Threat hunting method and device
By using the threat identification engine and the threat feature model demonstrated by security experts on the threat hunting cloud platform, threat feature identification is solved by solving the problem that internal administrators of the enterprise lack professional knowledge in threat hunting, and achieving efficient and accurate threat hunting effects.
Patent Information
- Application Number
- CN202411996942.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-31
- Publication Date
- 2025-05-13
AI Technical Summary
When conducting threat hunting, internal administrators lack professional knowledge and experience, which leads to inefficient threat hunting and prone to false alarms or missed reports, posing hidden dangers to corporate security.
Provide a threat hunting method and device, using the threat hunting cloud platform and threat identification engine, a threat hunting model built based on the threat characteristics demonstrated by security experts, to identify the terminal behavior logs and generate threat hunting results.
By leveraging the threat characteristics demonstrated by security experts, threat hunting can be carried out accurately and efficiently, reducing threat false alarms and underreporting, and improving the efficiency of network security operations.
Smart Images

Figure CN119989339A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of threat hunting technology, and in particular to a threat hunting method and device. Background Art
[0002] During the operation of the terminal, there are usually a large number of network threats such as attack behaviors. It is necessary to conduct threat hunting on the terminal to detect and deal with threats in a timely manner to reduce the damage caused by network threats.
[0003] Currently, threat hunting for enterprise terminals usually relies on the threat hunting experience of enterprise administrators. However, enterprise administrators are usually not professional security experts, and their threat hunting experience is limited and unprofessional. Not only is the threat hunting efficiency low, but it is also difficult to give accurate threat hunting results. Threat hunting results often contain false positives or omissions, which poses a hidden danger to enterprise security.
[0004] Therefore, how to accurately and efficiently conduct threat hunting on terminals has become an urgent problem that needs to be solved. Summary of the invention
[0005] The present application proposes a threat hunting method and device, the main purpose of which is to accurately and efficiently perform threat hunting on terminals.
[0006] In order to achieve the above objectives, this application mainly provides the following technical solutions:
[0007] In a first aspect, the present application provides a threat hunting method, which is applied to a threat hunting cloud platform, wherein the threat hunting cloud platform is remotely connected to at least one terminal, and the threat hunting cloud platform is deployed with a threat identification engine, wherein the threat identification engine identifies threat features of terminal behavior logs based on a threat hunting model, and the threat hunting model is constructed based on threat features corresponding to threats demonstrated by security experts. The threat hunting method provided in this embodiment includes:
[0008] If the terminal behavior log of any target terminal is remotely acquired, the threat identification engine is called to select a target threat hunting model suitable for the target terminal from the preset threat hunting models;
[0009] Calling the threat identification engine to identify threat features of the terminal behavior log of the target terminal based on the target threat hunting model;
[0010] If the threat identification engine identifies a threat feature from the terminal behavior log of the target terminal, a threat hunting result indicating that a threat exists in the target terminal is generated based on the identified threat feature.
[0011] In a second aspect, the present application provides a threat hunting device, which is applied to a threat hunting cloud platform, wherein the threat hunting cloud platform is remotely connected to at least one terminal, and the threat hunting cloud platform is deployed with a threat identification engine for identifying threat features of terminal behavior logs based on a threat hunting model, wherein the threat hunting model is constructed based on threat features corresponding to threats demonstrated by security experts. The threat hunting device provided in this embodiment includes:
[0012] A selection module, configured to call the threat identification engine to select a target threat hunting model suitable for the target terminal from preset threat hunting models if the terminal behavior log of any target terminal is remotely acquired;
[0013] An identification module, used for calling the threat identification engine to identify threat features of the terminal behavior log of the target terminal based on a target threat hunting model;
[0014] A generating module is used to generate a threat hunting result indicating that a threat exists in the target terminal based on the identified threat feature if the threat identification engine identifies a threat feature in the terminal behavior log of the target terminal.
[0015] In a third aspect, the present application provides a computer-readable storage medium, wherein the storage medium includes a stored program, wherein when the program is run, the device where the storage medium is located is controlled to execute the threat hunting method described in the first aspect.
[0016] In a fourth aspect, the present application provides an electronic device, comprising: a memory for storing a program; and a processor, coupled to the memory, for running the program to execute the threat hunting method described in the first aspect.
[0017] The threat hunting method and device provided by the present application deploy a threat identification engine for identifying threat features of terminal behavior logs based on threat hunting models on a threat hunting cloud platform. In this way, when the terminal behavior log of any terminal is remotely obtained, the threat identification engine is first called to select a target threat hunting model suitable for the target terminal from the preset threat hunting model, and then the threat identification engine is called to identify threat features of the terminal behavior log of the terminal based on the target threat hunting model. In the case where the threat identification engine identifies the threat features of the terminal behavior log of the target terminal, a threat hunting result indicating that a threat exists in the target terminal is generated based on the identified threat features. It can be seen that in the solution provided by the present application, the terminal in the enterprise remotely reports its own terminal behavior log to the threat hunting cloud platform, and the threat hunting cloud platform uses the threat hunting model constructed based on the threat features corresponding to the threats demonstrated by security experts to perform threat hunting on the terminal based on the terminal behavior log. In this way, it can fully use the knowledge of threat features corresponding to the threats demonstrated by security experts, and accurately and efficiently perform threat hunting on the terminal, thereby making up for the shortcomings in the network security operation of the enterprise where the terminal is located.
[0018] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0020] Figure 1 A flowchart of a threat hunting method provided by an embodiment of the present application is shown;
[0021] Figure 2 A schematic diagram showing a connection relationship between a threat hunting cloud platform and a terminal provided by an embodiment of the present application is shown;
[0022] Figure 3 A process framework diagram of a threat hunting method provided by an embodiment of the present application is shown;
[0023] Figure 4 A schematic diagram of the structure of a threat hunting device provided by an embodiment of the present application is shown;
[0024] Figure 5A schematic structural diagram of a threat hunting device provided in another embodiment of the present application is shown. DETAILED DESCRIPTION
[0025] The exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although the exemplary embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided in order to enable a more thorough understanding of the present disclosure and to fully convey the scope of the present disclosure to those skilled in the art.
[0026] After installing terminal products, enterprises need to conduct threat hunting on the terminals to timely detect threats such as attack behaviors and deal with them to reduce the damage caused by network threats. At present, threat hunting usually relies on the threat hunting experience of internal enterprise administrators. However, internal enterprise administrators are usually not professional security experts, and their threat hunting experience is limited and unprofessional. Not only is the threat hunting efficiency low and unable to detect and detect threats in time, but it is also difficult to give accurate threat hunting results. Threat hunting results often contain false positives or omissions, which poses a hidden danger to enterprise security.
[0027] After research, it was found that professional network security companies have a large number of professional security experts, and the security experts have more authoritative threats and threat characteristics corresponding to the threats. If the network security company provides a professional threat hunting cloud platform, then the terminals within the enterprise can remotely transmit the terminal behavior logs to the threat hunting cloud platform. Then the threat hunting cloud platform relies on the threat characteristics corresponding to the threats demonstrated by security experts, and conducts threat hunting on the terminals within the enterprise based on the terminal behavior logs. This can efficiently and accurately conduct threat hunting on the terminals to make up for the shortcomings in the network security operations of the enterprises where the terminals are located.
[0028] Based on the above findings, this embodiment specifically provides a technical solution for threat hunting, specifically: the threat hunting cloud platform is remotely connected to at least one terminal, and the threat hunting cloud platform is deployed with a threat identification engine, the threat identification engine identifies threat features of the terminal behavior log based on the threat hunting model, and the threat hunting model is constructed based on the threat features corresponding to the threats demonstrated by security experts. If the terminal behavior log of any target terminal is remotely acquired, the threat identification engine is called to select a target threat hunting model suitable for the target terminal from the preset threat hunting models. The threat identification engine is called to identify threat features of the terminal behavior log of the target terminal based on the target threat hunting model. If the threat identification engine identifies threat features of the terminal behavior log of the target terminal, a threat hunting result indicating the existence of a threat to the target terminal is generated based on the identified threat features.
[0029] The threat hunting technical solution provided in this embodiment can perform threat hunting on any type of terminal, and this embodiment does not limit the type of terminal. In principle, the threat hunting technical solution provided in this embodiment can perform threat hunting on any terminal that is remotely connected to the threat hunting cloud platform and can report terminal behavior logs to the threat hunting cloud platform through the remote communication connection.
[0030] Based on the above-mentioned technical solution of threat hunting, this embodiment specifically provides a threat hunting method and device. The threat hunting method and device provided by this embodiment are specifically described below.
[0031] The present application embodiment provides a threat hunting method, such as Figure 1 As shown, the threat hunting method provided in this embodiment may at least include the following steps 101 to 103:
[0032] 101. If the terminal behavior log of any target terminal is remotely obtained, the threat identification engine is called to select a target threat hunting model suitable for the target terminal from the preset threat hunting models.
[0033] The threat hunting method provided in this embodiment is applied to a threat hunting cloud platform. The threat hunting cloud platform is remotely connected to at least one terminal. The purpose of the remote communication connection between the threat hunting cloud platform and the terminal is to obtain the terminal behavior log of the terminal through the remote communication connection without visiting the network environment of the enterprise where the terminal is located and without contacting the business data in the enterprise network environment. In this way, the business data security of the enterprise can be guaranteed while threat hunting is performed on the terminal based on the terminal behavior log.
