Alarm association method and device, electronic equipment and storage medium
By comparing the access information, file information and command information of terminal alarms and network alarms, the problem of inaccurate alarm association caused by different IPs in the same terminal is solved, and the accuracy and reliability of alarm associations are improved.
Patent Information
- Application Number
- CN202411988409.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-30
- Publication Date
- 2025-05-06
AI Technical Summary
The association between network alarms and terminal alarms is heavily dependent on IP, resulting in inaccurate alarm associations in the same terminal but different IPs.
By obtaining target information of terminal alarms and network alarms, access information, file information and command information are extracted, and these information are compared to determine whether they belong to the same terminal and establish an alarm relationship.
It improves the accuracy of the association between network alarms and terminal alarms, facilitates alarm analysis and troubleshooting, and avoids the inappropriate relationship method caused by excessive IP dependence.
Smart Images

Figure CN119945875A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and more specifically, to an alarm association method, device, electronic device and storage medium. Background Art
[0002] The association between network alarms and terminal alarms is heavily dependent on the Internet Protocol (IP). However, due to network deployment reasons, in many scenarios, the IP corresponding to the network alarm and the IP corresponding to the terminal alarm corresponding to the same terminal are different. Summary of the invention
[0003] In view of the above problems, the present application proposes an alarm association method, device, electronic device and storage medium.
[0004] In a first aspect, an embodiment of the present application provides an alarm association method, the method comprising: obtaining target terminal alarm information corresponding to a terminal alarm and target network alarm information corresponding to a network alarm; extracting entity information from the target terminal alarm information as first entity information, the entity information comprising at least one of access information, file information and command information; extracting entity information from the target network alarm information as second entity information; if the first entity information is the same as the second entity information, determining that the target terminal alarm information and the target network alarm information are alarm information of the same target terminal, and establishing an association between the terminal alarm and the network alarm.
[0005] In some embodiments, before the method of determining that the target terminal alarm information and the target network alarm information are alarm information of the same target terminal and establishing an association between the terminal alarm and the network alarm if the first entity information is the same as the second entity information, the method further includes: obtaining a first alarm time corresponding to the target terminal alarm information and a second alarm time corresponding to the target network alarm information; if the time difference between the first alarm time and the second alarm time is less than or equal to a preset time difference, determining that the first entity information is the same as the second entity information.
[0006] In some embodiments, if the time difference between the first alarm time and the second alarm time is less than or equal to a preset time difference, determining that the first entity information is the same as the second entity information includes: if the time difference between the first alarm time and the second alarm time is less than or equal to the preset time difference, and there is only one set of entity information that is the same in the first entity information and the second entity information, determining that the first entity information is the same as the second entity information, and determining that the target terminal alarm information and the target network alarm information are alarm information of the same target terminal, and establishing an association between the terminal alarm and the network alarm
[0007] In some embodiments, the extracting entity information from the target terminal alarm information as the first entity information includes: extracting access information from the target terminal alarm information as the first access information based on a network access relationship, the access information including at least one of a source port of network access, a destination port of network access, and an external address of network access; extracting first file information corresponding to a first file from the target terminal alarm information based on a file creation time, the first file being a newly created file; extracting first command information from a command execution log in the target terminal alarm information based on a command rule; and determining the first entity information based on the first access information, the first file information, and the first command information.
[0008] In some embodiments, the extracting entity information from the target network alarm information as the second entity information includes: extracting access information from the target network alarm information as the second access information according to a network access relationship; determining a method for extracting the second file information according to an alarm type corresponding to the network alarm; extracting the second file information from the target network alarm information based on the method for extracting the file information; extracting the second command information from the target network alarm information according to a preset command information extraction method; and determining the second entity information according to the second access information, the second file information, and the second command information.
[0009] In some embodiments, the extraction method includes a first extraction method and a second extraction method, the first extraction method is used to extract from a vulnerability information write file, and the second extraction method is used to extract from a data interaction file, and the extraction method of the file information is determined according to the alarm type corresponding to the network alarm, including: if the alarm type is a vulnerability alarm type, then determining that the extraction method of the file information is the first extraction method; the extraction method based on the file information extracts the second file information from the target network alarm information, including: based on the first extraction method, extracting the second file information from the first alarm file in the target network alarm information, the first alarm file is a vulnerability information write file; if the alarm type is not a vulnerability alarm type, then determining that the extraction method of the file information is the second extraction method; the extraction method based on the file information extracts the second file information from the target network alarm information, including: based on the second extraction method, extracting the second file information from the second alarm file in the target network alarm information, the second alarm file is a data interaction file.
