks), threads T1, T2, and T3 can be returned to the thread pool without waiting for the completion of the next round of subtasks.

[0163] Step L4. After the N1 entity tracing tasks built in thread T1 enter the next round of tracing, each entity tracing task will build edge locks, namely latch111, Latch112... Latch11n. The parent locks of these n edge locks are all Latch11.

[0164] It should be noted that the subsequent deeper-level traceability locks cycle the above steps, based on which a multi-tree lock chain can be constructed. When the deepest-level traceability task is completed, the corresponding lock semaphore will be notified to decrease by 1. For example, each time a traceability task corresponding to Latch111 is completed, the semaphore of Latch111 will be notified to decrease by one. When the semaphore of Latch111 is 0, Latch111 is released, and the semaphore of Latch111's parent lock Latch11 is notified to decrease by one. When latch112 to Latch11n complete the traceability task and notify the parent lock Latch11 to decrease by one, the semaphore of the parent lock Latch11 is 0, and the Latch11 lock is released, so the semaphore of Latch11's parent lock Latch1 is notified to decrease by 1, until the traceability tasks corresponding to Latch12 and Latch13 complete the lock release, and notify Latch1 to decrease by one respectively, until the semaphore of Latch1 is zero, then Latch1 is finally released, and the external business thread obtains the most total traceability status and results.

[0165] It should also be noted that when the traceability level is deep and the top edge lock wait times out, it triggers the release notification of the lock chain from top to bottom, that is, Latch1 notifies Latch11, Latch12, and Latch13 to release, Latch11 notifies Latch111, Latch112...Latch11n to release, and so on. In the process logic, before submitting a task, it will determine whether the lock corresponding to the current task has been released. If it has been released, the task will not be submitted again.

[0166] It should be noted that the embodiment of the present application, by constructing a set of concurrent cascade traceability methods, can obtain corresponding related data from different systems starting from one entity, complete a multi-level automated traceability process, and greatly improve the traceability efficiency; at the same time, through the cascading parent-child lock mechanism, the resource utilization of the overall traceability process is greatly improved, and it can facilitate threads at all levels to obtain the status of traceability tasks in a timely manner.

[0167] Please refer to Figure 4 , Figure 4 The following is a block diagram showing the composition of the network security data tracing device provided by some embodiments of the present application. Figure 1 Corresponding to the method embodiment, it is able to execute each step involved in the above method embodiment. The specific functions of the network security data tracing device can be found in the description above. To avoid repetition, the detailed description is appropriately omitted here.

[0168] Figure 4 The network security data tracing device includes at least one software function module that can be stored in a memory in the form of software or firmware or fixed in the network security data tracing device, and the network security data tracing device includes:

[0169] A request response module 410, configured to, in response to a traceability request for a target IOC entity, use the target IOC entity as the current IOC entity to be traced;

[0170] An edge lock construction module 420, configured to create a traceability task for the IOC entity to be traced, determine a set of traceability edges corresponding to the IOC entity to be traced, and construct an edge lock corresponding to the IOC entity to be traced based on the set of traceability edges; wherein, an initial semaphore of the edge lock is equal to the number of edges in the set of traceability edges, and the edge lock is used to control whether to release the traceability task corresponding to the IOC entity to be traced according to its own semaphore;

[0171] A data pulling module 430, configured to respectively construct data pulling tasks for each traceability edge in the set of traceability edges, and call traceability threads based on a preset thread pool to execute each data pulling task, so as to obtain an initial data set corresponding to each traceability edge;

[0172] An entity screening module 440, configured to respectively screen out a list of valid IOC entities that meet preset conditions based on the initial data sets corresponding to the respective traceability edges, respectively construct an entity lock corresponding to each list of valid IOC entities, and use the IOC entities in each list of valid IOC entities as the IOC entities to be traced in the next round; wherein, a parent lock of each entity lock is the edge lock constructed in the previous round, an initial semaphore of each entity lock is equal to the number of IOC entities in the corresponding list of valid IOC entities, and when the semaphore of each entity lock decreases to zero, the semaphore of its parent lock is decreased by one respectively.

