Multi-source heterogeneous log information semantic association matching method and system in data interaction process
By performing multi-dimensional feature extraction and semantic correlation graph construction on multi-source heterogeneous log data, combined with the independence test and association adjustment of statistical hypothesis test method, the problem of low matching accuracy in multi-source heterogeneous log data analysis is solved, and the accuracy of network behavior analysis is improved.
Patent Information
- Application Number
- CN202411733966.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-29
- Publication Date
- 2025-05-09
AI Technical Summary
During the analysis process, the matching accuracy of multi-source heterogeneous log data is low due to data loss or clock drift, which affects the accuracy of network behavior analysis.
By performing multi-dimensional feature extraction on multi-source heterogeneous log data, a semantic association graph is constructed, and independence testing and association relationship adjustment are carried out through statistical hypothesis testing method, the feature alignment and association accuracy of data sources of different time-precision are improved.
It effectively avoids the error introduced by time drift, improves the correlation accuracy of heterogeneous data sources, and ensures the accuracy and reliability of user network behavior analysis.
Smart Images

Figure CN119961635A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a method and system for semantic association matching of multi-source heterogeneous log information in a data interaction process. Background Art
[0002] With the advancement of technology, all industries and fields are undergoing digital transformation. A large number of activities, transactions and communications of organizations and individuals are carried out on digital platforms, resulting in a large amount of digital data. This wave of digitalization has brought more complex challenges to data security, and a large amount of sensitive information needs to be protected.
[0003] Analyzing users' network behavior to detect anomalies and trace security incidents is an effective way to improve data security and prevent potential threats. A normal network access process often involves interactions with multiple servers, and different types of servers usually use different structures and accuracies to generate log data. The analysis of such multi-source heterogeneous log data is prone to errors due to data loss or clock drift, resulting in low matching accuracy of heterogeneous data sources, thus affecting the accuracy of behavior analysis. Summary of the invention
[0004] In order to overcome the problem of low accuracy in behavioral analysis based on multi-source heterogeneous log data, the present invention provides a method and system for semantic association matching of multi-source heterogeneous log information in a data interaction process.
[0005] On the one hand, the present invention provides a method for semantic association matching of multi-source heterogeneous log information in a data interaction process, comprising:
[0006] Based on the multi-source heterogeneous log data obtained during the user data interaction process, multi-dimensional features are extracted respectively to obtain the multi-dimensional features corresponding to each data source;
[0007] Based on the time feature, feature matching between multi-dimensional features corresponding to different data sources is performed to build a semantic association graph between the data sources;
[0008] Based on the statistical hypothesis testing method, an independence test is performed between the feature nodes corresponding to different data sources in the semantic association graph, and based on the test result, the association relationship between the feature nodes corresponding to different data sources in the semantic association graph is adjusted to obtain the semantic association graph of the multi-source heterogeneous log data;
[0009] The multi-source heterogeneous log data includes website log data and database log data, and the multi-dimensional features corresponding to each data source include time features.
[0010] Optionally, multi-dimensional features are extracted from the multi-source heterogeneous log data obtained during the user data interaction process to obtain multi-dimensional features corresponding to each data source, including:
[0011] Extracting access path and access time fields from the website log data based on the uniform resource locator field;
[0012] Using the access time field and the path entity field of the access path as multi-dimensional features of the website log data;
[0013] Extracting operation class information and table information of an abstract syntax tree corresponding to the parsing result and log capture time from the database log data based on the parsing of the database language;
[0014] The operation class information and table information of the abstract syntax tree and the log capture time are used as multi-dimensional features of the database log data.
[0015] Optionally, after extracting multi-dimensional features from the multi-source heterogeneous log data obtained in the user data interaction process to obtain multi-dimensional features corresponding to each data source, the method further includes:
[0016] Standardize the multi-dimensional features corresponding to each data source to obtain the standardized features corresponding to each data source;
[0017] For the standardized features corresponding to each data source, a corresponding standardized feature list is formed in chronological order.
[0018] Optionally, the multidimensional features corresponding to the website log data are multiple website log features, and the multidimensional features corresponding to the database log data are multiple database log features; the feature matching between the multidimensional features corresponding to different data sources based on the time feature to construct a semantic association graph between the data sources includes:
[0019] Based on the sliding time window, the feature lists corresponding to different data sources are traversed respectively, at least one database log feature in the same time window as each website log feature is determined, and the association relationship between each website log feature and at least one database log feature is obtained;
[0020] Take each website log feature as a website feature node, and take each database log feature as a database feature node;
[0021] Based on the association relationship between each website log feature and at least one database log feature, an edge is constructed between the website feature node and the database feature node to form a semantic association graph between the data sources;
[0022] Among them, the feature lists corresponding to different data sources are formed by sorting the multi-dimensional features corresponding to each data source based on the time feature.
[0023] Optionally, after obtaining the association relationship between each website log feature and at least one database log feature, the method further includes:
[0024] Count the occurrence frequency of the same database log feature corresponding to each website log feature;
[0025] For each website log feature, the occurrence frequency of a database log feature associated with the website log feature is used as the connection strength between the website log feature and the database log feature. Based on the connection strength between the website log feature and each database log feature, the target database log feature is screened out, and the association relationship between other database log features other than the target database log feature and the website log feature is deleted.
[0026] Optionally, the independence test between feature nodes corresponding to different data sources in the semantic association graph based on a statistical hypothesis testing method includes:
[0027] An independence test between feature nodes corresponding to different data sources in the semantic association graph is performed based on the chi-square test.
[0028] Optionally, the independence test between feature nodes corresponding to different data sources in the semantic association graph based on the chi-square test includes:
[0029] A pair of website feature nodes and database feature nodes with edges are used as node pairs to be evaluated; for each node pair to be evaluated, corresponding observation events are set;
[0030] Counting the occurrence frequency of each observed event to form a contingency table corresponding to the node pair to be evaluated;
[0031] Calculate a corresponding chi-square statistic based on a contingency table corresponding to the node pair to be evaluated;
[0032] The independence between the pair of nodes to be evaluated is determined based on a comparison result between the chi-square statistic corresponding to the pair of nodes to be evaluated and a preset significance level.