[0010] In some embodiments, after extracting the target file information from the first alarm file in the target network alarm information based on the first extraction method, the method further includes: obtaining usage status information of an echo function in the target terminal, the echo function being used to feedback the acquired information; if the usage status information indicates that the echo function is in an enabled state, extracting echo file information corresponding to the target file information from the echo file according to the target file information, and determining the echo file information corresponding to the target file information as the second file information; if the usage status information indicates that the echo function is in a disabled state, determining the target file information as the second file information.
[0011] In some embodiments, the preset command information extraction method includes a command name rule and a preset matching rule, and extracting the second command information from the target network alarm information according to the preset command information extraction method includes: using the command name rule to extract the first sub-command information from the target network alarm information, and determining the target network alarm information from which the command information is not successfully extracted as the target network alarm information; obtaining the command information that matches the preset matching rule from the target network alarm information as the second sub-command information; and determining the second command information based on the first sub-command information and the second sub-command information.
[0012] In a second aspect, an embodiment of the present application provides an alarm association device, the device comprising: an alarm information acquisition module, used to obtain target terminal alarm information corresponding to a terminal alarm and target network alarm information corresponding to a network alarm; a first entity information extraction module, used to extract entity information from the target terminal alarm information as first entity information, the entity information including access information, file information and command information; a second entity information extraction module, used to extract entity information from the target network alarm information as second entity information; an association establishment module, used to determine that the target terminal alarm information and the target network alarm information are alarm information of the same target terminal if the first entity information and the second entity information meet preset conditions, and establish an association between the terminal alarm and the network alarm.
[0013] In a third aspect, an embodiment of the present application provides an electronic device, comprising: one or more processors; a memory; one or more applications, wherein the one or more applications are stored in the memory and configured to be executed by the one or more processors, and the one or more programs are configured to execute the alarm association method provided in the first aspect above.
[0014] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, in which a program code is stored. The program code can be called by a processor to execute the alarm association method provided in the first aspect above.
[0015] The solution provided by the present application, when there are network alarms and terminal alarms, respectively obtains entity information consisting of access information, file information and command information in the target network alarm information and entity information consisting of access information, file information and command information in the target terminal alarm information, and jointly determines whether the network alarm and the terminal alarm belong to the same terminal through the access information, file information and command information. When the network alarm and the terminal alarm belong to the same terminal, an association between the network alarm and the terminal alarm is established, thereby improving the accuracy of the association between the network alarm and the terminal alarm, facilitating alarm analysis and alarm troubleshooting of the network alarm and the terminal alarm, and avoiding the problem of inapplicability of the association method caused by excessive reliance on IP for alarm association. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative work.
[0017] Figure 1A flowchart of an alarm association method provided in an embodiment of the present application is shown.
[0018] Figure 2 A flowchart of an alarm association method provided in another embodiment of the present application is shown.
[0019] Figure 3 A schematic diagram of the association process of an alarm association method provided in an embodiment of the present application is shown.
[0020] Figure 4 A structural block diagram of an alarm association device provided in an embodiment of the present application is shown.
[0021] Figure 5 A structural block diagram of an electronic device provided by an embodiment of the present application for executing the alarm association method according to an embodiment of the present application is shown.
[0022] Figure 6 A storage medium provided in an embodiment of the present application and used for storing or carrying a program code for implementing the alarm association method according to an embodiment of the present application is shown. DETAILED DESCRIPTION
[0023] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application.
[0024] In view of the problems in the background technology, the inventors have proposed the alarm association method, device, electronic device and storage medium provided by the embodiments of the present application. When there are network alarms and terminal alarms, the entity information composed of access information, file information and command information in the target network alarm information and the entity information composed of access information, file information and command information in the target terminal alarm information are obtained respectively, and the access information, file information and command information are used to jointly determine whether the network alarm and the terminal alarm belong to the same terminal. When the network alarm and the terminal alarm belong to the same terminal, the association between the network alarm and the terminal alarm is established, which improves the accuracy of the association between the network alarm and the terminal alarm, facilitates the alarm analysis and alarm troubleshooting of the network alarm and the terminal alarm, and avoids the problem of inapplicability of the association method caused by over-reliance on IP for alarm association.
[0025] The following will describe in detail the alarm association method, device, electronic device and storage medium provided in the embodiments of the present application in conjunction with the accompanying drawings.
[0026] See also Figure 2 , Figure 2 The flowchart of the alarm association method provided in the embodiment of the present application is shown. The alarm association method can be applied to Figure 4The alarm association device 300 and the electronic device 100 ( Figure 5 ).