[0034] The terminals connected to the threat hunting cloud platform for remote communication are from at least one enterprise. The number of enterprises and the number of terminals connected to the threat hunting cloud platform for remote communication by each enterprise and the terminal types can be selected based on business needs, which is not limited in this embodiment. Exemplary types of terminals may include, but are not limited to: network security terminals (e.g., firewalls, intrusion detection systems, etc.), enterprise business terminals (e.g., toll terminals, etc.).
[0035] For example, Figure 2 As shown, the threat hunting cloud platform is remotely connected to terminals 1 to 6, where terminals 1 to 3 are terminals of enterprise A, and terminals 4 to 6 are terminals of enterprise B. Terminals 1 to 6 respectively send their own terminal behavior logs to the threat hunting cloud platform through remote communication connections.
[0036] In some embodiments, the threat hunting cloud platform performs threat hunting on the terminal based on the terminal behavior log of the terminal. The terminal behavior log is a log generated by the terminal based on the execution of its own process. It is difficult for the threat hunting cloud platform to know when the terminal generates the terminal behavior log. Therefore, in actual applications, the terminal actively sends the terminal behavior log to the threat hunting cloud platform in real time or at a fixed time. When the threat hunting cloud platform remotely obtains the terminal behavior log sent by any terminal, it can perform threat hunting on the terminal based on the terminal behavior log. For the convenience of description, when the threat hunting cloud platform remotely obtains the terminal behavior log of any terminal, the terminal can be described as the target terminal in this embodiment.
[0037] Furthermore, if the terminal is subjected to a malicious attack related to remote communication, the terminal is very likely to be unable to send the terminal behavior log to the threat hunting cloud platform. Based on this, the threat hunting method provided by this embodiment may also include the following steps: customize the corresponding target duration for each terminal; perform for each terminal: after receiving the terminal behavior log sent by the current terminal, monitor whether the terminal behavior log sent by the current terminal is received again within the target duration after receiving the current terminal behavior log, and if not, send an abnormal prompt for the current terminal to the enterprise, so that the business personnel of the enterprise can check whether the current terminal has an abnormality that cannot communicate remotely with the threat hunting cloud platform based on the abnormal prompt.
[0038] In some embodiments, in order to achieve threat hunting for terminals based on terminal behavior logs, the threat hunting cloud platform provided in this embodiment is deployed with a threat identification engine, which identifies threat features of terminal behavior logs based on a threat hunting model, and the threat hunting model is constructed based on threat features corresponding to threats demonstrated by security experts. Based on this, the threat identification engine relies on the threat hunting model constructed by the threat features corresponding to the threats demonstrated by security experts, and has the ability to identify threat features of terminal logs. In this way, after receiving the terminal behavior logs transmitted remotely by the terminal, the threat hunting cloud platform can call the threat identification engine based on the threat hunting model applicable to the terminal to identify threat features of the terminal behavior logs, and then accurately give the threat hunting results of threat hunting for the terminal based on the threat feature identification results.
[0039] The threats for constructing threat hunting models may include but are not limited to at least one of the following: attack behavior, malicious domain name, and malicious IP address. The threat features corresponding to attack behavior are attack behavior features, the threat features corresponding to malicious domain name are domain name features, and the threat features corresponding to malicious IP address are IP address features. Attack behavior is an indicator of attack (IOA), and malicious domain name and malicious IP address are both indicators of compromise (IOC). Among them,
[0040] In some embodiments, when the terminal behavior log of the target terminal is remotely obtained, it is necessary to call the threat identification engine to select a target threat hunting model suitable for the target terminal from the preset threat hunting model, so that the threat identification engine can identify threat characteristics of the terminal behavior log of the target terminal in a more targeted manner based on the target threat hunting model suitable for the target terminal.
[0041] The method of calling the threat identification engine to select a target threat hunting model suitable for the target terminal from the preset threat hunting models may include at least the following three methods:
[0042] First, each preset threat hunting model is applicable to the corresponding terminal type. Then, the specific process of calling the threat identification engine to select a target threat hunting model applicable to the target terminal from the preset threat hunting models may include the following steps: calling the threat identification engine to select a threat hunting model corresponding to the terminal type of the target terminal in the preset threat hunting model as the target threat hunting model applicable to the target terminal.
[0043] In order to achieve more targeted threat hunting for terminals, each threat hunting model preset in this embodiment is applicable to the corresponding terminal type. The terminal type can be characterized by, but not limited to, at least one of the following parameters: the enterprise name of the enterprise to which the terminal belongs, the terminal name, the terminal function (e.g., firewall), etc. In this way, the threat identification engine is called to select the threat hunting model corresponding to the terminal type of the target terminal in the preset threat hunting model as the target threat hunting model applicable to the target terminal, so that the threat identification engine can more accurately identify the threat characteristics of the terminal behavior log of the target terminal based on the selected target threat hunting model.
[0044] Second, the specific process of calling the threat identification engine to select a target threat hunting model suitable for the target terminal from the preset threat hunting models may include the following steps: monitoring whether a customization request from the target terminal is received, the customization request is used to indicate the threat hunting model specified by the target terminal; if received, calling the threat identification engine to select the threat hunting model indicated by the customization request in the preset threat hunting model as the target threat hunting model suitable for the target terminal.
[0045] Considering that each enterprise may pay attention to different threats, for example, some enterprises may pay more attention to threats that may cause greater damage to them, while some threats exist but the damage to the enterprise is minimal, and enterprises usually do not pay much attention to these threats. In this embodiment, different threat hunting models support different threats. Based on this, in order to improve the customization of threat hunting, this embodiment opens the terminal to the permission to submit a customization request to the threat hunting cloud platform, and the customization request is used to indicate the threat hunting model specified by the target terminal. In this way, the terminal can flexibly specify the threat hunting model required for threat hunting on the terminal through a customization request based on the customized needs of the threat hunting of the enterprise to which it belongs.
[0046] When the threat hunting cloud platform receives a threat hunting request from the target terminal, it calls the threat identification engine to select the threat hunting model indicated by the customized request in the preset threat hunting model as the target threat hunting model suitable for the target terminal, so that the threat identification engine can customize the threat feature identification of the terminal behavior log of the target terminal based on the selected target threat hunting model.
[0047] Third, the specific process of calling the threat identification engine to select a target threat hunting model suitable for the target terminal from the preset threat hunting models may include the following steps: all threat hunting models preset by the threat hunting cloud platform are selected as target threat hunting models suitable for the target terminal.
[0048] All threat hunting models preset by the threat hunting cloud platform are selected as target threat hunting models suitable for the target terminal, so that the threat identification engine can more comprehensively identify threat features of the terminal behavior logs of the target terminal based on the selected target threat hunting models, so as to reduce the possibility of missing threat features.
[0049] The above three methods of calling the threat identification engine to select a target threat hunting model suitable for the target terminal from the preset threat hunting models can be flexibly selected for use based on business needs, and this embodiment does not limit this.
[0050] 102. Calling the threat identification engine to identify threat features of the terminal behavior log of the target terminal based on the target threat hunting model.
[0051] After selecting a target threat hunting model suitable for the target terminal, the threat identification engine is called to identify threat features of the terminal behavior log of the target terminal based on the target threat hunting model. The specific process of calling the threat identification engine to identify threat features of the terminal behavior log of the target terminal based on the target threat hunting model may include the following steps 102A to 102B:
[0052] 102A. Invoke the threat identification engine to identify the threat signature strategy corresponding to the target threat hunting model.
[0053] Each threat hunting model preset by the threat hunting cloud platform has a corresponding threat feature identification strategy, which is used to support the threat identification engine to identify threat features of terminal behavior logs based on the threat hunting model.
[0054] 102B. Invoke the threat identification engine to perform threat feature identification on the terminal behavior log of the target terminal based on the threat feature identification strategy.
[0055] The threat hunting model may include but is not limited to at least one of the following model types: rule model, neural network model. The following describes the methods for identifying threat features of the terminal behavior log of the target terminal based on the target threat hunting model under different model types:
[0056] First, the model type of the threat hunting model is a rule model. The rule model is based on a key-value pair, where the key is the threat corresponding to the threat hunting model and the value is the threat feature corresponding to the threat. Threats include attack behaviors, and the threat features corresponding to attack behaviors are attack behavior features. The threat feature identification strategy corresponding to the threat hunting model whose model type is a rule model includes: performing natural language processing on the terminal behavior log to obtain the behavior features, and matching the behavior features of each behavior recorded in the terminal behavior log with each value in the rule model.
[0057] Based on this, the specific process of calling the threat identification engine to identify the threat characteristics of the terminal behavior log of the target terminal based on the threat characteristic identification strategy may include the following steps: calling the attack behavior identification engine to perform natural language processing on the terminal behavior log through the natural language processing (NLP) algorithm to obtain the behavior characteristics; for each behavior in the terminal behavior log, respectively, the following is performed: the behavior characteristics of the current behavior are matched with each value in the rule model through the fuzzy matching algorithm, if the target value with the matching degree of the behavior characteristics is greater than the matching degree threshold, then the current behavior is determined to be an attack behavior corresponding to the target value, and the behavior characteristics corresponding to the current behavior in the terminal behavior log are determined as the threat characteristics identified by the threat identification engine for the terminal behavior log of the target terminal; if the target value with the matching degree of the behavior characteristics is not matched, then the current behavior is determined to be not an attack behavior. For any behavior, the corresponding behavior characteristics in the terminal behavior log may include but are not limited to at least one of the following: process name, process path, process command line, process chain relationship, operation performed by the process, target object of the process operation, context information of the target object, and context information of the process.
