Office equipment security event generation identification method and device and computer equipment

By identifying and analyzing the alarm information of office equipment and historical threat alarm information, the problem of low security incident identification efficiency in the existing technology is solved, and accurate identification and efficient screening of office equipment security incidents are achieved.

CN119939189APending Publication Date: 2025-05-06HANGZHOU YIGE CLOUD TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510046627.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-13
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The existing technology is difficult to effectively identify and analyze security incidents generated by office equipment, resulting in excessive false alarms and low-value alarm information, increasing the workload of security managers, and possibly causing important threats to be ignored.

Method used

By obtaining the alarm information and historical threat alarm information of office equipment, identifying the alarm type, querying the traceability policy, identifying the process information of the threat source, and identifying the associated historical threat alarm information through multi-dimensional association identification policies, thereby identifying security events.

Benefits of technology

It realizes accurate identification of office equipment safety incidents, reduces the number of alarms, improves the accuracy of alarms, reduces the work burden of security managers, and effectively screens out real security incidents.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939189A_ABST
    Figure CN119939189A_ABST
Patent Text Reader

Abstract

The invention relates to an office equipment security event generation identification method and device and computer equipment. The method comprises the following steps: acquiring alarm information and historical threat alarm information generated by office equipment, and identifying the alarm type of each alarm information; based on the alarm type of each piece of alarm information, inquiring an alarm tracing strategy of each piece of alarm information, and based on each piece of alarm information, identifying threat source process information corresponding to each piece of alarm information through the alarm tracing strategy of each piece of alarm information; based on the threat source process information of each piece of alarm information and the historical threat source process information of each piece of historical threat alarm information, identifying associated historical threat alarm information corresponding to each piece of alarm information through a multi-dimensional association identification strategy, and based on the associated historical threat alarm information corresponding to each piece of alarm information, identifying the associated historical threat alarm information corresponding to each piece of alarm information; and identifying security event information corresponding to each piece of alarm information. By adopting the method, the generation and identification efficiency of the security event of a large amount of alarm information can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of office terminal security technology in information security, and in particular to a method, device and computer equipment for identifying the generation of office equipment security events. Background Art

[0002] With the rapid development of information technology, enterprises and organizations are increasingly dependent on information systems. As an important node for information processing, the security of office equipment has been challenged unprecedentedly. In recent years, the means of network attacks have been constantly updated, from simple virus propagation to complex APT (advanced persistent threat) attacks. Attackers can use a variety of vulnerabilities and weaknesses to infiltrate the internal network of enterprises, seriously threatening data security and personal privacy. Some security alarm systems often generate a large number of alarm information, including a large number of false positives or low-value alarms, which not only increases the workload of security managers, but also easily leads to important threats being ignored. Therefore, how to improve the accurate identification of security incidents of office equipment is the current research focus.

[0003] In the existing technical solutions, the accuracy and efficiency of threat detection are improved by automatically learning and identifying abnormal behavior patterns through security analysis platforms based on machine learning and artificial intelligence. However, such methods usually focus on improving the accuracy of a single alarm. For large enterprises, due to the complexity of the office environment, simply improving the accuracy of a single alarm cannot solve the problem of the recognition and analysis efficiency of a large number of alarms, resulting in low recognition efficiency for security events with a large amount of alarm information. Summary of the invention

[0004] Based on this, it is necessary to provide a method, device, computer equipment, computer-readable storage medium and computer program product for identifying the occurrence of office equipment security incidents in response to the above technical problems.

[0005] In a first aspect, the present application provides a method for identifying the generation of office equipment security events, comprising:

[0006] Acquire each alarm information generated by the office equipment and the historical threat alarm information of the office equipment, and identify the alarm type of each alarm information;

[0007] Based on the alarm type of each alarm information, query the alarm tracing strategy of each alarm information, and based on each alarm information, identify the threat source process information corresponding to each alarm information through the alarm tracing strategy of each alarm information;

[0008] Based on the threat source process information of each alarm information and the historical threat source process information of each historical threat alarm information, a multi-dimensional correlation identification strategy is used to identify the associated historical threat alarm information corresponding to each alarm information, and based on the associated historical threat alarm information corresponding to each alarm information, the security event information corresponding to each alarm information is identified.

[0009] Optionally, the identifying the alarm type of each alarm information includes:

[0010] In each alarm information, query the alarm identification information of each alarm information, and locate the alarm position information and the alarm type identification generated by each alarm information in the office device based on the alarm identification information;

[0011] In the alarm database, the alarm type range corresponding to the alarm location information of each alarm information is queried, and based on the alarm type range corresponding to each alarm information and each alarm type identifier, the alarm type corresponding to each alarm information is identified through the alarm type identification strategy.

[0012] Optionally, the identifying the threat source process information corresponding to each alarm information based on each alarm feature of each alarm information and through the alarm tracing strategy of each alarm information includes:

[0013] For each alarm information, based on the tracing location information of the alarm tracing strategy of the alarm information, query the tracing log information of the alarm information in the device log of the office equipment, and query the target tracing content corresponding to the alarm information in the tracing log information through the tracing collection process of the alarm tracing strategy of the alarm information;

[0014] In each of the process information, the process information containing the target traceability content is searched as the hazardous source process information corresponding to the alarm information.

