Threat detection method and device, equipment and storage medium
By using the encrypted salt value in the threat intelligence data and the encrypted first encrypted data, the historical access data is encrypted and matched, and threats in historical access behavior in the enterprise network are detected, the problem of insufficient network security is solved, and the effect of timely discovery and patching vulnerabilities is achieved.
Patent Information
- Application Number
- CN202311504533.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-13
- Publication Date
- 2025-05-13
AI Technical Summary
There are omissions of historical attacks in the enterprise network, resulting in insufficient network security and it is difficult to detect and repair vulnerabilities in a timely manner.
By obtaining the encrypted salt value in the threat intelligence data and the encrypted first encrypted data, the historical access data is encrypted and matched with the first encrypted data, the threatened historical access behavior is detected.
Effectively detecting the missed threats in historical access behavior, improving the security of the enterprise network and ensuring that users can detect and patch vulnerabilities in a timely manner.
Smart Images

Figure CN119995906A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to a threat detection method, apparatus, device and storage medium. Background Art
[0002] In recent years, there have been more and more cyber attacks, such as APT (Advanced Persistent Threat) attacks, ransomware, mining software, stealing software, hacker tools, backdoor software, and botnets. For enterprises, network security is the basis for ensuring that all activities in the enterprise can operate normally. Once there is an attack in the enterprise, the enterprise's network and business system will be threatened, which will seriously interfere with the normal operation of various activities of the enterprise. Therefore, it is very necessary to conduct threat detection for enterprises. Summary of the invention
[0003] This application provides a threat detection method that can detect historical attack behaviors that are missed in historical access behaviors, thereby improving the security of enterprise networks. The technical solution is as follows:
[0004] In a first aspect, a threat detection method is provided, the method comprising:
[0005] In response to the threat detection instruction, threat intelligence data is acquired, the threat intelligence data including an encryption salt value and first encrypted data, the first encrypted data being obtained by encrypting the threat intelligence original text by using the encryption salt value, the threat intelligence original text including an IP address, a domain name, a uniform resource locator URL, and a message digest having a threat;
[0006] Encrypting multiple pieces of historical access data using the encryption salt value to obtain multiple pieces of second encrypted data, wherein the historical access data indicates an IP address, a domain name, a URL, and a message digest of the historical access behavior;
[0007] Matching the plurality of second encrypted data with the first encrypted data to obtain target encrypted data, where the target encrypted data is the second encrypted data among the plurality of second encrypted data that matches the first encrypted data;
[0008] Based on the target encrypted data, historical access behaviors with threats are detected.
[0009] In the present application, when a threat detection instruction is received, in response to the threat detection instruction, threat intelligence data is first obtained, that is, intelligence data known to be threatening is obtained. In addition, the threat intelligence data includes an encryption salt value and a first encrypted data obtained by encrypting the original text of the threat intelligence with the encryption salt value. Then, multiple historical access data are encrypted by the encryption salt value in the threat intelligence data to obtain multiple second encrypted data. Then, the multiple second encrypted data are matched with the first encrypted data, that is, the multiple second encrypted data obtained by encrypting the multiple historical access data with the encryption salt value are matched with the first encrypted data obtained by encrypting the original text of the threat intelligence with the encryption salt value to obtain the target encrypted data. Since the first encrypted data is obtained by encrypting the original text of the threat intelligence known to be threatening, when the target encrypted data matches the first encrypted data, it means that the target encrypted data is encrypted by the historical access data with threats, and then the historical access behavior corresponding to the target encrypted data is the historical access behavior with threats. Therefore, based on the target encrypted data, historical access behaviors with threats can be detected. In this way, the threats existing in historical access behaviors can be detected, and the threatening vulnerabilities missed in the historical access behaviors can be obtained, so that users can promptly discover the threatening vulnerabilities in the historical access behaviors, and then make corresponding vulnerability patches and maintenance in a timely manner, thereby improving the security of the enterprise network.
[0010] Optionally, the historical access data includes multiple types of first entity data, and the multiple pieces of historical access data are encrypted by using the encryption salt value to obtain multiple pieces of second encrypted data, including:
[0011] For any one of the plurality of pieces of historical access data, the plurality of types of first entity data of the historical access data are encrypted respectively by using the encryption salt value to obtain second encrypted data corresponding to the historical access data.
[0012] Optionally, the threat intelligence original text includes multiple categories of second entity data, the first encrypted data includes encrypted data of the multiple categories of second entity data, the multiple categories of first entity data are of the same type as the multiple categories of second entity data, and matching the multiple second encrypted data with the first encrypted data to obtain target encrypted data includes:
[0013] For encrypted data of any one type of first entity data among multiple types of first entity data in the second encrypted data corresponding to the historical access data, matching the encrypted data of the first entity data with encrypted data of a corresponding type of second entity data in the first encrypted data;
[0014] When the encrypted data of at least one type of first entity data in the multiple types of first entity data successfully matches the encrypted data of at least one type of second entity data in the multiple types of second entity data, the second encrypted data where the encrypted data of the at least one type of first entity data is located is determined to be the target encrypted data.
[0015] Optionally, the detecting threatening historical access behavior based on the target encrypted data includes:
[0016] Obtaining target historical access data corresponding to the target encrypted data;
[0017] Determining a target filtering condition based on the target historical access data;
[0018] The behaviors in the historical access behaviors that meet the target filtering condition are determined as threatening historical access behaviors.
[0019] Optionally, the plurality of pieces of historical access data are historical access data within a target time period, and obtaining threatening historical access behaviors based on the target encrypted data includes:
[0020] Based on the target encrypted data, historical access behaviors with threats are detected from historical access behaviors received within the target time period.
[0021] Optionally, before obtaining threat intelligence data in response to the threat detection instruction, the method further includes:
[0022] Get logs of historical access behavior;
[0023] Based on the log, generate historical access data corresponding to the log;
[0024] The historical access data corresponding to the log is stored in the target data table.
[0025] Optionally, before generating historical access data corresponding to the log based on the log, the method further includes:
[0026] Saving the log to a message queue;
[0027] The generating, based on the log, historical access data corresponding to the log includes:
[0028] Obtaining the log at the head of the queue from the message queue;
[0029] Based on the log at the head of the team, historical access data corresponding to the log at the head of the team is generated.
[0030] Optionally, after storing the historical access data corresponding to the log in the target data table, the method further includes:
[0031] Aggregate multiple pieces of historical access data in the target data table to obtain an updated target data table.