[0058] Second, the model type of the threat hunting model is a rule model, which is based on key-value pairs, where the key is the threat corresponding to the threat hunting model and the value is the threat feature corresponding to the threat. Threats include malicious domain names, and the threat features corresponding to malicious domain names are domain name features. The threat feature identification strategy corresponding to the threat hunting model whose model type is a rule model includes: performing natural language processing on the terminal behavior log to obtain domain name features, and matching the domain name features of each domain name recorded in the terminal behavior log with each value in the rule model.
[0059] Based on this, the specific process of calling the threat identification engine to identify the threat characteristics of the terminal behavior log of the target terminal based on the threat characteristic identification strategy may include the following steps: calling the attack behavior identification engine to perform natural language processing on the terminal behavior log through the natural language processing (NLP) algorithm to obtain the domain name characteristics; for each domain name in the terminal behavior log, respectively execute: using the fuzzy matching algorithm to match the domain name characteristics of the current domain name with each value in the rule model respectively, if the target value with a matching degree greater than the matching degree threshold is matched with the domain name characteristics, then it is determined that the current domain name is a malicious domain name corresponding to the target value, and the domain name characteristics corresponding to the current domain name in the terminal behavior log are determined as the threat characteristics identified by the threat identification engine for the terminal behavior log of the target terminal; if the target value with a matching degree greater than the matching degree threshold is not matched with the domain name characteristics, then it is determined that the current domain name is not a malicious domain name.
[0060] In addition, when the threat includes a malicious IP address and the threat feature corresponding to the malicious IP address is an IP address feature, the identification process of the threat feature is basically the same as the identification process of the threat including a malicious domain name, so it will not be repeated here.
[0061] Third, the model type of the threat hunting model is a neural network model. The neural network model is used to take the terminal behavior log as input, and the threats identified by the terminal behavior log and the threat features corresponding to the threats as output. Then, the corresponding threat feature identification strategy of the threat hunting model whose model type is a neural network model includes: taking the terminal behavior log as the model input and inputting it into the neural network model.
[0062] Based on this, the specific process of calling the threat identification engine to identify threat characteristics of the terminal behavior log of the target terminal based on the threat characteristic identification strategy may include the following steps: calling the threat identification engine to input the terminal behavior log into the target threat hunting model, so that the target threat hunting model can identify the threats and threat characteristics in the terminal behavior log; when the target threat hunting model outputs the threat and the threat characteristics corresponding to the threat, the output threat characteristics are determined as the threat characteristics identified by the threat identification engine for the terminal behavior log of the target terminal.
[0063] The above two methods of calling the threat identification engine to identify the threat characteristics of the terminal behavior log of the target terminal based on the target threat hunting model can be flexibly selected based on business needs. For example, the same threat hunting model exists in the above two model types. In this case, the threat identification engine is called to identify the threat characteristics of the terminal behavior log of the target terminal based on the target threat hunting model of each model type, so that the identification results obtained can complement and verify each other to improve the accuracy of the threat characteristic identification results.
[0064] 103. If the threat identification engine identifies a threat feature from the terminal behavior log of the target terminal, a threat hunting result indicating that a threat exists in the target terminal is generated based on the identified threat feature.
[0065] If the threat identification engine identifies threat features in the terminal behavior log of the target terminal, it means that the threats corresponding to these threat features exist in the target terminal, and the threats corresponding to these threat features will threaten the network security of the enterprise where the target terminal is located. Therefore, based on the identified threat features, a threat hunting result is generated to indicate that there are threats in the target terminal, so as to inform the enterprise where the target terminal is located which threats need to be dealt with through the threat hunting results, and indicate the threat features of the threats that need to be dealt with, so that the business personnel of the enterprise can quickly eliminate the threats and reduce the damage caused by the threats. The threat hunting results can be presented in the form of a report, and the threat hunting results may include but are not limited to: target terminal identification, threats, and threat features corresponding to the threats in the terminal behavior log.
[0066] In some embodiments, in order to facilitate the business personnel of the enterprise to quickly deal with threats, the threat hunting method provided in this embodiment may also include: determining corresponding disposal strategies for threats corresponding to the identified threat characteristics; and feeding back the threat hunting results and disposal strategies to the target terminal. The threat hunting cloud platform can preset corresponding disposal strategies for each threat, and the disposal strategies are used to guide the terminal to deal with the corresponding threats. In order to realize the difficulty of dealing with threats in the enterprise where the target terminal is located and provide a basis for dealing with threats, corresponding disposal strategies are determined for threats corresponding to the threat characteristics identified by the threat identification engine, and then the threat hunting results and disposal strategies are fed back to the target terminal, so that the target terminal can deal with the threats in the threat hunting results according to the disposal strategies, thereby improving threat disposal efficiency.
[0067] In some embodiments, after step 102, if the threat identification engine does not identify threat features in the terminal behavior log of the target terminal, a threat hunting result is generated to indicate that no threat exists in the target terminal, so as to inform the target terminal through the threat hunting result that no threat exists in the target terminal during the time period covered by the terminal behavior log.
[0068] The threat hunting method provided in the embodiment of the present application deploys a threat identification engine for identifying threat features of terminal behavior logs based on threat hunting models on the threat hunting cloud platform. In this way, when the terminal behavior log of any terminal is remotely obtained, the threat identification engine is first called to select a target threat hunting model suitable for the target terminal from the preset threat hunting model, and then the threat identification engine is called to identify threat features of the terminal behavior log of the terminal based on the target threat hunting model. In the case where the threat identification engine identifies the threat features of the terminal behavior log of the target terminal, based on the identified threat features, a threat hunting result is generated to indicate that there is a threat in the target terminal. It can be seen that in the solution provided by the present application, the terminal in the enterprise remotely reports its own terminal behavior log to the threat hunting cloud platform, and the threat hunting cloud platform uses the threat hunting model constructed based on the threat features corresponding to the threats demonstrated by security experts to perform threat hunting on the terminal based on the terminal behavior log. In this way, it can fully use the knowledge of threat features corresponding to the threats demonstrated by security experts, etc., to accurately and efficiently perform threat hunting on the terminal, thereby making up for the shortcomings in the network security operation of the enterprise where the terminal is located.
[0069] In some embodiments of the present application, leakage of enterprise sensitive data may cause damage to the enterprise. Based on this, in order to reduce the possibility of leakage of enterprise sensitive data, the threat hunting method provided in this embodiment may also include the following steps: detecting whether the terminal behavior log of the target terminal includes target data for indicating that the terminal behavior log includes sensitive data.
[0070] If it is detected that the terminal behavior log of the target terminal does not include target data for indicating that the terminal behavior log includes sensitive data, it means that threat hunting for the target terminal based on the terminal behavior log of the target terminal will not cause sensitive data leakage of the enterprise where the target terminal is located. Therefore, step 101 is executed to call the threat identification engine to select a target threat hunting model suitable for the target terminal from the preset threat hunting models.
[0071] If it is detected that the terminal behavior log of the target terminal includes target data indicating that the terminal behavior log includes sensitive data, in order to reduce the possibility of sensitive data leakage, any of the following operations A and B can be performed.
[0072] Operation A destroys the terminal behavior log of the target terminal and provides a target prompt to the target terminal. The target prompt is used to indicate that threat hunting cannot be performed based on the terminal behavior log because the terminal behavior log contains sensitive data.
[0073] In the case where the terminal behavior log contains sensitive data, if threat hunting is performed on the target terminal based on the terminal behavior log of the target terminal, sensitive data of the enterprise where the target terminal is located will be leaked. Based on this, in order to avoid sensitive data leakage, the terminal behavior log is destroyed, and threat hunting is no longer performed on the target terminal based on the acquired terminal behavior log to reduce the possibility of sensitive data leakage. While destroying the terminal behavior log, a target prompt is fed back to the target terminal to inform the reason why threat hunting cannot be performed based on the terminal behavior log through the target prompt.
[0074] Operation B, identifying the data type of sensitive data included in the terminal behavior log of the target terminal, desensitizing the sensitive data using desensitizing rules corresponding to the data type, and after desensitization is completed, executing step 101 to call the threat identification engine to identify threat features of the terminal behavior log of the target terminal based on the target threat hunting model.
[0075] In the case where the terminal behavior log includes sensitive data, if threat hunting is performed on the target terminal directly based on the terminal behavior log, sensitive data may be leaked. Based on this, this embodiment desensitizes the sensitive data in the terminal behavior log, and after the desensitization is completed, threat hunting is performed on the target terminal based on the desensitized terminal behavior log, so as to reduce the possibility of sensitive data leakage during the threat hunting process while implementing threat hunting on the target terminal based on the acquired terminal behavior log.
[0076] The specific process of desensitizing sensitive data in the terminal behavior log is: identifying the data type of sensitive data included in the terminal behavior log, where each data type has an applicable desensitization rule; using the desensitization rule corresponding to the data type to desensitize the sensitive data. The data type may include but is not limited to any of the following: name, phone number, account name, password, etc.
[0077] In some embodiments, in order to reduce the possibility that sensitive data is included in the terminal behavior log obtained by the threat hunting cloud platform, the threat hunting cloud platform may also issue sensitive data processing instructions to each terminal, so that each terminal, based on the instruction, first performs sensitive data detection on the terminal behavior log before remotely transmitting the terminal behavior log to the threat hunting cloud platform. If sensitive data is detected, the sensitive data is first desensitized, and then the terminal behavior log is sent to the threat hunting cloud platform to reduce the possibility of sensitive data being sent to the threat hunting cloud platform. If it is detected that no sensitive data exists, the terminal behavior log is directly sent to the threat hunting cloud platform. In this way, detecting whether the terminal behavior log of the target terminal includes target data for indicating that sensitive data is included in the terminal behavior log can be used as a secondary review of sensitive data to minimize the possibility of sensitive data leakage of the enterprise where the terminal is located.
