Network threat data entry method, device, equipment and medium
Through the preset entry system, the network security equipment with multiple brands and multiple versions are connected, and the data collection and entry are optimized using microservice clusters and transmission protocols, the problem of large workload of network threat log processing is solved, the sustainable expansion and optimization of data is achieved, and the workload of network security service personnel is reduced.
Patent Information
- Application Number
- CN202510187973.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-20
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2045-02-20
AI Technical Summary
Faced with multi-brand and multi-version network security equipment, enterprises need to invest a lot of manpower to view and extract network threat logs, resulting in problems such as large workload, high repetition, complex traceability, and prone to errors in statistics.
The preset entry system establishes connections with different network security devices, uses the microservice cluster to determine the target microservice, select the appropriate transmission protocol based on the data volume and frequency of the network threat log, obtain and extract key information, bind it with the device information, and save it to the local data warehouse.
It reduces the workload of network security service personnel, realizes sustainable data expansion and optimization, simplifies the data screening and query process, and improves work efficiency.
Smart Images

Figure CN119966742A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security, and in particular to a method, device, equipment and medium for entering network threat data. Background Art
[0002] Currently, there are more and more network security manufacturers in the market, and enterprises may purchase network security equipment from multiple manufacturers at the same time. Faced with network security equipment of multiple brands and versions, enterprises need to invest more network security service personnel to check the network threat logs generated by network security equipment one by one and extract effective information. Therefore, there are problems such as large workload, high repetition, complex tracing and easy statistical errors.
[0003] In the prior art, network threat logs from different network security devices are collected, pre-processed, and stored for subsequent search and viewing by network security service personnel. However, since network security devices from different manufacturers and versions will generate various types of network threat logs, upgrading or expanding the version of network security devices in the system may cause compatibility issues.
[0004] Therefore, how to achieve sustainable expansion and sustainable optimization of data collection and entry while reducing the workload of network security service personnel is an urgent problem to be solved. Summary of the invention
[0005] In view of this, the purpose of the present invention is to provide a network threat data extraction method for realizing sustainable expansion and sustainable optimization of data collection and entry while reducing the workload of network security service personnel. The specific scheme is as follows:
[0006] In a first aspect, the present application provides a network threat data entry method, which is applied to a preset entry system, wherein the preset entry system establishes connections with different network security devices through different network ports; wherein the method comprises:
[0007] Determine a target network security device from each of the network security devices to extract data, and determine a target microservice corresponding to the target network security device from a local preset microservice cluster;
[0008] Based on the data volume and log transmission frequency of the network threat log in the target network security device, determine a corresponding target transmission protocol from a preset transmission protocol set;
[0009] The network port corresponding to the target network security device is monitored by the target microservice and using a preset port monitoring instance, and a target network threat log of the target network security device monitored is obtained through a target transmission protocol;
[0010] Extract target key information from the target network threat log based on preset information extraction rules through the target microservice; the target key information includes attacker key information, attacked key information, network attack behavior information, network attack domain name information, protection behavior information corresponding to the network attack behavior, key request information corresponding to the target network request carrying the network attack, and key response information;
[0011] The target key information is bound to the device information of the target network security device through the target microservice, and the bound information is saved in a local preset data warehouse.
[0012] Optionally, determining a corresponding target transmission protocol from a preset transmission protocol set based on the data volume and log transmission frequency of the network threat log in the target network security device includes:
[0013] When the data volume is larger than a preset amount and the log frequency is larger than a preset frequency, determining that the target transmission protocol is the TCP protocol;
[0014] When the data volume is not greater than a preset amount and the log frequency is not greater than a preset frequency, it is determined that the target transmission protocol is the UDP protocol.
[0015] Optionally, the monitoring the network port corresponding to the target network security device by using the target microservice and a preset port monitoring instance, and obtaining the monitored target network threat log of the target network security device through a target transmission protocol, includes:
[0016] The target microservice is used to monitor the network port corresponding to the target network security device using DatagramSocket, and the target network threat log of the target network security device monitored is obtained through the UDP protocol;
[0017] Or, the network port corresponding to the target network security device is monitored by the target microservice using Socket, and the target network threat log of the monitored target network security device is obtained through the TCP protocol.
[0018] Optionally, extracting target key information from the target network threat log based on a preset information extraction rule by the target microservice includes:
[0019] Perform keyword segmentation on the target network threat log based on the split function through the target microservice to extract the target key information;
[0020] Or, the target network threat log is formatted by the target microservice based on the JSONObject function to extract the target key information;
[0021] Or, the target key information is extracted from the target network threat log based on a regular expression through the target microservice.
[0022] Optionally, binding the target key information with the device information of the target network security device through the target microservice includes:
[0023] The target key information is bound to the device IP, device name, device port, device type, creation time and unique identifier of the target network security device through the target microservice.
