Adaptation evaluation method and device, storage medium and electronic equipment

By conducting correlation analysis and effectiveness evaluation on data source log data in multi-source heterogeneous security management scenarios, the problem of difficult to ensure the adaptability of correlation analysis rules after log analysis rules is updated, and the effectiveness evaluation of rules and the improvement of security management results is achieved.

CN119995907APending Publication Date: 2025-05-13BEIJING HONGTENG INTELLIGENT TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311507003.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-13
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

In the multi-source heterogeneous security management scenario, after the log analysis rules are updated, the adaptation between the association analysis rules and the log analysis rules is difficult to ensure, resulting in the effectiveness of security alarm processing.

Method used

By obtaining the data source log data of multiple data source servers, the rule maintenance status of the data source analysis rule is detected. If the rule maintenance status is an update status, the data source analysis rule is evaluated based on the association analysis rule and the data source log data. The evaluation results are used to determine the adaptability and effectiveness of the rules.

Benefits of technology

It realizes timely evaluation of the adaptation between the association analysis rules and the log analysis rules to ensure the effectiveness of the rules, detect the effectiveness of the rules in advance, and ensure the effectiveness of the security management effect.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995907A_ABST
    Figure CN119995907A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses an adaptation evaluation method and device, a storage medium and electronic equipment, and the method comprises the steps: obtaining the data source log data of a plurality of data source servers in a multi-source heterogeneous security management scene, detecting the rule maintenance state of a data source analysis rule corresponding to the data source log data, and if the rule maintenance state is a rule updating state, performing association analysis effectiveness evaluation on the data source analysis rule based on the association analysis rule and the data source log data to obtain an analysis rule effectiveness result.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to an adaptation evaluation method, device, storage medium and electronic device. Background Art

[0002] With the rapid popularization of computer networks, security information management and security event management have gradually become the focus. Among them, obtaining network system status through logs is an important branch of security information management and security event management. Complex network systems are composed of a wide variety of security devices, network devices, host systems and their applications, which will generate a large amount of event log data.

[0003] Security information management and security event management are usually combined into a security management system (also known as a security management platform), which collects event log data from a wide range of sources, identifies activities that deviate from security specifications through real-time analysis, and takes appropriate measures. In simple terms, a security management system enables organizations to understand activities in their networks, so that they can quickly respond to possible network attacks, understand security conditions, discover potential threats and attacks, and respond quickly to abnormal events at the first opportunity, while meeting compliance requirements. Summary of the invention

[0004] The present application provides an adaptation evaluation method, device, storage medium and electronic device, and the technical solution is as follows:

[0005] In a first aspect, an embodiment of the present application provides an adaptation evaluation method, the method comprising:

[0006] Acquire data source log data of multiple data source service ends in a multi-source heterogeneous security management scenario, wherein the data source log data is used by the service platform to generate standard storage log data for the data source log data based on the data source parsing rule, and the standard storage log data is used by the service platform to perform security alarm processing based on the standard storage log data using association analysis rules;

[0007] Detecting a rule maintenance status of the data source parsing rule corresponding to the data source log data;

[0008] If the rule maintenance state is the rule update state, then the data source parsing rule is evaluated for association analysis effectiveness based on the association analysis rule and the data source log data to obtain an analysis rule effectiveness result.

[0009] In a feasible implementation manner, the performing association analysis effectiveness evaluation on the data source parsing rule based on the association analysis rule and the data source log data to obtain the analysis rule effectiveness result includes:

[0010] Determine at least one event source correlation analysis template type corresponding to the correlation analysis rule, and determine a correlation analysis effectiveness evaluation method corresponding to the event source correlation analysis model type;

[0011] The association analysis effectiveness evaluation method is adopted to perform association analysis effectiveness evaluation on the data source parsing rule based on the association analysis rule and the data source log data to obtain the analysis rule effectiveness result.

[0012] In a feasible implementation manner, the determining of at least one event source correlation analysis template type corresponding to the correlation analysis rule and the determining of the correlation analysis effectiveness evaluation method corresponding to the event source correlation analysis model type include:

[0013] Determining the number of associated events of at least one association analysis rule item in the association analysis rule;

[0014] If the number of associated data is one event source, determining that the event source association analysis template type is an independent event source association analysis template type, and determining an independent association analysis effectiveness evaluation method corresponding to the independent event source association analysis template type;

[0015] If the number of associated data is at least two event sources, the event source association analysis template type is determined to be a complex event source association analysis template type, and a complex association analysis effectiveness evaluation method corresponding to the complex event source association analysis template type is determined.