[0078] In some embodiments of the present application, threats include attack behaviors, and the threat features corresponding to the attack behaviors are attack behavior features, and the terminal behavior log records the behavior features generated during the process execution of the target terminal. In actual applications, enterprises sometimes allow some attack behaviors to exist due to business needs, and if these attack behaviors are disposed of, they may affect the corresponding business. Based on this, the threat hunting method provided by this embodiment may also include the following steps: after the above step 102, call the threat identification engine to determine the target attack behavior corresponding to the attack behavior features included in the identified threat features, and determine the target process corresponding to each target attack behavior based on the terminal behavior log; search for the target process corresponding to each target attack behavior in the process whitelist corresponding to the target terminal; if there is a target process found in the process whitelist, the attack behavior features of the target attack behavior of the corresponding target process are removed from the identified threat features.
[0079] For any target attack behavior: if the target process corresponding to the target attack behavior is in the process whitelist corresponding to the target terminal, it means that the target attack behavior is an attack behavior allowed by the target terminal due to business needs, so the attack behavior characteristics of the target attack behavior are removed from the identified threat characteristics to prevent the target attack behavior from being handled as a threat. If the target process corresponding to the target attack behavior is not included in the process whitelist, it means that the target attack behavior is not allowed by the target terminal, so in order to ensure that the target attack behavior can be blocked and handled as a threat, the attack behavior characteristics of the target attack behavior continue to be retained in the identified threat characteristics.
[0080] Similarly, in some embodiments of the present application, threats include malicious domain names and malicious IP addresses. In actual applications, enterprises sometimes allow some malicious domain names and malicious IP addresses to exist due to business needs. If these malicious domain names and malicious IP addresses are disposed of, it may affect the corresponding business. Based on this, the threat hunting method provided in this embodiment may also include the following steps: After the above step 102, if it is determined that the threat characteristics identified by calling the threat identification engine include malicious domain names or malicious IP addresses, the malicious domain names and malicious IP addresses are searched in the domain name and IP address whitelist corresponding to the target terminal; if a malicious domain name or malicious IP address is found in the process whitelist, the characteristics of the corresponding malicious domain name and malicious IP address are removed from the identified threat characteristics.
[0081] In some embodiments of the present application, some threats are associated with each other, and associated threats usually appear together or in sequence. Based on this, after the above step 102, if the threat identification engine identifies threat features from the terminal behavior log of the target terminal, then, in order to hunt threats as comprehensively as possible, after the threat identification engine identifies threat features from the terminal behavior log of the target terminal, the threat hunting method provided in this embodiment may further include the following steps: detecting whether the identified threat features include threat features corresponding to a specified threat, the specified threat being used to trigger a threat to a terminal associated with the target terminal; if included, initiating a terminal behavior log acquisition request to the terminal associated with the target terminal.
[0082] The designated threat is used to trigger a threat to the terminal associated with the target terminal, that is, the threat associated with the designated threat is likely to appear in the terminal associated with the target terminal. Therefore, it is necessary to detect whether the identified threat features include the threat features corresponding to the designated threat.
[0083] If it is detected that the identified threat features include the threat features corresponding to the specified threat, it means that the specified threat may have triggered other threats in the terminal associated with the target terminal. Therefore, a terminal behavior log acquisition request is initiated to the terminal associated with the target terminal, so as to inform the terminal associated with the target terminal to send its own terminal behavior log to the threat hunting cloud platform through the log acquisition request. In this way, after obtaining the target terminal log sent by the terminal associated with the target terminal, the terminal behavior log of the terminal associated with the target terminal can be used to perform threat hunting on the terminal associated with the target terminal, so as to hunt out the threats caused by the specified threat in the terminal associated with the target terminal, thereby realizing comprehensive investigation and disposal of the threats caused by the specified threat.
[0084] If it is detected that the identified threat signature does not include the threat signature corresponding to the specified threat, it means that the threat corresponding to the identified threat signature has most likely not caused other threats in the enterprise where the target terminal is located. Therefore, there is no need to initiate a terminal behavior log acquisition request to the terminal associated with the target terminal.
[0085] In some embodiments of the present application, considering that the threat identification engine may have false positives and false negatives, in order to improve the accuracy and credibility of the threat hunting results, after the above step 103 generates a threat hunting result indicating that a threat exists in the target terminal based on the identified threat features, the threat hunting method provided in this embodiment may further include the following steps 104A to 104D:
[0086] 104A. Push the threat hunting results and the terminal behavior log of the target terminal to the security expert terminal so that the security expert terminal can review whether the threat hunting results are correct.
[0087] Threat hunting results include identified threat features and threats determined based on the identified threat features. Threat hunting results and terminal behavior logs of target terminals are pushed to security expert terminals, so that security experts can visually display threat hunting results and terminal behavior logs of target terminals, and review whether the threat feature identification in the threat hunting results is correct based on the terminal behavior logs, especially whether there are false positives and false negatives in the threats in the threat hunting results.
[0088] 104B. If a confirmation instruction is received from the terminal of the security expert, the threat hunting result is determined as the final threat hunting result. If a confirmation instruction is received from the terminal of the security expert, it means that the security expert has verified that the threat feature identification in the threat hunting result is correct based on the terminal behavior log, and there are no false positives or vulnerabilities in the threat in the threat hunting result, so the threat hunting result is determined as the final threat hunting result.
[0089] 104C. If a modification instruction fed back by the security expert terminal is received, the threat hunting result is modified based on the modification instruction, and the modified threat hunting result is determined as the final threat hunting result.
[0090] If a modification instruction is received from the security expert's terminal feedback, it means that the security expert has found errors in the threat hunting results based on the terminal behavior log. Therefore, the threat hunting results are modified based on the modification instruction to correct the errors in the threat hunting results. After the modification is completed, the modified threat hunting results are determined as the final threat hunting results.
[0091] The modification instruction carries modification data. The modification data is used to modify the second threat in the threat hunting result. The method of modifying the threat hunting result based on the modification instruction may include the following three situations:
[0092] In case one, if there is a false positive in the threat hunting result, and the modification data indicates a second threat that does not exist in the target terminal, the second threat and the threat features corresponding to the second threat are deleted from the threat hunting result to avoid the appearance of threats that do not actually exist in the target terminal in the threat hunting result.
[0093] In case 2, if there is a false positive in the threat hunting result, and the modification data indicates that there is a second threat with an incorrect threat feature in the threat hunting result, the threat feature corresponding to the second threat in the threat hunting result is modified based on the modification data.
[0094] Considering that threat characteristics are one of the important bases for handling and troubleshooting threats on target terminals, the threat characteristics corresponding to the second threat in the threat hunting results are modified based on the modified data to ensure that the threat characteristics corresponding to the threats in the threat hunting results are all correct threat characteristics.
[0095] Case three, if there is a second threat that is missed in the threat hunting results, the second threat and the threat feature corresponding to the second threat are incrementally added to the threat hunting results based on the modified data, so that the threat hunting results can more comprehensively present the threats existing in the target terminal, so that the target terminal can completely eliminate threats based on the modified threat hunting results, reducing the possibility of eliminating threat vulnerabilities.
[0096] Through the above three situations of modifying the threat hunting results based on the modification instructions, after the threat hunting results are modified based on the modification instructions, the modified threat hunting results are determined as the final threat hunting results to be fed back to the target terminal.
[0097] 104D. If feedback is received from the security expert terminal that the target terminal does not have a threat, a final threat hunting result indicating that the target terminal does not have a threat is generated.
[0098] If the security expert terminal feedback indicates that there is no threat to the target terminal, it means that the threats and threat features in the threat results do not exist in the target terminal, and the threat results are inaccurate and unusable. Therefore, it is necessary to generate a new final threat hunting result to indicate that there is no threat to the target terminal.
[0099] After the final threat hunting result is obtained through the above steps 104A to 104D, the final threat hunting result is provided to the target terminal so that the target terminal knows the final hunting result of the threat hunting cloud platform on the target terminal based on the acquired terminal behavior log.
[0100] In some embodiments of the present application, if the threat identification engine does not identify threat features in the terminal behavior log of the target terminal in step 102, a threat hunting result indicating that there is no threat to the target terminal is generated. Considering that the threat identification engine may have false positives and false negatives, in order to improve the accuracy and credibility of the threat hunting results, the threat hunting method provided in this embodiment may also include the following steps 104E to 104G:
[0101] 104E. Push the threat hunting result and the terminal behavior log of the target terminal to the security expert terminal, so that the security expert terminal can review whether the threat hunting result is correct.
[0102] 104F. If a confirmation instruction fed back by the security expert terminal is received, the threat hunting result is determined as the final threat hunting result.
[0103] 104G. If a modification instruction is received from the security expert terminal, the threat hunting result is modified based on the modification instruction, and the modified threat hunting result is determined as the final threat hunting result. The modification instruction carries modification data, and the modification data is used to modify the second threat in the threat hunting result. The second threat is a threat that is missed by the threat hunting result. Based on the modification data, the second threat and the threat feature corresponding to the second threat are incrementally added to the threat hunting result.