[0024] Optionally, after the binding information is saved in a local preset data warehouse, the method further includes:
[0025] Based on a query condition, the bound information in the preset data warehouse is queried and exported; the query condition is the target key information or the device information.
[0026] Optionally, the attacker's key information includes source IP, source port, and source MAC; the victim's key information includes target IP, target port, and target MAC; the network attack behavior information includes attack type, threat level, attack status, and occurrence time; the network attack domain name information includes domain name and XFF header; the protection behavior information corresponding to the network attack behavior includes protection action; the key request information and key response information corresponding to the target network request carrying the network attack include url, host, and HTTP protocol request method, request body, request header, response body, and response header.
[0027] In a second aspect, the present application provides a network threat data entry device, which is applied to a preset entry system, wherein the preset entry system establishes connections with different network security devices through different network ports; wherein the device comprises:
[0028] A microservice determination module, used to determine a target network security device to be extracted from each of the network security devices, and determine a target microservice corresponding to the target network security device from a local preset microservice cluster;
[0029] A protocol determination module, configured to determine a corresponding target transmission protocol from a preset transmission protocol set based on the data volume and log transmission frequency of the network threat log in the target network security device;
[0030] A log acquisition module, used to monitor the network port corresponding to the target network security device through the target microservice and using a preset port monitoring instance, and obtain the monitored target network threat log of the target network security device through a target transmission protocol;
[0031] An information extraction module is used to extract target key information from the target network threat log based on preset information extraction rules through the target microservice; the target key information includes attacker key information, attacked key information, network attack behavior information, network attack domain name information, protection behavior information corresponding to the network attack behavior, key request information corresponding to the target network request carrying the network attack, and key response information;
[0032] The information saving module is used to bind the target key information with the device information of the target network security device through the target microservice, and save the bound information to a local preset data warehouse.
[0033] In a third aspect, the present application provides an electronic device, including:
[0034] Memory, used to store computer programs;
[0035] The processor is used to execute the computer program to implement the above-mentioned network threat data entry method.
[0036] In a fourth aspect, the present application provides a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the above-mentioned network threat data entry method is implemented.
[0037] In the present application, the preset entry system includes establishing connections with different network security devices through different network ports, and different network security devices correspond to a separate microservice in the preset microservice cluster of the preset entry system. The appropriate target transmission protocol is determined in the preset transmission protocol based on the size of a single data item of the network security device and the frequency of log transmission; the target microservice continuously monitors the network port connected to the target network security device, and obtains the target network threat log of the target network security device through the target transmission protocol; the target microservice extracts target key information including attacker key information, attacked key information, network attack behavior information, network attack domain name information, protection behavior information corresponding to the network attack behavior, key request information corresponding to the target network request carrying the network attack, and key response information from the target network threat log based on preset information extraction rules; the above-mentioned target key information is bound to the device information of the target network security device through the target microservice, and the bound information is saved to the local preset data warehouse. As can be seen from the above, the input system contains multiple microservice modules, each of which corresponds to a network security device, forming a distributed cluster architecture. The microservice module only collects and processes the data byte stream sent by a network security device to obtain a readable network threat log. At this time, if the network security device in the system changes the type of network threat log due to version upgrade or model replacement, it is only necessary to replace the corresponding microservice module, so sustainable expansion and sustainable optimization can be achieved. In addition, after the microservice module extracts the information field in the network threat log, it only binds the key information with the relevant information of the corresponding network security device and enters it into the data warehouse, so that network security service personnel can omit the time of screening data, and directly query and export the required key information in the data warehouse by setting query conditions for subsequent operations, which greatly reduces the workload. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying creative work.
[0039] Figure 1 A flowchart of a network threat data entry method disclosed in this application;
[0040] Figure 2 The technical architecture of the network threat data entry method disclosed in this application;
[0041] Figure 3 A diagram of the microservice steps disclosed in this application;
[0042] Figure 4 A flowchart of a specific network threat data entry method disclosed in this application;
[0043] Figure 5 A schematic diagram of a network threat data entry device disclosed in this application;
[0044] Figure 6 This is a structural diagram of an electronic device disclosed in this application. DETAILED DESCRIPTION
[0045] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0046] Currently, there are more and more network security manufacturers in the market, and enterprises may purchase network security equipment from multiple manufacturers at the same time. Faced with network security equipment of multiple brands and versions, enterprises need to invest more network security service personnel to check the network threat logs generated by network security equipment one by one and extract effective information. Therefore, there are problems such as large workload, high repetition, complex tracing and easy statistical errors.
[0047] Therefore, in the prior art, network threat logs from different network security devices are collected and stored after preprocessing so that network security service personnel can search and view them later. However, since network security devices from different manufacturers and different versions will generate various types of network threat logs, upgrading or expanding the version of network security devices in the system may cause compatibility issues.