[0015] Optionally, the identifying the associated historical threat alarm information corresponding to each alarm information through a multi-dimensional association identification strategy based on the threat source process information of each alarm information and the historical threat source process information of each historical threat alarm information includes:

[0016] Querying the historical threat source process information of each historical threat alarm information, and for each alarm information, when there is overlapping information between the threat source process information and the historical threat source process information, determining the historical threat alarm information corresponding to the historical threat source process information as the associated historical threat alarm information corresponding to the alarm information;

[0017] When there is no overlapping information between the threat source process information and the historical threat source process information, collect the historical generation time point of each of the historical threat source process information and the generation time point of the threat source process information, and when the time interval between the historical generation time point of the historical threat source process information and the generation time point of the threat source process information is lower than the time interval threshold preset in the terminal, determine the historical threat alarm information corresponding to the historical threat source process information as the associated historical threat alarm information corresponding to the alarm information;

[0018] When there is no historical generation time point of historical threat source process information and the time interval between the generation time point of the threat source process information is lower than a time interval threshold preset in the terminal, an alarm rule corresponding to each alarm information and a historical alarm rule corresponding to each historical threat alarm information are identified, and when there is historical threat alarm information with the same alarm rule, the historical threat alarm information is used as the associated historical threat alarm information corresponding to the alarm information.

[0019] Optionally, the identifying security event information corresponding to each alarm information based on the associated historical threat alarm information corresponding to each alarm information includes:

[0020] For each warning information, identifying the behavior pattern information of each associated historical threat warning information corresponding to the warning information, and calculating the similarity between each behavior pattern information and the sample behavior pattern information of each sample virus;

[0021] Using a sample virus corresponding to a similarity greater than a similarity threshold as security event information corresponding to the warning information, and identifying the warning level of each associated historical threat warning information corresponding to the warning information when there is no sample virus corresponding to a similarity greater than the similarity threshold;

[0022] The alarm levels of each of the associated historical threat alarm information are cumulatively scored to obtain a danger score of the alarm information, and when the danger score is greater than a danger score threshold, all the associated historical threat alarm information corresponding to the alarm information are used as security event information corresponding to the alarm information.

[0023] Optionally, after identifying the security event information corresponding to each alarm information based on the associated historical threat alarm information corresponding to each alarm information, the method further includes:

[0024] Identify the alarm source devices of each associated alarm information corresponding to each alarm information, and generate alarm warning information corresponding to the alarm information based on the security event information corresponding to the alarm information;

[0025] The alarm information corresponding to the alarm information is sent to each alarm source device respectively; the alarm information is used to control each alarm source device to execute the security prevention task corresponding to the alarm information.

[0026] In a second aspect, the present application also provides a device for identifying the generation of office equipment security events, including:

[0027] An acquisition module, used to acquire each alarm information generated by the office equipment and the historical threat alarm information of the office equipment, and identify the alarm type of each alarm information;

[0028] A query module, used to query the alarm tracing strategy of each alarm information based on the alarm type of each alarm information, and identify the threat source process information corresponding to each alarm information through the alarm tracing strategy of each alarm information based on each alarm information;

[0029] The identification module is used to identify the associated historical threat alarm information corresponding to each alarm information based on the threat source process information of each alarm information and the historical threat source process information of each historical threat alarm information through a multi-dimensional association identification strategy, and to identify the security event information corresponding to each alarm information based on the associated historical threat alarm information corresponding to each alarm information.

[0030] Optionally, the acquisition module is specifically used to:

[0031] In each alarm information, query the alarm identification information of each alarm information, and locate the alarm position information and the alarm type identification generated by each alarm information in the office device based on the alarm identification information;

[0032] In the alarm database, the alarm type range corresponding to the alarm location information of each alarm information is queried, and based on the alarm type range corresponding to each alarm information and each alarm type identifier, the alarm type corresponding to each alarm information is identified through the alarm type identification strategy.

[0033] Optionally, the query module is specifically used to:

[0034] For each alarm information, based on the tracing location information of the alarm tracing strategy of the alarm information, query the tracing log information of the alarm information in the device log of the office equipment, and query the target tracing content corresponding to the alarm information in the tracing log information through the tracing collection process of the alarm tracing strategy of the alarm information;

[0035] In each of the process information, the process information containing the target traceability content is searched as the hazardous source process information corresponding to the alarm information.

[0036] Optionally, the query module is specifically used to:

[0037] Querying the historical threat source process information of each historical threat alarm information, and for each alarm information, when there is overlapping information between the threat source process information and the historical threat source process information, determining the historical threat alarm information corresponding to the historical threat source process information as the associated historical threat alarm information corresponding to the alarm information;

[0038] When there is no overlapping information between the threat source process information and the historical threat source process information, collect the historical generation time point of each of the historical threat source process information and the generation time point of the threat source process information, and when the time interval between the historical generation time point of the historical threat source process information and the generation time point of the threat source process information is lower than the time interval threshold preset in the terminal, determine the historical threat alarm information corresponding to the historical threat source process information as the associated historical threat alarm information corresponding to the alarm information;

[0039] When there is no historical generation time point of historical threat source process information and the time interval between the generation time point of the threat source process information is lower than a time interval threshold preset in the terminal, an alarm rule corresponding to each alarm information and a historical alarm rule corresponding to each historical threat alarm information are identified, and when there is historical threat alarm information with the same alarm rule, the historical threat alarm information is used as the associated historical threat alarm information corresponding to the alarm information.