[0104] In some embodiments of the present application, based on the above steps 104A to 104D or steps 104E to 104G, in order to continuously optimize the threat hunting capability of the threat hunting cloud platform, it is necessary to continuously optimize and improve the threat hunting model. Based on this, the threat hunting method provided by this embodiment may also include the following steps: if a modification instruction fed back by a security expert terminal is received, then the threat hunting model corresponding to each second threat indicated by the modification data in the preset threat hunting model is determined, and the threat feature increments newly demonstrated by the experts corresponding to each second threat are added to the data set corresponding to the corresponding threat hunting model; if the security expert terminal feedback indicates that there is no threat in the target terminal, then the threat hunting model corresponding to each threat included in the threat hunting result is determined in the preset threat hunting model, and the threat feature increments newly demonstrated by the experts corresponding to each threat are added to the data set corresponding to the relevant threat hunting model; if an iterative update instruction for any threat hunting model is received, then the threat hunting model is iteratively updated based on the threat features corresponding to the threats currently included in the data set corresponding to the threat hunting model. The modification instruction carries modification data, and the modification data is used to modify the second threat in the threat hunting result.
[0105] In some embodiments, if a modification instruction is received from a security expert terminal, it indicates that the threat hunting model corresponding to the second threat in the preset threat hunting model has poor recognition capability for the threat features corresponding to the second threat, and these threat hunting models need to improve the recognition capability for the threat features corresponding to the second threat, so it is necessary to determine the threat hunting model corresponding to each second threat in the preset threat hunting model. For any second threat, the corresponding threat hunting model includes at least one of the following: one is that the threat hunting model corresponding to the second threat is a target hunting model applicable to the target terminal; the other is that the threat hunting model corresponding to the second threat is a threat hunting model in the preset threat hunting model, and the threat types used when constructing the threat hunting model include the threat types of the second threat.
[0106] After determining the threat hunting model corresponding to each second threat, the threat feature increment newly demonstrated by the experts corresponding to each second threat is added to the data set corresponding to the corresponding threat hunting model, so that the threat feature newly demonstrated by the experts corresponding to the second threat can be used as the data basis for iterative updating of the threat hunting model.
[0107] In some embodiments, if a security expert terminal feedback is received that there is no threat to the target terminal, it means that the threat hunting model corresponding to each threat included in the threat hunting result in the preset threat hunting model has poor recognition ability for the threat characteristics corresponding to the threat, and these threat hunting models need to improve the recognition ability for the threat characteristics corresponding to each threat in the threat hunting result, so it is necessary to determine the threat hunting model corresponding to each threat in the threat hunting result in the preset threat hunting model. For any threat in the threat hunting result, the corresponding threat hunting model includes at least one of the following: one is that the threat hunting model corresponding to the threat is a target hunting model applicable to the target terminal; the other is that the threat hunting model corresponding to the threat is a threat hunting model in the preset threat hunting model, and the threat type of the threat used when constructing the threat hunting model includes the threat type of the threat.
[0108] After determining the threat hunting model corresponding to each threat in the threat hunting results, the threat features newly demonstrated by experts corresponding to each threat are incrementally added to the data set corresponding to the corresponding threat hunting model, so that the threat features newly demonstrated by experts corresponding to the threat can be used as the data basis for iterative updating of the threat hunting model.
[0109] In some embodiments, the iterative update instructions are issued in the following two situations: one is that the threat hunting cloud platform sets an update cycle for each threat hunting model, and when the update cycle is reached, the iterative update instructions are issued for the threat hunting model. The other is that the security expert terminal issues an iterative update instruction to the threat hunting model specified by the security expert terminal based on the security expert's update requirements for the threat hunting model.
[0110] If an iterative update instruction is received for any threat hunting model, it indicates that the threat feature identification capability of the threat hunting model needs to be improved. Therefore, the threat hunting model is iteratively updated based on the threat features corresponding to the threats currently included in the data set corresponding to the threat hunting model.
[0111] In some embodiments of the present application, considering that attackers will continuously generate new threats or change threat characteristics for existing threats, and these new threats and changed threat characteristics usually appear in the terminal behavior log of the terminal, in order to continuously optimize the threat hunting capabilities of the threat hunting cloud platform, it is necessary to continuously optimize and improve the threat hunting model. Based on this, the threat hunting method provided in this embodiment may also include the following steps 105A to 105C:
[0112] 105A. Push the terminal behavior log of the target terminal to the security expert terminal, so that the security expert terminal can perform at least one of the following operations based on the terminal behavior log: analyze whether new threats appear based on the target terminal log, and analyze whether the threat characteristics corresponding to the proven threats change.
[0113] After receiving the terminal behavior log of the target terminal, the security expert terminal can perform at least one of the following operations: one is that the security expert terminal has a corresponding security expert, and the security expert terminal visually displays the terminal behavior log of the target terminal, so that the security expert can rely on his own threat hunting experience to analyze whether new threats appear based on the target terminal log, and analyze whether the threat characteristics corresponding to the proven threats have changed. Another is that the security expert terminal is deployed with at least one threat demonstration tool, and the threat demonstration tool is called to analyze whether new threats appear based on the target terminal log, and analyze whether the threat characteristics corresponding to the proven threats have changed; the threat demonstration attack tool has the ability to support the analysis of whether new threats appear based on the target terminal log, and analyze whether the threat characteristics corresponding to the proven threats have changed.
[0114] 105B. If a new threat is received from a security expert terminal, a threat hunting model to be updated corresponding to the new threat is selected from the preset threat hunting models, and the threat hunting model to be updated is iteratively updated based on the threat features demonstrated by the security experts corresponding to the new threat.
[0115] If a new threat is received from a security expert terminal, a threat hunting model to be updated corresponding to the new threat is selected from the preset threat hunting model, and the threat hunting model to be updated includes at least one of the following: a target threat hunting model, and a threat hunting model whose threat types used during construction include the threat type of the new threat. Then, the threat hunting model to be updated is iteratively updated based on the threat features demonstrated by the security expert corresponding to the new threat, so that the threat hunting model to be updated has the ability to identify the threat features of the new threat through iterative updates.
[0116] 105C. If the security expert terminal feeds back modification information of the threat characteristics corresponding to the proven threat, the threat characteristics corresponding to the proven threat are modified based on the modification information, and the corresponding threat hunting model is iteratively updated based on the modified threat characteristics corresponding to the proven threat.
[0117] If the security expert terminal feeds back modification information of the threat characteristics corresponding to the proven threats, it indicates that the threat characteristics corresponding to these threats have changed. Therefore, the threat characteristics corresponding to the corresponding proven threats are modified based on the modification information, and the corresponding threat hunting models are iteratively updated based on the modified threat characteristics corresponding to the proven threats, so that these threat hunting models can have the ability to identify these modified threat characteristics.
[0118] Through the above steps 105A to 105C, the threat feature identification capability of the threat hunting model in the threat hunting cloud platform can be continuously expanded and improved, thereby continuously improving the threat hunting capability of the threat hunting cloud platform.
[0119] In some embodiments of the present application, due to the limitation of data resources and threat hunting experience, some threats may not be clearly demonstrated by security experts, and these undemonstrated threats are difficult to hunt based on the preset threat hunting model. In order to identify these threats and reduce the damage caused by these threats, the threat identification engine also supports the identification of suspected threats in terminal behavior logs. Based on this, the threat hunting method provided in this embodiment may also include the following steps 106A to 106C:
[0120] Step 106A: Invoke a threat identification engine to identify suspected threats on the terminal behavior log of the target terminal.
[0121] The preset threat whitelist is used to record threats that are allowed to exist on the target terminal. Suspected threats are not included in the threats that have been proven by security experts and are not included in the preset threat whitelist. Suspected threats are currently unable to clearly determine whether they are threats.
[0122] Calling the threat identification engine to identify suspected threats in the terminal behavior log of the target terminal is related to the threat type. The following is an example of a threat including an attack behavior: the threat includes an attack behavior, and the terminal behavior log records the behavior characteristics corresponding to the behavior generated during the process execution of the target terminal. Based on this, the specific process of calling the threat identification engine to identify suspected threats in the terminal behavior log of the target terminal may include: calling the threat identification engine to select target behaviors from the behaviors recorded in the terminal behavior log that are not included in the threats that have been demonstrated by security experts and are not included in the preset threat whitelist. Calling the threat identification engine to perform the following for each target behavior: based on the corresponding behavior characteristics of the target behavior in the terminal behavior log, determine the behavior intention of the target behavior; determine the target probability that the behavior intention is malicious; if the target probability reaches the probability threshold, the target behavior is determined as a suspected threat.
[0123] The threat identification engine is called to select target behaviors from the behaviors recorded in the terminal behavior log that are not included in the threats proven by security experts and are not included in the preset threat whitelist. The target behavior is a behavior that is currently unclear whether it is an attack behavior.
[0124] After determining the target attack behavior, call the threat identification engine to execute for each target behavior separately: determine the behavioral intent of the current target behavior based on the behavioral features corresponding to the current target behavior in the terminal behavior log; determine the target probability that the behavioral intent is malicious; if the target probability reaches the probability threshold, the current target behavior is determined as a suspected threat. The log features corresponding to the current target behavior in the terminal behavior log are analyzed by a preset intention recognition model to obtain the behavioral intent of the current target behavior. The intention recognition model is trained based on multiple sets of data, and each set of data includes the behavioral features corresponding to the behavior and the behavioral intention corresponding to the behavior. The behavioral intention is used to reflect the purpose that the target behavior needs to achieve.