[0027] The alarm association method may specifically include the following steps:
[0028] Step S110: Acquire target terminal alarm information corresponding to the terminal alarm and target network alarm information corresponding to the network alarm.
[0029] Among them, the target terminal alarm information refers to the alarm signal sent by the terminal system when an abnormal situation occurs in the terminal device or the network used by the terminal, reminding the user or administrator to take appropriate measures. This information usually includes prompts of various abnormal situations. Terminal alarms include but are not limited to network connection problems, equipment failures, security threats and other issues. The target network alarm information refers to the notification or signal automatically sent by the network system when the device or system in the network detects an abnormal situation, in order to remind the administrator to take appropriate measures. Such abnormal situations may include network equipment failures, performance problems or other events that require attention. The purpose of the target network alarm information is to help network administrators quickly locate problems and take timely measures to solve them, thereby ensuring the stability and safe operation of the network.
[0030] The target terminal alarm information can be obtained from the alarm management system of the terminal, from the alarm log, or from the monitoring system. The target network alarm information can be obtained through the network management system. It can also be obtained from the terminal device connected to the alarm network. In the embodiment of the present application, the target network alarm information can be obtained from the target terminal. The target network alarm information can also be obtained from the network alarm log. The method for obtaining the target terminal alarm information and the target network alarm information is not specifically limited here.
[0031] Step S120: extracting entity information from the target terminal alarm information as first entity information, where the entity information includes at least one of access information, file information and command information.
[0032] The entity information refers to information related to an objectively existing object. In the embodiment of the present application, the entity information refers to information corresponding to an access entity. The access entity can be a terminal or a user.
[0033] Furthermore, access information refers to various behavioral data generated when users access network resources. Access information is not limited to various activities of users on the network, such as access source port, access destination port, access external address, etc. File information includes but is not limited to file creation information, file format information, file content and other information. Command information includes but is not limited to commands used for file management, system monitoring, network operation, etc. in various operating systems.
[0034] In this embodiment, the entity information may be extracted by using an information extraction network, and the information extraction network is trained based on the alarm information sample. The extraction method may also be to extract from the target terminal alarm information according to a preset extraction instruction, or to extract from the target terminal alarm information according to a preset naming rule. The entity information extraction method may be determined according to the actual situation, and is not specifically limited here.
[0035] Step S130: extracting entity information from the target network alarm information as second entity information.
[0036] In an embodiment of the present application, in order to establish an association between the target terminal alarm information and the target network alarm information, the entity information extracted from the target network alarm information is the same as the entity information extracted from the target terminal alarm information. The extraction method can refer to the aforementioned step S120 and will not be repeated here.
[0037] Step S140: If the first entity information is the same as the second entity information, it is determined that the target terminal alarm information and the target network alarm information are alarm information of the same target terminal, and an association is established between the terminal alarm and the network alarm.
[0038] The preset condition may be that the first entity information is the same as the second entity information, or that the first entity information is the same as the second entity information and is unique, or that the similarity between the first entity information and the second entity information reaches a similarity threshold. The preset condition is not specifically limited here.
[0039] In an embodiment of the present application, establishing an association between a terminal alarm and a network alarm may be establishing a corresponding relationship between the terminal alarm and the network alarm, or may be setting the same identifier for the terminal alarm and the network alarm. The manner of associating the network alarm and the terminal alarm is not specifically limited herein.
[0040] The solution provided in this embodiment, when there are network alarms and terminal alarms, respectively obtains entity information consisting of access information, file information and command information in the target network alarm information and entity information consisting of access information, file information and command information in the target terminal alarm information, and jointly determines whether the network alarm and the terminal alarm belong to the same terminal through the access information, file information and command information. When the network alarm and the terminal alarm belong to the same terminal, an association between the network alarm and the terminal alarm is established, thereby improving the accuracy of the association between the network alarm and the terminal alarm, facilitating alarm analysis and alarm troubleshooting of the network alarm and the terminal alarm, and avoiding the problem of inapplicability of the association method caused by excessive reliance on IP for alarm association.
[0041] See also Figure 2 , Figure 2 A flowchart of an alarm association method provided in another embodiment of the present application is shown.
[0042] Step S201: Acquire target terminal alarm information corresponding to the terminal alarm and target network alarm information corresponding to the network alarm.
[0043] For the detailed description of step S201, please refer to step S110 in the aforementioned embodiment, which will not be repeated here.
[0044] Step S202: according to the network access relationship, extract access information from the target terminal alarm information as first access information, wherein the access information includes at least one of a source port of the network access, a destination port of the network access, and an external address of the network access.