[0040] Optionally, the identification module is specifically used to:

[0041] For each warning information, identifying the behavior pattern information of each associated historical threat warning information corresponding to the warning information, and calculating the similarity between each behavior pattern information and the sample behavior pattern information of each sample virus;

[0042] Using a sample virus corresponding to a similarity greater than a similarity threshold as security event information corresponding to the warning information, and identifying the warning level of each associated historical threat warning information corresponding to the warning information when there is no sample virus corresponding to a similarity greater than the similarity threshold;

[0043] The alarm levels of each of the associated historical threat alarm information are cumulatively scored to obtain a danger score of the alarm information, and when the danger score is greater than a danger score threshold, all the associated historical threat alarm information corresponding to the alarm information are used as security event information corresponding to the alarm information.

[0044] Optionally, the device further comprises:

[0045] A generating module, used for identifying the alarm source device of each associated alarm information corresponding to each alarm information, and generating the alarm warning information corresponding to the alarm information based on the security event information corresponding to the alarm information;

[0046] The sending module is used to send the alarm warning information corresponding to the alarm information to each alarm source device respectively; the alarm warning information is used to control each alarm source device to execute the security prevention task corresponding to the alarm warning information.

[0047] In a third aspect, the present application provides a computer device, wherein the computer device comprises a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the steps of any one of the methods in the first aspect are implemented.

[0048] In a fourth aspect, the present application provides a computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the steps of any one of the methods in the first aspect are implemented.

[0049] In a fifth aspect, the present application provides a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, the steps of any one of the methods in the first aspect are implemented.

[0050] The above-mentioned method, device and computer equipment for identifying the generation of office equipment security events obtain the alarm information generated by the office equipment and the historical threat alarm information of the office equipment, and identify the alarm type of each alarm information; based on the alarm type of each alarm information, query the alarm tracing strategy of each alarm information, and based on each alarm information, identify the threat source process information corresponding to each alarm information through the alarm tracing strategy of each alarm information; based on the threat source process information of each alarm information and the historical threat source process information of each historical threat alarm information, identify the associated historical threat alarm information corresponding to each alarm information through a multi-dimensional correlation identification strategy, and identify the security event information corresponding to each alarm information based on the associated historical threat alarm information corresponding to each alarm information. This solution, by classifying and tracing the alarm information, identifies the threat source process information of each alarm information, and thereby identifies the associated historical threat alarm information corresponding to each alarm information in the historical threat alarm information, realizes the traceability and aggregation tasks of office equipment security alarms, thereby effectively conducting a comprehensive analysis of the security events of each alarm information, improving the comprehensiveness and accuracy of the security event analysis of the alarm information, and thus screening out the terminals where the security events actually occurred. This invention can reduce the amount of alarms from office terminals and improve the accuracy of alarms. This method does not require complex algorithms and complex model recognition and calculation processes, thereby reducing the amount of alarm information generated and the recognition efficiency of security events generated by a large amount of alarm information. It can also effectively adapt to office equipment of any system and has wide compatibility. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the related technologies, the drawings required for use in the embodiments or the related technical descriptions are briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0052] Figure 1 A schematic diagram of a flow chart of a method for identifying the generation of office equipment security events in one embodiment;

[0053] Figure 2 A schematic diagram of a process for generating and identifying an example of an office equipment security incident in one embodiment;

[0054] Figure 3 It is a structural block diagram of a device for identifying the generation of security events of office equipment in one embodiment;

[0055] Figure 4 FIG. 4 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION

[0056] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0057] The method for identifying the generation of office equipment security events provided by the embodiment of the present application can be applied to the application environment of the generation and identification of office equipment security events. Among them, the method can be applied to a terminal, a server, or a system including a terminal and a server, and is implemented through the interaction between the terminal and the server. Among them, the terminal can be, but is not limited to, various personal computers, laptops, medium-sized computers, etc. Among them, the terminal classifies and traces the alarm information, identifies the threat source process information of each alarm information, and thereby identifies the associated historical threat alarm information corresponding to each alarm information in the historical threat alarm information, thereby realizing the traceability and aggregation tasks of the office equipment security alarm, thereby effectively performing a comprehensive analysis of the security events of each alarm information, improving the comprehensiveness and accuracy of the security event analysis of the alarm information, and thus screening out the terminal where the security event actually occurred. The invention can reduce the alarm volume of office terminals and improve the accuracy of alarms, and the method does not require complex algorithms and complex model recognition and calculation processes, thereby reducing the amount of alarm information generated and the recognition efficiency of security events generated by a large amount of alarm information, and can also effectively adapt to office equipment of any system, with wide compatibility.

[0058] In an exemplary embodiment, Figure 1 As shown, a method for identifying the generation of security events of office equipment is provided, and the method is applied to a terminal as an example for explanation, including the following steps S101 to S103. Among them:

[0059] Step S101: Acquire each alarm information generated by the office equipment and the historical threat alarm information of the office equipment, and identify the alarm type of each alarm information.

[0060] In this embodiment, the terminal collects various alarm information generated by the office equipment through the alarm information collection program set in the office equipment, wherein each alarm information includes the alarm level, the security rules hit by the alarm, and the behavior source information triggered by the alarm. Then, the terminal queries the alarm database for various historical threat alarm information that has been generated. Finally, the terminal identifies the alarm type of each alarm information. Among them, the alarm type is the type classified according to the alarm information, which is divided into four categories, namely threat domain name alarm, abnormal behavior alarm, virus file alarm, and malicious memory alarm. The specific alarm type identification process will be described in detail later.

[0061] Step S102, based on the alarm type of each alarm information, query the alarm tracing strategy of each alarm information, and based on each alarm information, identify the threat source process information corresponding to each alarm information through the alarm tracing strategy of each alarm information.