[0173] It can be understood that the above device item embodiments correspond to the method item embodiments of the present invention. A network security data traceability device provided by the embodiments of the present invention can implement the network security data traceability method provided by any method item embodiment of the present invention.

[0174] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working process of the device described above can refer to the corresponding process in the foregoing method, and will not be elaborated herein too much.

[0175] As Figure 5 shown, some embodiments of the present application provide an electronic device 500, which includes: a memory 510, a processor 520, and a computer program stored on the memory 510 and executable on the processor 520. Wherein, when the processor 520 reads the program from the memory 510 through a bus 530 and executes the program, it can implement the method of any embodiment included in the above network security data traceability method.

[0176] The processor 520 can process digital signals and can include various computing architectures. For example, a complex instruction set computer architecture, a reduced instruction set computer architecture, or an architecture that implements a combination of multiple instruction sets. In some examples, the processor 520 can be a microprocessor.

[0177] The memory 510 can be used to store instructions executed by the processor 520 or data related to the execution of the instructions. These instructions and / or data can include code for implementing some or all of the functions of one or more modules described in the embodiments of the present application. The processor 520 of the embodiments of the present disclosure can be used to execute the instructions in the memory 510 to implement the method shown above. The memory 510 includes dynamic random access memory, static random access memory, flash memory, optical memory, or other memories well known to those skilled in the art.

[0178] Some embodiments of the present application also provide a computer-readable storage medium, on which a computer program is stored, and when the computer program is run by a processor, it executes the method described in the method embodiments.

[0179] Some embodiments of the present application also provide a computer program product, which, when running on a computer, causes the computer to execute the method described in the method embodiments.

[0180] It should be noted that the embodiments in this specification are all described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts among the embodiments can be referred to each other. For the device embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the description of the method embodiments.

[0181] In several embodiments provided by the present application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions, and operations of devices, methods, and computer program products according to multiple embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.

[0182] In addition, in each embodiment of the present application, the functional modules can be integrated together to form an independent part, or each module can exist separately, or two or more modules can be integrated to form an independent part.

[0183] If the function is implemented in the form of a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.

[0184] The above are only embodiments of the present application and are not intended to limit the protection scope of the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application. It should be noted that similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.

[0185] As described above, this is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily conceive of changes or replacements within the technical scope disclosed by the present application, and all such changes or replacements should be covered by the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claimed rights.

[0186] It should be noted that in this document, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the existence of additional identical elements in the process, method, article or device comprising the element.

Claims

1. A network security data tracing method, characterized in that: include: S1. In response to a traceability request for a target IOC entity, taking the target IOC entity as the current IOC entity to be traced; S2. Create a traceability task for the IOC entity to be traced, determine the traceability edge set corresponding to the IOC entity to be traced, and construct an edge lock corresponding to the IOC entity to be traced based on the traceability edge set; wherein the initial semaphore of the edge lock is equal to the number of edges in the traceability edge set, and the edge lock is used to control whether to release the traceability task corresponding to the IOC entity to be traced according to its own semaphore; S3, constructing a data pulling task for each traceability edge in the traceability edge set, and calling a traceability thread based on a preset thread pool to execute each data pulling task, to obtain an initial data set corresponding to each traceability edge; S4. Based on the initial data set corresponding to each traceability edge, a valid IOC entity list that meets the preset conditions is screened out respectively, and an entity lock corresponding to each of the valid IOC entity lists is constructed respectively, and the IOC entities in each of the valid IOC entity lists are used as the IOC entities to be traced in the next round, so as to jump to the execution step S2; wherein the parent lock of each of the entity locks is the edge lock constructed in the previous round, and the initial semaphore of each of the entity locks is equal to the number of IOC entities in the corresponding valid IOC entity list. When the semaphore of each of the entity locks decreases to zero, the semaphore of its parent lock is reduced by one respectively; After creating the tracing task for the next round of IOC entities to be traced, the tracing thread corresponding to the tracing task at the current level is released to the thread pool.