[0045] Among them, the method of extracting access information can be to extract the access information from the alarm log corresponding to the target terminal alarm information according to the source port of network access, the destination port of network access and the external address of network access, or to extract the access information from the alarm log corresponding to the target terminal alarm information using a trained access information extraction model. The access information is not specifically limited here.
[0046] Step S203: extracting first file information corresponding to the first file from the target terminal alarm information according to the file creation time, where the first file is a newly created file.
[0047] The file information includes but is not limited to file creation time, file format information, file name, etc. When a terminal alarm occurs, a new file will be created to record the alarm information. Therefore, the alarm can be determined based on whether the file information of the newly created first file exists in the target terminal alarm information.
[0048] Step S204: extracting first command information from the command execution log in the target terminal alarm information according to the command rule.
[0049] In the embodiment of the present application, the command execution log is the operation information recorded by the program during execution. This information usually includes the execution time, execution result and related system status of the command, which is helpful for subsequent troubleshooting and system auditing. Since the terminal will collect the command execution log when the terminal alarms, the command information executed when the terminal alarms can be obtained from the command execution log to improve the efficiency of obtaining command information.
[0050] Step S205: Determine the first entity information according to the first access information, the first file information and the first command information.
[0051] Step S206: extracting access information from the target network alarm information according to the network access relationship as second access information.
[0052] The method for extracting access information from the target network alarm information may refer to the method for extracting access information from the target terminal alarm information, which will not be described in detail here.
[0053] Step S207: Determine a method for extracting the second file information according to the alarm type corresponding to the network alarm.
[0054] The second file information is the same as the first file information and will not be described in detail here.
[0055] Furthermore, the alarm types include, but are not limited to, vulnerability alarms, normal alarms, and gray behavior alarms. When the network alarm is a vulnerability alarm, the alarm information will be stored in a vulnerability write file and stored in a corresponding storage location. Normal alarms and gray behavior alarms are usually alarms triggered by users. At this time, it can be determined whether the user has triggered the alarm based on the file interacted with the user. Therefore, for normal alarms and gray behavior alarms, the second file information can be extracted from the interactive file. It can be understood that the interactive file can be a file generated in response to a user interaction instruction, and the interactive file can also be a file used to store the interaction between the target terminal and the user. The interactive file is not specifically limited here.
[0056] In some embodiments, for different network alarm types, the manner in which the alarm file of the network alarm is uploaded to the target terminal is different. When the alarm type of the network alarm is a vulnerability alarm, the vulnerability alarm information will be written into the vulnerability information write file, and at this time, the second file information is extracted from the vulnerability information write file. When the alarm type of the network alarm is other alarm types, the alarm information is uploaded to the target terminal through a form that interacts with the user. Then the second file information can be extracted from the form at this time. The method for extracting the second file information is related to the alarm type and the file information corresponding to the alarm type, and the method for extracting the second file information is not specifically limited here.
[0057] Step S208: extracting the second file information from the target network alarm information based on the file information extraction method.
[0058] In some embodiments, the extraction method includes a first extraction method and a second extraction method, the first extraction method is used to extract from a file written with vulnerability information, and the second extraction method is used to extract from a data interaction file, and the method for extracting the file information is determined according to the alarm type corresponding to the network alarm, including: if the alarm type is a vulnerability alarm type, then determining that the method for extracting the file information is the first extraction method; based on the first extraction method, extracting the second file information from a first alarm file in the target network alarm information, the first alarm file being a file written with vulnerability information; if the alarm type is not a vulnerability alarm type, then determining that the method for extracting the file information is the second extraction method; based on the second extraction method, extracting the second file information from a second alarm file in the target network alarm information, the second alarm file being a data interaction file.
[0059] In an optional embodiment, after extracting the target file information from the first alarm file in the target network alarm information based on the first extraction method, the method further includes: obtaining usage status information of an echo function in the target terminal, the echo function being used to feedback the acquired information; if the usage status information indicates that the echo function is in an enabled state, extracting echo file information corresponding to the target file information from the echo file according to the target file information, and determining the echo file information corresponding to the target file information as the second file information; if the usage status information indicates that the echo function is in a disabled state, determining the target file information as the second file information.
[0060] In this embodiment, the echo function means that after the user uploads the file, the system can immediately display the uploaded content on the interface so that the user can preview or confirm the uploaded file. However, the file information used for the user to preview or confirm the upload under the echo function may be different from the file information when the user uploads, and the file stored in the target terminal is the file under the echo function. Therefore, in order to improve the accuracy of the alarm association, the echoed file information after the echo is used as the second file information.