[0062] In this embodiment, the terminal queries the alarm tracing strategy of each alarm information based on the alarm type of each alarm information, and identifies the threat source process information corresponding to each alarm information through the alarm tracing strategy of each alarm information based on each alarm information. Among them, each alarm type corresponds to a tracing collection action, and the tracing collection action is the alarm tracing strategy for each alarm information. Among them, the threat source process information is the source information of the alarm information, and the threat source process information includes detailed process information (process unique identifier, process command line, process file information, process user information, etc.), and also includes the process chain information of the process. The process chain information includes the process unique identifier information from the ancestor process to the process, which is stored in the form of a linked list. The specific identification process will be described in detail later.

[0063] Step S103, based on the threat source process information of each alarm information and the historical threat source process information of each historical threat alarm information, identify the associated historical threat alarm information corresponding to each alarm information through a multi-dimensional association identification strategy, and identify the security event information corresponding to each alarm information based on the associated historical threat alarm information corresponding to each alarm information.

[0064] In this embodiment, the terminal identifies the associated historical threat alarm information corresponding to each alarm information based on the threat source process information of each alarm information and the historical threat source process information of each historical threat alarm information through a multi-dimensional association identification strategy, and identifies the security event information corresponding to each alarm information based on the associated historical threat alarm information corresponding to each alarm information. Among them, one alarm information can be associated with one or more historical threat alarm information, and the multi-dimensional association identification strategy is a method for identifying the association between the alarm information and the historical threat alarm information from multiple angles. The specific identification process will be described in detail later.

[0065] Based on the above scheme, by classifying and tracing the alarm information, identifying the threat source process information of each alarm information, and then identifying the associated historical threat alarm information corresponding to each alarm information in the historical threat alarm information, the traceability and aggregation tasks of office equipment security alarms are realized, thereby effectively conducting a comprehensive analysis of the security events of each alarm information, improving the comprehensiveness and accuracy of the security event analysis of the alarm information, and thus screening out the terminals where the security events actually occurred. This invention can reduce the amount of alarms on office terminals and improve the accuracy of alarms. This method does not require complex algorithms and complex model recognition and calculation processes, thereby reducing the amount of alarm information generated and the recognition efficiency of security events generated by a large amount of alarm information. It can also effectively adapt to office equipment of any system and has wide compatibility.

[0066] Optionally, identifying the alarm type of each alarm message includes: in each alarm message, querying the alarm identification information of each alarm message, and based on the alarm identification information, locating the alarm location information generated by each alarm message and the alarm type identification in the office equipment; in the alarm database, querying the alarm type range corresponding to the alarm location information of each alarm message, and based on the alarm type range corresponding to each alarm message and each alarm type identification, identifying the alarm type corresponding to each alarm message through the alarm type identification strategy.

[0067] In this embodiment, the terminal queries the alarm identification information of each alarm information in each alarm information, and locates the alarm location information and the alarm type identification generated by each alarm information in the office device based on the alarm identification information. Wherein, each alarm identification information is the attribute information of the alarm information, and the attribute information includes the address information (i.e., the alarm location information) of the office device generating the alarm information, and the alarm type identification, and the alarm type identification is used to query the alarm type corresponding to the alarm information.

[0068] In the alarm database, the terminal queries the alarm type range corresponding to the alarm location information of each alarm information, and identifies the alarm type corresponding to each alarm information through the alarm type identification strategy based on the alarm type range corresponding to each alarm information and each alarm type identifier.

[0069] Based on the above solution, the alarm type corresponding to each alarm message is identified through alarm information positioning and identification recognition strategy, thereby improving the recognition efficiency and accuracy of the alarm type.

[0070] Optionally, based on the alarm features of each alarm information and through the alarm tracing strategy of each alarm information, the threat source process information corresponding to each alarm information is identified, including: for each alarm information, based on the tracing location information of the alarm tracing strategy of the alarm information, querying the tracing log information of the alarm information in the equipment log of the office equipment, and through the tracing collection process of the alarm tracing strategy of the alarm information, querying the target tracing content corresponding to the alarm information in the tracing log information; in each process information, querying the process information containing the target tracing content as the hazard source process information corresponding to the alarm information.

[0071] In this embodiment, for each alarm information, the terminal queries the tracing log information of the alarm information in the device log of the office equipment based on the tracing location information of the alarm tracing strategy of the alarm information, and queries the target tracing content corresponding to the alarm information in the tracing log information through the tracing collection process of the alarm tracing strategy of the alarm information.

[0072] Then, the terminal searches for process information containing target traceability content in each process information as the hazardous source process information corresponding to the alarm information.

[0073] Specifically, the alarm tracing processes for different alarm types are:

[0074] a. For threat domain name alerts, match the threat domain name in the terminal's DNS request log and obtain the process that initiates the threat domain name request as the threat source process.

[0075] b. For virus file alarms, match the virus file path in the terminal's read and write file logs and obtain the process that reads and writes the virus file as the threat source process.

[0076] c. For malicious memory alarms, find the process injection logs in which the target process is a malicious memory process in the process injection logs of the terminal, and obtain the source process as the threat source process.

[0077] d. For abnormal behavior alerts, look for the process corresponding to the behavior in the terminal's action log as the threat source process.

[0078] Based on the above solution, by collecting the threat tracing process of each alarm type from the alarm tracing strategies corresponding to different alarm types, the accuracy and efficiency of collection are improved.

