Network security event detection method and device, equipment and storage medium

By acquiring and processing network data, extracting attack information and judging security incident conditions, the accuracy and efficiency of network security incident detection in the prior art are solved, and efficient network security incident detection and early warning are achieved.

CN119966743APending Publication Date: 2025-05-09ANXIN TUORI INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510188892.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-20
Publication Date
2025-05-09

AI Technical Summary

Technical Problem

Existing network security incident detection systems are difficult to accurately predict the risks of network security incidents, and their response and disposal efficiency is low, making them prone to false alarms and missed alarms.

Method used

By using the preset reception tool to obtain the original network data, perform structure division processing and store it in the preset database, extract attack information of security log data from it, determine the type of attack behavior, and judge whether the preset security event conditions are met based on statistical indicators.

Benefits of technology

It has achieved accurate prediction of the risks of network security incidents, improved network security protection efficiency, and reduced false alarms and underreports.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119966743A_ABST
    Figure CN119966743A_ABST
Patent Text Reader

Abstract

The invention discloses a network security event detection method and device, equipment and a storage medium, and relates to the field of network security, and the method comprises the steps: obtaining original network data through employing a preset receiving tool, carrying out the structure division of the obtained original network data, and obtaining processed network data, storing the processed network data to a corresponding preset database; acquiring attack information of security log data in the processed network data from a preset database, and determining an attack behavior type of a corresponding target attack event based on the attack information; performing information statistics on the attack information based on a statistical index corresponding to the attack behavior type of the target attack event to obtain a corresponding statistical result, and judging whether the statistical result meets a corresponding preset security event condition or not; and if the statistical index satisfies a corresponding preset security event condition, determining that the target attack event is a network security event. According to the invention, the network security event risk can be accurately predicted and the network security protection can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security, and in particular to a network security event detection method, device, equipment and storage medium. Background Art

[0002] While sharing the convenience brought by open and interconnected technologies, we are also facing increasingly severe network security risks. The current network security incident operation and maintenance system was originally developed from SIEM (security information and event management), but it is based on a response and disposal method that is mainly based on manual operation and maintenance. It uses manual issuance of security defense adjustment strategies and adjustment of security defense forces, which requires the collaboration of multiple people, multiple systems, and multiple interfaces. While it brings complexity to the response to security incidents, it further reduces the efficiency of response and disposal.

[0003] At present, with the development of technology, attackers are constantly developing new attack methods and tools. These new methods may not be within the detection range of existing security monitoring systems, making security incidents difficult to detect; many network security incidents, especially APT (Advanced Persistent Threat) attacks, are hidden and complex. Attackers will use complex technical means to hide their attack behaviors, making these incidents difficult to be discovered by conventional security monitoring systems. The detection system of network security incidents usually faces the problems of false positives and false negatives. The signature-based detection system has a high detection accuracy rate for known attacks, but its detection ability for unknown attacks is limited; while the anomaly-based detection system can detect new attacks, but the false positive rate is relatively high; network security threats are diverse, and the attack methods are constantly evolving. It is necessary to quickly detect security incidents in a short period of time and make timely and effective responses.

[0004] To sum up, how to accurately predict the risks of network security incidents and improve network security protection is an urgent problem to be solved. Summary of the invention

[0005] In view of this, the purpose of the present invention is to provide a network security event detection method, device, equipment and storage medium, which can accurately predict the risk of network security events and improve network security protection. The specific scheme is as follows:

[0006] In a first aspect, the present application provides a network security incident detection method, comprising:

[0007] Using a preset receiving tool to obtain original network data, performing structural division processing on the obtained original network data to obtain processed network data, and storing the processed network data in a corresponding preset database;

[0008] Acquire attack information of security log data in the processed network data from the preset database, and determine the attack behavior type of the corresponding target attack event based on the attack information;

[0009] Performing information statistics on the attack information based on the statistical indicators corresponding to the attack behavior type of the target attack event to obtain corresponding statistical results, and determining whether the statistical results meet corresponding preset security event conditions;

[0010] If the statistical indicator meets the corresponding preset security event conditions, the target attack event is determined to be a network security event.

[0011] Optionally, the obtaining original network data by using a preset receiving tool includes:

[0012] The original network data is received by using a preset process orchestration tool, and the original network data received by the preset process orchestration tool is transmitted through a preset distributed message middleware server, so that the original network data transmitted by the preset distributed message middleware server is structurally divided and processed to obtain processed network data.