[0125] After determining the behavioral intention of the current target behavior, it is necessary to determine the target probability of the behavioral intention. The target probability is used to indicate the probability that the behavioral intention is malicious, and it is positively correlated with the possibility that the behavioral intention is malicious. The specific process of determining the target probability of the behavioral intention may include the following steps: identifying the behavioral intention through a preset probability recognition model to obtain the target probability of the behavioral intention. The probability recognition model is trained based on multiple sets of data corresponding to the terminal type, and each set of data includes the behavioral intention corresponding to the terminal and the target probability corresponding to the behavioral intention. If the target probability reaches the probability threshold, it means that the target behavior is likely to be an attack behavior with malicious intent, so the target behavior is determined as a suspected threat. If the target probability does not reach the probability threshold, it means that the target behavior is likely to be a safe behavior, so there is no need to determine it as a suspected threat.
[0126] 106B. If the threat identification engine identifies a suspected threat, the log data corresponding to the identified suspected threat in the terminal behavior log is pushed to the security expert terminal, so that the security expert terminal can verify whether the suspected threat is a threat.
[0127] If the threat identification engine identifies a suspected threat, it means that the suspected threat is likely to be a threat. Therefore, the log data corresponding to the identified suspected threat in the terminal behavior log is pushed to the security expert terminal, so that the security expert terminal can verify whether the suspected threat is a threat based on the log data corresponding to the suspected threat in the terminal behavior log.
[0128] The method for the security expert terminal to prove whether a suspected threat is a threat based on the log data corresponding to the suspected threat in the terminal behavior log may include at least one of the following: one is that the security expert terminal has a corresponding security expert, then the security expert terminal visually displays the log data corresponding to the suspected threat in the terminal behavior log, so that the security expert can rely on his own threat hunting experience to prove whether the suspected threat is a threat. Another is that the security expert terminal is deployed with at least one threat proof tool, and the threat proof tool is called to prove whether the suspected threat is a threat based on the log data. The threat proof tool is a tool that proves whether the suspected threat is a threat based on the log data.
[0129] 106C. If the argumentation conclusion indicating that the suspected threat is the first threat is fed back by the security expert terminal, at least one of the following operations C to D is performed.
[0130] Operation C: If the threat identification engine identifies a threat feature from the terminal behavior log of the target terminal, after generating a threat hunting result indicating the existence of a threat in the target terminal based on the identified threat feature, data describing the first threat indicated by the argumentation conclusion that exists in the target terminal is incrementally added to the threat hunting result. This allows the first threat indicated by the argumentation conclusion and the threat feature corresponding to the first threat to appear in the threat hunting result, so that the target terminal and the business personnel of the enterprise where the target terminal is located can handle the first threat based on the threat hunting result.
[0131] Operation D: If the threat identification engine does not identify threat features in the terminal behavior log of the target terminal, then based on the first threat indicated by the argumentation conclusion, a threat hunting result is generated to indicate that a threat exists in the target terminal, so as to obtain a threat hunting result indicating that the first threat exists in the target terminal, so that the business personnel of the target terminal and the enterprise where the target terminal is located can deal with the first threat based on the threat hunting result.
[0132] In some embodiments, the threat hunting method provided in this embodiment may also include: selecting a threat hunting model to be updated corresponding to the first threat indicated by the argumentation conclusion from a preset threat hunting model, and iteratively updating the selected threat hunting model based on the threat characteristics demonstrated by security experts corresponding to the first threat.
[0133] The threat hunting model to be updated corresponding to the first threat indicated by the argumentation conclusion may include at least one of the following: a target threat hunting model, and a threat hunting model whose threat type includes the threat type of the first threat among the threat types used during construction. Based on the threat features demonstrated by the security experts corresponding to the first threat, the selected threat hunting model is iteratively updated, so that the threat feature identification capability of the threat hunting model in the threat hunting cloud platform can be continuously expanded and improved, thereby continuously improving the threat hunting capability of the threat hunting cloud platform.
[0134] In some embodiments of the present application, Figure 3 The flowchart of the threat hunting method provided in this embodiment is shown. Figure 3 The terminal, threat hunting cloud platform, and security expert terminal are illustrated in FIG. The threat hunting cloud platform is deployed with a threat identification engine. The threat identification engine identifies threat features of the terminal behavior log based on the threat hunting model. The threat hunting model is constructed based on the threat features corresponding to the threats demonstrated by the security expert. The terminal sends the terminal behavior log to the threat hunting cloud platform through remote communication. The threat hunting cloud platform calls the threat identification engine to select a target threat hunting model suitable for the target terminal from the preset threat hunting model. Then the threat identification engine is called to identify threat features of the terminal behavior log of the target terminal based on the target threat hunting model. If the threat identification engine identifies threat features of the terminal behavior log of the target terminal, a threat hunting result indicating that a threat exists in the target terminal is generated based on the identified threat features. The threat hunting cloud platform pushes the threat hunting results and the terminal behavior log of the target terminal as data to be reviewed to the security expert terminal, so that the security expert terminal can visualize the threat hunting results and the terminal behavior log, so that the security expert can review whether the threat hunting results are correct. If a confirmation instruction is received from the security expert terminal, the threat hunting result is determined as the final threat hunting result, and the final threat hunting result is provided to the target terminal so that the target terminal can perform threat disposal based on the threat hunting result.
[0135] Furthermore, an embodiment of the present application also provides a threat hunting device, which is applied to a threat hunting cloud platform, wherein the threat hunting cloud platform is remotely connected to at least one terminal, and the threat hunting cloud platform is deployed with a threat identification engine for identifying threat features of terminal behavior logs based on a threat hunting model, wherein the threat hunting model is constructed based on threat features corresponding to threats demonstrated by security experts, such as Figure 4 As shown, the threat hunting device provided in this embodiment may include:
[0136] A selection module 21 is used for calling the threat identification engine to select a target threat hunting model suitable for the target terminal from preset threat hunting models if the terminal behavior log of any target terminal is remotely acquired;
[0137] An identification module 22 is used to call the threat identification engine to perform threat feature identification on the terminal behavior log of the target terminal based on a target threat hunting model;
[0138] The generating module 23 is configured to generate a threat hunting result indicating that a threat exists in the target terminal based on the identified threat feature if the threat identification engine identifies a threat feature from the terminal behavior log of the target terminal.
[0139] The threat hunting device provided in the embodiment of the present application deploys a threat identification engine for identifying threat features of terminal behavior logs based on threat hunting models on the threat hunting cloud platform. In this way, when the terminal behavior log of any terminal is remotely obtained, the threat identification engine is first called to select a target threat hunting model suitable for the target terminal from the preset threat hunting model, and then the threat identification engine is called to identify threat features of the terminal behavior log of the terminal based on the target threat hunting model. In the case where the threat identification engine identifies the threat features of the terminal behavior log of the target terminal, based on the identified threat features, a threat hunting result is generated to indicate that there is a threat in the target terminal. It can be seen that in the solution provided by the present application, the terminal in the enterprise remotely reports its own terminal behavior log to the threat hunting cloud platform, and the threat hunting cloud platform uses the threat hunting model constructed based on the threat features corresponding to the threats demonstrated by security experts to perform threat hunting on the terminal based on the terminal behavior log. In this way, it can fully use the knowledge of threat features corresponding to the threats demonstrated by security experts, etc., to accurately and efficiently perform threat hunting on the terminal, thereby making up for the shortcomings in the network security operation of the enterprise where the terminal is located.
[0140] In some embodiments of the present application, Figure 5 As shown, each preset threat hunting model is applicable to the corresponding terminal type, then, the selection module 21 includes: a first selection unit 211, which is used to call the threat identification engine to select a target threat hunting model applicable to the target terminal from the preset threat hunting model, including: calling the threat identification engine to select the threat hunting model corresponding to the terminal type of the target terminal in the preset threat hunting model as the target threat hunting model applicable to the target terminal.
[0141] In some embodiments of the present application, Figure 5As shown, the selection module 21 includes: a second selection unit 212, which is used to monitor whether a customization request of the target terminal is received, and the customization request is used to indicate the threat hunting model specified by the target terminal; if received, the threat identification engine is called to select the threat hunting model indicated by the customization request in the preset threat hunting model as the target threat hunting model suitable for the target terminal.
[0142] In some embodiments of the present application, Figure 5 As shown, the threat identification engine also supports suspected threat identification of terminal behavior logs. Then, the threat hunting device provided in this embodiment may also include:
[0143] A suspected identification module 24, configured to call the threat identification engine to identify suspected threats on the terminal behavior log of the target terminal, wherein the suspected threats are not included in the threats that have been demonstrated by security experts and are not included in the preset threat whitelist;
[0144] The first push module 25 is used for pushing the log data corresponding to the identified suspected threat in the terminal behavior log to the security expert terminal if the threat identification engine identifies a suspected threat, so that the security expert terminal can verify whether the suspected threat is a threat;
[0145] The first handling module 26 is used to perform the following operations after receiving the argumentation conclusion indicating that the suspected threat is the first threat fed back by the security expert terminal: if the identification module 22 calls the threat identification engine to identify threat features from the terminal behavior log of the target terminal, then after the generation module 23 generates a threat hunting result indicating that a threat exists at the target terminal based on the identified threat features, data describing the first threat indicated by the argumentation conclusion is incrementally added to the threat hunting result; if the identification module 22 calls the threat identification engine to fail to identify threat features from the terminal behavior log of the target terminal, then based on the first threat indicated by the argumentation conclusion, a threat hunting result indicating that a threat exists at the target terminal is generated.
[0146] In some embodiments of the present application, Figure 5As shown, the threat includes attack behavior, and the terminal behavior log records the behavior characteristics corresponding to the behavior generated during the process execution of the target terminal. Then, the suspected identification module 24 is specifically used to call the threat identification engine to select target behaviors that are not included in the threats that have been demonstrated by security experts and are not included in the preset threat whitelist from the behaviors recorded in the terminal behavior log; call the threat identification engine to perform for each target behavior: based on the behavior characteristics corresponding to the target behavior in the terminal behavior log, determine the behavior intention of the target behavior; determine the target probability that the behavior intention is a malicious intention; if the target probability reaches the probability threshold, determine the target behavior as a suspected threat.