[0033] Optionally, the observation events include the appearance of a first database log feature within a time window corresponding to the first website log feature, the non-appearance of the first database log feature within a time window corresponding to the first website log feature, the appearance of the first database log feature within a time window corresponding to the second website log feature, and the non-appearance of the first database log feature within a time window corresponding to the second website log feature; wherein, the first website log feature and the first database log feature correspond to the node pair to be evaluated, and the second website log feature is other website log features in the semantic association graph except the first website log feature.
[0034] Optionally, adjusting the association relationship between the feature nodes corresponding to different data sources in the semantic association graph based on the test result to obtain the semantic association matching result of the multi-source heterogeneous log data includes:
[0035] If the node pairs to be evaluated are independent of each other, deleting the edges between the independent node pairs to be evaluated;
[0036] If the node pairs to be evaluated are related to each other, the connection strength between the website log features and the database log features corresponding to the node pairs to be evaluated is used as the attribute of the edge between the node pairs to be evaluated.
[0037] Optionally, after obtaining the semantic association matching result of the multi-source heterogeneous log data, the method further includes:
[0038] A behavior analysis of the user data interaction process is performed based on the semantic association matching results of the multi-source heterogeneous log data.
[0039] Optionally, after obtaining the semantic association matching result of the multi-source heterogeneous log data, the method further includes:
[0040] Based on the key information of the security incident obtained, determining the log data source associated with the key information of the security incident using the semantic association matching result of the multi-source heterogeneous log data;
[0041] A corresponding visitor address is determined based on a log data source associated with key information of the security event.
[0042] On the other hand, the present invention also provides a semantic association matching system for multi-source heterogeneous log information in a data interaction process, comprising:
[0043] A feature extraction module is used to extract multi-dimensional features from the multi-source heterogeneous log data obtained during the user data interaction process, and obtain multi-dimensional features corresponding to each data source;
[0044] The feature matching module is used to match the multi-dimensional features corresponding to different data sources based on the time features and build a semantic association graph between the data sources;
[0045] An association relationship adjustment module is used to perform an independence test between feature nodes corresponding to different data sources in the semantic association graph based on a statistical hypothesis test method, and adjust the association relationship between feature nodes corresponding to different data sources in the semantic association graph based on the test result to obtain a semantic association matching result of the multi-source heterogeneous log data;
[0046] The multi-source heterogeneous log data includes website log data and database log data, and the multi-dimensional features corresponding to each data source include time features.
[0047] On the other hand, the present invention also provides an electronic device, comprising: at least one processor and a memory; the memory and the processor are connected via a bus;
[0048] The memory is used to store one or more programs;
[0049] When the one or more programs are executed by the at least one processor, any one of the above-mentioned methods for semantic association and matching of multi-source heterogeneous log information in a data interaction process is implemented.
[0050] On the other hand, the present invention also provides a readable storage medium having an execution program stored thereon, and when the execution program is executed, the method for semantic association matching of multi-source heterogeneous log information in a data interaction process described in any one of the above is implemented.
[0051] Compared with the prior art, the present invention has the following beneficial effects:
[0052] The present invention provides a method and system for semantic association matching of multi-source heterogeneous log information in a data interaction process. By extracting multi-dimensional features from multi-source heterogeneous log data acquired in a user data interaction process and matching multi-dimensional features corresponding to different data sources based on time features, a semantic association graph between the data sources is constructed, feature alignment of data sources with different time precisions is achieved, errors introduced by time drift are avoided, the association accuracy of heterogeneous data sources is improved, and the accuracy of user network behavior analysis is guaranteed.
[0053] The present invention performs an independence test between feature nodes corresponding to different data sources in the semantic association graph based on a statistical hypothesis test method, and adjusts the association relationship between feature nodes corresponding to different data sources in the semantic association graph based on the test result. The independence test based on the statistical hypothesis test can reduce the probability of erroneous association, thereby improving the reliability of the association relationship in the model, avoiding errors introduced by data loss or other problems, and further improving the association accuracy of heterogeneous data sources, thereby ensuring the accuracy of user network behavior analysis. BRIEF DESCRIPTION OF THE DRAWINGS
[0054] Figure 1 This is one of the flow charts of a method for semantic association matching of multi-source heterogeneous log information in a data interaction process of the present invention;
[0055] Figure 2 The second flowchart of the method for semantic association matching of multi-source heterogeneous log information in a data interaction process of the present invention;
[0056] Figure 3 It is a schematic structural diagram of the electronic device of the present invention. DETAILED DESCRIPTION
[0057] The specific implementation modes of the present invention are further described in detail below with reference to the accompanying drawings.
[0058] Embodiment 1:
[0059] The present invention provides a method for semantic association matching of multi-source heterogeneous log information in a data interaction process, as shown in the schematic diagram Figure 1 As shown, including:
[0060] Step S110, extracting multi-dimensional features from the multi-source heterogeneous log data obtained during the user data interaction process to obtain multi-dimensional features corresponding to each data source;
[0061] Step S120, performing feature matching between multi-dimensional features corresponding to different data sources based on the time feature, and constructing a semantic association graph between the data sources;
[0062] Step S130, performing an independence test between feature nodes corresponding to different data sources in the semantic association graph based on a statistical hypothesis test method, and adjusting the association relationship between feature nodes corresponding to different data sources in the semantic association graph based on the test result, to obtain a semantic association matching result of the multi-source heterogeneous log data;
[0063] In this example implementation, multi-source heterogeneous log data can be log data formed on different types of servers based on the user data interaction process (such as the user's network access behavior), and corresponding log data can be obtained from different types of servers. For example, different types of servers include at least one or more website servers (such as HTTP servers) and one or more database servers, such as SQL (Structured Query Language) database servers. Accordingly, multi-source heterogeneous log data includes website log data obtained from the website server and database log data obtained from the database server. The website log data can be a website access log, and the database log data can be an audit log of the database. The multi-dimensional features corresponding to each data source can include time features, source addresses, target addresses, and access entity information. The multi-dimensional features corresponding to different data sources can be different. The statistical hypothesis test method can be a variety of statistical test methods for independence testing. The present invention solves the problem of constructing a semantic association graph of multi-source heterogeneous log data by combining a method based on matching of time features and independence testing. By identifying the causal relationship between log events of different sources, the quality and availability of the drawn log semantic association graph are improved, making subsequent data analysis and mining more efficient and accurate, providing effective support for data security situation awareness.