[0016] In a feasible implementation manner, the association analysis effectiveness evaluation method is used to perform association analysis effectiveness evaluation on the data source parsing rule based on the association analysis rule and the data source log data to obtain the analysis rule effectiveness result, including:

[0017] If the association analysis effectiveness evaluation method is an independent association analysis effectiveness evaluation method, the data source device type is determined based on the data source log data, and based on the data source device type, a first association analysis effectiveness evaluation is performed on the parsing chain corresponding to the data source parsing rule and the association analysis rule item corresponding to the association analysis rule to obtain a first analysis rule effectiveness result;

[0018] If the association analysis effectiveness evaluation method is a complex association analysis effectiveness evaluation method, then detect whether the data source device type corresponding to the data source log data matches the event source device type corresponding to the association analysis rule to obtain a device type matching result; according to the device type matching result, perform a second association analysis effectiveness evaluation on the parsing chain corresponding to the data source parsing rule and the association analysis rule item corresponding to the association analysis rule based on the data source device type to obtain a second analysis rule effectiveness result.

[0019] In a feasible implementation manner, the first association analysis effectiveness evaluation is performed on the parsing chain corresponding to the data source parsing rule and the association analysis rule item corresponding to the association analysis rule based on the data source device type to obtain the first analysis rule effectiveness result, including:

[0020] Determining an association analysis rule item associated with the data source device type from the association analysis rule, and determining a parsing chain corresponding to the data source parsing rule;

[0021] A first association analysis effectiveness evaluation is performed on the analysis chain based on at least one event dependency element in the association analysis rule item to obtain a first analysis rule effectiveness result.

[0022] In a feasible implementation manner, the first association analysis effectiveness evaluation is performed on the analysis chain based on at least one event dependency element in the association analysis rule item to obtain a first analysis rule effectiveness result, including:

[0023] Determine a first event name, a first event field set, and a first event field value set in the association analysis rule item, and determine a second event name, a second event field set, and a second event field value set in the resolution chain;

[0024] An event name is evaluated based on the first event name and the second event name to obtain an event name matching result, a field evaluation is performed based on the first event field set and the second event field set to obtain an event field set matching result, and a field value evaluation is performed based on the first event field value set and the second event field value set to obtain an event field set matching result;

[0025] If the event name matching result, the event field set matching result and the event field value matching result are all matching types, generating a first analysis rule effectiveness result;

[0026] If at least one of the event name matching result, the event field set matching result and the event field value matching result is a mismatch type, a first analysis rule failure result is generated, and an analysis rule failure reason of the first analysis rule failure result is determined.

[0027] In a feasible implementation manner, according to the device type matching result, based on the data source device type, a second association analysis effectiveness evaluation is performed on the parsing chain corresponding to the data source parsing rule and the association analysis rule item corresponding to the association analysis rule to obtain a second analysis rule effectiveness result, including:

[0028] If the device type matching result is that the device type does not match, generating a second analysis rule failure result, and determining an analysis rule failure reason of the second analysis rule failure result;

[0029] If the device type matching result is a device type match, determine the reference event source corresponding to the device type match, determine the association analysis rule item associated with the reference event source device type from the association analysis rule, and determine the parsing chain corresponding to the data source parsing rule, and sequentially take the reference event source as a benchmark and perform a second association analysis effectiveness evaluation on the parsing chain based on at least one event dependency element in the association analysis rule item to obtain a reference analysis rule effectiveness result corresponding to the reference event source;

[0030] Based on the reference analysis rule effectiveness result corresponding to each of the reference event sources, a second analysis rule effectiveness result is obtained.

[0031] In a feasible implementation manner, the reference event source is used as a benchmark, and a second association analysis effectiveness evaluation is performed on the analysis chain based on at least one event dependency element in the association analysis rule item to obtain a reference analysis rule effectiveness result corresponding to the reference event source, including:

[0032] Based on the reference event source, determine the third event name, the third event field set and the third event field value set in the association analysis rule item, and determine the fourth event name, the fourth event field set and the fourth event field value set in the resolution chain;

[0033] An event name evaluation is performed based on the third event name and the fourth event name to obtain an event name matching result, a field evaluation is performed based on the third event field set and the fourth event field set to obtain an event field set matching result, and a field value evaluation is performed based on the third event field value set and the fourth event field value set to obtain an event field set matching result;

[0034] If the event name matching result, the event field set matching result and the event field value matching result are all matching types, generating a reference analysis rule effectiveness result;

[0035] If at least one of the event name matching result, the event field set matching result and the event field value matching result is a mismatch type, a reference analysis rule failure result is generated, and an analysis rule failure reason of the reference analysis rule failure result is determined.