[0048] To this end, the present application provides a network threat data entry method to reduce the workload of network security service personnel while achieving sustainable expansion and sustainable optimization of data collection and entry.
[0049] See also Figure 1 As shown, an embodiment of the present invention discloses a method for entering network threat data, which may include:
[0050] Step S11: determining a target network security device to be extracted from each of the network security devices, and determining a target microservice corresponding to the target network security device from a local preset microservice cluster;
[0051] In this embodiment, in a network security device connected to the entry system, a target security device waiting to be extracted is determined, and a target microservice corresponding to the target security device in a local preset microservice cluster is determined.
[0052] Among them, each network security device is connected to the preset entry system through different network interfaces. Network security devices include IP protocol cipher machines, security routers, line cipher machines, firewalls, etc. They are important tools to ensure network security. They can prevent unauthorized access, detect and resist network attacks, and monitor and record network activities.
[0053] It should be noted that the microservices in the preset microservice cluster run relatively independently, such as Figure 2 As shown, in the data layer of the preset entry system, each network security device corresponds to a microservice one by one. The working process of a single microservice will not affect other microservices. Even if a microservice fails, due to its independence, it will not cause the entire system to crash like a single application.
[0054] In addition, since the network threat logs generated by different network security vendors and different versions of network security devices have different formats, in order to adapt to the corresponding network security devices, the target microservice also needs to select the appropriate transmission protocol, port monitoring instance, and information extraction rules according to the format of the network threat logs generated by the network security device.
[0055] Step S12: determining a corresponding target transmission protocol from a preset transmission protocol set based on the data volume and log transmission frequency of the network threat log in the target network security device;
[0056] In this embodiment, the target transmission protocol to be used is determined according to the amount of a single data item in the network threat log in the target network security device and the transmission frequency.
[0057] In this embodiment, when the data volume is greater than a preset number and the log frequency is greater than a preset frequency, the target transmission protocol is determined to be the TCP protocol (Transmission Control Protocol); when the data volume is not greater than a preset number and the log frequency is not greater than a preset frequency, the target transmission protocol is determined to be the UDP protocol (User Datagram Protocol). It should be noted that the TCP protocol is a connection-oriented, reliable, byte stream-based transport layer protocol. For a single network threat log with a large data volume and a high transmission frequency, the integrity and accuracy of the data are crucial. Any data loss or error may affect the accurate analysis and judgment of network threats. Therefore, when the data volume and log frequency of the network threat log to be received are greater than the preset value, the TCP protocol is selected as the target transmission protocol. UDP is a connectionless transport layer protocol. For network threat logs with a small data volume and a low transmission frequency, there is no need to frequently establish and maintain connections, and data can be sent out faster, improving transmission efficiency. In addition, compared with the 20 bytes or more of the TCP header, the UDP header is only 8 bytes, which can carry more valid data in a limited amount of data, and is suitable for log transmission with a small amount of data, which can improve the utilization of network bandwidth. Therefore, when the data volume and log frequency of the network threat log to be received are not greater than the preset value, the UDP protocol is selected as the target transmission protocol.
[0058] Step S13: monitoring the network port corresponding to the target network security device through the target microservice and using a preset port monitoring instance, and obtaining the monitored target network threat log of the target network security device through a target transmission protocol;
[0059] In this embodiment, in order to identify and receive requests for its own services, the target microservice needs to use a preset port listening instance to listen to the network port connected to the target network security port, and obtain the network threat log generated by the target network security port based on the above-mentioned target transmission protocol.
[0060] In order to monitor the network port, the selected preset port monitoring instance can be determined based on the above-mentioned target transmission protocol. In a specific implementation, the network port corresponding to the target network security device is monitored through the target microservice and using DatagramSocket, and the target network threat log of the target network security device monitored is obtained through the UDP protocol. It should be noted that DatagramSocket is a communication socket specially designed for the UDP protocol, and its operation is fully in line with the characteristics of the UDP protocol, such as directly sending and receiving datagrams, and does not guarantee the order, integrity and reliability of the data. DatagramSocket realizes UDP communication by operating DatagramPacket, i.e., datagram packets. When sending data, the data is encapsulated into a DatagramPacket, and then the datagram is sent out through the DatagramSocket; when receiving data, the DatagramSocket listens on the specified port and extracts data from the received DatagramPacket for processing.