[0064] In an example implementation, step S110 extracts multi-dimensional features from the multi-source heterogeneous log data of the acquired user data interaction process to obtain multi-dimensional features corresponding to each data source, including:
[0065] Extracting access path and access time fields from the website log data based on the uniform resource locator field;
[0066] Using the access time field and the path entity field of the access path as multi-dimensional features of the website log data;
[0067] Extracting operation class information and table information of an abstract syntax tree corresponding to the parsing result and log capture time from the database log data based on the parsing of the database language;
[0068] The operation class information and table information of the abstract syntax tree and the log capture time are used as multi-dimensional features of the database log data.
[0069] In this example implementation, for the website log data, all URLs and access time fields appearing in the log data can be extracted, the access path can be extracted from the URL field, and then the path entity field in the access path can be extracted. Exemplarily, the website log data can be multiple log data of an HTTP server log file, and each log data can include timestamp, source IP, source port, destination IP, destination port, request URL (uniform resource locator), request content, request length, response code, response length and other information. Regular expressions can be used to extract the corresponding request URL and timestamp for HTTP server log files from different server sources, and other information can be filtered, for example, filtering invalid requests whose response codes are not 200. Extract the path entity field of the access path of the request URL. For example, for the following URL obtained:
[0070] http: / / example.com:80 / products / item?id=123
[0071] Among them, http represents the protocol, example.com represents the host name, 80 represents the port, / products / item represents the path, and id=123 represents the query parameter. The extracted access path field is / products / item?id=123, and the corresponding path entity field is / products / item.
[0072] Taking SQL database as an example, for database log data, all SQL statements and capture time fields appearing in the database server logs from different sources can be extracted, and the SQL statements can be parsed, and then the table name and column name (table information) and action (operation class information) are extracted as SQL mode names, and the capture time field is used as SQL mode time. Exemplarily, SQL database access log files usually include multiple logs, and the multiple logs can include information such as timestamp, source IP, source port, destination IP, destination port, and request SQL. The SQL statement can be parsed, and then the table name, column name, and action are extracted as SQL mode names, and the capture time field is used as SQL mode time. For example, the SQLGlot library can be used to parse SQL statements, and the parse_one method can be used to parse the SQL statement into an abstract syntax tree (AST), obtain the class name of the parsed AST, determine the operation type of the SQL statement, and extract the table name and column name from the AST.
[0073] In an example implementation, after multi-dimensional features are extracted from the multi-source heterogeneous log data of the acquired user data interaction process to obtain the multi-dimensional features corresponding to each data source, the method further includes:
[0074] Standardize the multi-dimensional features corresponding to each data source to obtain the standardized features corresponding to each data source;
[0075] For the standardized features corresponding to each data source, a corresponding standardized feature list is formed in chronological order.
[0076] In this example implementation, the standardization process may include unifying the format of the extracted features, for example, standardizing the format of the time features, and the standardization process may also include regularization. For example, the variable part of the request URL is restored to a variable name through a regular expression, and the restored URL is used as the HTTP mode name (path feature); the access time field is used as the HTTP mode time (time feature), and the parameters in the above access path field can also be converted into formal parameter names through regular expressions, for example, common parameter names such as ID, EMAIL, UUID, etc. An HTTP mode access list (a standardized feature list corresponding to the website log data) is formed in chronological order based on the HTTP mode name and the HTTP mode time. The standardized processing for database log data may also include normalized output, for example, the output format is: action name|table name|column name, and the SQL mode name and SQL mode time are arranged in chronological order to form an SQL mode access list (a standardized feature list corresponding to the database log data).
[0077] In an example implementation, the step S120 of performing feature matching between multi-dimensional features corresponding to different data sources based on the time feature to construct a semantic association graph between the data sources includes:
[0078] Based on the sliding time window, the feature lists corresponding to different data sources are traversed respectively, at least one database log feature in the same time window as each website log feature is determined, and the association relationship between each website log feature and at least one database log feature is obtained;
[0079] Take each website log feature as a website feature node, and take each database log feature as a database feature node;
[0080] Based on the association relationship between each website log feature and at least one database log feature, an edge is constructed between the website feature node and the database feature node to form a semantic association graph between the data sources.
[0081] In this example implementation, the multi-dimensional features corresponding to each data source can be sorted based on the time feature to form a feature list corresponding to different data sources, such as the HTTP mode access list and the SQL mode access list in the above example. The multi-dimensional features corresponding to the website log data are multiple website log features, such as HTTP mode name (access path feature) and HTTP mode time (website access time); the multi-dimensional features corresponding to the database log data are multiple database log features, such as SQL mode name (action name, table name, column name) and SQL mode time (capture time). Exemplarily, the HTTP mode access list and the SQL mode access list are queried and merged based on the sliding time window, and a one-to-many connection is established between each HTTP mode with different HTTP mode names and one or more SQL modes. Specifically, for each HTTP mode time corresponding to each HTTP mode name, a corresponding HTTP mode time window is constructed, and the SQL mode is counted within the time range expressed by each HTTP mode time window, thereby forming an association relationship between the HTTP mode and the SQL mode. Each data source can correspond to a node type, and each feature corresponding to each data source corresponds to a node. Each website log feature is used as a website feature node, and each database log feature is used as a database feature node. Edges are built between feature nodes with association relationships to form a semantic association graph between different data sources. For example, the HTTP mode name and SQL mode name are used as HTTP node names and SQL node names, so that the HTTP mode and SQL mode are converted into HTTP nodes and SQL nodes in the semantic association graph.
[0082] Exemplarily, after obtaining the association relationship between each website log feature and at least one database log feature, the method further includes:
[0083] Count the occurrence frequency of the same database log feature corresponding to each website log feature;
[0084] For each website log feature, the occurrence frequency of a database log feature associated with the website log feature is used as the connection strength between the website log feature and the database log feature. Based on the connection strength between the website log feature and each database log feature, the target database log feature is screened out, and the association relationship between other database log features other than the target database log feature and the website log feature is deleted.