[0032] In a second aspect, a threat detection device is provided, the device comprising:
[0033] A first acquisition module is used to obtain threat intelligence data in response to a threat detection instruction, wherein the threat intelligence data includes an encryption salt value and first encrypted data, wherein the first encrypted data is obtained by encrypting the threat intelligence original text by using the encryption salt value, and the threat intelligence original text includes an IP address, a domain name, a uniform resource locator URL, and a message digest that contain a threat;
[0034] An encryption module, used to encrypt multiple pieces of historical access data by using the encryption salt value to obtain multiple pieces of second encrypted data, wherein the historical access data indicates an IP address, a domain name, a URL, and a message digest of the historical access behavior;
[0035] a matching module, configured to match the plurality of second encrypted data with the first encrypted data to obtain target encrypted data, wherein the target encrypted data is second encrypted data among the plurality of second encrypted data that matches the first encrypted data;
[0036] The detection module is used to detect threatening historical access behaviors based on the target encrypted data.
[0037] Optionally, the historical access data includes multiple types of first entity data, and the encryption module is used to:
[0038] For any one of the plurality of pieces of historical access data, the plurality of types of first entity data of the historical access data are encrypted respectively by using the encryption salt value to obtain second encrypted data corresponding to the historical access data.
[0039] Optionally, the matching module is used to:
[0040] For encrypted data of any one type of first entity data among multiple types of first entity data in the second encrypted data corresponding to the historical access data, matching the encrypted data of the first entity data with encrypted data of a corresponding type of second entity data in the first encrypted data;
[0041] When the encrypted data of at least one type of first entity data in the multiple types of first entity data successfully matches the encrypted data of at least one type of second entity data in the multiple types of second entity data, the second encrypted data where the encrypted data of the at least one type of first entity data is located is determined to be the target encrypted data.
[0042] Optionally, the detection module is used to:
[0043] Obtaining target historical access data corresponding to the target encrypted data;
[0044] Determining a target filtering condition based on the target historical access data;
[0045] The behaviors in the historical access behaviors that meet the target filtering condition are determined as threatening historical access behaviors.
[0046] Optionally, the plurality of pieces of historical access data are historical access data within a target duration, and the detection module is used to:
[0047] Based on the target encrypted data, historical access behaviors with threats are detected from historical access behaviors received within the target time period.
[0048] Optionally, the device further comprises:
[0049] The second acquisition module is used to obtain logs of historical access behaviors;
[0050] A generating module, used for generating historical access data corresponding to the log based on the log;
[0051] The storage module is used to store the historical access data corresponding to the log into the target data table.
[0052] Optionally, the device further comprises:
[0053] A saving module, used for saving the log into a message queue;
[0054] The generation module is used for:
[0055] Obtaining the log at the head of the queue from the message queue;
[0056] Based on the log at the head of the team, historical access data corresponding to the log at the head of the team is generated.
[0057] Optionally, the device further comprises:
[0058] The aggregation module is used to aggregate multiple historical access data in the target data table to obtain the updated target data table.
[0059] In a third aspect, a computer device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program implements the above-mentioned threat detection method when executed by the processor.
[0060] In a fourth aspect, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the above-mentioned threat detection method is implemented.
[0061] In a fifth aspect, a computer program product comprising instructions is provided, which, when executed on a computer, enables the computer to execute the steps of the above-mentioned threat detection method.
[0062] It can be understood that the beneficial effects of the second, third, fourth and fifth aspects mentioned above can be found in the relevant description of the first aspect mentioned above, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0063] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0064] Figure 1 is a flowchart of a threat detection method provided by an embodiment of the present application;
[0065] Figure 2 This is a flow chart of entity data generation provided by an embodiment of the present application;
[0066] Figure 3 is a flowchart of another threat detection method provided by an embodiment of the present application;
[0067] Figure 4 is a structural diagram of a threat detection device provided in an embodiment of the present application;
[0068] Figure 5 It is a structural diagram of a computer device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0069] In order to make the objectives, technical solutions and advantages of the present application clearer, the implementation methods of the present application will be further described in detail below in conjunction with the accompanying drawings.
[0070] It should be understood that the "multiple" mentioned in this application refers to two or more. In the description of this application, unless otherwise specified, " / " means or, for example, A / B can mean A or B; "and / or" in this article is only a description of the association relationship of associated objects, indicating that there can be three relationships, for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, in order to facilitate the clear description of the technical solution of this application, the words "first" and "second" are used to distinguish between the same items or similar items with basically the same functions and effects. Those skilled in the art can understand that the words "first" and "second" do not limit the quantity and execution order, and the words "first" and "second" do not limit them to be different.
[0071] Before explaining the embodiments of the present application in detail, the application scenarios of the embodiments of the present application are first described.
[0072] In recent years, cyber attacks have become more and more common. For enterprises, network security is the basis for ensuring the normal operation of all activities in the enterprise. Once an attack occurs in an enterprise, the enterprise's network and business system will be threatened, which will seriously interfere with the normal operation of various activities of the enterprise.
[0073] At present, threat detection for enterprises is real-time, that is, every time an access data is received in the enterprise network, the source of the access data and other information are detected to determine whether the access data is threatening.
[0074] However, as time goes by, the types of attacks vary, and new attack behaviors will also appear. For the historical data of an enterprise, there may be some threats that have not been detected before, or there may be some new attack behaviors that cannot be detected. This will lead to threat loopholes in the historical data, thus threatening the network security of the enterprise.
[0075] To this end, an embodiment of the present application provides a threat detection method, which can be applied to a scenario of detecting threats in historical data.
[0076] For example, the threat detection method provided in the embodiment of the present application can be applied to the scenario of threat detection of historical data within half a year in an enterprise. Specifically, the historical data within half a year in the enterprise is first processed, and then the processed historical data is stored in the target data table. When the historical data within half a year in the enterprise is to be threat detected, the intelligence data of known threats is first obtained. The intelligence data of known threats is the IP address, domain name, uniform resource locator URL, and message digest with threats. The intelligence data includes an encryption salt value and a first encrypted data obtained by encrypting the intelligence data known to be threatening by the encryption salt value. Then, the processed historical data within half a year is obtained from the target data table. The processed historical data within half a year is encrypted by the encryption salt value to obtain the second encrypted data. Then, the first encrypted data and the second encrypted data are matched to obtain the second encrypted data matching the first encrypted data. Then, the historical data of the enterprise with threats within half a year is detected by the second encrypted data matching the first encrypted data. In this way, the threats existing in the enterprise's historical data can be detected, and the threatening vulnerabilities missed in the historical data can be obtained, so that users can promptly discover the threatening vulnerabilities in the historical data, and then make corresponding vulnerability patches and maintenance in a timely manner, thereby improving the security of the enterprise network.
[0077] The threat detection method provided in the embodiment of the present application is explained in detail below. The method can be applied to a computer device, which can be a terminal or a server, and the server can be a server or a server cluster composed of multiple servers. The embodiment of the present application does not limit this.