[0061] In another specific implementation, the network port corresponding to the target network security device is monitored by the target microservice and using Socket, and the target network threat log of the target network security device monitored is obtained through the TCP protocol. It should be noted that the TCP protocol is a connection-oriented, reliable, byte stream-based transport layer protocol, and Socket plays the role of a protocol adaptation layer to a certain extent. Socket can convert the communication requirements of the application layer into operations that can be understood by the underlying network protocol. For example, in TCP-based Socket communication, Socket will handle the three-way handshake in the TCP protocol to establish a connection, sequence number management during data transmission, confirmation response, and four waves to close the connection. Therefore, you only need to use the interface provided by Socket without directly processing the complex details of the TCP protocol to achieve data sending and receiving.
[0062] It should be noted that the target network threat log obtained by the microservice from the network security device is a data byte stream, not a readable form of the microservice. Figure 3 As shown, after obtaining the data byte stream corresponding to the target network threat log generated by the target network security device through the above-mentioned target transmission protocol TCP or UDP, it is also necessary to convert the above-mentioned data byte stream into a string through GBK or UTF-8 encoding through the encoding method provided by the network security manufacturer. If the target network threat log is encrypted, it is also necessary to decrypt the above-mentioned string into a readable log based on the encryption method provided by the network security manufacturer.
[0063] Step S14: extract target key information from the target network threat log through the target microservice based on preset information extraction rules; the target key information includes attacker key information, attacked key information, network attack behavior information, network attack domain name information, protection behavior information corresponding to the network attack behavior, key request information corresponding to the target network request carrying the network attack, and key response information;
[0064] In this embodiment, by presetting information extraction rules, the target microservice can extract target key information from the target network threat log obtained above. It is understandable that the network threat log may contain a large amount of information, and its format and content are often very complicated, including many details that are not critical for analyzing specific network threats. Therefore, after extracting the target network threat log and obtaining all the information, in order to improve the efficiency of analyzing network threats, it is also necessary to extract target important information from all the information.
[0065] In addition, since the formats of network threat logs vary, in order to obtain all the information of the target network threat log, such as Figure 3 As shown, after converting and decrypting the acquired target network threat log, it is also necessary to extract the information field of the target network threat log based on the corresponding network threat log interpretation provided by the network security equipment manufacturer. It can be understood that the method of extracting information includes split function, JSONObject function, regular expression, etc., and all the information in the target network threat log can be extracted by using one or a combination of them.
[0066] In the first specific implementation, the target microservice performs keyword segmentation on the target network threat log based on the split function to extract the target key information. It is understandable that the network threat log usually has a certain format, and the information is separated by a specific delimiter. For example, in the common Syslog format log, different parts such as the timestamp, device identifier, message level, and event description may use spaces as delimiters. The main function of the split function is to split a string into multiple substrings according to the specified delimiter and return a list containing these substrings. Therefore, for the above-mentioned Syslog format network threat log, using the split function, it can be split according to spaces to obtain a list containing each part, and the target key information can be extracted based on the list.
[0067] In a second specific implementation, the target network threat log is formatted based on the JSONObject function by the target microservice to extract the target key information. It is understandable that the target network threat log may be in the standard JSON (JavaScript Object Notation, JS key-value pair data) format. Data in JSON format has a hierarchical structure and consists of key-value pairs, where the key is a string and the value can be a string, number, Boolean value, array, object and other data types. The JSONObject function is a tool specifically used to process JSON data. It can understand the hierarchical structure of JSON and the representation of key-value pairs to easily access and extract information from the target network threat log, rather than further screening out the target key information.
[0068] In a third specific implementation, the target key information is extracted from the target network threat log based on a regular expression by the target microservice. When it is necessary to extract information with a specific pattern from the log, regular expressions can also be used directly. Regular expressions are a tool for describing character patterns that allow users to define a series of rules to match specific patterns in text. In network threat logs, information usually has a certain pattern. For example, IP addresses follow specific numeric combinations and separator patterns, dates and times also have common formats, and attack types may contain specific keywords. By using regular expressions, these patterns can be precisely defined, so that information that meets the pattern can be found from complex log texts and target key information can be determined.
[0069] In this embodiment, the attacker's key information includes the source IP, source port, and source MAC; the attacked key information includes the target IP, target port, and target MAC; the network attack behavior information includes the attack type, threat level, attack status, and occurrence time; the network attack domain name information includes the domain name and the XFF (X-Forwarded-For, HTTP request header field) header; the protection behavior information corresponding to the network attack behavior includes the protection action; the key request information and key response information corresponding to the target network request carrying the network attack include the url (Uniform Resource Locator), host, and the HTTP protocol request method, request body, request header, response body, and response header.
[0070] Among them, the source IP, source port, and source MAC in the attacker's key information can be used to identify the initiator of the network attack, and it is possible to track whether the attack comes from the internal network or the external network. If a large amount of malicious traffic is detected to come from the same external IP address, measures can be taken to block it or further investigate its source.