[0013] Optionally, the original network data includes real-time data, file data, message record data and text data.

[0014] Optionally, performing structural division processing on the acquired original network data to obtain processed network data, and storing the processed network data in a corresponding preset database includes:

[0015] Performing structural division processing on the acquired original network data to obtain structured processed network data, semi-structured processed network data, and unstructured processed network data;

[0016] The semi-structured processed network data and the unstructured processed network data are stored in a preset column-based distributed database through a preset high-availability distributed microservice cluster architecture, and the structured processed network data is stored in a preset relational database.

[0017] Optionally, determining the attack behavior type of the corresponding target attack event based on the attack information includes:

[0018] Determine a target attack event based on the attack information in the security log data, and determine an attack behavior type of the target attack event corresponding to the attack information according to the target attack event;

[0019] The target attack events include any one or more of Trojan attack events, mining events, computer virus attack events, web attack events, scanning attack events, and remote control attack events.

[0020] Optionally, the performing information statistics on the attack information based on the statistical indicator corresponding to the attack behavior type of the target attack event to obtain a corresponding statistical result, and judging whether the statistical result meets a corresponding preset security event condition, includes:

[0021] Determine whether the statistical index corresponding to the attack behavior type of the target attack event is greater than the corresponding preset index range; wherein the statistical index includes the number of attacks, attack time, attack target, attack range, attack type, attack danger level, and importance of the attacked asset;

[0022] If the statistical indicator is within the corresponding preset indicator range, it is determined that the target attack event meets the preset security event condition;

[0023] If the statistical indicator is not within the corresponding preset indicator range, it is determined that the target attack event does not meet the preset security event condition.

[0024] Optionally, after determining that the target attack event is a network security event, the method further includes:

[0025] The preset security device is used to perform a preset processing operation on the IP address corresponding to the target attack event; wherein the preset processing operation includes a preset blocking operation, a preset network disconnection operation, and a preset interception operation.

[0026] In a second aspect, the present application provides a network security event detection device, comprising:

[0027] A processed network data storage module, used to obtain original network data using a preset receiving tool, perform structural division processing on the obtained original network data to obtain processed network data, and store the processed network data in a corresponding preset database;

[0028] An attack behavior type determination module, used to obtain attack information of the security log data in the processed network data from the preset database, and determine the attack behavior type of the corresponding target attack event based on the attack information;

[0029] A statistical result judgment module is used to perform information statistics on the attack information based on the statistical indicators corresponding to the attack behavior type of the target attack event to obtain corresponding statistical results, and to judge whether the statistical results meet the corresponding preset security event conditions;

[0030] A preset security event determination module is used to determine that the target attack event is a network security event if the statistical indicator meets the corresponding preset security event conditions.

[0031] In a third aspect, the present application provides an electronic device, including:

[0032] Memory, used to store computer programs;

[0033] The processor is used to execute the computer program to implement the network security incident detection method as described above.

[0034] In a fourth aspect, the present application provides a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the network security incident detection method as described above is implemented.

[0035] In summary, the present application first uses a preset receiving tool to obtain the original network data, performs structural division processing on the obtained original network data to obtain processed network data, and stores the processed network data in the corresponding preset database; obtains the attack information of the security log data in the processed network data from the preset database, and determines the attack behavior type of the corresponding target attack event based on the attack information; performs information statistics on the attack information based on the statistical indicators corresponding to the attack behavior type of the target attack event to obtain the corresponding statistical results, and determines whether the statistical results meet the corresponding preset security event conditions; if the statistical indicators meet the corresponding preset security event conditions, the target attack event is determined to be a network security event. As can be seen from the above, the present application first uses a preset receiving tool to obtain the original network data, and then performs structural division processing on the obtained original network data to obtain the processed network data. After the processing is completed, the processed network data is stored in the corresponding preset database. Afterwards, the attack information of the security log data in the processed network data is obtained from the preset database, and then the attack behavior type of the corresponding target attack event is determined based on these attack information. Subsequently, based on the statistical indicators corresponding to the attack behavior type of the target attack event, the attack information is counted to obtain the corresponding statistical results. After the statistics are completed, it is determined whether the statistical results meet the corresponding preset security event conditions. If the statistical results meet the corresponding preset security event conditions, then the target attack event can be determined as a network security event. In this way, by obtaining the security logs in the network data, it is determined whether a security event has occurred, so as to accurately predict network security events and improve network security protection. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying creative work.