[0078] Figure 1 is a flowchart of a threat detection method provided by an embodiment of the present application. Figure 1 , the method comprises the following steps.
[0079] Step 101: The computer device obtains threat intelligence data in response to a threat detection instruction, where the threat intelligence data includes an encryption salt value and first encrypted data.
[0080] The threat detection instruction is used to instruct the computer device to start threat detection. Optionally, the threat detection instruction can be triggered by the user. For example, the user can trigger the threat detection instruction through a click operation, a voice operation, a somatosensory operation, etc. As an example, when the user wants to perform threat detection, the threat detection instruction can be triggered by clicking a threat detection button, thereby instructing the computer device to start threat detection.
[0081] In some embodiments, the technician can also set the triggering time of the threat detection instruction, such as automatically triggering the threat detection instruction every first preset time to instruct the computer device to start threat detection. The first preset time can be set in advance, and the first preset time can be set by the technician according to actual needs.
[0082] In this case, the computer device performs threat detection on historical data within the first preset time period every first preset time period. As an example, the technician may set the first preset time period to be half a year, and then a threat detection instruction may be triggered after half a year to instruct the computer device to perform threat detection on historical data within the half year.
[0083] The threat intelligence data is intelligence data that is known to be threatening. The threat intelligence data includes an encryption salt value and first encrypted data. The first encrypted data is obtained by encrypting the original threat intelligence text with the encryption salt value. The encryption salt value is used to increase the complexity of encrypting the original threat intelligence text. By using the encryption salt value in the process of encrypting the original threat intelligence text, the first encrypted data obtained can be made more secure. In an embodiment of the present application, in an embodiment of the present application, the original threat intelligence text includes a threatening IP address (Internet Protocol), domain name, URL (Uniform Resource Locator), and message digest (HASH hash value). For example, a threat intelligence original text is "192.168.0.0".
[0084] Alternatively, the intelligence cloud can collect threat intelligence texts through various channels, and then send the threat intelligence texts to computer devices so that the computer devices can obtain threatening intelligence data. However, in order to prevent attackers from maliciously obtaining the threat intelligence texts, the threat intelligence texts are all sent in the form of ciphertext. The emergence of ciphertext query tools makes it very easy to encrypt ciphertext, so ordinary encryption methods can no longer meet the current situation.
[0085] Intelligence Cloud is a cloud that collects and stores the original text of threat intelligence. It is used to discover attack organizations and obtain relevant information about them, that is, to obtain the original text of threat intelligence. Thus, Intelligence Cloud can obtain IP addresses, domain names, URLs, and message summaries that are known to be threatening.
[0086] In an embodiment of the present application, a possible implementation method is that before the intelligence cloud sends the original threat intelligence text to the computer device, an encryption salt value can be added when encrypting the original threat intelligence text, so as to encrypt the original threat intelligence text with the encryption salt value, that is, to obtain the first encrypted data. Then, the first encrypted data and the encryption salt value are sent to the computer device together, that is, the threat intelligence data is sent to the computer device, so that the computer device can obtain the threat intelligence data. In this way, the confidentiality of the threat intelligence data is improved.
[0087] Another possible implementation method is that after the intelligence cloud collects the original threat intelligence text through various channels, it first saves the collected original threat intelligence text in the intelligence cloud, and then obtains the threat intelligence data from the intelligence cloud when the computer device wants to perform threat detection. Similarly, before sending the threat intelligence data to the computer device, the intelligence cloud encrypts the original threat intelligence text with an encryption salt value to obtain the first encrypted data. Then, the first encrypted data and the encryption salt value are sent to the computer device together, that is, the threat intelligence data is sent to the computer device, so that the computer device can obtain the threat intelligence data. In this way, the threat intelligence data is only sent to the computer device when the computer device needs to use it, thereby saving processing resources.
[0088] In this case, the computer device can obtain encrypted data of IP addresses, domain names, URLs, and message digests that are known to be threatening.
[0089] Optionally, the threat intelligence original text may include multiple categories of second entity data, and the first encrypted data may include encrypted data of the multiple categories of second entity data, that is, the first encrypted data includes encrypted data obtained by encrypting the multiple categories of second entity data respectively using encryption salt values.
[0090] In the case where the original threat intelligence includes a threatening IP address, domain name, URL, and message digest, the multiple types of second entity data may include IP entity data, domain name entity data, URL entity data, and HASH entity data. Among them, the IP entity data may be a threatening IP address, the domain name entity data may be a threatening domain name, the URL entity data may be a threatening URL, and the HASH entity data may be a threatening message digest.
[0091] Step 102: The computer device encrypts multiple pieces of historical access data using the encryption salt value to obtain multiple pieces of second encrypted data.
[0092] Each piece of the plurality of pieces of historical access data is used to indicate an IP address, a domain name, a URL, or a message digest of a historical access behavior.
[0093] In this case, the computer device can obtain the encrypted data of historical access data, that is, the encrypted data of the IP address, domain name, URL, and message digest of the historical access behavior. In this way, threat detection can be performed based on this and the encrypted data of the IP address, domain name, URL, and message digest of known threats.
[0094] Optionally, the computer device can encrypt multiple pieces of historical access data within a target duration using the encryption salt value to obtain second encrypted data. The target duration can be set in advance, and the target duration can be set by a technician according to actual needs. In this way, the computer device can selectively encrypt historical access data within a period of time, so that the computer device can subsequently perform threat detection on the data within a period of time, thereby improving the flexibility of threat detection.
[0095] Optionally, each of the multiple pieces of historical access data includes multiple types of first entity data. Optionally, the multiple types of first entity data may correspond to multiple types of second entity data in the threat intelligence original text, that is, the multiple types of first entity data and the multiple types of second entity data are the same, and the multiple types of first entity data and the multiple types of second entity data both include IP entities, domain name entities, URL entities, and HASH entities.
[0096] For example, if the multiple types of second entity data include IP entity data, domain name entity data, URL entity data, and HASH entity data, then a piece of historical access data may also include IP entity data, domain name entity data, URL entity data, and HASH entity data. Among them, the IP entity data in the multiple types of first entity data may be the IP address of the historical access behavior; the domain name entity data may be the domain name of the historical access behavior; the URL entity data may be the URL value of the historical access behavior; and the HASH entity data may be the HASH value obtained by performing a message digest algorithm on the historical access behavior.
[0097] In this case, the operation of step 102 may be: for any one of the multiple historical access data, the computer device encrypts multiple types of first entity data of the historical access data respectively by using the encryption salt value to obtain second encrypted data corresponding to the historical access data.