[0071] The target IP, target port, and target MAC in the key information of the attacked party can determine the target under attack and help evaluate which network resources (such as servers, databases, key application systems, etc.) are at risk. For example, when the target IP corresponds to the core database server of the enterprise, it is necessary to immediately take higher-level defense and protection measures and evaluate the possible data leakage risk.
[0072] Network attack behavior information includes attack type, threat level, attack status, and occurrence time. Among them, clarifying the attack type is crucial to choosing an appropriate response strategy. Different types of attacks require different defense and mitigation measures. For example, for SQL (Structured Query Language) injection attacks, it is necessary to check and repair the application's database query statements; for malware infection, malware removal and system reinforcement may be required.
[0073] Network attack domain information includes domain name and XFF. Among them, domain name plays a key role in tracing the source of network attacks. When a malicious domain name appears in the network threat log, security service personnel can track the attacker through the domain name registration information. Different network attacks may use the same malicious domain name as the command and control center, so by analyzing the domain name related logs, security service personnel can associate multiple seemingly independent attack events. The XFF header information can help security service personnel more accurately analyze the source and path of network traffic.
[0074] In addition, the key request information and key response information corresponding to the target network request carrying the network attack can also help security service personnel analyze the network threat situation. Among them, the URL can help security service personnel determine the entry point of the attack. At the same time, establishing a malicious URL blacklist can not only identify malicious attacks, but also help discover new threat patterns. Host helps to identify the target of the attack, distinguish the attacks on different servers, and adjust the security policy in a targeted manner based on its service classification.
[0075] The HTTP protocol request method can help security service personnel distinguish operation types, check whether the operation permissions are compliant, whether they are within the scope of user permissions, and ensure compliance with relevant laws and regulations and standards. The HTTP protocol request body is an important basis for detecting injection attacks and data tampering risks; the HTTP protocol request header can be used to verify user credentials and identify unauthorized access attempts to detect identity theft or abuse of permissions. The HTTP protocol response body can determine whether the attack is successful and evaluate the degree of data leakage; the HTTP protocol response header can evaluate the health of the server and check the implementation of security policies;
[0076] Step S15: Bind the target key information with the device information of the target network security device through the target microservice, and save the bound information to a local preset data warehouse.
[0077] In this embodiment, Figure 2 As shown, in the data layer of the preset input system, after obtaining the target key information, it is also necessary to bind the target key information with the device information of the target network security device and store it in the local preset data warehouse. It can be understood that binding the target key information with the device information of the target network security device can help trace the source of the network threat.
[0078] Furthermore, as the first line of defense for network security protection, network security devices record information such as the in and out status of network traffic, detection of abnormal behavior, etc. For example, when a malicious IP address is found attempting to attack, by binding with the firewall device, it is possible to view how the IP address breaks through the firewall rules or under which firewall policy it is detected, which helps to understand the attack path and the means that the attacker may use.
[0079] In this embodiment, the bound target key information is stored in the data warehouse, which can coordinate the management of network threat logs generated by different network security devices, and reduce the workload of security service personnel in collecting and analyzing data. In addition, the information recorded by each network security device is only a partial perspective of the network security status. For example, the firewall log mainly records network access control information, including allowed or denied connections, source IP and destination IP, etc.; the IDS log focuses on the details of detecting intrusion behaviors, such as attack types, attack signatures, etc. Storing information from these different sources in the same data warehouse can integrate these partial perspectives, thereby gaining a more comprehensive understanding of the network security situation.
[0080] It is understandable that the data warehouse stores network security history records consisting of target key information of multiple network threat log information. By analyzing these network security history records, the long-term trend and changing rules of network threats can be discovered.
[0081] As can be seen from the above, the input system contains multiple microservice modules, each microservice module corresponds to a network security device, forming a distributed cluster architecture. The microservice module only collects and processes the data byte stream sent by a network security device to obtain a readable log. At this time, if the network security device in the system changes the type of network threat log due to version upgrade or model replacement, it is only necessary to replace the corresponding microservice module, so sustainable expansion and sustainable optimization can be achieved. In addition, after the microservice module extracts the information field in the network threat log, it only binds the key information with the relevant information of the corresponding network security device and enters it into the data warehouse, so that network security service personnel can omit the time of screening data, and directly query and export the required key information in the data warehouse by setting query conditions for subsequent operations, which greatly reduces the workload.