[0079] Optionally, based on the threat source process information of each alarm information and the historical threat source process information of each historical threat alarm information, the associated historical threat alarm information corresponding to each alarm information is identified through a multi-dimensional association identification strategy, including: querying the historical threat source process information of each historical threat alarm information, and for each alarm information, when there is overlapping information between the threat source process information and the historical threat source process information, determining the historical threat alarm information corresponding to the historical threat source process information as the associated historical threat alarm information corresponding to the alarm information; when there is no overlapping information between the threat source process information and the historical threat source process information, collecting the historical generation time point of each historical threat source process information and the generation time point of the threat source process information, and When the time interval between the historical generation time point of the historical threat source process information and the generation time point of the threat source process information is lower than the time interval threshold preset in the terminal, the historical threat alarm information corresponding to the historical threat source process information is determined as the associated historical threat alarm information corresponding to the alarm information; when the time interval between the historical generation time point of the historical threat source process information and the generation time point of the threat source process information is lower than the time interval threshold preset in the terminal, the alarm rule corresponding to each alarm information and the historical alarm rule corresponding to each historical threat alarm information are identified, and when historical threat alarm information with the same alarm rule exists, the historical threat alarm information is used as the associated historical threat alarm information corresponding to the alarm information.

[0080] In this embodiment, the terminal queries the historical threat source process information of each historical threat alarm information, and for each alarm information, when there is overlapping information between the threat source process information and the historical threat source process information, the historical threat alarm information corresponding to the historical threat source process information is determined as the associated historical threat alarm information corresponding to the alarm information. Specifically, the process chains of the threat source processes of the two alarm information have cross nodes, and the two alarms become associated alarms. In addition, in order to avoid interference with association by common parent processes such as explorer (file explorer) in Windows and ssh process in Linux, it is determined whether there are cross nodes to exclude such common nodes.

[0081] Secondly, when there is no overlapping information between the threat source process information and the historical threat source process information, the historical generation time point of each historical threat source process information and the generation time point of the threat source process information are collected, and when the time interval between the historical generation time point of the historical threat source process information and the generation time point of the threat source process information is lower than the time interval threshold preset in the terminal, the historical threat alarm information corresponding to the historical threat source process information is determined as the associated historical threat alarm information corresponding to the alarm information. Specifically, the device that generates the alarm has generated more than a certain number of alarms within a short period of time when the alarm is generated, and these alarms become associated alarms. The device that generates the alarm has generated alarms with the same hit rule within a short period of time when the alarm is generated, and these alarms become associated alarms.

[0082] Then, when there is no historical generation time point of historical threat source process information and the time interval between the generation time point of the threat source process information is lower than the time interval threshold preset in the terminal, the alarm rule corresponding to each alarm information and the historical alarm rule corresponding to each historical threat alarm information are identified, and when there is historical threat alarm information with the same alarm rule, the historical threat alarm information is used as the associated historical threat alarm information corresponding to the alarm information. Specifically, for some scenarios where process chains cannot be associated, matching will be performed according to the pattern of the alarm hit rule. For example, for the scenario of suspicious service execution, in addition to the above association, the alarm created by the service will be additionally associated.

[0083] Based on the above solution, by judging the associated historical threat alarm information corresponding to each alarm information from multiple dimensions, the comprehensiveness and accuracy of the identification of the associated historical threat alarm information are improved.

[0084] Optionally, based on the associated historical threat alarm information corresponding to each alarm information, the security event information corresponding to each alarm information is identified, including: for each alarm information, the behavior pattern information of each associated historical threat alarm information corresponding to the alarm information is identified, and the similarity between each behavior pattern information and the sample behavior pattern information of each sample virus is calculated; the sample virus corresponding to the similarity greater than the similarity threshold is used as the security event information corresponding to the alarm information, and in the absence of the sample virus corresponding to the similarity greater than the similarity threshold, the alarm level of each associated historical threat alarm information corresponding to the alarm information is identified; the alarm level of each associated historical threat alarm information is graded and accumulated to obtain a danger score of the alarm information, and when the danger score is greater than the danger score threshold, all associated historical threat alarm information corresponding to the alarm information is used as the security event information corresponding to the alarm information.

[0085] In this embodiment, the terminal identifies the behavior pattern information of each associated historical threat alarm information corresponding to the alarm information for each alarm information, and calculates the similarity between each behavior pattern information and the sample behavior pattern information of each sample virus. The similarity is calculated as follows: the similar behavior pattern part between two behavior pattern information accounts for the proportion of the behavior pattern information. Specifically, whether this batch of associated alarms meets the behavior pattern of known common Trojan samples. For example, for common ransomware viruses, it usually includes the behavior of deleting shadow copies and traversing drive letters. If the associated alarm contains these two behaviors, it is considered that the ransomware alarm is hit. All associated alarms are aggregated into security events.

[0086] Then, the terminal uses the sample virus corresponding to the similarity greater than the similarity threshold as the security event information corresponding to the alarm information, and identifies the alarm level of each associated historical threat alarm information corresponding to the alarm information when there is no sample virus corresponding to the similarity greater than the similarity threshold. The alarm level of each alarm information is included in each alarm information.

[0087] Finally, the terminal will accumulate the alarm levels of each associated historical threat alarm information and obtain the danger score of the alarm information. When the danger score is greater than the danger score threshold, all the associated historical threat alarm information corresponding to the alarm information will be used as the security event information corresponding to the alarm information. Among them, if the associated alarm cannot match the behavior pattern of the known common Trojan samples, all the associated alarms will be accumulated according to the alarm level statistics. The higher the threat level, the higher the danger score of a single alarm. When the terminal's danger score exceeds the set security threshold, it is considered that the terminal has a security risk, and all the associated alarms are aggregated into a security event.