[0098] For any one of the multiple pieces of historical access data, the computer device encrypts each of the multiple types of first entity data of the historical access data by using the encryption salt value, thereby obtaining the encrypted data of the multiple types of first entity data, that is, obtaining the second encrypted data corresponding to the historical access data. The second encrypted data corresponding to the historical access data includes the encrypted data of each of the multiple types of first entity data.
[0099] In this way, the computer device encrypts each of the multiple categories of first entity data through the encryption salt value, and can obtain encrypted data of multiple types of entity data related to historical access behaviors, that is, encrypted data of IP addresses, domain names, URLs, and message digests can be obtained, thereby providing multiple detection possibilities for threat detection and improving threat detection efficiency.
[0100] Through the above-mentioned step 102, each of the multiple historical access data can be encrypted to obtain the multiple second encrypted data, and the encrypted data of the multiple categories of first entity data in the multiple second encrypted data corresponds to the encrypted data of the multiple categories of second entity data in the first encrypted data, thereby facilitating subsequent threat detection and improving threat detection efficiency.
[0101] It is worth noting that the computer device may also pre-generate multiple pieces of historical access data and store them in a target data table, so that the multiple pieces of historical access data can be obtained from the target data table when performing threat detection.
[0102] Specifically, the operation of the computer device pre-generating a plurality of historical access data and storing them in the target data table includes the following steps (1) to (3).
[0103] (1) Computer devices obtain logs of historical access behaviors.
[0104] As an example, for an enterprise internal host, each time an external user accesses the enterprise internal host, it is a historical access behavior. Each time the enterprise internal host is accessed, the relevant information of this historical access behavior can be recorded, thereby forming a log of this historical access behavior, which contains the IP address, URL, domain name, MD5 (Message Digest) and other information of this historical access behavior.
[0105] Optionally, the computer device may obtain the log of historical access behaviors in at least one of the following possible ways.
[0106] First, the computer device obtains the log of historical access behavior through the terminal behavior log of the internal host of the enterprise.
[0107] In some embodiments, the internal host of the enterprise has a behavior recording function, that is, for each access behavior, the internal host of the enterprise will record the relevant information of the access behavior, thereby forming a terminal behavior log of the access behavior, and store it in the internal host of the enterprise for viewing when needed.
[0108] In this case, the computer device can obtain the log of historical access behavior to the internal host of the enterprise through the terminal behavior log stored in the internal host of the enterprise, that is, obtain the relevant information of the historical access behavior.
[0109] Optionally, the computer device may obtain the log of historical access behavior through the terminal behavior log of the internal host of the enterprise every second preset time. The second preset time can be set in advance, and the second preset time can be set by the technician according to actual needs. For example, the second preset time can be set to 10 minutes, and the computer device can obtain the log of historical access behavior through the terminal behavior log every 10 minutes.
[0110] In this way, by obtaining logs of historical access behaviors at certain intervals, after the computer device obtains the logs of historical access behaviors, the relevant logs obtained by the computer device can be deleted from the terminal behavior logs, thereby alleviating the storage pressure of the internal host of the enterprise.
[0111] Second, computer devices obtain logs of historical access behaviors through network traffic logs of internal enterprise hosts.
[0112] Generally, network traffic logs provide collection services, which are used to collect traffic accessing the enterprise's internal hosts, thereby collecting relevant information about visitors and storing it in the enterprise's internal hosts.
[0113] For example, the network traffic logs of an enterprise's internal host can collect the following information about visitors:
[0114] 1. Visitor IP address: 192.168.0.0.
[0115] 2. Request time: [18 / Sep / 2013:06:51:35+0000].
[0116] 3. Request protocol: HTTP / 1.1.
[0117] 4. Returned data traffic: 0.
[0118] 5. The source URL of the visitor: http: / / 123.me / nodejs-socketio-chat / .
[0119] 6. The visitor’s domain name: www.yuming.com.
[0120] Optionally, the computer device may obtain the log of the historical access behavior through the network traffic log of the internal host of the enterprise every third preset time. The third preset time can be set in advance, and the third preset time can be set by the technician according to actual needs. For example, the third preset time can be set to 5 minutes, and the computer device can obtain the log of the historical access behavior through the network traffic log every 5 minutes.
[0121] Third, the computer equipment obtains logs of historical access behaviors through the firewall of the internal host of the enterprise.
[0122] The firewall of the internal host of the enterprise can selectively block or allow visitors to access the internal host of the enterprise. In the process, the firewall can also record the relevant information of the visitor's access to the internal host of the enterprise.
[0123] In this case, the computer device can obtain relevant information about the visitor's access to the enterprise's internal host from the firewall of the enterprise's internal host, that is, obtain the log of the access behavior of the enterprise's internal host.
[0124] Optionally, the computer device may obtain the log of historical access behavior through the firewall of the internal host of the enterprise every fourth preset time. The fourth preset time may be set in advance, and the fourth preset time may be set by a technician according to actual needs. For example, the fourth preset time may be set to 20 minutes, and the computer device may obtain the log of historical access behavior through the firewall of the internal host of the enterprise every 20 minutes.
[0125] Of course, in addition to obtaining logs of historical access behaviors through one or more of the above three methods, logs of historical access behaviors can also be obtained through other possible methods, such as obtaining logs of historical access behaviors through honeypot technology, etc., which is not limited to the embodiments of the present application.
[0126] It is worth noting that after obtaining the logs of historical access behaviors, the computer device can also perform data cleaning and data normalization on the logs of historical access behaviors.
[0127] Data cleaning is used to clean up dirty data in the logs of historical access behaviors, that is, to delete duplicate logs, clean up logs with data anomalies, etc., so that the logs of historical access behaviors are valid after data cleaning, thereby improving the quality of the generated historical access data later.
[0128] Since the logs of historical access behaviors are multi-source heterogeneous data, they need to be normalized. Data normalization is used to normalize the format of the acquired logs of historical access behaviors, so that the format of the logs of historical access behaviors is unified, which can improve the processing efficiency of subsequent generation of historical access data.
[0129] (2) The computer device generates historical access data corresponding to the log based on the log of the historical access behavior.
[0130] In this case, the computer device can generate an IP address, domain name, URL, and message digest for indicating historical access behaviors, that is, for each access behavior received by the internal host of the enterprise, the computer device can obtain the IP address, domain name, URL, and message digest for indicating historical access behaviors. The computer device can then perform threat detection on the historical access behaviors accordingly.
[0131] Optionally, after obtaining each log of a historical access behavior, the computer device may first save the log of the historical access behavior to a message queue. In this case, the computer device may obtain the log at the head of the queue from the message queue; based on the log at the head of the queue, generate historical access data corresponding to the log at the head of the queue.