[0082] refer to Figure 4 As shown, in order to improve the work efficiency of security service personnel and ensure the comprehensiveness of analysis results, the embodiment of the present application further provides a specific network threat data entry method, which may include:
[0083] Step S21: determining a target network security device to be extracted from each of the network security devices, and determining a target microservice corresponding to the target network security device from a local preset microservice cluster;
[0084] Step S22: determining a corresponding target transmission protocol from a preset transmission protocol set based on the data volume and log transmission frequency of the network threat log in the target network security device;
[0085] Step S23: monitor the network port corresponding to the target network security device through the target microservice and using a preset port monitoring instance, and obtain the monitored target network threat log of the target network security device through a target transmission protocol;
[0086] Step S24, extracting target key information from the target network threat log through the target microservice based on preset information extraction rules; the target key information includes attacker key information, attacked key information, network attack behavior information, network attack domain name information, protection behavior information corresponding to the network attack behavior, key request information corresponding to the target network request carrying the network attack, and key response information;
[0087] Step S25: Bind the target key information with the device IP, device name, device port, device type, creation time and unique identifier of the target network security device through the target microservice, and save the bound information to a local preset data warehouse.
[0088] In this embodiment, the device IP, device name, device port, device type, creation time and unique identifier of the target network security device are bound to the target key information and uniformly stored in a local preset data warehouse.
[0089] Among them, security service personnel can determine the specific network security device that the attack traffic passes through through the device IP of the target network security device, thereby constructing the attack path, and combining it with the device name, it can also help security personnel quickly locate specific devices in a complex network environment and clarify the role of different types of devices in attack events. In addition, the device name can also be combined with the unique identifier to ensure that the target key information stored in the preset data warehouse is consistent with the corresponding target network security device configuration.
[0090] The device type and port information can help security service personnel evaluate whether the existing security policies are effective based on the bound target key information. For example, for services corresponding to specific ports that are frequently attacked, firewall rules or intrusion detection rules can be strengthened in a targeted manner.
[0091] Additionally, since older devices may present more security risks, creation time can also be used as a factor when security services personnel conduct risk assessments on target security devices.
[0092] Step S26: Based on a query condition, query and export the bound information in the preset data warehouse; the query condition is the target key information or the device information.
[0093] In this embodiment, Figure 2 As shown, at the application layer of the preset input system, the preset data warehouse can filter and export the bound information that meets the requirements based on the query conditions and display it to the security service personnel. It can be understood that the query conditions can be one or more of the target key information or device information.
[0094] It can be understood that by querying the preset data warehouse based on target key information and device information, not only can possible security threats be quickly screened out, which helps to intercept them before they cause serious damage, but also after confirming the security threat, the queried relevant target key information and device information can be used for accurate emergency response.
[0095] Furthermore, based on the query and extraction functions in the preset data warehouse, different target key information in the network threat log can be correlated and analyzed with the device information of the target network security device. It is also possible to query and trace past security events to find similar attack patterns or device anomalies, so as to help security service personnel clearly depict the full picture of the attack, including the attack path, attack means and possible attack targets, and find the cause of the security vulnerability. For example, by extracting all target key information related to a specific device in the past period of time and the bound device information, analyze the configuration changes and traffic pattern changes of the device before and after each security incident, so as to find out the root cause of the security vulnerability, such as device configuration errors, compatibility issues after software updates, etc.
[0096] Among them, the specific implementation process of steps S21 to S24 can refer to the corresponding content disclosed in the above-mentioned embodiments, and will not be repeated here.
[0097] From the above, it can be concluded that the bound information is saved in the preset data warehouse. At this time, the preset data warehouse also saves the target key information and device information generated at different times and by different devices, so that security service personnel can filter the data in the preset data warehouse based on the target key information and specific query conditions in the device information to obtain more accurate and comprehensive data, thereby speeding up work efficiency and ensuring the comprehensiveness of the analysis results.
[0098] Accordingly, see Figure 5 As shown, the embodiment of the present application also provides a network threat data entry device, which is applied to a server and may include:
[0099] A microservice determination module 11 is used to determine a target network security device to be extracted from each of the network security devices, and to determine a target microservice corresponding to the target network security device from a local preset microservice cluster;
[0100] The protocol determination module 12 is used to determine the corresponding target transmission protocol from the preset transmission protocol set based on the data volume and log transmission frequency of the network threat log in the target network security device;
[0101] The log acquisition module 13 is used to monitor the network port corresponding to the target network security device through the target microservice and using a preset port monitoring instance, and obtain the monitored target network threat log of the target network security device through a target transmission protocol;
[0102] The information extraction module 14 is used to extract target key information from the target network threat log based on preset information extraction rules through the target microservice; the target key information includes attacker key information, attacked key information, network attack behavior information, network attack domain name information, protection behavior information corresponding to the network attack behavior, key request information corresponding to the target network request carrying the network attack, and key response information;
[0103] The information saving module 15 is used to bind the target key information with the device information of the target network security device through the target microservice, and save the bound information to a local preset data warehouse.