[0088] Based on the above solution, the security events corresponding to the alarm information are identified from two perspectives: behavior pattern adaptation and score judgment, which improves the comprehensiveness and accuracy of security event identification.

[0089] Optionally, after identifying the security event information corresponding to each alarm information based on the associated historical threat alarm information corresponding to each alarm information, it also includes: identifying the alarm source devices of each associated alarm information corresponding to each alarm information, and generating alarm warning information corresponding to the alarm information based on the security event information corresponding to the alarm information; sending the alarm warning information corresponding to the alarm information to each alarm source device respectively; the alarm warning information is used to control each alarm source device to perform the security prevention task corresponding to the alarm warning information.

[0090] In this embodiment, the terminal identifies the alarm source device of each associated alarm information corresponding to each alarm information, and generates the alarm warning information corresponding to the alarm information based on the security event information corresponding to the alarm information. Among them, the terminal presets each alarm warning information template, and based on the security event type (i.e., virus type, or the number of associated historical threat alarm information included) to which the security event information corresponding to each alarm information belongs, adapts the target alarm warning information template corresponding to each alarm information, wherein each alarm warning information template corresponds to a security event type, and then, the terminal fills the target alarm warning information template corresponding to each alarm information with the security event information corresponding to each alarm information, and obtains the alarm warning information corresponding to each alarm information.

[0091] Finally, the terminal sends the alarm information corresponding to the alarm information to each alarm source device, wherein the alarm information is used to control each alarm source device to execute the security prevention task corresponding to the alarm information.

[0092] Based on the above scheme, each alarm source device is warned based on the security event information corresponding to each alarm information, thereby improving the comprehensiveness of security prevention against the security event information of the alarm information.

[0093] This application also provides an example of identifying the generation of office equipment security events, such as Figure 2 As shown, the specific processing process includes the following steps:

[0094] Step S201: Acquire various alarm information generated by office equipment and historical threat alarm information of office equipment.

[0095] Step S202: in each alarm information, query the alarm identification information of each alarm information, and locate the alarm position information and the alarm type identification generated by each alarm information in the office device based on the alarm identification information.

[0096] Step S203, in the alarm database, query the alarm type range corresponding to the alarm location information of each alarm information, and identify the alarm type corresponding to each alarm information through the alarm type identification strategy based on the alarm type range corresponding to each alarm information and each alarm type identifier.

[0097] Step S204, for each alarm information, based on the traceability positioning information of the alarm traceability strategy of the alarm information, query the traceability log information of the alarm information in the equipment log of the office equipment, and through the traceability collection process of the alarm traceability strategy of the alarm information, query the target traceability content corresponding to the alarm information in the traceability log information.

[0098] Step S205: In each process information, search for process information containing target traceability content as the hazardous source process information corresponding to the alarm information.

[0099] Step S206, query the historical threat source process information of each historical threat alarm information, and for each alarm information, when there is overlapping information between the threat source process information and the historical threat source process information, determine the historical threat alarm information corresponding to the historical threat source process information as the associated historical threat alarm information corresponding to the alarm information.

[0100] Step S207, when there is no overlapping information between the threat source process information and the historical threat source process information, collect the historical generation time point of each historical threat source process information and the generation time point of the threat source process information, and when the time interval between the historical generation time point of the historical threat source process information and the generation time point of the threat source process information is lower than the time interval threshold preset in the terminal, determine the historical threat alarm information corresponding to the historical threat source process information as the associated historical threat alarm information corresponding to the alarm information.

[0101] Step S208, when there is no historical generation time point of the historical threat source process information and the time interval between the generation time point of the threat source process information is lower than the time interval threshold preset in the terminal, identify the alarm rule corresponding to each alarm information and the historical alarm rule corresponding to each historical threat alarm information, and when there is historical threat alarm information with the same alarm rule, use the historical threat alarm information as the associated historical threat alarm information corresponding to the alarm information.

[0102] Step S209: for each warning information, identifying the behavior pattern information of each associated historical threat warning information corresponding to the warning information, and calculating the similarity between each behavior pattern information and the sample behavior pattern information of each sample virus.

[0103] Step S210: taking the sample virus corresponding to the similarity greater than the similarity threshold as the security event information corresponding to the alarm information, and identifying the alarm level of each associated historical threat alarm information corresponding to the alarm information when there is no sample virus corresponding to the similarity greater than the similarity threshold.

[0104] In step S211, the alarm levels of each associated historical threat alarm information are cumulatively scored to obtain a danger score of the alarm information, and when the danger score is greater than a danger score threshold, all associated historical threat alarm information corresponding to the alarm information is used as security event information corresponding to the alarm information.

[0105] It should be understood that, although the various steps in the flowcharts involved in the above-mentioned embodiments are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence according to the order indicated by the arrows. Unless there is a clear explanation in this article, the execution of these steps does not have a strict order restriction, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-mentioned embodiments can include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a part of the steps or stages in other steps.

[0106] Based on the same inventive concept, the embodiment of the present application also provides an office equipment security event generation and identification device for implementing the above-mentioned office equipment security event generation and identification method. The implementation scheme for solving the problem provided by the device is similar to the implementation scheme recorded in the above-mentioned method, so the specific limitations in the embodiments of one or more office equipment security event generation and identification devices provided below can refer to the limitations of the office equipment security event generation and identification method above, and will not be repeated here.