[0147] In some embodiments of the present application, Figure 5 As shown, the threat hunting device provided by this embodiment may also include: a first update module 27, which is used to select, from the preset threat hunting models, a threat hunting model to be updated corresponding to the first threat indicated by the argumentation conclusion after receiving the argumentation conclusion fed back by the security expert terminal indicating that the suspected threat is the first threat, and the threat hunting model to be updated includes at least one of the following: the target threat hunting model, a threat hunting model whose threat type includes the threat type of the first threat among the threat types used during construction; based on the threat characteristics demonstrated by the security expert corresponding to the first threat, iteratively updating the selected threat hunting model.
[0148] In some embodiments of the present application, Figure 5 As shown, the threat hunting result includes the identified threat features and the threats determined based on the identified threat features. Then, the threat hunting device provided in this embodiment may further include:
[0149] A second push module 28 is used to push the threat hunting result and the terminal behavior log of the target terminal to the security expert terminal, so that the security expert terminal can review whether the threat hunting result is correct;
[0150] The second handling module 29 is used to determine the threat hunting result generated by the generation module 23 as the final threat hunting result if a confirmation instruction is received from the security expert terminal; to modify the threat hunting result generated by the generation module 23 based on the modification instruction and determine the modified threat hunting result as the final threat hunting result if a modification instruction is received from the security expert terminal; and to generate a final threat hunting result indicating that there is no threat to the target terminal if feedback is received from the security expert terminal that there is no threat to the target terminal.
[0151] In some embodiments of the present application, Figure 5As shown, the modification instruction carries modification data, and the modification data is used to modify the second threat in the threat hunting result. Then, the second handling module 29 is specifically used to delete the second threat and the threat characteristics corresponding to the second threat from the threat hunting result if there is a false alarm in the threat hunting result and the modification data indicates that the second threat does not exist in the target terminal; if there is a false alarm in the threat hunting result and the modification data indicates that there is a second threat with an incorrect threat characteristic in the threat hunting result, modify the threat characteristics corresponding to the second threat in the threat hunting result based on the modification data; if there is a missed second threat in the threat hunting result, add the second threat and the threat characteristics corresponding to the second threat to the threat hunting result based on the modification data.
[0152] In some embodiments of the present application, Figure 5 As shown, the threat hunting device provided by the present embodiment may further include: a second update module 30, which is used for, after the second push module 28 pushes the threat hunting result and the terminal behavior log of the target terminal to the security expert terminal, if a modification instruction fed back by the security expert terminal is received, determining the threat hunting model corresponding to each second threat indicated by the modification data in the preset threat hunting model, and adding the threat feature increments newly demonstrated by the experts corresponding to each second threat to the data set corresponding to the corresponding threat hunting model; if feedback from the security expert terminal is received that there is no threat to the target terminal, determining the threat hunting model corresponding to each threat included in the threat hunting result in the preset threat hunting model, and adding the threat feature increments newly demonstrated by the experts corresponding to each threat to the data set corresponding to the corresponding threat hunting model; if an iterative update instruction for any threat hunting model is received, iteratively updating the threat hunting model based on the threat features corresponding to the threats currently included in the data set corresponding to the threat hunting model.
[0153] In some embodiments of the present application, Figure 5 As shown, each preset threat hunting model has a corresponding threat feature identification strategy, and the threat feature identification strategy is used to support the threat identification engine to identify threat features of the terminal behavior log based on the threat hunting model. Then, the identification module 22 is specifically used to call the threat identification engine to identify threat features of the terminal behavior log of the target terminal based on the threat feature identification strategy through the threat feature identification strategy corresponding to the target threat hunting model.
[0154] In some embodiments of the present application, Figure 5As shown, the threat hunting device provided by this embodiment may also include: a third handling module 31, which is used to perform any of the following operations if it is detected that the terminal behavior log of the target terminal includes target data for indicating that the terminal behavior log includes sensitive data: destroying the terminal behavior log of the target terminal, and feeding back a target prompt to the target terminal, wherein the target prompt is used to prompt that threat hunting cannot be performed based on the terminal behavior log because the terminal behavior log includes sensitive data; or, identifying the data type of the sensitive data included in the terminal behavior log of the target terminal, desensitizing the sensitive data using a desensitization rule corresponding to the data type, and after desensitization is completed, executing the step of calling the threat identification engine to perform threat feature identification on the terminal behavior log of the target terminal based on the target threat hunting model;
[0155] In some embodiments of the present application, Figure 5 As shown, the threat includes attack behavior, the threat feature corresponding to the attack behavior is the attack behavior feature, and the terminal behavior log records the behavior feature generated during the process execution of the target terminal, then the threat hunting device provided by this embodiment may also include:
[0156] The fourth disposal module 32 is used to call the threat identification engine to determine the target attack behavior corresponding to the attack behavior characteristics included in the identified threat characteristics, and determine the target process corresponding to each target attack behavior based on the terminal behavior log; search for the target process corresponding to each target attack behavior in the process whitelist corresponding to the target terminal; if a target process is found in the process whitelist, the attack behavior characteristics of the target attack behavior of the corresponding target process are removed from the identified threat characteristics.
[0157] In some embodiments of the present application, the threat hunting device provided in this embodiment may also include: a detection module 33, which is used to detect whether the identified threat characteristics include threat characteristics corresponding to specified threats after the identification module 22 calls the threat identification engine to identify threat characteristics from the terminal behavior log of the target terminal, and the specified threat is used to trigger a threat to the terminal associated with the target terminal; if included, a terminal behavior log acquisition request is initiated to the terminal associated with the target terminal.
[0158] In some embodiments of the present application, the threat hunting device provided by this embodiment may also include:
[0159] The third push module 34 is used to push the terminal behavior log of the target terminal to the security expert terminal, so that the security expert terminal can perform at least one of the following operations based on the terminal behavior log: analyze whether a new threat appears based on the target terminal log, and analyze whether the threat characteristics corresponding to the demonstrated threat have changed;
[0160] The third updating module 35 is used for, if a new threat is received from the security expert terminal, selecting a to-be-updated threat hunting model corresponding to the new threat from the preset threat hunting model, and iteratively updating the to-be-updated threat hunting model based on the threat characteristics demonstrated by the security experts corresponding to the new threat, wherein the to-be-updated threat hunting model includes at least one of the following: the target threat hunting model, and a threat hunting model whose threat types include the threat types of the new threat used during construction; if the security expert terminal feedbacks modification information for the threat characteristics corresponding to the demonstrated threat, modifying the threat characteristics corresponding to the corresponding demonstrated threat based on the modification information, and iteratively updating the corresponding threat hunting model based on the modified threat characteristics corresponding to the demonstrated threat.
[0161] In some embodiments of the present application, the threat hunting device provided by this embodiment may also include:
[0162] A determination module 36, configured to determine a corresponding handling strategy for the threat corresponding to the identified threat feature;
[0163] The feedback module 37 is used to feed back the threat hunting result generated by the generation module 23 and the disposal strategy determined by the determination module 36 to the target terminal.
[0164] In the threat hunting device provided in the embodiment of the present application, the detailed explanations used in the operation of each functional module can be referred to the corresponding detailed explanations of the above-mentioned threat hunting method embodiment, which will not be repeated here.
[0165] Furthermore, an embodiment of the present application also provides a computer-readable storage medium, wherein the storage medium includes a stored program, wherein when the program is executed, the device where the storage medium is located is controlled to execute the above-mentioned threat hunting method.
[0166] Furthermore, an embodiment of the present application also provides an electronic device, comprising: a memory for storing a program; and a processor, coupled to the memory, for running the program to execute the above-mentioned threat hunting method.
[0167] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0168] It is understandable that the related features in the above methods and devices can be referenced to each other. In addition, the "first", "second" and the like in the above embodiments are used to distinguish the embodiments, but do not represent the advantages and disadvantages of the embodiments.
[0169] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0170] The algorithm and display provided herein are not inherently related to any particular computer, virtual system or other device. Various general purpose systems can also be used together with the teachings based on this. According to the above description, it is obvious to construct the structure required for this type of system. In addition, the application is not directed to any specific programming language either. It should be understood that various programming languages can be utilized to realize the content of the application described herein, and the description of the above specific language is to disclose the preferred embodiment of the application.
[0171] In addition, the memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.
[0172] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that include computer-usable program code.
[0173] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of the processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data cutover device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data cutover device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0174] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data switching device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured product including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0175] These computer program instructions can also be loaded onto a computer or other programmable data transfer device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable device to implement the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0176] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0177] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.
[0178] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0179] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0180] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0181] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included within the scope of the claims of the present application.
Claims
1. A threat hunting method, characterized in that: Applied to a threat hunting cloud platform, the threat hunting cloud platform is remotely connected to at least one terminal, and the threat hunting cloud platform is deployed with a threat identification engine, the threat identification engine identifies threat features of terminal behavior logs based on a threat hunting model, and the threat hunting model is constructed based on threat features corresponding to threats demonstrated by security experts, the method includes: If the terminal behavior log of any target terminal is remotely acquired, the threat identification engine is called to select a target threat hunting model suitable for the target terminal from the preset threat hunting models; Calling the threat identification engine to identify threat features of the terminal behavior log of the target terminal based on the target threat hunting model; If the threat identification engine identifies a threat feature from the terminal behavior log of the target terminal, a threat hunting result indicating that a threat exists in the target terminal is generated based on the identified threat feature.