[0037] Figure 1 A flow chart of a network security incident detection method disclosed in the present invention;

[0038] Figure 2 This is a schematic diagram of the structure of a network security event detection device disclosed in the present invention;

[0039] Figure 3 The present invention is a structural diagram of an electronic device disclosed in the present invention. DETAILED DESCRIPTION

[0040] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0041] At present, with the development of technology, attackers are constantly developing new attack methods and tools. These new methods may not be within the detection range of existing security monitoring systems, making security incidents difficult to detect; many network security incidents, especially APT (Advanced Persistent Threat) attacks, are concealed and complex. Attackers will use complex technical means to hide their attack behaviors, making these incidents difficult to be discovered by conventional security monitoring systems. The detection system of network security incidents usually faces the problems of false positives and false negatives. The signature-based detection system has a high detection accuracy for known attacks, but has limited detection capabilities for unknown attacks; while the anomaly-based detection system can detect new attacks, but the false positive rate is relatively high; network security threats are diverse in form, and the means of attack are constantly evolving. It is necessary to quickly detect security incidents in a short time and make timely and effective responses. In order to solve the above technical problems, the present application discloses a network security incident detection method, device, equipment and storage medium, which can accurately predict the risk of network security incidents and improve network security protection.

[0042] See also Figure 1 As shown, an embodiment of the present invention discloses a network security event detection method, including:

[0043] Step S11: using a preset receiving tool to obtain original network data, performing structural division processing on the obtained original network data to obtain processed network data, and storing the processed network data in a corresponding preset database.

[0044] In this embodiment, it is first necessary to obtain the original network data, and the preset process orchestration tool can be used to receive the original network data, and the original network data received by the preset process orchestration tool can be transmitted through the preset distributed message middleware server, so as to structurally divide and process the original network data transmitted by the preset distributed message middleware server to obtain processed network data. Specifically, a high-performance and flexible process orchestration tool, such as node-red and other preset process orchestration tools, is used to receive data of various communication protocols and data formats, and a high-throughput and distributed message middleware server, such as emqx and other preset distributed message middleware servers, is used to transmit massive original network data, wherein the original network data may include real-time data, file data, message record data and text data.

[0045] Then, after obtaining the original network data, the obtained original network data is processed by structural division to obtain structured network data, semi-structured network data, and unstructured network data; the semi-structured network data and unstructured network data are stored in a preset column-based distributed database through a preset high-availability distributed microservice cluster architecture, and the structured network data is stored in a preset relational database. Specifically, the original network data is first processed by structural division to obtain structured network data, semi-structured network data, and unstructured network data, and then a data persistence management system is built to manage the obtained original network data, for example, using a highly available and high-performance distributed cluster application architecture SpringCloud. For semi-structured and unstructured data, with the help of the adaptability of SpringCloud and the preset column-based distributed database, the data is directly stored in the preset column-based distributed database, wherein the preset column-based distributed database includes but is not limited to ClickHouse. For structured application data, the data is stored in the preset relational database in an orderly manner through the SpringCloud configuration and the connection with the preset relational database. In this way, effective and persistent management of different types of data can be fully realized.

[0046] Step S12: acquiring attack information of the security log data in the processed network data from the preset database, and determining the attack behavior type of the corresponding target attack event based on the attack information.

[0047] In this embodiment, after storing the data in a preset database, the target attack event is determined based on the attack information in the security log data, and the attack behavior type of the target attack event corresponding to the attack information is determined according to the target attack event; wherein the target attack event includes any one or more of a Trojan attack event, a mining event, a computer virus attack event, a web attack event, a scanning attack event, and a remote control attack event. Specifically, the security log data is obtained from the preset database, and then the attack information is extracted from the security log data. By carefully screening the key elements in the log, such as the source IP address, the destination IP address, the attack time, the ports involved in the attack, the protocol type, and the related abnormal behavior characteristics, the target attack event can be accurately determined. Once the target attack event is identified, the typical characteristics of various types of attack events will be analyzed next. For example, if a target attack event involves the appearance of an unknown program in the system, and the program has the characteristics of running secretly, obtaining key system information without authorization, or performing malicious operations, and is highly consistent with the behavior patterns of common Trojan programs, then the target attack event can be determined to be a Trojan attack event; if a large amount of abnormal computing resource usage is found in the security log data, and the relevant process is suspected of mining cryptocurrency, such as the presence of specific mining algorithm features, communication records with the mining pool, etc., it can be identified as a mining event. In addition, target attack events also include but are not limited to computer virus attack events, web attack events, scanning attack events, and remote control attack events.