[0061] Exemplarily, the file name corresponding to the target file is 1doc. When the echo function of the target terminal is enabled, the file name of the target file is changed according to the file naming convention corresponding to the echo function, for example, 1doc is changed to 1_2024doc. At this time, 1_2024doc is determined as the second file information. When the echo function of the target terminal is not enabled, 1doc is determined as the second file information.
[0062] Step S209: extracting second command information from the target network alarm information according to a preset command information extraction method.
[0063] In the embodiment of the present application, the method for extracting the second file information and the second command information may be the same as or different from the method for extracting the first file information and the first command information, and is not specifically limited here.
[0064] In some embodiments, the preset command information extraction method includes a command name rule and a preset matching rule, and extracting the second command information from the target network alarm information according to the preset command information extraction method includes: using the command name rule to extract the first sub-command information from the target network alarm information, and determining the target network alarm information from which the command information is not successfully extracted as the target network alarm information; obtaining the command information that matches the preset matching rule from the target network alarm information as the second sub-command information; and determining the second command information based on the first sub-command information and the second sub-command information.
[0065] In this embodiment, the command name rule may be a standard command name rule in the development language. Different development languages and development requirements may have different command name rules. The preset matching rule may be to analyze multiple command names after integrating multiple development languages and development requirements, obtain relevant regular expressions, and use regular expressions to match command information.
[0066] For example, the command executed by the rule named "whoami command execution" is whoami.
[0067] Step S210: Determine the second entity information according to the second access information, the second file information and the second command information.
[0068] Step S211: Acquire a first alarm time corresponding to the target terminal alarm information and a second alarm time corresponding to the target network alarm information.
[0069] Step S212: If the time difference between the first alarm time and the second alarm time is less than or equal to a preset time difference, it is determined that the first entity information is the same as the second entity information.
[0070] Since network alarms are affected by many factors, such as network speed, information processing speed, etc. There is a time difference between the acquisition of target network alarm information and the acquisition of target terminal alarm information. Therefore, in order to improve the accuracy of the association between terminal alarms and network alarms, it should be ensured that the time difference between the first alarm time corresponding to the target terminal alarm information and the second alarm time corresponding to the target network alarm information is within the preset time difference. Then, it is determined that the terminal corresponding to the target terminal alarm information and the terminal corresponding to the target network alarm information are the same terminal, and an association between the terminal alarm and the network alarm is established to facilitate subsequent alarm investigation and improve the accuracy of alarm investigation. For example, the preset time difference can be 3 minutes, 5 minutes, and 15 minutes. The preset time difference can be determined according to actual conditions, and the preset time difference is not specifically limited here.
[0071] In some embodiments, if the time difference between the first alarm time and the second alarm time is less than or equal to a preset time difference, then the first entity information is determined to be the same as the second entity information, including: if the time difference between the first alarm time and the second alarm time is less than or equal to the preset time difference, and there is only one set of entity information that is the same in the first entity information and the second entity information, it is determined that the first entity information is the same as the second entity information, and the target terminal alarm information and the target network alarm information are determined to be alarm information of the same target terminal, and an association between the terminal alarm and the network alarm is established.
[0072] When the time difference between the first alarm time and the second alarm time is less than or equal to the preset time difference, if there are multiple groups of second entity information that are the same as a group of first entity information or multiple groups of first entity information that are the same as a group of second entity information within the time difference, it can only be explained that within the preset time difference, there may be terminal alarm information and network alarm information of the same target terminal, but it cannot be determined which terminal alarm information of the target terminal is and which network alarm information of the target terminal is. Therefore, when the time difference between the first alarm time and the second alarm time is less than or equal to the preset time difference, there is only one group of first entity information that is the same as a group of second entity information. At this time, it can be determined that the terminal alarm information where the first entity information is located and the network alarm information where the second entity information is located are the alarm information of the same target terminal. The terminal alarm information and network alarm information of the target terminal are further determined according to the entity information within the preset time difference, thereby ensuring the accuracy of the alarm information of the target terminal.
[0073] The solution provided in this embodiment, when there are network alarms and terminal alarms, respectively obtains entity information consisting of access information, file information and command information in the target network alarm information and entity information consisting of access information, file information and command information in the target terminal alarm information, and jointly determines whether the network alarm and the terminal alarm belong to the same terminal through the access information, file information and command information. When the network alarm and the terminal alarm belong to the same terminal, an association between the network alarm and the terminal alarm is established, thereby improving the accuracy of the association between the network alarm and the terminal alarm, facilitating alarm analysis and alarm troubleshooting of the network alarm and the terminal alarm, and avoiding the problem of inapplicability of the association method caused by excessive reliance on IP for alarm association.