[0104] As can be seen from the above, the input system contains multiple microservice modules, each microservice module corresponds to a network security device, forming a distributed cluster architecture. The microservice module only collects and processes the data byte stream sent by a network security device to obtain a readable log. At this time, if the network security device in the system changes the type of network threat log due to version upgrade or model replacement, it is only necessary to replace the corresponding microservice module, so sustainable expansion and sustainable optimization can be achieved. In addition, after the microservice module extracts the information field in the network threat log, it only binds the key information with the relevant information of the corresponding network security device and enters it into the data warehouse, so that network security service personnel can omit the time of screening data, and directly query and export the required key information in the data warehouse by setting query conditions for subsequent operations, which greatly reduces the workload.
[0105] In some specific implementations, the protocol determination module 12 includes:
[0106] A first protocol determination unit, configured to determine that the target transmission protocol is the TCP protocol when the data volume is greater than a preset amount and the log frequency is greater than a preset frequency;
[0107] The second protocol determination unit is used to determine that the target transmission protocol is the UDP protocol when the data volume is not greater than a preset amount and the log frequency is not greater than a preset frequency.
[0108] In some specific implementations, the log acquisition module 13 includes:
[0109] A first log acquisition unit is used to monitor the network port corresponding to the target network security device through the target microservice and using DatagramSocket, and obtain the monitored target network threat log of the target network security device through the UDP protocol;
[0110] The second log acquisition unit is used to monitor the network port corresponding to the target network security device through the target microservice and using Socket, and obtain the monitored target network threat log of the target network security device through the TCP protocol.
[0111] In some specific implementations, the information extraction module 14 includes:
[0112] A first information extraction unit is used to perform keyword segmentation on the target network threat log based on a split function through the target microservice to extract the target key information;
[0113] A second information extraction unit is used to format the target network threat log based on the JSONObject function through the target microservice to extract the target key information;
[0114] The third information extraction unit is used to extract the target key information from the target network threat log based on a regular expression through the target microservice.
[0115] In some specific implementations, the information storage module 15 includes:
[0116] The information storage unit is used to bind the target key information with the device IP, device name, device port, device type, creation time and unique identifier of the target network security device through the target microservice.
[0117] In some specific implementations, the network threat data entry device further includes:
[0118] An information query unit is used to query and export the bound information in the preset data warehouse based on a query condition; the query condition is the target key information or the device information.
[0119] In some specific embodiments, in the information extraction module 14, the attacker's key information includes source IP, source port, and source MAC; the attacked key information includes target IP, target port, and target MAC; the network attack behavior information includes attack type, threat level, attack status, and occurrence time; the network attack domain name information includes domain name and XFF header; the protection behavior information corresponding to the network attack behavior includes protection action; the key request information and key response information corresponding to the target network request carrying the network attack include url, host, and HTTP protocol request method, request body, request header, response body, and response header.
[0120] Furthermore, the present application also discloses an electronic device. Figure 6It is a structural diagram of an electronic device 20 shown according to an exemplary embodiment, and the content in the figure cannot be regarded as any limitation on the scope of use of this application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input and output interface 25 and a communication bus 26. Among them, the memory 22 is used to store a computer program, and the computer program is loaded and executed by the processor 21 to implement the relevant steps in the network threat data entry method disclosed in any of the aforementioned embodiments. In addition, the electronic device 20 in this embodiment may specifically be an electronic computer.
[0121] In this embodiment, the power supply 23 is used to provide working voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and the external device, and the communication protocol it follows is any communication protocol that can be applied to the technical solution of the present application, and is not specifically limited here; the input and output interface 25 is used to obtain external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs and is not specifically limited here.
[0122] In addition, the memory 22, as a carrier for storing resources, can be a read-only memory, a random access memory, a disk or an optical disk, etc. The resources stored thereon can include an operating system 221, a computer program 222, etc., and the storage method can be temporary storage or permanent storage.
[0123] The operating system 221 is used to manage and control the hardware devices and computer programs 222 on the electronic device 20, which can be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program that can be used to complete the network threat data entry method performed by the electronic device 20 disclosed in any of the aforementioned embodiments, the computer program 222 can further include a computer program that can be used to complete other specific tasks.
[0124] Furthermore, the present application also discloses a computer-readable storage medium for storing a computer program; wherein the computer program, when executed by a processor, implements the aforementioned disclosed network threat data entry method. The specific steps of the method can refer to the corresponding contents disclosed in the aforementioned embodiments, and will not be repeated here.
[0125] In this specification, each embodiment is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part.
[0126] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in the above description according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0127] The steps of the method or algorithm described in conjunction with the embodiments disclosed herein may be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.
[0128] Finally, it should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the presence of other identical elements in the process, method, article or device including the elements.
[0129] The technical solution provided by the present application is introduced in detail above. Specific examples are used in this article to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea. At the same time, for general technicians in this field, according to the idea of the present application, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.