2. The network security data tracing method according to claim 1, characterized in that: The determining of the traceability edge set corresponding to the IOC entity to be traced includes: Determine a plurality of traceability paths corresponding to the IOC entity to be traced based on the entity type of the IOC entity to be traced; A combination of the IOC entity to be traced and each of the traceability paths is respectively used as a traceability edge to obtain a set of traceability edges corresponding to the IOC entity to be traced.

3. The network security data tracing method according to claim 1, characterized in that: Also includes: When the waiting time of the top-level edge lock exceeds the preset time threshold, a chain release event starting from the top-level edge lock is triggered from top to bottom to end the tracing tasks at each level for the target IOC entity.

4. The network security data tracing method according to claim 1, characterized in that: Also includes: Construct a global traceable data list corresponding to the target IOC entity, and record the traceability task information that has been executed in real time; The calling of the tracing thread based on the preset thread pool to execute each of the data pulling tasks also includes: Determine whether the global traceable data list contains traceability task information corresponding to the current data pulling task; If yes, the current data pulling task is terminated and the semaphore of the current edge lock is reduced by one; If not, the tracing thread is called based on the preset thread pool to execute the current data pulling task.

5. The network security data tracing method according to claim 1, characterized in that: The step of respectively constructing an entity lock corresponding to each of the valid IOC entity lists, and taking the IOC entities in each of the valid IOC entity lists as the IOC entities to be traced in the next round, includes: Determine whether the current traceability level has reached the preset level upper limit; If yes, then the tracing task for the valid IOC entity list is terminated, and the parent lock semaphore corresponding to the valid IOC entity is reduced by one; If not, then construct entity locks corresponding to each of the valid IOC entity lists respectively, and use the IOC entities in each of the valid IOC entity lists as the IOC entities to be traced in the next round.

6. The network security data tracing method according to claim 1, characterized in that: The step of constructing a data pulling task for each source tracing edge in the source tracing edge set includes: Determine a data pulling rule corresponding to each source tracing edge based on the type of each source tracing edge in the source tracing edge set, and construct a data pulling task for each source tracing edge according to the corresponding data pulling rule; Based on the initial data set corresponding to each traceability edge, a valid IOC entity list that meets the preset conditions is screened out, including: The entity screening rules corresponding to each tracing edge are determined according to the type of each tracing edge, and based on the initial data set corresponding to each tracing edge, a list of valid IOC entities that meet the preset conditions is screened out according to the corresponding entity screening rules.

7. The network security data tracing method according to claim 1, characterized in that: Also includes: Record the basic information of source tracing for all entity data in the initial data set corresponding to each source tracing edge; wherein the basic information of source tracing includes the source tracing path information and parent entity information to which each entity data belongs; When the waiting time of the top-level edge lock exceeds the preset time threshold, or when all traceability tasks are completed, the final traceability result corresponding to the traceability request is generated based on the valid IOC entities in the list of all valid IOC entities and their corresponding traceability basic information.

8. The network security data tracing method according to any one of claims 1 to 7, characterized in that: The entity type of the IOC entity to be traced includes at least one of an IP address, a domain name, a sample hash, an email, a digital certificate, a subdomain, filing information, and a registrant.

9. An electronic device, characterized in that: It includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor can implement the network security data tracing method described in any one of claims 1 to 8 when executing the program.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by the processor, the network security data tracing method according to any one of claims 1 to 8 is executed.

11. A computer program product, characterized in that The computer program product includes a computer program, and when the computer program is executed by a processor, the network security data tracing method according to any one of claims 1 to 8 is implemented.

Citation Information

Patent Citations

  • Network attack event traceability processing method and device, equipment and storage medium

    CN111935192A

  • Attack path restoration method and device based on IOC, electronic equipment and medium

    CN118337403A