[0036] In a feasible implementation manner, obtaining the second analysis rule effectiveness result based on the reference analysis rule effectiveness result corresponding to each reference event source includes:

[0037] If the reference analysis rule validity result corresponding to each of the reference event sources is a reference analysis rule validity result, generating a second analysis rule validity result;

[0038] If the reference analysis rule validity result corresponding to at least one of the reference event sources is a reference analysis rule failure result, a second analysis rule failure result is generated, and an analysis rule failure reason of the second analysis rule failure result is determined.

[0039] In a second aspect, an embodiment of the present application provides an adaptation evaluation device, the device comprising:

[0040] A data acquisition module, used to acquire data source log data of multiple data source service terminals in a multi-source heterogeneous security management scenario, wherein the data source log data is used to instruct the service platform to generate standard storage log data for the data source log data based on the data source parsing rule, and the standard storage log data is used to instruct the service platform to use the association analysis rule to perform security alarm processing based on the standard storage log data;

[0041] A status detection module, used to detect the rule maintenance status of the data source parsing rule corresponding to the data source log data;

[0042] The effectiveness evaluation module is used to perform an effectiveness evaluation of the data source parsing rule based on the association analysis rule and the data source log data if the rule maintenance state is the rule update state, and obtain the analysis rule effectiveness result.

[0043] In a feasible implementation manner, the effectiveness evaluation module is used to:

[0044] Determine at least one event source correlation analysis template type corresponding to the correlation analysis rule, and determine a correlation analysis effectiveness evaluation method corresponding to the event source correlation analysis model type;

[0045] The association analysis effectiveness evaluation method is adopted to perform association analysis effectiveness evaluation on the data source parsing rule based on the association analysis rule and the data source log data to obtain the analysis rule effectiveness result.

[0046] In a feasible implementation manner, the effectiveness evaluation module is used to:

[0047] Determining the number of associated events of at least one association analysis rule item in the association analysis rule;

[0048] If the number of associated data is one event source, determining that the event source association analysis template type is an independent event source association analysis template type, and determining an independent association analysis effectiveness evaluation method corresponding to the independent event source association analysis template type;

[0049] If the number of associated data is at least two event sources, the event source association analysis template type is determined to be a complex event source association analysis template type, and a complex association analysis effectiveness evaluation method corresponding to the complex event source association analysis template type is determined.

[0050] In a feasible implementation manner, the effectiveness evaluation module is used to:

[0051] If the association analysis effectiveness evaluation method is an independent association analysis effectiveness evaluation method, the data source device type is determined based on the data source log data, and based on the data source device type, a first association analysis effectiveness evaluation is performed on the parsing chain corresponding to the data source parsing rule and the association analysis rule item corresponding to the association analysis rule to obtain a first analysis rule effectiveness result;

[0052] If the association analysis effectiveness evaluation method is a complex association analysis effectiveness evaluation method, then detect whether the data source device type corresponding to the data source log data matches the event source device type corresponding to the association analysis rule to obtain a device type matching result; according to the device type matching result, perform a second association analysis effectiveness evaluation on the parsing chain corresponding to the data source parsing rule and the association analysis rule item corresponding to the association analysis rule based on the data source device type to obtain a second analysis rule effectiveness result.

[0053] In a feasible implementation manner, the effectiveness evaluation module is used to:

[0054] Determining an association analysis rule item associated with the data source device type from the association analysis rule, and determining a parsing chain corresponding to the data source parsing rule;

[0055] A first association analysis effectiveness evaluation is performed on the analysis chain based on at least one event dependency element in the association analysis rule item to obtain a first analysis rule effectiveness result.

[0056] In a feasible implementation manner, the effectiveness evaluation module is used to:

[0057] Determine a first event name, a first event field set, and a first event field value set in the association analysis rule item, and determine a second event name, a second event field set, and a second event field value set in the resolution chain;

[0058] An event name is evaluated based on the first event name and the second event name to obtain an event name matching result, a field evaluation is performed based on the first event field set and the second event field set to obtain an event field set matching result, and a field value evaluation is performed based on the first event field value set and the second event field value set to obtain an event field set matching result;

[0059] If the event name matching result, the event field set matching result and the event field value matching result are all matching types, generating a first analysis rule effectiveness result;

[0060] If at least one of the event name matching result, the event field set matching result and the event field value matching result is a mismatch type, a first analysis rule failure result is generated, and an analysis rule failure reason of the first analysis rule failure result is determined.