[0085] In this example implementation, the frequency of occurrence of each database log feature (SQL mode name) can be counted within the time range expressed by the time window of each website log feature (HTTP mode name) as the frequency of the SQL mode name under a time window of the HTTP mode name, and then the frequency of the same SQL mode name under all time windows of the HTTP mode name is accumulated, and the accumulated frequency can also be used as the connection strength of the HTTP mode-SQL mode. Traverse each HTTP mode name to form a pattern connection table consisting of HTTP mode name, SQL mode name, and HTTP mode-SQL mode connection strength. Each website log feature can be traversed, and the corresponding database log feature can be ranked according to the connection strength, and the target database log feature can be screened. For example, the top-K query method is used to screen out the database log feature with the cumulative frequency (connection strength) in the top K positions as the target data log feature. When multiple database log features with the same cumulative number of times appear, multiple database log features (SQL modes) with the same ranking can be retained, and the number of target database log features corresponding to the current website log feature obtained in the end is greater than or equal to K. The above operation is performed for each website log feature. Finally, the edges between each website log feature and the non-target database log feature in the semantic association graph are deleted, thereby deleting the associated edges with low connection strength to ensure the association reliability of the semantic association graph.
[0086] In some embodiments, the independence test between feature nodes corresponding to different data sources in the semantic association graph based on the statistical hypothesis testing method in step S130 includes: performing an independence test between feature nodes corresponding to different data sources in the semantic association graph based on the chi-square test.
[0087] In this example implementation, the chi-square test is a hypothesis testing method in statistics, which is mainly used to determine whether there is a significant difference between the observed data and the theoretical expectations, and then analyze whether the two categorical variables are independent or correlated. This example applies the chi-square test to the test of the association relationship between nodes in the semantic association graph, that is, the node independence test.
[0088] Exemplarily, the independence test process between feature nodes is:
[0089] A pair of website feature nodes and database feature nodes with edges are used as node pairs to be evaluated; for each node pair to be evaluated, corresponding observation events are set;
[0090] Counting the occurrence frequency of each observed event to form a contingency table corresponding to the node pair to be evaluated;
[0091] Calculate a corresponding chi-square statistic based on a contingency table corresponding to the node pair to be evaluated;
[0092] The independence between the pair of nodes to be evaluated is determined based on a comparison result between the chi-square statistic corresponding to the pair of nodes to be evaluated and a preset significance level.
[0093] In this example implementation, an independence test is performed on each pair of nodes to be evaluated, an observation event is set, and a corresponding contingency table is generated based on the statistical results of the observation time; illustratively, the pair of nodes to be evaluated includes a node corresponding to the first website log feature and a node corresponding to the first database log feature, then the observation event includes the first database log feature appearing in the time window corresponding to the first website log feature, the first database log feature not appearing in the time window corresponding to the first website log feature, the first database log feature appearing in the time window corresponding to the second website log feature, and the first database log feature not appearing in the time window corresponding to the second website log feature; wherein the second website log feature is the other website log feature in the semantic association graph except the first website log feature. The frequency of occurrence of each observation event is counted to form a corresponding 2×2 contingency table. Based on the contingency table, the corresponding chi-square statistic can be calculated, such as x 2 Or p-value, which is used to characterize the probability of two nodes being independent of each other. The p-value can be used as a score for the reasonableness of the edge between two nodes. The p-value can be compared with the preset significance level to determine the independence between the corresponding nodes. For example, if the p-value is greater than the preset significance level (such as 0.05), it is determined that the corresponding nodes are independent of each other; if the p-value is less than or equal to the preset significance level, it is determined that the corresponding nodes are related to each other.
[0094] Exemplarily, if the node pairs to be evaluated are independent of each other, the edges between the independent node pairs to be evaluated are deleted; if the node pairs to be evaluated are correlated with each other, the strength of the connection between the website log features and the database log features corresponding to the node pairs to be evaluated is used as the attribute of the edge between the node pairs to be evaluated. In other words, if the p-value is greater than 0.05, the result is considered insignificant, indicating that the correlation between the HTTP node and the SQL node is low, and the edge setting between the HTTP node and the SQL node is unreasonable, and the edge is deleted to form a reliable log semantic association result. Exemplarily, the chi2_contingency function of the stats module in the SciPy library can be used to perform the chi-square test.
[0095] In some implementations, after obtaining the semantic association matching result of the multi-source heterogeneous log data, the method further includes:
[0096] A behavior analysis of the user data interaction process is performed based on the semantic association matching results of the multi-source heterogeneous log data.
[0097] In this example implementation, the user's complete activity track can be analyzed based on the semantic association matching results, and the behavior pattern of the user data interaction process can be determined by comparing it with the abnormal behavior rule library, that is, normal behavior or abnormal behavior. This example can create a user's complete activity track by analyzing the semantic association matching results of the HTTP server access log (the log comes from the TAP switch in the server) and the database access log, which helps to identify normal user behavior patterns and detect abnormal activities.
[0098] In some implementations, after obtaining the semantic association matching result of the multi-source heterogeneous log data, the method further includes:
[0099] Based on the key information of the security incident obtained, determining the log data source associated with the key information of the security incident using the semantic association matching result of the multi-source heterogeneous log data;
[0100] A corresponding visitor address is determined based on a log data source associated with key information of the security event.
[0101] In this example implementation, the key information of a security incident may be access information related to security incidents such as data theft or privacy leakage, such as access registration information, access logs, or access applications. Based on the access information, it can be associated with database log features (such as database passwords) through a semantic association graph. If a password leak occurs, the visitor's IP address can be located by tracing the HTTP log of the access information to achieve the source tracing of network security incidents. This example is based on the analysis technology of the association matching results of heterogeneous log data, which can track the association between a specific event and the database, which helps to trace the source of security incidents, quickly locate and respond to potential threats, and improve response speed and efficiency.