[0107] In an exemplary embodiment, Figure 3 As shown, a device for identifying the generation of office equipment security events is provided, including: an acquisition module 310, a query module 320 and an identification module 330, wherein:

[0108] An acquisition module 310 is used to acquire each alarm information generated by the office equipment and the historical threat alarm information of the office equipment, and identify the alarm type of each alarm information;

[0109] The query module 320 is used to query the alarm tracing strategy of each alarm information based on the alarm type of each alarm information, and identify the threat source process information corresponding to each alarm information through the alarm tracing strategy of each alarm information based on each alarm information;

[0110] The identification module 330 is used to identify the associated historical threat alarm information corresponding to each alarm information based on the threat source process information of each alarm information and the historical threat source process information of each historical threat alarm information through a multi-dimensional association identification strategy, and to identify the security event information corresponding to each alarm information based on the associated historical threat alarm information corresponding to each alarm information.

[0111] Optionally, the acquisition module 310 is specifically configured to:

[0112] In each alarm information, query the alarm identification information of each alarm information, and locate the alarm position information and the alarm type identification generated by each alarm information in the office device based on the alarm identification information;

[0113] In the alarm database, the alarm type range corresponding to the alarm location information of each alarm information is queried, and based on the alarm type range corresponding to each alarm information and each alarm type identifier, the alarm type corresponding to each alarm information is identified through the alarm type identification strategy.

[0114] Optionally, the query module 320 is specifically used to:

[0115] For each alarm information, based on the tracing location information of the alarm tracing strategy of the alarm information, query the tracing log information of the alarm information in the device log of the office equipment, and query the target tracing content corresponding to the alarm information in the tracing log information through the tracing collection process of the alarm tracing strategy of the alarm information;

[0116] In each of the process information, the process information containing the target traceability content is searched as the hazardous source process information corresponding to the alarm information.

[0117] Optionally, the query module 320 is specifically used to:

[0118] Querying the historical threat source process information of each historical threat alarm information, and for each alarm information, when there is overlapping information between the threat source process information and the historical threat source process information, determining the historical threat alarm information corresponding to the historical threat source process information as the associated historical threat alarm information corresponding to the alarm information;

[0119] When there is no overlapping information between the threat source process information and the historical threat source process information, collect the historical generation time point of each of the historical threat source process information and the generation time point of the threat source process information, and when the time interval between the historical generation time point of the historical threat source process information and the generation time point of the threat source process information is lower than the time interval threshold preset in the terminal, determine the historical threat alarm information corresponding to the historical threat source process information as the associated historical threat alarm information corresponding to the alarm information;

[0120] When there is no historical generation time point of historical threat source process information and the time interval between the generation time point of the threat source process information is lower than a time interval threshold preset in the terminal, an alarm rule corresponding to each alarm information and a historical alarm rule corresponding to each historical threat alarm information are identified, and when there is historical threat alarm information with the same alarm rule, the historical threat alarm information is used as the associated historical threat alarm information corresponding to the alarm information.

[0121] Optionally, the identification module 330 is specifically used to:

[0122] For each warning information, identifying the behavior pattern information of each associated historical threat warning information corresponding to the warning information, and calculating the similarity between each behavior pattern information and the sample behavior pattern information of each sample virus;

[0123] Using a sample virus corresponding to a similarity greater than a similarity threshold as security event information corresponding to the warning information, and identifying the warning level of each associated historical threat warning information corresponding to the warning information when there is no sample virus corresponding to a similarity greater than the similarity threshold;

[0124] The alarm levels of each of the associated historical threat alarm information are cumulatively scored to obtain a danger score of the alarm information, and when the danger score is greater than a danger score threshold, all the associated historical threat alarm information corresponding to the alarm information are used as security event information corresponding to the alarm information.

[0125] Optionally, the device further comprises:

[0126] A generating module, used for identifying the alarm source device of each associated alarm information corresponding to each alarm information, and generating the alarm warning information corresponding to the alarm information based on the security event information corresponding to the alarm information;

[0127] The sending module is used to send the alarm warning information corresponding to the alarm information to each alarm source device respectively; the alarm warning information is used to control each alarm source device to execute the security prevention task corresponding to the alarm warning information.

[0128] Each module in the above-mentioned office equipment security event generation and identification device can be implemented in whole or in part by software, hardware, or a combination thereof. Each of the above-mentioned modules can be embedded in or independent of a processor in a computer device in the form of hardware, or can be stored in a memory in a computer device in the form of software, so that the processor can call and execute operations corresponding to each of the above modules.

[0129] In an exemplary embodiment, a computer device is provided. The computer device may be a terminal, and its internal structure diagram may be as shown in FIG. Figure 4 As shown. The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit and an input device. The processor, the memory and the input / output interface are connected through a system bus, and the communication interface, the display unit and the input device are connected to the system bus through the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and the external device. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be realized through WIFI, a mobile cellular network, NFC (near field communication) or other technologies. When the computer program is executed by the processor, a method for generating and identifying office equipment security events is realized. The display unit of the computer device is used to form a visually visible picture, which can be a display screen, a projection device or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covering the display screen, or a button, trackball or touchpad set on the computer device shell, or an external keyboard, touchpad or mouse.

[0130] Those skilled in the art will understand that Figure 4 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.

[0131] In an exemplary embodiment, a computer device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and when the processor executes the computer program, steps of a method for identifying generation of security events of office equipment are implemented.

[0132] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps of a method for identifying the generation of security events of office equipment are implemented.

[0133] In one embodiment, a computer program product is provided, including a computer program, which, when executed by a processor, implements the steps of a method for identifying the generation of security events of office equipment.