[0048] Step S13: performing information statistics on the attack information based on the statistical indicators corresponding to the attack behavior type of the target attack event to obtain corresponding statistical results, and determining whether the statistical results meet corresponding preset security event conditions.

[0049] In this embodiment, after the attack behavior type of the target attack event is determined, it is necessary to perform information statistics on the target attack event to obtain the corresponding statistical results, and then determine whether the statistical index corresponding to the attack behavior type of the target attack event is greater than the corresponding preset index range; wherein the statistical index includes the number of attacks, attack time, attack target, attack range, attack type, attack danger level and importance of the attacked asset; if the statistical index is within the corresponding preset index range, it is determined that the target attack event meets the preset security event conditions; if the statistical index is not within the corresponding preset index range, it is determined that the target attack event does not meet the preset security event conditions. Specifically, different attack behavior types have their own unique statistical indicators. By comprehensively considering multiple statistical indicators such as the number of attacks, attack time, attack target, attack range, attack type, attack danger level and importance of the attacked asset, security event judgment standards with different precisions can be formed. For each statistical indicator, the corresponding security event threshold and indicator range are pre-set. When making a specific judgment, it is first necessary to determine whether each statistical indicator is greater than the corresponding preset indicator range. For example, for the indicator of the number of attacks, assuming that the preset indicator range is 50 times per hour, if the actual number of attacks counted per hour exceeds 50 times, this meets the preliminary judgment condition; for the attack time, if the preset attack duration exceeds 30 minutes to trigger a security event, and the actual attack duration reaches or exceeds 30 minutes, it also meets the judgment condition. If all relevant statistical indicators are within the corresponding preset indicator range, or some key statistical indicators are both greater than the corresponding preset indicator range and within the preset indicator range, it is determined that the target attack event meets the preset security event conditions.

[0050] Step S14: If the statistical indicator meets the corresponding preset security event condition, the target attack event is determined to be a network security event.

[0051] In this embodiment, when the statistical indicators meet the corresponding preset security event conditions, the target attack event is determined as a network security event. Network security events can be divided into three levels of security events: high precision, medium precision and low precision.

[0052] In a specific embodiment, for the high-precision level, for large-scale attacks on the intranet, the number of attacks and the type of attacks need to be monitored at the same time within a configurable time period. If the number of attacks of the same type reaches a specific number, it can be determined. For high-risk attacks on the intranet, the number of attacks and the attack threat level are comprehensively considered within the configurable time period, and they are determined when both meet the corresponding conditions. Intranet APT attacks are based on the number of attack targets within the configurable time period. If more than a certain number of key intranet targets are attacked, it is determined as this event. For large-scale attacks on the external network, the number and type of attacks are controlled within the configurable time period, and they are determined when the conditions such as the specified number of times are reached. High-risk attacks on the external network are determined within the configurable time period when the corresponding requirements are met in combination with the number of attacks and the threat level. External APT attacks are determined based on the number of attack targets within the configurable time period. When more than a specific number of external network key business targets are attacked, they are attacked. Business vulnerability system events are determined within the configurable time period when no less than a specific number of different IPs launch attacks of the same attack type against the same intranet IP.

[0053] In another specific embodiment, for medium-precision configuration, large-scale attacks on the intranet are determined only based on the number of attacks within a configurable time period, reaching a certain value. High-risk attacks on the intranet are determined by the attack threat level within a configurable time period, reaching a preset high threat level or above. Intranet APT attacks are determined based on the number of intranet targets attacked within a configurable time period, exceeding a certain number. Large-scale attacks on the extranet are determined within a configurable time period based on the number of attacks reaching the corresponding standard. High-risk attacks on the extranet are determined within a configurable time period based on the attack threat level being a preset high threat level or above. Extranet APT attacks are determined within a configurable time period based on the number of extranet targets attacked exceeding a certain number.

[0054] In the third specific embodiment, for high-risk intranet events under low-precision configuration, the attack threat level is determined to be a preset high threat level and the number of attacks reaches a certain number within a configurable time period. Although this configuration method is relatively simple, it can perform preliminary screening and early warning of intranet attacks that pose certain threats and are relatively frequent.