[0102] The present invention can improve data security and prevent potential security threats by performing anomaly detection and security event tracing through behavioral analysis. The following is a specific example to illustrate the specific steps of the semantic association matching method of multi-source heterogeneous log information in a data interaction process of the present invention. Figure 2 As shown, taking HTTP access log data and SQL access log data as an example, the following process may be included:
[0103] (1) Feature extraction of HTTP log data: The corresponding regular expressions can be used to extract the request URL and timestamp from HTTP server log files from different sources, and invalid requests with response codes other than 200 can be filtered out. The variable part of the request URL can be restored to a variable name through regular expressions, and the restored URL is used as the HTTP mode name. The access time field is used as the HTTP mode time, and the HTTP log list is converted into an HTTP mode access list of HTTP mode time + HTTP mode name.
[0104] (2) Feature extraction of SQL log data: Parse the SQL statement, extract the table name, column name, and action as the SQL mode name, use the capture time field as the SQL mode time, and then convert the SQL log list into an SQL mode access list of SQL mode time + SQL mode name.
[0105] (3) Content matching between HTTP mode access list and SQL mode access list: The HTTP mode access list and SQL mode access list are queried and merged based on the sliding time window method to form a mode connection table based on the HTTP mode. The specific steps are as follows:
[0106] (a) Note {H n} is the HTTP mode access list, {S m} is the SQL mode access list, and the HTTP mode name is in the HTTP mode access list {H n} in the HTTP mode, if H n1 , H n2 , ..., H nk Have the same HTTP mode name, H n1 , H n2 , H nk are the 1st, 2nd, and kth elements in the HTTP mode access list, respectively. n1 , H n2 , ..., H nk Merge into a single HTTP mode A n , with A n HTTP Mode H nk HTTP mode time t Hnk As the center of the HTTP mode time window, l is the width of the HTTP mode time window, forming the HTTP mode time window Wt Hnk .
[0107] (b) Query SQL mode access list {S m} in SQL mode time t Sm Falls in HTTP mode time window Wt HnkIn SQL mode, if S m1 , S m2 ,...,S mk have the same SQL mode name, S m1 , S m2 , S mk are the 1st, 2nd, and kth elements in the SQL mode access list, respectively. m1 , S m2 ,...,S mk Merge into the only SQL pattern B in the HTTP pattern time window km , count its occurrence frequency f k , then added to HTTP mode A n Corresponding multiple HTTP mode time windows Wt Hnk The results in the HTTP mode time window are merged into the unique SQL mode B m , the accumulated frequency is used as HTTP mode-SQL mode connection A n -B m The connection strength.
[0108] (c) Traverse each HTTP mode name and obtain {A n -B m} is the mode connection table from the perspective of HTTP mode.
[0109] (4) Semantic association graph establishment: First, the pattern connection table {A n -B m} as the HTTP node name and SQL node name, thereby converting the deduplicated HTTP pattern and SQL pattern into the HTTP node and SQL node in the log semantic association graph G0, denoted as v i . Next, for the HTTP mode A in the mode connection table n SQL mode B of the join nk According to the connection strength f nk Ranking, using the top-K query method and retaining SQL patterns with the same join strength B K , the number of SQL patterns after filtering|{B K}|>=K, connect the filtered HTTP mode-SQL mode to A n -B k Transformed into the edge e between HTTP nodes and SQL nodes in the log semantic association graph nk . Traverse the pattern join table {A n -B m}, the obtained semantic association graph G0({v i},{e nk}).
[0110] (5) Independence test of node pairs in the semantic association graph: A statistical method is used to evaluate the correlation between HTTP nodes and SQL nodes in the log semantic association graph. nk} Rationality is scored. The specific steps are as follows:
[0111] (a) An independence test is conducted on the node pair A1-B1 consisting of HTTP node A1 and SQL node B1. The following observation events are designed: SQL pattern B1 appears within 3 minutes before and after HTTP pattern A1 appears, SQL pattern B1 does not appear within 3 minutes before and after HTTP pattern A1 appears, SQL pattern B1 appears within 3 minutes before and after other HTTP patterns appear, and SQL pattern B1 does not appear within 3 minutes before and after other HTTP patterns appear. The HTTP pattern access list {H n Each pattern in {H} is checked one by one. If an observation event occurs, the corresponding observation event count is increased by one. In this way, the HTTP pattern access list {H n} forms a 2×2 contingency table for the node pair A1-B1 consisting of HTTP node A1 and SQL node B1. n and SQL Node B k The node pair A n -B k Repeat the above operation to obtain the contingency table of each node pair.
[0112] (b) According to the results of the contingency table, an independence test method is used. In particular, a chi-square test is used to calculate the p-value of the observation results of the node pair consisting of the HTTP node and the SQL node as the score of the edge rationality of the HTTP node and the SQL node, and record it in the edge attributes of the HTTP node and the SQL node in the log semantic association graph to obtain the log semantic association graph G1 after the node independence test.
[0113] (6) Semantic association graph optimization
[0114] According to the edge attribute values of HTTP nodes and SQL nodes in the log semantic association graph G1, the edges of HTTP nodes and SQL nodes are deleted. If the significance level of 0.05 commonly used in statistics is used as the standard, the p value is greater than 0.05, which means that the result is not significant, indicating that the correlation between HTTP nodes and SQL nodes is low, and the edge setting between HTTP nodes and SQL nodes is unreasonable. The edge is deleted to form a reliable semantic association graph G1. d , which is the semantic association matching result of multi-source heterogeneous log data.
[0115] The current correlation matching analysis technology for HTTP server access logs and database access logs still has some shortcomings and challenges. The main problems include: HTTP server access logs and database access logs usually use different formats, structures and standards, so when aligning and merging, it is necessary to face the heterogeneity of data; multiple data sources may generate log data with different timestamps and precisions, and log correlation matching analysis needs to deal with the consistency issues between these data sources. Timestamp offsets and clock drifts of different data sources may introduce errors; complex correlation analysis is required in the process of constructing the log semantic correlation graph, especially in the case of multiple data sources, which may lead to information overload or misleading. Determining which associations are meaningful and how to avoid incorrect associations is a complex problem.