[0061] In a feasible implementation manner, the effectiveness evaluation module is used to:

[0062] If the device type matching result is that the device type does not match, generating a second analysis rule failure result, and determining an analysis rule failure reason of the second analysis rule failure result;

[0063] If the device type matching result is a device type match, determine the reference event source corresponding to the device type match, determine the association analysis rule item associated with the reference event source device type from the association analysis rule, and determine the parsing chain corresponding to the data source parsing rule, and sequentially take the reference event source as a benchmark and perform a second association analysis effectiveness evaluation on the parsing chain based on at least one event dependency element in the association analysis rule item to obtain a reference analysis rule effectiveness result corresponding to the reference event source;

[0064] Based on the reference analysis rule effectiveness result corresponding to each of the reference event sources, a second analysis rule effectiveness result is obtained.

[0065] In a feasible implementation manner, the effectiveness evaluation module is used to:

[0066] Based on the reference event source, determine the third event name, the third event field set and the third event field value set in the association analysis rule item, and determine the fourth event name, the fourth event field set and the fourth event field value set in the resolution chain;

[0067] An event name evaluation is performed based on the third event name and the fourth event name to obtain an event name matching result, a field evaluation is performed based on the third event field set and the fourth event field set to obtain an event field set matching result, and a field value evaluation is performed based on the third event field value set and the fourth event field value set to obtain an event field set matching result;

[0068] If the event name matching result, the event field set matching result and the event field value matching result are all matching types, generating a reference analysis rule effectiveness result;

[0069] If at least one of the event name matching result, the event field set matching result and the event field value matching result is a mismatch type, a reference analysis rule failure result is generated, and an analysis rule failure reason of the reference analysis rule failure result is determined.

[0070] In a feasible implementation manner, the effectiveness evaluation module is used to:

[0071] If the reference analysis rule validity result corresponding to each of the reference event sources is a reference analysis rule validity result, generating a second analysis rule validity result;

[0072] If the reference analysis rule validity result corresponding to at least one of the reference event sources is a reference analysis rule failure result, a second analysis rule failure result is generated, and an analysis rule failure reason of the second analysis rule failure result is determined.

[0073] In a third aspect, an embodiment of the present application provides a computer storage medium, wherein the computer storage medium stores a plurality of instructions, wherein the instructions are suitable for being loaded by a processor and executing the above-mentioned method steps.

[0074] In a fourth aspect, an embodiment of the present application provides an electronic device, which may include: a processor and a memory; wherein the memory stores a computer program, and the computer program is suitable for being loaded by the processor and executing the above-mentioned method steps.

[0075] The beneficial effects brought about by the technical solutions provided by some embodiments of the present application include at least:

[0076] In one or more embodiments of the present specification, the service platform obtains data source log data from multiple data source servers in a multi-source heterogeneous security management scenario, detects the rule maintenance status of the data source parsing rule corresponding to the data source log data, and if the rule maintenance status is the rule update status, performs an association analysis effectiveness evaluation on the data source parsing rule based on the association analysis rule and the data source log data to obtain the effectiveness result of the analysis rule. After the log parsing rule is updated, the association analysis rule adaptation effect evaluation can be performed for the log parsing rule of each data source server, and the adaptation status between the association analysis rule and the log parsing rule can be determined in time, and the effectiveness of the association analysis rule can be determined. The reason why the rule is not effective can be determined based on the effectiveness result of the analysis rule, which can be used for subsequent guidance and optimization of log parsing or the analysis rule itself, and the effectiveness of the rule can be detected in advance before the real risk threat arrives to ensure the security management effect. BRIEF DESCRIPTION OF THE DRAWINGS

[0077] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0078] Figure 1 It is a flowchart of an adaptation evaluation method provided in an embodiment of the present application;

[0079] Figure 2A It is a flow chart of a method for evaluating effectiveness provided in an embodiment of the present application;

[0080] Figure 2B It is a schematic diagram of a flow chart of effectiveness evaluation provided in an embodiment of the present application;

[0081] Figure 3 It is a schematic diagram of a scenario of analysis adaptation provided by an embodiment of the present application;

[0082] Figure 4 It is a schematic diagram of an analysis rule adaptation evaluation provided in an embodiment of the present application;

[0083] Figure 5 It is a schematic diagram of a scenario of a second association analysis effectiveness evaluation provided in an embodiment of the present application;

[0084] Figure 6 It is a schematic diagram of another scenario of the second association analysis effectiveness evaluation provided in an embodiment of the present application;

[0085] Figure 7It is a schematic diagram of another flow chart of effectiveness evaluation provided in an embodiment of the present application;

[0086] Figure 8 It is a structural diagram of an adaptation evaluation device provided in an embodiment of the present application;