[0055] In this embodiment, when the target attack event is determined through the security event generation configuration of different precisions, it is necessary to quickly link the preset security devices such as the border firewall to carry out the preset processing operation on the risk IP address involved in the event. Among them, the preset processing operation includes a preset blocking operation, a preset network disconnection operation, and a preset interception operation. It can be understood that the firewall can perform a preset blocking operation on the risk IP address according to the preset rules, reject all network connection requests initiated by the IP address, and effectively cut off the attack path. In addition, the preset security device can also perform a preset network disconnection operation. For example, when the risk IP address causes significant damage to the entire network architecture, the linked security device will quickly cut off the connection of the network where the IP address is located. Similarly, the preset security device can also perform a preset interception operation. For example, once a malicious data packet from a risk IP address is detected, such as containing malicious scripts, viruses, or special instructions intended to invade the system, the interception mechanism will be immediately activated. These malicious data packets will be directly discarded and cannot reach the target server or network node, thereby ensuring the secure transmission of network data and the stable operation of the system.

[0056] As can be seen from the above, the embodiment of the present application first uses a preset receiving tool to obtain the original network data, and then performs structural division processing on the obtained original network data to obtain the processed network data. After the processing is completed, the processed network data is stored in the corresponding preset database. After that, the attack information of the security log data in the processed network data is obtained from the preset database, and then the attack behavior type of the corresponding target attack event is determined based on these attack information. Subsequently, based on the statistical indicators corresponding to the attack behavior type of the target attack event, the attack information is statistically analyzed to obtain the corresponding statistical results. After the statistics are completed, it is determined whether the statistical results meet the corresponding preset security event conditions. If the statistical results meet the corresponding preset security event conditions, then the target attack event can be determined as a network security event. In this way, by obtaining the security log in the network data, it is determined whether a security event has occurred, so as to accurately predict network security events and improve network security protection.

[0057] Based on the above embodiment, it can be seen that the present application discloses a network security incident detection method, which can accurately predict the risk of network security incidents and improve network security protection. Figure 2 The specific network security incident detection method shown is described in detail.

[0058] This application first uses a preset process orchestration tool to receive raw network data, and uses a high-throughput, distributed message middleware server, such as emqx and other preset distributed message middleware servers to transmit massive raw network data. Then, after obtaining the raw network data, the obtained raw network data is structured and processed to obtain structured network data, semi-structured network data, and unstructured network data. Then, for semi-structured and unstructured data, it is directly stored in a preset column-based distributed database, and for structured application data, the data is stored in a preset relational database in an orderly manner. After storing the data in the preset database, the target attack event is determined based on the attack information in the security log data, and the attack behavior type of the target attack event is determined according to the target attack event, such as Trojan attack events, mining events, computer virus attack events, web attack events, scanning attack events, and remote control attack events. After the attack behavior type of the target attack event is determined, it is necessary to collect information statistics for the target attack event and obtain the corresponding statistical results. Then, by comprehensively considering multiple statistical indicators such as the number of attacks, attack time, attack target, attack range, attack type, attack danger level, and importance of the attacked assets, it is possible to form security event judgment standards with different precisions. For each statistical indicator, the corresponding security event threshold and indicator range are pre-set. Determine whether the statistical indicator corresponding to the attack behavior type of the target attack event is greater than the corresponding preset indicator range. Finally, when the statistical indicator meets the corresponding preset security event conditions, the target attack event is determined as a network security event.

[0059] See also Figure 2 As shown, an embodiment of the present invention discloses a network security event detection device, including:

[0060] A processed network data storage module 11 is used to obtain original network data using a preset receiving tool, perform structural division processing on the obtained original network data to obtain processed network data, and store the processed network data in a corresponding preset database;

[0061] An attack behavior type determination module 12 is used to obtain attack information of the security log data in the processed network data from the preset database, and determine the attack behavior type of the corresponding target attack event based on the attack information;

[0062] A statistical result judgment module 13 is used to perform information statistics on the attack information based on the statistical indicators corresponding to the attack behavior type of the target attack event to obtain corresponding statistical results, and to judge whether the statistical results meet the corresponding preset security event conditions;

[0063] The preset security event determination module 14 is used to determine that the target attack event is a network security event if the statistical indicator meets the corresponding preset security event condition.