[0116] The present invention solves the problem of constructing a semantic association graph of multi-source heterogeneous HTTP server access log data (the logs come from the TAP switch in the server) and database access log data. By identifying the causal relationship between log events from different sources, the quality and availability of the constructed semantic association graph are improved, making subsequent data analysis and mining more efficient and accurate, and providing effective support for data security situation awareness.
[0117] The present invention effectively solves the problem of constructing a semantic association graph of multi-source heterogeneous HTTP server access log data and database access log data, and improves the quality and usability of the constructed semantic association graph by identifying the causal relationship between log events from different sources, thereby improving the association accuracy of multi-source data.
[0118] Example 2
[0119] Based on the same inventive concept, the present invention also provides a semantic association matching system for multi-source heterogeneous log information in a data interaction process, including:
[0120] A feature extraction module is used to extract multi-dimensional features from the multi-source heterogeneous log data obtained during the user data interaction process, and obtain multi-dimensional features corresponding to each data source;
[0121] The feature matching module is used to match the multi-dimensional features corresponding to different data sources based on the time features and build a semantic association graph between the data sources;
[0122] An association relationship adjustment module is used to perform an independence test between feature nodes corresponding to different data sources in the semantic association graph based on a statistical hypothesis test method, and adjust the association relationship between feature nodes corresponding to different data sources in the semantic association graph based on the test result to obtain a semantic association matching result of the multi-source heterogeneous log data;
[0123] The multi-source heterogeneous log data includes website log data and database log data, and the multi-dimensional features corresponding to each data source include time features.
[0124] In a possible implementation, the feature extraction module includes:
[0125] A website feature extraction submodule is used to extract the access path and access time fields from the website log data based on the uniform resource locator field; and use the access time field and the path entity field of the access path as multi-dimensional features of the website log data;
[0126] The database feature extraction submodule is used to extract the operation class information and table information of the abstract syntax tree corresponding to the parsing result and the log capture time from the database log data based on the parsing of the database language; and use the operation class information and table information of the abstract syntax tree and the log capture time as the multi-dimensional features of the database log data.
[0127] In a possible implementation, the feature extraction module further includes:
[0128] The standardization submodule is used to standardize the multi-dimensional features corresponding to each data source to obtain the standardized features corresponding to each data source;
[0129] The list submodule is used to form a corresponding standardized feature list in chronological order for the standardized features corresponding to each data source.
[0130] In a possible implementation, the multi-dimensional features corresponding to the website log data are multiple website log features, and the multi-dimensional features corresponding to the database log data are multiple database log features; the feature matching module includes:
[0131] A relationship determination submodule, used to traverse the feature lists corresponding to different data sources based on the sliding time window, determine at least one database log feature in the same time window as each website log feature, and obtain the association relationship between each website log feature and at least one database log feature;
[0132] A graph construction submodule is used to treat each website log feature as a website feature node and each database log feature as a database feature node; based on the association relationship between each website log feature and at least one database log feature, an edge is constructed between the website feature node and the database feature node to form a semantic association graph between the data sources;
[0133] Among them, the feature lists corresponding to different data sources are formed by sorting the multi-dimensional features corresponding to each data source based on the time feature.
[0134] In a possible implementation, the feature matching module further includes a feature screening submodule, and the feature screening submodule is used to:
[0135] Count the occurrence frequency of the same database log feature corresponding to each website log feature;
[0136] For each website log feature, the occurrence frequency of a database log feature associated with the website log feature is used as the connection strength between the website log feature and the database log feature. Based on the connection strength between the website log feature and each database log feature, the target database log feature is screened out, and the association relationship between other database log features other than the target database log feature and the website log feature is deleted.
[0137] In a possible implementation, the association relationship adjustment module includes:
[0138] The independence test submodule is used to perform independence test between feature nodes corresponding to different data sources in the semantic association graph based on the chi-square test.
[0139] In a possible implementation, the independence test submodule is specifically used for:
[0140] A pair of website feature nodes and database feature nodes with edges are used as node pairs to be evaluated; for each node pair to be evaluated, corresponding observation events are set;
[0141] Counting the occurrence frequency of each observed event to form a contingency table corresponding to the node pair to be evaluated;
[0142] Calculate a corresponding chi-square statistic based on a contingency table corresponding to the node pair to be evaluated;
[0143] Based on the comparison result of the chi-square statistic corresponding to the node pair to be evaluated and the preset significance level, the independence between the node pair to be evaluated is determined.
[0144] In a possible implementation, the observation event includes the appearance of a first database log feature within a time window corresponding to a first website log feature, the non-appearance of the first database log feature within a time window corresponding to the first website log feature, the appearance of the first database log feature within a time window corresponding to a second website log feature, and the non-appearance of the first database log feature within a time window corresponding to the second website log feature; wherein, the first website log feature and the first database log feature correspond to the node pair to be evaluated, and the second website log feature is other website log features in the semantic association graph except the first website log feature.
[0145] In a possible implementation, the association relationship adjustment module further includes a pruning submodule, and the pruning submodule is used to:
[0146] If the node pairs to be evaluated are independent of each other, deleting the edges between the independent node pairs to be evaluated;
[0147] If the node pairs to be evaluated are related to each other, the connection strength between the website log features and the database log features corresponding to the node pairs to be evaluated is used as the attribute of the edge between the node pairs to be evaluated.
[0148] In a possible implementation, the system further includes:
[0149] The analysis module is used to perform behavior analysis of the user data interaction process based on the semantic association matching results of the multi-source heterogeneous log data.
[0150] In a possible implementation, the system further includes:
[0151] The security tracing module is used to determine the log data source associated with the key information of the security event based on the key information of the security event obtained and the semantic association matching results of the multi-source heterogeneous log data; and determine the corresponding visitor address based on the log data source associated with the key information of the security event.
[0152] Example 3
[0153] like Figure 3 As shown, the present invention also provides an electronic device, which may be a computer device, a single-chip device, an intelligent mobile device, etc. The electronic device in this embodiment may include a processor, a memory, a transceiver component, etc. The memory, the processor, and the transceiver component are connected via a bus; the memory may be used to store an execution program, and an exemplary execution program may include instructions; the processor is used to execute the instructions stored in the memory. The memory may also be used to store data, which may be called and / or modified when the instructions are executed.