Claims
1. A method for entering network threat data, characterized in that: Applied to a preset entry system, the preset entry system establishes connections with different network security devices through different network ports; wherein the method comprises: Determine a target network security device from each of the network security devices to extract data, and determine a target microservice corresponding to the target network security device from a local preset microservice cluster; Determining a corresponding target transmission protocol from a preset transmission protocol set based on the data volume and log transmission frequency of the network threat log in the target network security device; The network port corresponding to the target network security device is monitored by the target microservice and using a preset port monitoring instance, and a target network threat log of the target network security device monitored is obtained through a target transmission protocol; Extract target key information from the target network threat log based on preset information extraction rules through the target microservice; the target key information includes attacker key information, attacked key information, network attack behavior information, network attack domain name information, protection behavior information corresponding to the network attack behavior, key request information corresponding to the target network request carrying the network attack, and key response information; The target key information is bound to the device information of the target network security device through the target microservice, and the bound information is saved in a local preset data warehouse.
2. The network threat data entry method according to claim 1, characterized in that: Determining a corresponding target transmission protocol from a preset transmission protocol set based on the data volume and log transmission frequency of the network threat log in the target network security device includes: When the data volume is larger than a preset amount and the log frequency is larger than a preset frequency, determining that the target transmission protocol is the TCP protocol; When the data volume is not greater than a preset amount and the log frequency is not greater than a preset frequency, it is determined that the target transmission protocol is the UDP protocol.
3. The network threat data entry method according to claim 2, characterized in that: The method of monitoring the network port corresponding to the target network security device by using the target microservice and a preset port monitoring instance, and obtaining the monitored target network threat log of the target network security device through a target transmission protocol, includes: The target microservice is used to monitor the network port corresponding to the target network security device using DatagramSocket, and the target network threat log of the target network security device monitored is obtained through the UDP protocol; Or, the network port corresponding to the target network security device is monitored by the target microservice using Socket, and the target network threat log of the monitored target network security device is obtained through the TCP protocol.
4. The network threat data entry method according to claim 1, characterized in that: The extracting target key information from the target network threat log based on a preset information extraction rule by the target microservice includes: Perform keyword segmentation on the target network threat log based on the split function through the target microservice to extract the target key information; Or, the target network threat log is formatted by the target microservice based on the JSONObject function to extract the target key information; Or, the target key information is extracted from the target network threat log based on a regular expression through the target microservice.
5. The network threat data entry method according to claim 1, characterized in that: The binding the target key information with the device information of the target network security device through the target microservice includes: The target key information is bound to the device IP, device name, device port, device type, creation time and unique identifier of the target network security device through the target microservice.
6. The network threat data entry method according to claim 5, characterized in that: After the binding information is saved in the local preset data warehouse, the method further includes: Based on a query condition, the bound information in the preset data warehouse is queried and exported; the query condition is the target key information or the device information.
7. The network threat data entry method according to any one of claims 1 to 6, characterized in that: The attacker's key information includes source IP, source port, and source MAC; the victim's key information includes target IP, target port, and target MAC; the network attack behavior information includes attack type, threat level, attack status, and occurrence time; the network attack domain name information includes domain name and XFF header; the protection behavior information corresponding to the network attack behavior includes protection action; the key request information and key response information corresponding to the target network request carrying the network attack include url, host, and HTTP protocol request method, request body, request header, response body, and response header.
8. A network threat data entry device, characterized in that: Applied to a preset entry system, the preset entry system establishes connections with different network security devices through different network ports; wherein the device comprises: A microservice determination module, used to determine a target network security device to be extracted from each of the network security devices, and determine a target microservice corresponding to the target network security device from a local preset microservice cluster; A protocol determination module, configured to determine a corresponding target transmission protocol from a preset transmission protocol set based on the data volume and log transmission frequency of the network threat log in the target network security device; A log acquisition module, used to monitor the network port corresponding to the target network security device through the target microservice and using a preset port monitoring instance, and obtain the monitored target network threat log of the target network security device through a target transmission protocol; An information extraction module is used to extract target key information from the target network threat log based on preset information extraction rules through the target microservice; the target key information includes attacker key information, attacked key information, network attack behavior information, network attack domain name information, protection behavior information corresponding to the network attack behavior, key request information corresponding to the target network request carrying the network attack, and key response information; The information saving module is used to bind the target key information with the device information of the target network security device through the target microservice, and save the bound information to a local preset data warehouse.
9. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor, configured to execute the computer program to implement the network threat data entry method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: Used to store a computer program; wherein, when the computer program is executed by a processor, the network threat data entry method according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Multi-source security threat detection method and device
CN116089940A
Vulnerability attack protection system and method for micro-service architecture application
CN118114247A
Systems and methods for network security event filtering and translation
US20180083985A1