[0074] In conjunction with the above embodiments, please refer to Figure 3 , Figure 3 A schematic diagram of an association process of an alarm association method provided by an embodiment of the present application is shown. When there are network alarms and terminal alarms, access information, file information, and command information are extracted from the target alarm information corresponding to the network alarm and the target terminal alarm information corresponding to the terminal alarm, respectively. If within a preset time period, there is only one set of access information, file information, and command information in the target terminal alarm information that is the same as a set of access information, file information, and command information in the target network alarm information, then it is determined that the target terminal alarm information and the target network alarm information are alarm information of the same terminal, and an association between the terminal alarm and the network alarm is established, which is convenient for troubleshooting alarm problems. Moreover, by establishing alarm association through multiple information, the accuracy of alarm association can be improved.
[0075] See also Figure 4, which shows a structural block diagram of an alarm association device 300 provided in an embodiment of the present application. The alarm association device 300 is applied to an electronic device 100, and the alarm association device 300 includes: an alarm information acquisition module 310, which is used to obtain target terminal alarm information corresponding to the terminal alarm and target network alarm information corresponding to the network alarm; a first entity information extraction module 320, which is used to extract entity information from the target terminal alarm information as the first entity information, and the entity information includes at least one of access information, file information and command information; a second entity information extraction module 330, which is used to extract entity information from the target network alarm information as the second entity information; an association establishment module 340, which is used to determine that the target terminal alarm information and the target network alarm information are the alarm information of the same target terminal if the first entity information is the same as the second entity information, and establish an association between the terminal alarm and the network alarm.
[0076] In some embodiments of the present application, the alarm association device 300 also includes: an alarm time acquisition module, used to obtain a first alarm time corresponding to the target terminal alarm information, and a second alarm time corresponding to the target network alarm information; an information determination module, used to determine that the first entity information is the same as the second entity information if the time difference between the first alarm time and the second alarm time is less than or equal to a preset time difference.
[0077] In some embodiments of the present application, the information determination module includes: an association establishment submodule, which is used to determine that the first entity information is the same as the second entity information if the time difference between the first alarm time and the second alarm time is less than or equal to a preset time difference, and there is only one set of entity information that is the same in the first entity information and the second entity information, and determine that the target terminal alarm information and the target network alarm information are alarm information of the same target terminal, and establish an association between the terminal alarm and the network alarm.
[0078] In some embodiments of the present application, the first entity information extraction module 320 includes: a first access information sub-module, which is used to extract access information from the target terminal alarm information according to the network access relationship, as the first access information, the access information includes at least one of the source port of the network access, the destination port of the network access and the external address of the network access; a first file information extraction sub-module, which is used to extract first file information corresponding to the first file from the target terminal alarm information according to the file creation time, and the first file is a newly created file; a first command information extraction sub-module, which is used to extract first command information from the command execution log in the target terminal alarm information according to the command rule; a first entity information determination sub-module, which is used to determine the first entity information based on the first access information, the first file information and the first command information.
[0079] In some embodiments of the present application, the second entity information extraction module 330 includes: a second access information extraction submodule, used to extract access information from the target network alarm information as the second access information according to the network access relationship; an extraction method determination submodule, used to determine the extraction method of the second file information according to the alarm type corresponding to the network alarm; a second file information extraction submodule, used to extract the second file information from the target network alarm information based on the file information extraction method; a second command information extraction submodule, used to extract the second command information from the target network alarm information according to a preset command information extraction method; a second entity information determination submodule, used to determine the second entity information based on the second access information, the second file information and the second command information.
[0080] In some embodiments of the present application, the extraction method includes a first extraction method and a second extraction method, the first extraction method is used to extract from a vulnerability information write file, and the second extraction method is used to extract from a data interaction file, and the extraction method determination submodule includes: a first extraction method determination unit, which is used to determine that the extraction method of the file information is the first extraction method if the alarm type is a vulnerability alarm type; a second file information extraction submodule, including: a first extraction unit, which is used to extract the second file information from the first alarm file in the target network alarm information based on the first extraction method, and the first alarm file is a vulnerability information write file; a second extraction method determination unit, which is used to determine that the extraction method of the file information is the second extraction method if the alarm type is not a vulnerability alarm type; the second file information extraction submodule includes: a second extraction unit, which is used to extract the second file information from the second alarm file in the target network alarm information based on the second extraction method, and the second alarm file is a data interaction file.