2. The method according to claim 1, characterized in that If each preset threat hunting model is applicable to a corresponding terminal type, then calling the threat identification engine to select a target threat hunting model applicable to the target terminal from the preset threat hunting models includes: calling the threat identification engine to select a threat hunting model corresponding to the terminal type of the target terminal from the preset threat hunting models as the target threat hunting model applicable to the target terminal; and / or, Calling the threat identification engine to select a target threat hunting model suitable for the target terminal from a preset threat hunting model, including: monitoring whether a customization request from the target terminal is received, the customization request being used to indicate the threat hunting model specified by the target terminal; if received, calling the threat identification engine to select the threat hunting model indicated by the customization request from the preset threat hunting model as the target threat hunting model suitable for the target terminal.
3. The method according to claim 1, characterized in that The threat identification engine further supports suspected threat identification of terminal behavior logs, and the method further includes: Calling the threat identification engine to identify suspected threats on the terminal behavior log of the target terminal, wherein the suspected threats are not included in the threats that have been demonstrated by security experts and are not included in the preset threat whitelist; If the threat identification engine identifies a suspected threat, the log data corresponding to the identified suspected threat in the terminal behavior log is pushed to the security expert terminal, so that the security expert terminal can verify whether the suspected threat is a threat; After receiving the argumentation conclusion indicating that the suspected threat is the first threat fed back by the security expert terminal, the following operations are performed: If the threat identification engine identifies a threat feature from the terminal behavior log of the target terminal, after generating a threat hunting result indicating that a threat exists in the target terminal based on the identified threat feature, incrementally adding data describing that the target terminal has a first threat indicated by the argumentation conclusion to the threat hunting result; If the threat identification engine does not identify a threat feature from the terminal behavior log of the target terminal, a threat hunting result indicating that a threat exists in the target terminal is generated based on the first threat indicated by the argumentation conclusion.
4. The method according to claim 3, characterized in that The threat includes an attack behavior, and the terminal behavior log records the behavior characteristics corresponding to the behavior generated during the process execution of the target terminal, then, calling the threat identification engine to identify suspected threats on the terminal behavior log of the target terminal includes: Calling the threat identification engine to select target behaviors from the behaviors recorded in the terminal behavior log that are not included in the threats demonstrated by security experts and are not included in the preset threat whitelist; Calling the threat identification engine to perform, for each target behavior, respectively: determining the behavior intention of the target behavior based on the behavior characteristics corresponding to the target behavior in the terminal behavior log; determining the target probability that the behavior intention is malicious; if the target probability reaches a probability threshold, determining the target behavior as a suspected threat; and / or, The method also includes: selecting, from preset threat hunting models, a threat hunting model to be updated corresponding to the first threat indicated by the argumentation conclusion, the threat hunting model to be updated including at least one of the following: the target threat hunting model, a threat hunting model whose threat types used during construction include the threat type of the first threat; and iteratively updating the selected threat hunting model based on threat features demonstrated by security experts corresponding to the first threat.
5. The method according to claim 1, characterized in that: The threat hunting result includes the identified threat features and the threats determined based on the identified threat features, then, the method further includes: Pushing the threat hunting results and the terminal behavior log of the target terminal to the security expert terminal so that the security expert terminal can review whether the threat hunting results are correct; If a confirmation instruction fed back by the security expert terminal is received, the threat hunting result is determined as the final threat hunting result; If a modification instruction fed back by the security expert terminal is received, the threat hunting result is modified based on the modification instruction, and the modified threat hunting result is determined as the final threat hunting result; If feedback is received from the security expert terminal that the target terminal does not have a threat, a final threat hunting result indicating that the target terminal does not have a threat is generated.
6. The method according to claim 5, characterized in that The modification instruction carries modification data, and the modification data is used to modify the second threat in the threat hunting result. Then, modifying the threat hunting result based on the modification instruction includes: If there is a false positive in the threat hunting result, and the modification data indicates a second threat that does not exist in the target terminal, the second threat and the threat features corresponding to the second threat are deleted from the threat hunting result; if there is a false positive in the threat hunting result, and the modification data indicates that there is a second threat with an incorrect threat feature in the threat hunting result, the threat features corresponding to the second threat in the threat hunting result are modified based on the modification data; if there is a missed second threat in the threat hunting result, the second threat and the threat features corresponding to the second threat are incrementally added to the threat hunting result based on the modification data; and / or, The method also includes: if a modification instruction fed back by the security expert terminal is received, determining the threat hunting model corresponding to each second threat indicated by the modification data in the preset threat hunting model, and adding the threat feature increments newly demonstrated by the experts corresponding to each second threat to the data set corresponding to the corresponding threat hunting model; if feedback is received from the security expert terminal that there is no threat to the target terminal, determining the threat hunting model corresponding to each threat included in the threat hunting result in the preset threat hunting model, and adding the threat feature increments newly demonstrated by the experts corresponding to each threat to the data set corresponding to the corresponding threat hunting model; if an iterative update instruction for any threat hunting model is received, iteratively updating the threat hunting model based on the threat features corresponding to the threats currently included in the data set corresponding to the threat hunting model.
7. The method according to any one of claims 1 to 6, characterized in that Each preset threat hunting model has a corresponding threat feature identification strategy, and the threat feature identification strategy is used to support the threat identification engine to perform threat feature identification on the terminal behavior log based on the threat hunting model. Then, calling the threat identification engine to perform threat feature identification on the terminal behavior log of the target terminal based on the target threat hunting model includes: calling the threat identification engine to perform threat feature identification on the terminal behavior log of the target terminal based on the threat feature identification strategy through the threat feature identification strategy corresponding to the target threat hunting model; and / or, The method further includes: if it is detected that the terminal behavior log of the target terminal includes target data for indicating that the terminal behavior log includes sensitive data, performing any of the following operations: destroying the terminal behavior log of the target terminal, and feeding back a target prompt to the target terminal, wherein the target prompt is used to prompt that threat hunting cannot be performed based on the terminal behavior log because the terminal behavior log includes sensitive data; or, identifying the data type of the sensitive data included in the terminal behavior log of the target terminal, desensitizing the sensitive data using a desensitization rule corresponding to the data type, and after desensitization is completed, executing the step of calling the threat identification engine to perform threat feature identification on the terminal behavior log of the target terminal based on a target threat hunting model; and / or, The threat includes an attack behavior, the threat feature corresponding to the attack behavior is an attack behavior feature, and the terminal behavior log records the behavior feature generated during the process execution of the target terminal, then the method further includes: calling the threat identification engine to determine the target attack behavior corresponding to the attack behavior feature included in the identified threat feature, and determining the target process corresponding to each target attack behavior based on the terminal behavior log; searching for the target process corresponding to each target attack behavior in the process whitelist corresponding to the target terminal; if a target process is found in the process whitelist, then removing the attack behavior feature of the target attack behavior of the corresponding target process from the identified threat feature; and / or, After the threat identification engine identifies the threat characteristics of the terminal behavior log of the target terminal, the method further includes: detecting whether the identified threat characteristics include a threat characteristic corresponding to a specified threat, where the specified threat is used to cause a threat to a terminal associated with the target terminal; if included, initiating a terminal behavior log acquisition request to the terminal associated with the target terminal; and / or, The method further includes: pushing the terminal behavior log of the target terminal to the security expert terminal, so that the security expert terminal performs at least one of the following operations based on the terminal behavior log: analyzing whether a new threat appears based on the target terminal log, and analyzing whether the threat characteristics corresponding to the demonstrated threat have changed; If a new threat fed back by the security expert terminal is received, a threat hunting model to be updated corresponding to the new threat is selected from the preset threat hunting models, and the threat hunting model to be updated is iteratively updated based on the threat characteristics demonstrated by the security expert corresponding to the new threat, wherein the threat hunting model to be updated includes at least one of the following: the target threat hunting model, and a threat hunting model whose threat type used during construction includes the threat type of the new threat; If the security expert terminal feeds back modification information of the threat feature corresponding to the proven threat, the threat feature corresponding to the proven threat is modified based on the modification information, and the corresponding threat hunting model is iteratively updated based on the modified threat feature corresponding to the proven threat; and / or, The method further includes: determining a corresponding disposal strategy for the threat corresponding to the identified threat feature; and feeding back the threat hunting result and the disposal strategy to the target terminal.
8. A threat hunting device, characterized in that: Applied to a threat hunting cloud platform, the threat hunting cloud platform is remotely connected to at least one terminal, and the threat hunting cloud platform is deployed with a threat identification engine for identifying threat features of terminal behavior logs based on a threat hunting model, the threat hunting model is constructed based on threat features corresponding to threats demonstrated by security experts, and the device includes: A selection module, configured to call the threat identification engine to select a target threat hunting model suitable for the target terminal from preset threat hunting models if a terminal behavior log of any target terminal is remotely acquired; An identification module, used for calling the threat identification engine to identify threat features of the terminal behavior log of the target terminal based on a target threat hunting model; A generating module is used to generate a threat hunting result indicating that a threat exists in the target terminal based on the identified threat feature if the threat identification engine identifies a threat feature in the terminal behavior log of the target terminal.
9. A computer-readable storage medium, characterized in that: The storage medium includes a stored program, wherein when the program is executed, the device where the storage medium is located is controlled to execute the threat hunting method according to any one of claims 1 to 7.
10. An electronic device, characterized in that: The electronic device comprises: Memory, used to store programs; A processor, coupled to the memory, configured to run the program to execute the threat hunting method according to any one of claims 1 to 7.