[0087] Fig. 9 It is a structural schematic diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0088] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0089] In the description of the present application, it should be understood that the terms "first", "second", etc. are only used for descriptive purposes and cannot be understood as indicating or implying relative importance. In the description of the present application, it should be noted that, unless otherwise clearly specified and limited, "including" and "having" and any of their variations are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but optionally also includes steps or units that are not listed, or optionally also includes other steps or units inherent to these processes, methods, products or devices. For those of ordinary skill in the art, the specific meanings of the above terms in the present application can be understood in specific circumstances. In addition, in the description of the present application, unless otherwise specified, "multiple" refers to two or more. "And / or" describes the association relationship of associated objects, indicating that there can be three relationships, for example, A and / or B, which can represent: A exists alone, A and B exist at the same time, and B exists alone. The character " / " generally indicates that the associated objects before and after are an "or" relationship.

[0090] The present application is described in detail below with reference to specific embodiments.

[0091] In one embodiment, Figure 1 As shown, a method for adapting and evaluating is proposed, which can be implemented by a computer program and can be run on an adaptation and evaluation device based on the von Neumann system. The computer program can be integrated into an application or run as an independent tool application. The adaptation and evaluation device can be a service platform.

[0092] Specifically, the adaptation evaluation method includes:

[0093] S102: Acquire data source log data of multiple data source service terminals in a multi-source heterogeneous security management scenario, wherein the data source log data is used by the service platform to generate standard storage log data for the data source log data based on the data source parsing rule, and the standard storage log data is used by the service platform to perform security alarm processing based on the standard storage log data using an association analysis rule;

[0094] Specifically, the data source log data of multiple data source servers in the multi-source heterogeneous security management scenario includes various types of network security log information generated by different manufacturers and different devices;

[0095] For example, the data sources of data source log data (i.e., multiple data source servers) include: IPS / IDS devices, SCM / SAS devices, SG devices, and WAF devices of Company A, IPS / IDS devices of Company B, SCM / SAS devices of Company C, and SG devices of Company D, etc.

[0096] The corresponding acquisition methods of data source log data of multiple data source servers are: the service platform uses an interface to receive data source log data sent by various data source servers, the service platform can use log data reading to read data source log data pieces from multiple data source servers, the service platform can read data source log data in Redis, and obtain network security log information in other ways.

[0097] Exemplarily, the service platform is equipped with a security management system to maintain multi-source heterogeneous security management scenarios. The security management system integrates security information management and security event management (SIEM), collects event log data from a wide range of sources, identifies activities that deviate from security specifications through real-time analysis, and takes appropriate measures. Simply put, the security management system enables organizations to understand the activities in their networks so that they can quickly respond to possible network attacks, understand the security status, discover potential threats and attacks, and respond quickly to abnormal events at the first time while meeting compliance requirements. The service platform involves log parsing and log correlation analysis in multi-source heterogeneous security management scenarios;

[0098] Multi-source heterogeneous security management scenario: The service platform equipped with a security management system will access data source log data from multiple different data source servers. The service platform is configured with log parsing rules by the corresponding log parsing maintenance end in the log parsing phase, and with correlation analysis rules by the corresponding correlation analysis maintenance end in the log correlation analysis phase;

[0099] Log parsing: The service platform will parse the data source log data of the corresponding data source server based on the data source parsing rules to generate standard storage log data that meets the standards. Schematically: the log parsing link is the process of standardizing the log storage of multi-source heterogeneous data source log data. For example, for the same firewall product, the source IP in the log of data source server A is represented by src_ip, and the source IP in the log of data source server B is represented by source_ip. The service platform needs to map them uniformly into src_address based on the data source parsing rules and write them into standard storage log data to achieve standardization of log data fields.

[0100] Log correlation analysis: The service platform will use correlation analysis rules to perform security alarm processing based on the standard storage log data, that is, the standard storage log data will be subjected to multiple correlation analysis rules. If the corresponding data in the standard storage log data meets the conditions of the correlation analysis rules, an alarm can be generated. If the standard storage log data does not meet the conditions of the correlation analysis rules, no alarm can be generated.