[0154] The processor may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. It is the computing core and control core of the terminal, which is suitable for implementing one or more instructions, and is specifically suitable for loading and executing one or more instructions in a storage medium to implement a corresponding method flow or a corresponding function, so as to implement the steps of a semantic association matching method for multi-source heterogeneous log information in a data interaction process in the above embodiment.
[0155] Example 4
[0156] Based on the same inventive concept, the present invention also provides a readable storage medium, specifically an electronic device readable storage medium (Memory), which is a memory device in an electronic device for storing programs and data. It can be understood that the storage medium here can include both built-in storage media in electronic devices and, of course, extended storage media supported by electronic devices. The storage medium provides a storage space that stores the operating system of the terminal. In addition, one or more instructions suitable for being loaded and executed by a processor are also stored in the storage space, and these instructions can be one or more execution programs (including program codes). It should be noted that the storage medium here can be a high-speed RAM memory or a non-volatile memory, such as at least one disk storage. The processor loads and executes one or more instructions stored in the storage medium, which can implement the steps of a method for semantic association matching of multi-source heterogeneous log information in a data interaction process in the above embodiment.
[0157] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0158] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0159] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0160] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0161] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit its protection scope. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the field should understand that after reading the present invention, those skilled in the art can still make various changes, modifications or equivalent substitutions to the specific implementation methods of the application, but these changes, modifications or equivalent substitutions are all within the protection scope of the claims to be approved.
Claims
1. A semantic association matching method for multi-source heterogeneous log information in a data interaction process, characterized in that: include: Based on the multi-source heterogeneous log data obtained during the user data interaction process, multi-dimensional features are extracted respectively to obtain the multi-dimensional features corresponding to each data source; Based on the time feature, feature matching between multi-dimensional features corresponding to different data sources is performed to build a semantic association graph between the data sources; Based on the statistical hypothesis test method, an independence test is performed between the feature nodes corresponding to different data sources in the semantic association graph, and based on the test result, the association relationship between the feature nodes corresponding to different data sources in the semantic association graph is adjusted to obtain the semantic association matching result of the multi-source heterogeneous log data; The multi-source heterogeneous log data includes website log data and database log data, and the multi-dimensional features corresponding to each data source include time features.
2. The method according to claim 1, characterized in that Based on the multi-source heterogeneous log data obtained during the user data interaction process, multi-dimensional features are extracted respectively to obtain the multi-dimensional features corresponding to each data source, including: Extracting access path and access time fields from the website log data based on the uniform resource locator field; Using the access time field and the path entity field of the access path as multi-dimensional features of the website log data; Extracting operation class information and table information of an abstract syntax tree corresponding to the parsing result and log capture time from the database log data based on the parsing of the database language; The operation class information and table information of the abstract syntax tree and the log capture time are used as multi-dimensional features of the database log data.
3. The method according to claim 1, characterized in that After extracting multi-dimensional features from the multi-source heterogeneous log data obtained during the user data interaction process to obtain the multi-dimensional features corresponding to each data source, the following steps are also included: Standardize the multi-dimensional features corresponding to each data source to obtain the standardized features corresponding to each data source; For the standardized features corresponding to each data source, a corresponding standardized feature list is formed in chronological order.
4. The method according to claim 1, characterized in that: The multi-dimensional features corresponding to the website log data are multiple website log features, and the multi-dimensional features corresponding to the database log data are multiple database log features; the feature matching between the multi-dimensional features corresponding to different data sources based on the time feature to construct a semantic association graph between the data sources includes: Based on the sliding time window, the feature lists corresponding to different data sources are traversed respectively, at least one database log feature in the same time window as each website log feature is determined, and the association relationship between each website log feature and at least one database log feature is obtained; Take each website log feature as a website feature node, and take each database log feature as a database feature node; Based on the association relationship between each website log feature and at least one database log feature, an edge is constructed between the website feature node and the database feature node to form a semantic association graph between the data sources; Among them, the feature lists corresponding to different data sources are formed by sorting the multi-dimensional features corresponding to each data source based on the time feature.
5. The method according to claim 4, characterized in that After obtaining the association relationship between each website log feature and at least one database log feature, the method further includes: Count the occurrence frequency of the same database log feature corresponding to each website log feature; For each website log feature, the occurrence frequency of a database log feature associated with the website log feature is used as the connection strength between the website log feature and the database log feature. Based on the connection strength between the website log feature and each database log feature, the target database log feature is screened out, and the association relationship between other database log features other than the target database log feature and the website log feature is deleted.
6. The method according to claim 4, characterized in that The independence test between the feature nodes corresponding to different data sources in the semantic association graph based on the statistical hypothesis testing method includes: An independence test between feature nodes corresponding to different data sources in the semantic association graph is performed based on the chi-square test.
7. The method according to claim 6, characterized in that The independence test between the feature nodes corresponding to different data sources in the semantic association graph based on the chi-square test includes: A pair of website feature nodes and database feature nodes with edges are used as node pairs to be evaluated; for each node pair to be evaluated, corresponding observation events are set; Counting the occurrence frequency of each observed event to form a contingency table corresponding to the node pair to be evaluated; Calculate a corresponding chi-square statistic based on a contingency table corresponding to the node pair to be evaluated; The independence between the pair of nodes to be evaluated is determined based on a comparison result between the chi-square statistic corresponding to the pair of nodes to be evaluated and a preset significance level.
8. The method according to claim 7, characterized in that The observed events include the appearance of the first database log feature within the time window corresponding to the first website log feature, the non-appearance of the first database log feature within the time window corresponding to the first website log feature, the appearance of the first database log feature within the time window corresponding to the second website log feature, and the non-appearance of the first database log feature within the time window corresponding to the second website log feature; wherein, the first website log feature and the first database log feature correspond to the node pair to be evaluated, and the second website log feature is other website log features in the semantic association graph except the first website log feature.
9. The method according to claim 8, characterized in that The adjusting the association relationship between the feature nodes corresponding to different data sources in the semantic association graph based on the test result to obtain the semantic association matching result of the multi-source heterogeneous log data includes: If the node pairs to be evaluated are independent of each other, deleting the edges between the independent node pairs to be evaluated; If the node pairs to be evaluated are related to each other, the connection strength between the website log features and the database log features corresponding to the node pairs to be evaluated is used as the attribute of the edge between the node pairs to be evaluated.