[0132] The message queue is a first-in, first-out queue, that is, the log that first enters the message queue is taken out first. The message queue is used to save the log of historical access behavior, so as to ensure that the logs in the message queue can be processed in a stream manner, that is, to ensure that the logs in the message queue can be processed in sequence. In this way, the processing resources of the computer device can be saved. For example, the message queue can be a Kafka message queue.
[0133] In a possible implementation, when the historical access data includes multiple types of first entity data, the computer device may generate the multiple types of first entity data based on the log of the historical access behavior.
[0134] Since the log of the historical access behavior includes an IP address field, a URL field, a domain name field, and an MD5 field, when the multiple categories of first entity data are IP entity data, URL entity data, domain name entity data, and hash entity data, the computer device can determine the field value of the IP address field in the log as IP entity data; the computer device can determine the field value of the URL field in the log as URL entity data; the computer device can determine the field value of the domain name field in the log as domain name entity data; the computer device can determine the MD5 field in the log as hash entity data.
[0135] Optionally, in some embodiments, the original threat intelligence text also includes the IP address + port type. In this case, if the log of the historical access behavior also includes the port number, the computer device can also determine the port number in the log of the historical access behavior as IP address data. In this case, the IP address data includes the IP address and the port number.
[0136] (3) The computer device stores the historical access data corresponding to the log in the target data table.
[0137] The target data table is used to store historical access data corresponding to the log of historical access behavior, that is, to store multiple types of first entity data corresponding to each historical access behavior, so as to ensure that the historical access data can be obtained when threat detection is performed.
[0138] Optionally, when the historical access data includes multiple types of first entity data, there may be multiple target data tables, and the multiple types of first entity data correspond to the multiple target data tables one by one. Then the operation of step (3) may be: the computer device stores the multiple types of first entity data of the historical access data into multiple target data tables respectively.
[0139] In this case, each of the multiple target data tables is used to store a type of first entity data. For example, if the historical access data includes four types of first entity data, four target data tables can be set. One target data table is used to store IP entity data in the four types of first entity data, one target data table is used to store domain name entity data in the four types of first entity data, one target data table is used to store URL entity data in the four types of first entity data, and one target data table is used to store hash entity data in the four types of first entity data.
[0140] In this way, each target data table stores a corresponding type of first entity data, that is, the same target data table stores the same type of first entity data, thereby saving storage space of the target data table.
[0141] It is worth noting that the computer device can store multiple historical access data in the target data table through the above steps (1) to (3). Furthermore, the computer device can also aggregate multiple historical access data in the target data table to obtain an updated target data table.
[0142] Aggregation refers to removing duplicate historical access data from multiple historical access data. For example, if the multiple historical access data include three duplicate historical access data, the computer device can only retain one historical access data after aggregation processing, thereby removing the duplicate historical access data.
[0143] In this way, when the computer device subsequently performs threat detection based on multiple historical access data in the target data table, the threat detection efficiency can be improved.
[0144] For ease of understanding, now combined Figure 2 The method for generating multiple historical access data provided in the embodiment of the present application is described by example, see Figure 2 The method includes the following steps 201-204.
[0145] Step 201: Obtain logs of historical access behaviors.
[0146] Specifically, logs of historical access behaviors can be obtained through terminal behavior logs, network traffic logs, honeypots, firewalls, etc.
[0147] Step 202: Perform data cleaning and data normalization on the logs of historical access behaviors.
[0148] Step 203: Generate multiple types of first entity data based on the log of historical access behavior, that is, generate historical access data corresponding to the log.
[0149] Specifically, the computer device can generate IP entity data, domain name entity data, URL entity data, HASH entity data, etc. based on the log.
[0150] Step 204: the computer device may store the generated multiple types of first entity data in the target data table, that is, store the historical access data corresponding to the log in the target data table.
[0151] It is worth noting that the computer device can obtain the encrypted data of the known threatening IP addresses, domain names, URLs, and message digests, as well as the encrypted data of the IP addresses, domain names, URLs, and message digests of multiple historical access behaviors through the above steps 101-102. In this way, the computer device can subsequently perform threat detection on the historical access behaviors based on the encrypted data of the known threatening IP addresses, domain names, URLs, and message digests, as well as the encrypted data of the IP addresses, domain names, URLs, and message digests of multiple historical access behaviors, that is, continue to execute the following step 103.
[0152] Step 103: The computer device matches the multiple second encrypted data with the first encrypted data to obtain target encrypted data, where the target encrypted data is the second encrypted data in the multiple second encrypted data that matches the first encrypted data.
[0153] The computer device matches the multiple second encrypted data with the first encrypted data, that is, the computer device determines whether the multiple second encrypted data are the same as the first encrypted data. If any one of the multiple second encrypted data is the same as the first encrypted data, it is determined that the second encrypted data successfully matches the first encrypted data; if the multiple second encrypted data are not the same as the first encrypted data, it is determined that the multiple second encrypted data fail to match the first encrypted data.
[0154] In this case, the computer device can obtain the second encrypted data matching the first encrypted data among the multiple second encrypted data, thereby obtaining the second encrypted data with threats among the multiple second encrypted data, that is, obtaining the target encrypted data.
[0155] Optionally, when the historical access data includes multiple types of first entity data, the second encrypted data corresponding to the historical access data may include the encrypted data of each type of first entity data in the multiple types of first entity data. When the threat intelligence original includes multiple types of second entity data, the first encrypted data may include the encrypted data of the multiple types of second entity data.
[0156] The operation of step 103 may be: for the encrypted data of any one type of first entity data among the multiple types of first entity data in the second encrypted data corresponding to the historical access data, match the encrypted data of this type of first entity data with the encrypted data of the corresponding type of second entity data in the first encrypted data; when the encrypted data of at least one type of first entity data among the multiple types of first entity data successfully matches the encrypted data of at least one type of second entity data among the multiple types of second entity data, determine that the second encrypted data where the encrypted data of the at least one type of first entity data is located is the target encrypted data.
[0157] For the encrypted data of any one type of first entity data among the multiple types of first entity data in the second encrypted data corresponding to the historical access data, the encrypted data of this type of first entity data is matched with the encrypted data of the second entity data of the corresponding type in the first encrypted data, that is, it is determined whether the encrypted data of this type of first entity data exists in the encrypted data of the second entity data of the corresponding type in the first encrypted data. In the case where the encrypted data of this type of first entity data matches the encrypted data of the second entity data of the corresponding type in the first encrypted data, it means that the encrypted data of the second entity data of the corresponding type in the first encrypted data is the same as the encrypted data of this type of first entity data. That is, the historical access data corresponding to this type of first entity data is threatening.