[0064] As can be seen from the above, the present application first uses a preset receiving tool to obtain the original network data, and then performs structural division processing on the obtained original network data to obtain the processed network data. After the processing is completed, the processed network data is stored in the corresponding preset database. After that, the attack information of the security log data in the processed network data is obtained from the preset database, and then the attack behavior type of the corresponding target attack event is determined based on these attack information. Subsequently, based on the statistical indicators corresponding to the attack behavior type of the target attack event, the attack information is statistically analyzed to obtain the corresponding statistical results. After the statistics are completed, it is determined whether the statistical results meet the corresponding preset security event conditions. If the statistical results meet the corresponding preset security event conditions, then the target attack event can be determined as a network security event. In this way, by obtaining the security log in the network data, it is determined whether a security event has occurred, so as to accurately predict network security events and improve network security protection.

[0065] In some specific embodiments, the processed network data storage module 11 may specifically include:

[0066] The processed network data acquisition unit is used to receive original network data using a preset process orchestration tool, and transmit the original network data received by the preset process orchestration tool through a preset distributed message middleware server, so as to perform structural division processing on the original network data transmitted by the preset distributed message middleware server to obtain processed network data.

[0067] In some specific embodiments, the original network data includes real-time data, file data, message record data and text data.

[0068] In some specific embodiments, the processed network data storage module 11 may specifically include:

[0069] The original network data partitioning unit is used to perform structural partitioning on the acquired original network data to obtain structured processed network data, semi-structured processed network data, and unstructured processed network data;

[0070] The processed network data storage unit is used to store the semi-structured processed network data and the unstructured processed network data in a preset column-based distributed database through a preset high-availability distributed microservice cluster architecture, and to store the structured processed network data in a preset relational database.

[0071] In some specific embodiments, the attack behavior type determination module 12 may specifically include:

[0072] An attack behavior type determination unit is used to determine a target attack event based on the attack information in the security log data, and determine the attack behavior type of the target attack event corresponding to the attack information according to the target attack event; wherein the target attack event includes any one or more of a Trojan attack event, a mining event, a computer virus attack event, a web attack event, a scanning attack event, and a remote control attack event.

[0073] In some specific embodiments, the statistical result judgment module 13 may specifically include:

[0074] A statistical indicator judgment unit, used to judge whether the statistical indicator corresponding to the attack behavior type of the target attack event is greater than the corresponding preset indicator range; wherein the statistical indicator includes the number of attacks, attack time, attack target, attack range, attack type, attack danger level and importance of the attacked asset;

[0075] A first preset security event condition determination unit, configured to determine that the target attack event satisfies a preset security event condition if the statistical indicator is within a corresponding preset indicator range;

[0076] The second preset security event condition determination unit is used to determine that the target attack event does not meet the preset security event condition if the statistical indicator is not within the corresponding preset indicator range.

[0077] In some specific embodiments, the network security event detection device may further include:

[0078] The preset processing operation execution module is used to use the preset security device to perform the preset processing operation on the corresponding IP address in the target attack event; wherein the preset processing operation includes a preset blocking operation, a preset network disconnection operation, and a preset interception operation.

[0079] Furthermore, the present application also discloses an electronic device. Figure 3 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content in the diagram cannot be regarded as any limitation on the scope of use of the present application.

[0080] Figure 3A schematic diagram of the structure of an electronic device 20 provided in an embodiment of the present application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 is used to store a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the network security incident detection method disclosed in any of the aforementioned embodiments. In addition, the electronic device 20 in this embodiment may specifically be an electronic computer.

[0081] In this embodiment, the power supply 23 is used to provide working voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and the external device, and the communication protocol it follows is any communication protocol that can be applied to the technical solution of the present application, and is not specifically limited here; the input and output interface 25 is used to obtain external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs and is not specifically limited here.

[0082] In addition, the memory 22, as a carrier for storing resources, can be a read-only memory, a random access memory, a disk or an optical disk, etc. The resources stored thereon can include an operating system 221, a computer program 222, etc., and the storage method can be temporary storage or permanent storage.

[0083] The operating system 221 is used to manage and control the hardware devices and computer program 222 on the electronic device 20, which can be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program that can be used to complete the network security incident detection method performed by the electronic device 20 disclosed in any of the aforementioned embodiments, the computer program 222 can further include a computer program that can be used to complete other specific tasks.

[0084] Furthermore, the present application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the aforementioned disclosed network security incident detection method is implemented. The specific steps of the method can refer to the corresponding contents disclosed in the aforementioned embodiments, and will not be repeated here.