10. The method according to any one of claims 1 to 9, characterized in that: After obtaining the semantic association matching result of the multi-source heterogeneous log data, the method further includes: A behavior analysis of the user data interaction process is performed based on the semantic association matching results of the multi-source heterogeneous log data.
11. The method according to any one of claims 1 to 9, characterized in that: After obtaining the semantic association matching result of the multi-source heterogeneous log data, the method further includes: Based on the key information of the security incident obtained, determining the log data source associated with the key information of the security incident using the semantic association matching result of the multi-source heterogeneous log data; A corresponding visitor address is determined based on a log data source associated with key information of the security event.
12. A semantic association matching system for multi-source heterogeneous log information in a data interaction process, characterized in that: include: A feature extraction module is used to extract multi-dimensional features from the multi-source heterogeneous log data obtained during the user data interaction process, and obtain multi-dimensional features corresponding to each data source; The feature matching module is used to match the multi-dimensional features corresponding to different data sources based on the time features and build a semantic association graph between the data sources; An association relationship adjustment module is used to perform an independence test between feature nodes corresponding to different data sources in the semantic association graph based on a statistical hypothesis test method, and adjust the association relationship between feature nodes corresponding to different data sources in the semantic association graph based on the test result to obtain a semantic association matching result of the multi-source heterogeneous log data; The multi-source heterogeneous log data includes website log data and database log data, and the multi-dimensional features corresponding to each data source include time features.
13. The system according to claim 12, characterized in that The feature extraction module comprises: A website feature extraction submodule is used to extract the access path and access time fields from the website log data based on the uniform resource locator field; and use the access time field and the path entity field of the access path as multi-dimensional features of the website log data; The database feature extraction submodule is used to extract the operation class information and table information of the abstract syntax tree corresponding to the parsing result and the log capture time from the database log data based on the parsing of the database language; and use the operation class information and table information of the abstract syntax tree and the log capture time as the multi-dimensional features of the database log data.
14. The system according to claim 12, characterized in that The feature extraction module also includes: The standardization submodule is used to standardize the multi-dimensional features corresponding to each data source to obtain the standardized features corresponding to each data source; The list submodule is used to form a corresponding standardized feature list in chronological order for the standardized features corresponding to each data source.
15. The system according to claim 12, characterized in that The multi-dimensional features corresponding to the website log data are multiple website log features, and the multi-dimensional features corresponding to the database log data are multiple database log features; the feature matching module includes: A relationship determination submodule, used to traverse the feature lists corresponding to different data sources based on the sliding time window, determine at least one database log feature in the same time window as each website log feature, and obtain the association relationship between each website log feature and at least one database log feature; A graph construction submodule is used to treat each website log feature as a website feature node and each database log feature as a database feature node; based on the association relationship between each website log feature and at least one database log feature, an edge is constructed between the website feature node and the database feature node to form a semantic association graph between the data sources; Among them, the feature lists corresponding to different data sources are formed by sorting the multi-dimensional features corresponding to each data source based on the time feature.
16. The system according to claim 15, characterized in that The feature matching module also includes a feature screening submodule, which is used to: Count the occurrence frequency of the same database log feature corresponding to each website log feature; For each website log feature, the occurrence frequency of a database log feature associated with the website log feature is used as the connection strength between the website log feature and the database log feature. Based on the connection strength between the website log feature and each database log feature, the target database log feature is screened out, and the association relationship between other database log features other than the target database log feature and the website log feature is deleted.
17. The system according to claim 15, characterized in that The association relationship adjustment module includes: The independence test submodule is used to perform independence test between feature nodes corresponding to different data sources in the semantic association graph based on the chi-square test.
18. The system according to claim 17, characterized in that The independence test submodule is specifically used for: A pair of website feature nodes and database feature nodes with edges are used as node pairs to be evaluated; for each node pair to be evaluated, corresponding observation events are set; Counting the occurrence frequency of each observed event to form a contingency table corresponding to the node pair to be evaluated; Calculate a corresponding chi-square statistic based on a contingency table corresponding to the node pair to be evaluated; Based on the comparison result of the chi-square statistic corresponding to the node pair to be evaluated and the preset significance level, the independence between the node pair to be evaluated is determined.
19. The system according to claim 18, characterized in that The observed events include the appearance of the first database log feature within the time window corresponding to the first website log feature, the non-appearance of the first database log feature within the time window corresponding to the first website log feature, the appearance of the first database log feature within the time window corresponding to the second website log feature, and the non-appearance of the first database log feature within the time window corresponding to the second website log feature; wherein, the first website log feature and the first database log feature correspond to the node pair to be evaluated, and the second website log feature is other website log features in the semantic association graph except the first website log feature.
20. The system according to claim 19, characterized in that The association relationship adjustment module further includes a pruning submodule, and the pruning submodule is used to: If the node pairs to be evaluated are independent of each other, deleting the edges between the independent node pairs to be evaluated; If the node pairs to be evaluated are related to each other, the connection strength between the website log features and the database log features corresponding to the node pairs to be evaluated is used as the attribute of the edge between the node pairs to be evaluated.
21. The system according to any one of claims 12 to 20, characterized in that: The system further comprises: The analysis module is used to perform behavior analysis of the user data interaction process based on the semantic association matching results of the multi-source heterogeneous log data.
22. The system according to any one of claims 12 to 20, characterized in that: The system further comprises: The security tracing module is used to determine the log data source associated with the key information of the security event based on the key information of the security event obtained and the semantic association matching results of the multi-source heterogeneous log data; and determine the corresponding visitor address based on the log data source associated with the key information of the security event.
23. An electronic device, characterized in that: include: at least one processor and memory; The memory and the processor are connected via a bus; The memory is used to store one or more programs; When the one or more programs are executed by the at least one processor, the method according to any one of claims 1 to 10 is implemented.
24. A readable storage medium, characterized in that: An execution program is stored thereon, and when the execution program is executed, the method according to any one of claims 1 to 10 is implemented.