[0158] After performing the above matching operation on each type of first entity data in the second encrypted data corresponding to the historical access data, it can be obtained which types of first entity data in the second encrypted data corresponding to the historical access data have the same encrypted data as the second entity data in the first encrypted data. When the encrypted data of at least one type of first entity data in the multiple types of first entity data successfully matches the encrypted data of at least one type of second entity data in the multiple types of second entity data, it means that the encrypted data of the at least one type of first entity data is the same as the encrypted data of the at least one type of second entity data, that is, the first encrypted data known to be threatening has the same encrypted data as the encrypted data of the at least one type of first entity data, which means that the second encrypted data where the encrypted data of the at least one type of first entity data is located is the encrypted data with threats, so that the computer device can determine that the second encrypted data where the encrypted data of the at least one type of first entity data is located is the target encrypted data.
[0159] When the encrypted data of the multiple categories of first entity data fails to match the encrypted data of each category of second entity data in the multiple categories of second entity data, it means that the encrypted data of the multiple categories of first entity data is different from the encrypted data of each category of second entity data, which means that the second encrypted data where the encrypted data of the multiple categories of first entity data is located is encrypted data that does not pose a threat. After the encrypted data of the multiple categories of first entity data of each historical access data in the multiple historical access data is matched with the encrypted data of each category of second entity data in the first encrypted data, if the encrypted data of the multiple categories of first entity data of each historical access data fails to match the encrypted data of each category of second entity data in the first encrypted data, it means that the encrypted data of the multiple categories of first entity data of each historical access data is different from each encrypted data in the first encrypted data, which means that there is no encrypted data that poses a threat in the second encrypted data corresponding to each historical access data.
[0160] Furthermore, the computer device may determine that the multiple pieces of historical access data are non-threatening access data, and thus may also determine that the historical access behaviors corresponding to the multiple pieces of historical access data are non-threatening.
[0161] Step 104: The computer device detects threatening historical access behaviors based on the target encrypted data.
[0162] Since the target encrypted data is threatening encrypted data, the historical access data corresponding to the target encrypted data is also threatening historical access data, and thus the historical access behavior corresponding to the historical access data is also threatening. Therefore, threatening historical access behavior can be detected based on the target encrypted data.
[0163] In this case, the computer device can quickly detect threatening historical access behaviors among multiple historical access behaviors, and the computer device detects missed threat vulnerabilities in multiple historical access behaviors based on the latest threat intelligence data, thereby improving the security of the enterprise network.
[0164] Specifically, the operation of step 104 may be: the computer device obtains the target historical access data corresponding to the target encrypted data; determines the target filtering condition based on the target historical access data; and determines the behavior in the historical access behavior that meets the target filtering condition as a threatening historical access behavior.
[0165] The target historical access data is historical access data that is threatening among the multiple historical access data.
[0166] Target filtering conditions are used to filter historical access behaviors that may pose a threat.
[0167] In this case, based on the threatening historical access data, a target filtering condition for filtering threatening historical access behaviors can be determined, so that the threatening historical access behaviors among the multiple historical access behaviors can be more accurately determined through the target filtering condition.
[0168] For example, a computer device obtains a target historical access data, and the IP address in the IP entity data is "196.168.0.0" and the destination port is "011". Then the target filtering condition that the computer device can determine based on the target historical access data is: (IP address = "196.168.0.0") or (IP address = "196.168.0.0" and destination port = 011). After that, the computer device can filter the historical access behaviors based on the determined target filtering conditions, thereby filtering out the historical access behaviors that are threatening.
[0169] Optionally, when the computer device encrypts the historical access data within the target duration, the operation of step 104 may be: the computer device detects threatening historical access behaviors from the historical access behaviors received within the target duration based on the target encrypted data. For example, the target duration may be set to 6 months.
[0170] In this way, the computer device can perform threat detection on historical access behaviors within a certain period of time, thereby improving the flexibility of threat detection.
[0171] Optionally, the threat intelligence data may also include a threat level, which is used to indicate the threat level of the first encrypted data in the threat intelligence data. Then, after detecting and obtaining a threatening historical access behavior, the computer device may also determine the threat level of the threatening historical access behavior.
[0172] Specifically, the computer device may determine the threat level corresponding to the first encrypted data matching the target encrypted data as the threat level of the historical access behavior with threats.
[0173] In this way, the computer device can also know the threat level of the threatening historical access behavior, so that the user can make a corresponding response in time based on the threat level later.
[0174] Optionally, after detecting a threatening historical access behavior, the computer device can display relevant information about the threatening historical access behavior on a threat display page. For example, the computer device can display a log of threatening historical access behaviors on the threat display page, and can also display the threat level of the historical access behavior, etc., so that users can find vulnerabilities in historical access behaviors in a timely manner. Furthermore, it is also convenient for users to perform corresponding vulnerability patching and maintenance in a timely manner, thereby improving the security of the enterprise network.
[0175] It is worth noting that the threat detection method provided in the embodiment of the present application can help enterprises quickly discover threats that have already invaded, timely discover missed historical attack behaviors, and facilitate users to respond in a timely manner. In addition, the threat detection method provided in the embodiment of the present application can also help enterprises to timely understand the threats they are suffering from or will face in the future, and further users can provide reasonable suggestions for some decisions based on this, thereby improving user experience.
[0176] For ease of understanding, now combined Figure 3 The threat detection method provided in the embodiment of the present application is illustrated by example. Figure 3 The method includes the following steps 301-307.
[0177] Step 301: The computer device obtains threat intelligence data.
[0178] Specifically, the computer device can receive threat intelligence data sent by the intelligence cloud, where the threat intelligence data includes an encryption salt value and first encrypted data.
[0179] Step 302: The computer device encrypts multiple pieces of historical access data using the encryption salt value to obtain multiple pieces of second encrypted data.
[0180] Step 303: The computer device matches the plurality of second encrypted data with the plurality of first encrypted data.
[0181] Specifically, the computer device may respectively match the encrypted data of the multiple categories of first entity data in each second encrypted data with the encrypted data of the multiple categories of second entity data in the first encrypted data to obtain the target encrypted data.
[0182] Step 304: The computer device obtains the target historical access data corresponding to the target encrypted data.
[0183] Step 305: The computer device determines a target filtering condition based on the target historical access data.
[0184] Step 306: The computer device determines the historical access behaviors that meet the target filtering condition as threatening historical access behaviors.
[0185] Step 307: The computer device displays the threatening historical access behaviors on the threat display page.