[0085] In this specification, each embodiment is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part.

[0086] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in the above description according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0087] The steps of the method or algorithm described in conjunction with the embodiments disclosed herein may be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.

[0088] Finally, it should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the presence of other identical elements in the process, method, article or device including the elements.

[0089] The technical solution provided by the present application is introduced in detail above. Specific examples are used in this article to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea. At the same time, for general technical personnel in this field, according to the idea of ​​the present application, there will be changes in the specific implementation method and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.

Claims

1. A network security incident detection method, characterized in that: include: Using a preset receiving tool to obtain original network data, performing structural division processing on the obtained original network data to obtain processed network data, and storing the processed network data in a corresponding preset database; Acquire attack information of security log data in the processed network data from the preset database, and determine the attack behavior type of the corresponding target attack event based on the attack information; Performing information statistics on the attack information based on the statistical indicators corresponding to the attack behavior type of the target attack event to obtain corresponding statistical results, and determining whether the statistical results meet corresponding preset security event conditions; If the statistical indicator meets the corresponding preset security event conditions, the target attack event is determined to be a network security event.

2. The network security incident detection method according to claim 1, characterized in that: The method of obtaining the original network data by using a preset receiving tool includes: The original network data is received by using a preset process orchestration tool, and the original network data received by the preset process orchestration tool is transmitted through a preset distributed message middleware server, so that the original network data transmitted by the preset distributed message middleware server is structurally divided and processed to obtain processed network data.

3. The network security incident detection method according to claim 1, characterized in that: The original network data includes real-time data, file data, message record data and text data.

4. The network security incident detection method according to claim 1, characterized in that: The obtaining of the original network data by structural division to obtain processed network data, and storing the processed network data in a corresponding preset database, comprises: Performing structural division processing on the acquired original network data to obtain structured processed network data, semi-structured processed network data, and unstructured processed network data; The semi-structured processed network data and the unstructured processed network data are stored in a preset column-based distributed database through a preset high-availability distributed microservice cluster architecture, and the structured processed network data is stored in a preset relational database.

5. The network security incident detection method according to claim 1, characterized in that: The determining the attack behavior type of the corresponding target attack event based on the attack information includes: Determine a target attack event based on the attack information in the security log data, and determine an attack behavior type of the target attack event corresponding to the attack information according to the target attack event; The target attack events include any one or more of Trojan attack events, mining events, computer virus attack events, web attack events, scanning attack events, and remote control attack events.

6. The network security incident detection method according to any one of claims 1 to 5, characterized in that: The statistical indicators corresponding to the attack behavior type of the target attack event are used to perform information statistics on the attack information to obtain corresponding statistical results, and judging whether the statistical results meet corresponding preset security event conditions, including: Determine whether the statistical index corresponding to the attack behavior type of the target attack event is greater than the corresponding preset index range; wherein the statistical index includes the number of attacks, attack time, attack target, attack range, attack type, attack danger level, and importance of the attacked asset; If the statistical indicator is within the corresponding preset indicator range, it is determined that the target attack event meets the preset security event condition; If the statistical indicator is not within the corresponding preset indicator range, it is determined that the target attack event does not meet the preset security event condition.

7. The network security incident detection method according to claim 6, characterized in that: After determining that the target attack event is a network security event, the method further includes: The preset security device is used to perform a preset processing operation on the IP address corresponding to the target attack event; wherein the preset processing operation includes a preset blocking operation, a preset network disconnection operation, and a preset interception operation.

8. A network security incident detection device, characterized in that: include: A processed network data storage module, used to obtain original network data using a preset receiving tool, perform structural division processing on the obtained original network data to obtain processed network data, and store the processed network data in a corresponding preset database; An attack behavior type determination module, used to obtain attack information of the security log data in the processed network data from the preset database, and determine the attack behavior type of the corresponding target attack event based on the attack information; A statistical result judgment module is used to perform information statistics on the attack information based on the statistical indicators corresponding to the attack behavior type of the target attack event to obtain corresponding statistical results, and to judge whether the statistical results meet the corresponding preset security event conditions; A preset security event determination module is used to determine that the target attack event is a network security event if the statistical indicator meets the corresponding preset security event conditions.

9. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor, configured to execute the computer program to implement the network security incident detection method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: Used to store computer programs; wherein, when the computer program is executed by a processor, it implements the network security incident detection method as described in any one of claims 1 to 7.