[0101] In the related technology, due to product version iterations of data source vendors, the complexity of the multi-source heterogeneous architecture, human errors and other factors, the corresponding log parsing maintenance end will configure the updated log parsing rules, and the log parsing maintenance end and the correlation analysis maintenance end are often difficult to synchronize in time, making it difficult to ensure that the log parsing of multiple different data source vendors is completely correct, and it is also impossible to ensure that multiple correlation analysis rules are applicable to the logs of different data source vendors. That is, after the log parsing rules are updated, due to the complex characteristics of multi-source heterogeneous logs, there are great difficulties in the adaptation and running-in between the correlation analysis rules and the log parsing. For example, for the same firewall, data source vendor A can parse out field F, and data source vendor B cannot parse out field F. Then, for a certain correlation analysis rule that depends on field F, the log of data source vendor B will definitely not generate an alarm, and the log of data source vendor A may generate an alarm.

[0102] In the multi-source heterogeneous security management scenario, after the log parsing rules are updated, it is unknown whether the association analysis rules are adapted to the updated log parsing rules. By executing the adaptation evaluation method of one or more embodiments of this specification, the association analysis rule adaptation effect evaluation can be performed for the log parsing rules of each data source server to ensure the multi-source heterogeneous security management effect.

[0103] S106: Detecting the rule maintenance status of the data source parsing rule corresponding to the data source log data;

[0104] In a feasible implementation, the update maintenance record of the data source parsing rule may be detected, and the rule maintenance state may be determined based on the update maintenance record, where the rule maintenance state includes a rule update state and a rule non-updated state;

[0105] In a feasible implementation, considering that not all data source parsing rules need to be updated, it is necessary to trigger the evaluation of the adaptation effect of the association analysis rules. The update difference rule quantity of the data source parsing rules can be detected, and a difference rule quantity threshold can be set. When the update difference rule quantity exceeds the difference rule quantity threshold, the rule maintenance state is determined to be the rule update state, otherwise the rule maintenance state is determined to be the rule non-updated state.

[0106] In a feasible implementation, the parsing rule attribute information of the data source parsing rule can be detected, and based on the parsing rule attribute information, it can be determined whether the parsing rule attribute information is updated. If updated, the rule maintenance state is determined to be the rule update state, otherwise, the rule maintenance state is determined to be the rule non-updated state.

[0107] S108: If the rule maintenance state is the rule update state, then based on the association analysis rule and the data source log data, the data source parsing rule is evaluated for association analysis effectiveness to obtain an analysis rule effectiveness result.

[0108] Log correlation analysis based on correlation analysis rules is a process of generating alarms based on standardized standard storage log data through correlation analysis rules. Correlation analysis rules correspond to multiple templates;

[0109] The template can refer to the following illustrative example, as follows:

[0110] Normal template: for event name conversion based on a single attribute

[0111] Normal template - having count: the number of times a certain event occurs

[0112] Normal template - having count (DISTINCT): the number of times a certain attribute appears in multiple consecutive events

[0113] Normal template - having sum: the sum of a property value in multiple consecutive events

[0114] Related template - follow by: Event B occurs after event A

[0115] Association template - or_follow_by: Event A and event B occur at the same time (no order of occurrence required)

[0116] Association template - not follow by: Event A occurs and event B does not occur within a period of time.

[0117] Related template - not before: Event A did not occur within a period of time before event B occurred ......

[0119] The association analysis rule items associated with the above-mentioned several common templates involve one event source and can be regarded as an independent event source association analysis template type; the association analysis rule items associated with the above-mentioned several association templates involve at least two event sources and can be regarded as a complex event source association analysis template type.

[0120] The association analysis rule pre-configures several association analysis rule items based on the actual security protection scenario. The association analysis rule item: establishes one or more association analysis rule items for scenarios that may be associated or require device security policy linkage in the actual security protection scenario.

[0121] For example, for intrusion monitoring systems and firewalls, sometimes it is necessary to establish a protection strategy in the firewall based on the information of the target being attacked in the intrusion monitoring system. Therefore, the intrusion monitoring-firewall correlation analysis rule item can be configured. The content of the analysis is whether the log information recorded by the intrusion monitoring detection and the log information recorded by the firewall have matching information within a certain sliding time window. When the information such as the attack target and the attack source is consistent, it is considered that in this attack event, the two devices responded to the security event. Otherwise, when one of the attack or protection information is missing, it is considered that in this attack event, the two devices did not respond to the same security event. The role of the log correlation analysis rule item is to determine which protection devices have responded and which network security protection devices have not responded to the same security event.

[0122] For another example, the association analysis rule items in the association analysis rule may be for intrusion monitoring and firewall association analysis items, intrusion monitoring and antivirus association analysis items, etc.;

[0123] In a feasible manner, the service platform may determine at least one event source correlation analysis template type corresponding to the correlation analysis rule, and different event source correlation analysis template types correspond to different correlation analysis effectiveness evaluation methods;

[0124] The service platform can then determine the correlation analysis effectiveness evaluation method corresponding to the event source correlation analysis model type, and use the correlation analysis effectiveness evaluation method to perform correlation analysis effectiveness evaluation on the data source parsing rules based on the correlation analysis rules and data source log data to obtain the analysis rule effectiveness results.