[0134] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant regulations.

[0135] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to the memory, database or other medium used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in each embodiment provided in this application may include at least one of a relational database and a non-relational database. Non-relational databases may include distributed databases based on blockchains, etc., but are not limited to this. The processor involved in each embodiment provided in this application may be a general-purpose processor, a central processing unit, a graphics processor, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., but are not limited to this.

[0136] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0137] The above-described embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the present application. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the attached claims.

Claims

1. A method for identifying the generation of office equipment security events, characterized in that: The method comprises: Acquire each alarm information generated by the office equipment and the historical threat alarm information of the office equipment, and identify the alarm type of each alarm information; Based on the alarm type of each alarm information, query the alarm tracing strategy of each alarm information, and based on each alarm information, identify the threat source process information corresponding to each alarm information through the alarm tracing strategy of each alarm information; Based on the threat source process information of each alarm information and the historical threat source process information of each historical threat alarm information, a multi-dimensional correlation identification strategy is used to identify the associated historical threat alarm information corresponding to each alarm information, and based on the associated historical threat alarm information corresponding to each alarm information, the security event information corresponding to each alarm information is identified.

2. The method according to claim 1, characterized in that The identifying the alarm type of each alarm information includes: In each alarm information, query the alarm identification information of each alarm information, and locate the alarm position information and the alarm type identification generated by each alarm information in the office device based on the alarm identification information; In the alarm database, the alarm type range corresponding to the alarm location information of each alarm information is queried, and based on the alarm type range corresponding to each alarm information and each alarm type identifier, the alarm type corresponding to each alarm information is identified through the alarm type identification strategy.

3. The method according to claim 1, characterized in that The method of identifying the threat source process information corresponding to each alarm information based on each alarm feature of each alarm information and through the alarm tracing strategy of each alarm information includes: For each alarm information, based on the tracing location information of the alarm tracing strategy of the alarm information, query the tracing log information of the alarm information in the device log of the office equipment, and query the target tracing content corresponding to the alarm information in the tracing log information through the tracing collection process of the alarm tracing strategy of the alarm information; In each of the process information, the process information containing the target traceability content is searched as the hazardous source process information corresponding to the alarm information.

4. The method according to claim 1, characterized in that: The method of identifying the associated historical threat alarm information corresponding to each alarm information through a multi-dimensional association identification strategy based on the threat source process information of each alarm information and the historical threat source process information of each historical threat alarm information includes: Querying the historical threat source process information of each historical threat alarm information, and for each alarm information, when there is overlapping information between the threat source process information and the historical threat source process information, determining the historical threat alarm information corresponding to the historical threat source process information as the associated historical threat alarm information corresponding to the alarm information; When there is no overlapping information between the threat source process information and the historical threat source process information, collect the historical generation time point of each of the historical threat source process information and the generation time point of the threat source process information, and when the time interval between the historical generation time point of the historical threat source process information and the generation time point of the threat source process information is lower than the time interval threshold preset in the terminal, determine the historical threat alarm information corresponding to the historical threat source process information as the associated historical threat alarm information corresponding to the alarm information; When there is no historical generation time point of historical threat source process information and the time interval between the generation time point of the threat source process information is lower than a time interval threshold preset in the terminal, an alarm rule corresponding to each alarm information and a historical alarm rule corresponding to each historical threat alarm information are identified, and when there is historical threat alarm information with the same alarm rule, the historical threat alarm information is used as the associated historical threat alarm information corresponding to the alarm information.

5. The method according to claim 1, characterized in that The identifying the security event information corresponding to each alarm information based on the associated historical threat alarm information corresponding to each alarm information includes: For each warning information, identifying the behavior pattern information of each associated historical threat warning information corresponding to the warning information, and calculating the similarity between each behavior pattern information and the sample behavior pattern information of each sample virus; Using a sample virus corresponding to a similarity greater than a similarity threshold as security event information corresponding to the warning information, and identifying the warning level of each associated historical threat warning information corresponding to the warning information when there is no sample virus corresponding to a similarity greater than the similarity threshold; The alarm levels of each of the associated historical threat alarm information are cumulatively scored to obtain a danger score of the alarm information, and when the danger score is greater than a danger score threshold, all the associated historical threat alarm information corresponding to the alarm information are used as security event information corresponding to the alarm information.

6. The method according to claim 1, characterized in that After identifying the security event information corresponding to each alarm information based on the associated historical threat alarm information corresponding to each alarm information, the method further includes: Identify the alarm source devices of each associated alarm information corresponding to each alarm information, and generate alarm warning information corresponding to the alarm information based on the security event information corresponding to the alarm information; The alarm information corresponding to the alarm information is sent to each alarm source device respectively; the alarm information is used to control each alarm source device to execute the security prevention task corresponding to the alarm information.

7. A device for identifying the occurrence of office equipment security events, characterized in that: The device comprises: An acquisition module, used to acquire each alarm information generated by the office equipment and the historical threat alarm information of the office equipment, and identify the alarm type of each alarm information; A query module, used to query the alarm tracing strategy of each alarm information based on the alarm type of each alarm information, and identify the threat source process information corresponding to each alarm information through the alarm tracing strategy of each alarm information based on each alarm information; The identification module is used to identify the associated historical threat alarm information corresponding to each alarm information based on the threat source process information of each alarm information and the historical threat source process information of each historical threat alarm information through a multi-dimensional association identification strategy, and to identify the security event information corresponding to each alarm information based on the associated historical threat alarm information corresponding to each alarm information.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.