[0186] In an embodiment of the present application, when a computer device receives a threat detection instruction, it responds to the threat detection instruction and first obtains threat intelligence data, that is, obtains intelligence data known to be threatening. In addition, the threat intelligence data includes an encryption salt value and a first encrypted data obtained by encrypting the original text of the threat intelligence with the encryption salt value. Then, multiple historical access data are encrypted by the encryption salt value in the threat intelligence data to obtain multiple second encrypted data. Then, the multiple second encrypted data are matched with the first encrypted data, that is, the multiple second encrypted data obtained by encrypting the multiple historical access data with the encryption salt value are matched with the first encrypted data obtained by encrypting the original text of the threat intelligence with the encryption salt value to obtain the target encrypted data. Since the first encrypted data is obtained by encrypting the original text of the threat intelligence known to be threatening, when the target encrypted data matches the first encrypted data, it means that the target encrypted data is encrypted by the historical access data with threats, and then the historical access behavior corresponding to the target encrypted data is the historical access behavior with threats. Therefore, based on the target encrypted data, the historical access behavior with threats can be detected. In this way, the threats existing in historical access behaviors can be detected, and the threatening vulnerabilities missed in the historical access behaviors can be obtained, so that users can promptly discover the threatening vulnerabilities in the historical access behaviors, and then make corresponding vulnerability patches and maintenance in a timely manner, thereby improving the security of the enterprise network.
[0187] Figure 4 Schematic diagram of a threat detection device provided in an embodiment of the present application. The threat detection device can be implemented as part or all of a computer device by software, hardware, or a combination of both. The computer device can be as follows Figure 5 Computer equipment shown. Figure 4 The device includes: a first acquisition module 401, an encryption module 402, a matching module 403, and a detection module 404.
[0188] A first acquisition module 401 is used to obtain threat intelligence data in response to a threat detection instruction, where the threat intelligence data includes an encryption salt value and first encrypted data, where the first encrypted data is obtained by encrypting the original threat intelligence text by using the encryption salt value, and the original threat intelligence text includes an IP address, a domain name, a uniform resource locator URL, and a message digest that contains a threat;
[0189] An encryption module 402, used to encrypt multiple pieces of historical access data using the encryption salt value to obtain multiple pieces of second encrypted data, where the historical access data indicates an IP address, a domain name, a URL, and a message digest of the historical access behavior;
[0190] A matching module 403 is used to match the plurality of second encrypted data with the first encrypted data to obtain target encrypted data, where the target encrypted data is the second encrypted data among the plurality of second encrypted data that matches the first encrypted data;
[0191] The detection module 404 is used to detect threatening historical access behaviors based on the target encrypted data.
[0192] Optionally, the historical access data includes multiple types of first entity data, and the encryption module 402 is used to:
[0193] For any one of the multiple pieces of historical access data, multiple types of first entity data of the historical access data are encrypted respectively by using the encryption salt value to obtain second encrypted data corresponding to the historical access data.
[0194] Optionally, the matching module 403 is used to:
[0195] For encrypted data of any one type of first entity data among multiple types of first entity data in the second encrypted data corresponding to the historical access data, matching the encrypted data of the first entity data with encrypted data of a corresponding type of second entity data in the first encrypted data;
[0196] When the encrypted data of at least one type of first entity data in the multiple types of first entity data successfully matches the encrypted data of at least one type of second entity data in the multiple types of second entity data, the second encrypted data where the encrypted data of the at least one type of first entity data is located is determined to be the target encrypted data.
[0197] Optionally, the detection module 404 is used to:
[0198] Obtain target historical access data corresponding to target encrypted data;
[0199] Determine target filtering conditions based on target historical access data;
[0200] The behaviors that meet the target filtering conditions in the historical access behaviors are determined as threatening historical access behaviors.
[0201] Optionally, the plurality of historical access data are historical access data within a target duration, and the detection module 404 is used to:
[0202] Based on the target encrypted data, detect threatening historical access behaviors from the historical access behaviors received within the target time period.
[0203] Optionally, the device further comprises:
[0204] The second acquisition module is used to obtain logs of historical access behaviors;
[0205] A generation module, used to generate historical access data corresponding to the log based on the log;
[0206] The storage module is used to store the historical access data corresponding to the log into the target data table.
[0207] Optionally, the device further comprises:
[0208] The saving module is used to save the log into the message queue;
[0209] This build module is used to:
[0210] Get the log at the head of the queue from the message queue;
[0211] Based on the log at the head of the queue, historical access data corresponding to the log at the head of the queue is generated.
[0212] Optionally, the device further comprises:
[0213] The aggregation module is used to aggregate multiple historical access data in the target data table to obtain an updated target data table.
[0214] In an embodiment of the present application, upon receiving a threat detection instruction, in response to the threat detection instruction, threat intelligence data is first obtained, that is, intelligence data known to be threatening is obtained. In addition, the threat intelligence data includes an encryption salt value and first encrypted data obtained by encrypting the original text of the threat intelligence with the encryption salt value. Then, multiple historical access data are encrypted with the encryption salt value in the threat intelligence data to obtain multiple second encrypted data. Then, the multiple second encrypted data are matched with the first encrypted data, that is, the multiple second encrypted data obtained by encrypting the multiple historical access data with the encryption salt value are matched with the first encrypted data obtained by encrypting the original text of the threat intelligence with the encryption salt value to obtain the target encrypted data. Since the first encrypted data is obtained by encrypting the original text of the threat intelligence known to be threatening, when the target encrypted data matches the first encrypted data, it means that the target encrypted data is encrypted by the historical access data with threats, and then the historical access behavior corresponding to the target encrypted data is the historical access behavior with threats. Therefore, based on the target encrypted data, the historical access behavior with threats can be detected. In this way, the threats existing in historical access behaviors can be detected, and the threatening vulnerabilities missed in the historical access behaviors can be obtained, so that users can promptly discover the threatening vulnerabilities in the historical access behaviors, and then make corresponding vulnerability patches and maintenance in a timely manner, thereby improving the security of the enterprise network.
[0215] It should be noted that: when the threat detection device provided in the above embodiment performs threat detection, it only uses the division of the above-mentioned functional modules as an example. In actual applications, the above-mentioned functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.
[0216] The functional units and modules in the above embodiments may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit, and the above integrated units may be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other, and are not used to limit the protection scope of the embodiments of the present application.
[0217] The threat detection device and threat detection method embodiments provided in the above embodiments belong to the same concept. The specific working process of the units and modules in the above embodiments and the technical effects brought about can be found in the method embodiment part and will not be repeated here.
[0218] Figure 5 This is a schematic diagram of the structure of a computer device provided in an embodiment of the present application. Figure 5As shown, the computer device 5 includes: a processor 50, a memory 51, and a computer program 52 stored in the memory 51 and executable on the processor 50. When the processor 50 executes the computer program 52, the steps of the threat detection method in the above embodiment are implemented.