[0125] The analysis rule effectiveness results include the analysis rule effectiveness type and the analysis rule failure type;

[0126] In one or more embodiments of the present specification, the service platform obtains data source log data from multiple data source servers in a multi-source heterogeneous security management scenario, detects the rule maintenance status of the data source parsing rule corresponding to the data source log data, and if the rule maintenance status is the rule update status, performs an association analysis effectiveness evaluation on the data source parsing rule based on the association analysis rule and the data source log data to obtain the effectiveness result of the analysis rule. After the log parsing rule is updated, the association analysis rule adaptation effect evaluation can be performed for the log parsing rule of each data source server, and the adaptation status between the association analysis rule and the log parsing rule can be determined in time, the effectiveness of the association analysis rule can be determined, and the reason why the rule is not effective can be determined based on the effectiveness result of the analysis rule, which can be used for subsequent guidance and optimization of log parsing or the analysis rule itself, and the effectiveness of the rule can be detected in advance before the real threat arrives to ensure the security management effect.

[0127] See also Figure 2A , Figure 2A It is a flow chart of a effectiveness evaluation method proposed in this application.

[0128] Specific:

[0129] S202: Determine the number of associated events of at least one association analysis rule item in the association analysis rule;

[0130] The correlation analysis rule is composed of multiple correlation analysis rule items. The process of generating alarms by correlation analysis rule items is implemented based on the event source correlation analysis template. The number of events involved in the event source correlation analysis template is also the number of correlation events.

[0131] The template can refer to the following illustrative example, as follows:

[0132] Normal template: for event name conversion based on a single attribute

[0133] Normal template - having count: the number of times a certain event occurs

[0134] Normal template - having count (DISTINCT): the number of times a certain attribute appears in multiple consecutive events

[0135] Normal template - having sum: the sum of a property value in multiple consecutive events

[0136] Related template - follow by: Event B occurs after event A

[0137] Association template - or_follow_by: Event A and event B occur at the same time (no order of occurrence required)

[0138] Association template - not follow by: Event A occurs and event B does not occur within a period of time.

[0139] Related template - not before: Event A did not occur within a period of time before event B occurred ......

[0141] The event source association analysis template involved in the association analysis rule items associated with the above-mentioned several common templates involves one event source, and the number of associated events is 1, which can be regarded as an independent event source association analysis template type; the event source association analysis template of the association analysis rule items associated with the above-mentioned several association templates involves at least two event sources, and the number of associated events is usually greater than 2, which can be regarded as a complex event source association analysis template type.

[0142] S204: If the number of associated data is one event source, determining that the event source association analysis template type is an independent event source association analysis template type, and determining an independent association analysis effectiveness evaluation method corresponding to the independent event source association analysis template type;

[0143] S206: If the number of associated data is at least two event sources, determine that the event source association analysis template type is a complex event source association analysis template type, and determine a complex association analysis effectiveness evaluation method corresponding to the complex event source association analysis template type.

[0144] S208: If the association analysis effectiveness evaluation method is an independent association analysis effectiveness evaluation method, determining the data source device type based on the data source log data, and performing a first association analysis effectiveness evaluation on the parsing chain corresponding to the data source parsing rule and the association analysis rule item corresponding to the association analysis rule based on the data source device type to obtain a first analysis rule effectiveness result;

[0145] The independent correlation analysis effectiveness evaluation method can be understood as targeting an independent event source. The independent correlation analysis effectiveness evaluation method involves an event source, which is usually an analysis rule for a common template for correlation analysis.

[0146] The data source device type is the device type of the data source server parsed from the data source log data.

[0147] In a feasible implementation manner, the first association analysis effectiveness evaluation is performed on the parsing chain corresponding to the data source parsing rule and the association analysis rule item corresponding to the association analysis rule based on the data source device type to obtain the first analysis rule effectiveness result, which may be:

[0148] A2: determining an association analysis rule item associated with the data source device type from the association analysis rule, and determining a parsing chain corresponding to the data source parsing rule;

[0149] A4: Based on at least one event dependency element in the association analysis rule item, a first association analysis effectiveness evaluation is performed on the analysis chain to obtain a first analysis rule effectiveness result.