[0081] In some embodiments of the present application, the extraction method determination submodule includes: an echo function status acquisition unit, used to acquire usage status information of the echo function in the target terminal, the echo function being used to feedback the acquired information; a first unit, used to extract echo file information corresponding to the target file information from the echo file according to the target file information if the usage status information indicates that the echo function is in an enabled state, and determine the echo file information corresponding to the target file information as the second file information; a second unit, used to determine the target file information as the second file information if the usage status information indicates that the echo function is in a disabled state.
[0082] In some embodiments of the present application, the preset command information extraction method includes a command name rule and a preset matching rule, and the second command information extraction submodule includes: a first sub-command information acquisition unit, used to use the command name rule to extract the first sub-command information from the target network alarm information, and determine the target network alarm information from which the command information is not successfully extracted as the target target network alarm information; a second sub-command information acquisition unit, used to obtain command information that matches the preset matching rule from the target target network alarm information as the second sub-command information; a second command information determination unit, used to determine the second command information based on the first sub-command information and the second sub-command information.
[0083] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described devices and modules can refer to the corresponding processes in the aforementioned method embodiments, and will not be repeated here.
[0084] In several embodiments provided in the present application, the coupling between modules may be electrical, mechanical or other forms of coupling.
[0085] In addition, each functional module in each embodiment of the present application can be integrated into a processing module, or each module can exist physically separately, or two or more modules can be integrated into one module. The above integrated modules can be implemented in the form of hardware or software functional modules.
[0086] A structural block diagram of an electronic device provided in an embodiment of the present application. Please refer to Figure 5, which shows a structural block diagram of an electronic device provided in an embodiment of the present application. The electronic device 100 can be an electronic device such as a computer, a server, etc. that can run an application. The electronic device 100 in the present application may include one or more of the following components: a processor 101, a memory 102, and one or more applications, wherein the one or more applications may be stored in the memory 102 and configured to be executed by one or more processors 101, and the one or more programs are configured to execute the method described in the aforementioned method embodiment.
[0087] The processor 101 may include one or more processing cores. The processor 101 uses various interfaces and lines to connect various parts of the entire electronic device 100, and executes various functions and processes data of the electronic device 100 by running or executing instructions, programs, code sets or instruction sets stored in the memory 102, and calling data stored in the memory 102. Optionally, the processor 101 can be implemented in at least one hardware form of digital signal processing (DSP), field-programmable gate array (FPGA), and programmable logic array (PLA). The processor 101 can integrate one or a combination of a central processing unit (CPU), a graphics processing unit (GPU), and a modem. Among them, the CPU mainly processes the operating system, user interface, and application programs; the GPU is responsible for rendering and drawing display content; and the modem is used to process wireless communications. It can be understood that the above-mentioned modem may not be integrated into the processor 101, but may be implemented separately through a communication chip.
[0088] The memory 102 may include a random access memory (RAM) or a read-only memory (ROM). The memory 102 may be used to store instructions, programs, codes, code sets or instruction sets. The memory 102 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for implementing at least one function (such as a touch function, a sound playback function, an image playback function, etc.), instructions for implementing the following various method embodiments, etc. The data storage area may also store data (such as a phone book, audio and video data, chat record data) created by the electronic device 100 during use.
[0089] Please refer to Figure 6, which shows a structural block diagram of a computer-readable storage medium provided in an embodiment of the present application. The computer-readable storage medium 200 stores program codes, which can be called by a processor to execute the method described in the above method embodiment.
[0090] The computer-readable storage medium 200 may be an electronic memory such as a flash memory, an EEPROM (electrically erasable programmable read-only memory), an EPROM, a hard disk, or a ROM. Optionally, the computer-readable storage medium 200 includes a non-transitory computer-readable storage medium. The computer-readable storage medium 200 has storage space for program code 210 that performs any method steps of the above method. These program codes can be read from or written to one or more computer program products. The program code 210 can be compressed, for example, in an appropriate form.
[0091] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit it. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. An alarm association method, characterized in that: The method comprises: Obtain target terminal alarm information corresponding to the terminal alarm and target network alarm information corresponding to the network alarm; Extracting entity information from the target terminal alarm information as first entity information, where the entity information includes at least one of access information, file information, and command information; Extracting entity information from the target network alarm information as second entity information; If the first entity information is the same as the second entity information, it is determined that the target terminal alarm information and the target network alarm information are alarm information of the same target terminal, and an association between the terminal alarm and the network alarm is established.