[0219] The computer device 5 may be a general-purpose computer device or a dedicated computer device. In a specific implementation, the computer device 5 may be a desktop computer, a portable computer, a network server, a PDA, a mobile phone, a tablet computer, etc. The embodiment of the present application does not limit the type of the computer device 5. Those skilled in the art will understand that Figure 5 It is only an example of the computer device 5 and does not constitute a limitation on the computer device 5. It may include more or fewer components than shown in the figure, or a combination of certain components, or different components, such as input and output devices, network access devices, etc.
[0220] The processor 50 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor.
[0221] In some embodiments, the memory 51 may be an internal storage unit of the computer device 5, such as a hard disk or memory of the computer device 5. In other embodiments, the memory 51 may also be an external storage device of the computer device 5, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the computer device 5. Further, the memory 51 may also include both an internal storage unit of the computer device 5 and an external storage device. The memory 51 is used to store an operating system, an application program, a boot loader, data, and other programs. The memory 51 may also be used to temporarily store data that has been output or is to be output.
[0222] An embodiment of the present application also provides a computer device, which includes: at least one processor, a memory, and a computer program stored in the memory and executable on the at least one processor, and when the processor executes the computer program, the steps in any of the above-mentioned method embodiments are implemented.
[0223] An embodiment of the present application further provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments can be implemented.
[0224] An embodiment of the present application provides a computer program product, which, when executed on a computer, enables the computer to execute the steps in the above-mentioned method embodiments.
[0225] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application implements all or part of the processes in the above method embodiments, which can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by the processor, the steps of the above method embodiments can be implemented. Among them, the computer program includes computer program code, which can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may at least include: any entity or device that can carry the computer program code to the camera / terminal device, recording medium, computer memory, ROM (Read-Only Memory), RAM (Random Access Memory), CD-ROM (Compact Disc Read-Only Memory), magnetic tape, floppy disk and optical data storage device. The computer-readable storage medium mentioned in the present application can be a non-volatile storage medium, in other words, it can be a non-transient storage medium.
[0226] It should be understood that all or part of the steps to implement the above embodiments can be implemented by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. The computer instructions can be stored in the above-mentioned computer readable storage medium.
[0227] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0228] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0229] In the embodiments provided in the present application, it should be understood that the disclosed devices / computer equipment and methods can be implemented in other ways. For example, the device / computer equipment embodiments described above are only schematic, for example, the division of modules or units is only a logical function division, and there may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0230] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0231] The embodiments described above are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, a person skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features may be replaced by equivalents. Such modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.
Claims
1. A threat detection method, characterized in that: The method comprises: In response to the threat detection instruction, threat intelligence data is acquired, the threat intelligence data including an encryption salt value and first encrypted data, the first encrypted data being obtained by encrypting the threat intelligence original text by using the encryption salt value, the threat intelligence original text including an IP address, a domain name, a uniform resource locator URL, and a message digest having a threat; Encrypting multiple pieces of historical access data using the encryption salt value to obtain multiple pieces of second encrypted data, wherein the historical access data indicates an IP address, a domain name, a URL, and a message digest of the historical access behavior; Matching the plurality of second encrypted data with the first encrypted data to obtain target encrypted data, where the target encrypted data is the second encrypted data among the plurality of second encrypted data that matches the first encrypted data; Based on the target encrypted data, historical access behaviors with threats are detected.
2. The method according to claim 1, characterized in that The historical access data includes multiple types of first entity data, and the multiple pieces of historical access data are encrypted by the encryption salt value to obtain multiple pieces of second encrypted data, including: For any one of the plurality of pieces of historical access data, the plurality of types of first entity data of the historical access data are encrypted respectively by using the encryption salt value to obtain second encrypted data corresponding to the historical access data.
3. The method according to claim 2, characterized in that The threat intelligence original text includes multiple types of second entity data, the first encrypted data includes encrypted data of the multiple types of second entity data, the multiple types of first entity data and the multiple types of second entity data are of the same type, and matching the multiple second encrypted data with the first encrypted data to obtain target encrypted data includes: For encrypted data of any one type of first entity data among multiple types of first entity data in the second encrypted data corresponding to the historical access data, matching the encrypted data of the first entity data with encrypted data of a corresponding type of second entity data in the first encrypted data; When the encrypted data of at least one type of first entity data in the multiple types of first entity data successfully matches the encrypted data of at least one type of second entity data in the multiple types of second entity data, the second encrypted data where the encrypted data of the at least one type of first entity data is located is determined to be the target encrypted data.
4. The method according to claim 1, characterized in that The detecting, based on the target encrypted data, historical access behaviors with threats includes: Obtaining target historical access data corresponding to the target encrypted data; Determining a target filtering condition based on the target historical access data; The behaviors in the historical access behaviors that meet the target filtering condition are determined as threatening historical access behaviors.
5. The method according to claim 1, characterized in that The plurality of historical access data are historical access data within a target time period, and the detecting threatening historical access behaviors based on the target encrypted data includes: Based on the target encrypted data, historical access behaviors with threats are detected from historical access behaviors received within the target time period.
6. The method according to claim 1, characterized in that Before obtaining threat intelligence data in response to the threat detection instruction, the method further includes: Get logs of historical access behavior; Based on the log, generate historical access data corresponding to the log; The historical access data corresponding to the log is stored in the target data table.
7. The method according to claim 6, characterized in that Before generating the historical access data corresponding to the log based on the log, the method further includes: Saving the log to a message queue; The generating, based on the log, historical access data corresponding to the log includes: Obtaining the log at the head of the queue from the message queue; Based on the log at the head of the team, historical access data corresponding to the log at the head of the team is generated.
8. A threat detection device, characterized in that: The device comprises: A first acquisition module is used to obtain threat intelligence data in response to a threat detection instruction, wherein the threat intelligence data includes an encryption salt value and first encrypted data, wherein the first encrypted data is obtained by encrypting the threat intelligence original text by using the encryption salt value, and the threat intelligence original text includes an IP address, a domain name, a uniform resource locator URL, and a message digest that contain a threat; An encryption module, used to encrypt multiple pieces of historical access data by using the encryption salt value to obtain multiple pieces of second encrypted data, wherein the historical access data indicates an IP address, a domain name, a URL, and a message digest of the historical access behavior; a matching module, configured to match the plurality of second encrypted data with the first encrypted data to obtain target encrypted data, wherein the target encrypted data is second encrypted data among the plurality of second encrypted data that matches the first encrypted data; The detection module is used to detect threatening historical access behaviors based on the target encrypted data.
9. A computer device, characterized in that: The computer device comprises a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program implements the method according to any one of claims 1 to 7 when executed by the processor.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed, the method according to any one of claims 1 to 7 is implemented.