2. The method according to claim 1, characterized in that Before determining that the target terminal alarm information and the target network alarm information are alarm information of the same target terminal if the first entity information is the same as the second entity information, and establishing an association between the terminal alarm and the network alarm, the method further includes: Obtaining a first alarm time corresponding to the target terminal alarm information and a second alarm time corresponding to the target network alarm information; If the time difference between the first alarm time and the second alarm time is less than or equal to the preset time difference, it is determined that the first entity information is the same as the second entity information.
3. The method according to claim 2, characterized in that If the time difference between the first alarm time and the second alarm time is less than or equal to a preset time difference, determining that the first entity information is the same as the second entity information includes: If the time difference between the first alarm time and the second alarm time is less than or equal to the preset time difference, and there is only one set of entity information that is the same in the first entity information and the second entity information, it is determined that the first entity information is the same as the second entity information, and the target terminal alarm information and the target network alarm information are determined to be alarm information of the same target terminal, and an association between the terminal alarm and the network alarm is established.
4. The method according to claim 1, characterized in that: The extracting entity information from the target terminal alarm information as first entity information includes: Extracting access information from the target terminal alarm information as first access information according to the network access relationship, wherein the access information includes at least one of a source port of the network access, a destination port of the network access, and an external address of the network access; Extracting first file information corresponding to a first file from the target terminal alarm information according to the file creation time, where the first file is a newly created file; Extracting first command information from a command execution log in the target terminal alarm information according to a command rule; The first entity information is determined according to the first access information, the first file information, and the first command information.
5. The method according to claim 1, characterized in that The extracting entity information from the target network alarm information as second entity information includes: extracting access information from the target network alarm information according to the network access relationship as second access information; Determining a method for extracting the second file information according to the alarm type corresponding to the network alarm; Extracting the second file information from the target network alarm information based on the file information extraction method; Extracting second command information from the target network alarm information according to a preset command information extraction method; The second entity information is determined according to the second access information, the second file information and the second command information.
6. The method according to claim 5, characterized in that The extraction method includes a first extraction method and a second extraction method, the first extraction method is used to extract from a file written with vulnerability information, and the second extraction method is used to extract from a data interaction file, and the method of extracting the file information is determined according to the alarm type corresponding to the network alarm, including: If the alarm type is a vulnerability alarm type, determining that the method for extracting the file information is the first extraction method; The extracting method based on the file information, extracting the second file information from the target network alarm information, includes: Based on the first extraction method, extracting the second file information from a first alarm file in the target network alarm information, where the first alarm file is a file in which vulnerability information is written; If the alarm type is not a vulnerability alarm type, determining that the method for extracting the file information is the second extraction method; The extracting method based on the file information, extracting the second file information from the target network alarm information, includes: Based on the second extraction method, the second file information is extracted from the second alarm file in the target network alarm information, where the second alarm file is a data interaction file.
7. The method according to claim 6, characterized in that After extracting the target file information from the first alarm file in the target network alarm information based on the first extraction method, the method further includes: Acquire usage status information of an echo function in the target terminal, where the echo function is used to provide feedback on the acquired information; If the usage status information indicates that the echo function is in an enabled state, extracting echo file information corresponding to the target file information from the echo file according to the target file information, and determining the echo file information corresponding to the target file information as the second file information; If the usage status information indicates that the echo function is in a closed state, the target file information is determined as the second file information.
8. The method according to claim 5, characterized in that The preset command information extraction method includes a command name rule and a preset matching rule, and extracting the second command information from the target network alarm information according to the preset command information extraction method includes: Extracting the first sub-command information from the target network alarm information by using the command name rule, and determining the target network alarm information from which the command information is not successfully extracted as the target target network alarm information; Acquire command information matching the preset matching rule from the target network alarm information as second sub-command information; The second command information is determined according to the first sub-command information and the second sub-command information.
9. An alarm association device, characterized in that: The device comprises: An alarm information acquisition module is used to acquire target terminal alarm information corresponding to the terminal alarm and target network alarm information corresponding to the network alarm; A first entity information extraction module, configured to extract entity information from the target terminal alarm information as first entity information, wherein the entity information includes at least one of access information, file information and command information; A second entity information extraction module, used to extract entity information from the target network alarm information as second entity information; The association establishing module is used to determine that the target terminal alarm information and the target network alarm information are alarm information of the same target terminal if the first entity information is the same as the second entity information, and to establish an association between the terminal alarm and the network alarm.
10. An electronic device, characterized in that: The electronic device comprises: one or more processors; Memory; One or more application programs, wherein the one or more application programs are stored in the memory and configured to be executed by the one or more processors, and the one or more programs are configured to execute the method according to any one of claims 1 to 8.
11. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores program codes, which can be called by a processor to execute the method according to any one of claims 1 to 8.