[0150] After determining the data source device type, the "analysis chain corresponding to the data source parsing rule" and "association analysis rule item corresponding to the association analysis rule" involving the same data source device type can be determined based on the same data source device type as an evaluation reference, and then the "analysis chain corresponding to the data source parsing rule" and "association analysis rule item corresponding to the association analysis rule" of the same data source device type are subjected to event element adaptation detection, so as to obtain the first analysis rule effectiveness result;

[0151] Optionally, the event (dependency) element includes but is not limited to event name, event field, event field value, etc.

[0152] Independent correlation analysis effectiveness evaluation method: The evaluation target of the data source parsing rule can be understood as identifying the device type of the data source (log parsing), and the evaluation object of the correlation analysis rule can be understood as identifying all correlation analysis rule items (analysis rules) that mark the device type of the data source. By refining the evaluation target: the event name, field, and field value contained in each parsing chain, and refining the evaluation object: the event name, field, and field value contained in each correlation analysis rule item, event element adaptation detection is performed to obtain the first analysis rule effectiveness result. The first analysis rule effectiveness result can be used to feedback the effectiveness type of the analysis rule, the set of rule items supported by each data source in the analysis rule, which data source corresponding to the parsing chain each analysis rule is adapted or not adapted to, the reason for the failure of the relationship analysis rule, etc.

[0153] In a possible implementation, Figure 2B As shown, Figure 2B This is a flow chart of effectiveness evaluation, as follows:

[0154] S3002: Determine the first event name, the first event field set and the first event field value set in the association analysis rule item, and determine the second event name, the second event field set and the second event field value set in the resolution chain;

[0155] Several association analysis rule items include corresponding event elements, and a first event name, a first event field set, and a first event field value set in the association analysis rule item can be determined;

[0156] A plurality of resolution chains include corresponding event elements, and a second event name, a second event field set, and a second event field value set in the resolution chain can be determined;

[0157] Based on this, after determining the data source device type, the same data source device type can be used as an evaluation reference to compare whether the first event name matches the second event name, whether the first event field set matches the second event field set, and whether the first event field value set matches the second event field value set.

[0158] S3004: Performing an event name evaluation based on the first event name and the second event name to obtain an event name matching result, performing a field evaluation based on the first event field set and the second event field set to obtain an event field set matching result, and performing a field value evaluation based on the first event field value set and the second event field value set to obtain an event field set matching result;

[0159] Compare the first event name and the second event name to perform event name evaluation and obtain an event name matching result, where the event name matching result includes an event name match and an event name mismatch;

[0160] Comparing the first event field set and the second event field set to perform event field set evaluation, and obtaining an event field set matching result, wherein the event field set matching result includes an event field set match and an event field set mismatch;

[0161] Comparing the first event field value set and the second event field value set to perform event field value set evaluation, and obtaining an event field value set matching result, wherein the event field value set matching result includes an event field value set match and an event field value set mismatch;

[0162] S3006: If the event name matching result, the event field set matching result and the event field value matching result are all matching types, generating a first analysis rule effectiveness result;

[0163] S3008: If at least one of the event name matching result, the event field set matching result and the event field value matching result is a mismatch type, a first analysis rule failure result is generated, and the analysis rule failure reason of the first analysis rule failure result is determined.

[0164] In a specific implementation scenario, such as Figure 3 As shown, Figure 3 It is a schematic diagram of a scenario for analysis and adaptation.

[0165] The service platform triggers an independent correlation analysis effectiveness evaluation method. The evaluation target of the data source parsing rule can be understood as identifying the device type of the data source (log parsing), and the evaluation object of the correlation analysis rule can be understood as identifying all correlation analysis rule items (analysis rules) that mark the device type of the data source. By refining the evaluation target: the event name, field, and field value contained in each parsing chain, and refining the evaluation object: the event name, field, and field value contained in each correlation analysis rule item, event element adaptation detection is performed to obtain the first analysis rule effectiveness result. The first analysis rule effectiveness result can be used to feedback the effectiveness type of the analysis rule, the set of rule items supported by each data source in the analysis rule, which data source corresponding to the parsing chain each analysis rule is adapted or not adapted to, the reason for the failure of the relationship analysis rule, etc. Figure 4 As shown, Figure 4 It is a schematic diagram of an analysis rule adaptation evaluation involved in this specification. After determining the data source device type, the "association analysis rule items corresponding to the association analysis rule" and the "analysis chain corresponding to the data source analysis rule" involving the same data source device type can be determined based on the same data source device type as an evaluation reference, and then the "association analysis rule items corresponding to the association analysis rule" and each "analysis chain corresponding to the data source analysis rule" of the same data source device type are evaluated one by one to perform event element adaptation detection, and so on. Figure 4 , compare the association analysis rule 1 with each "analysis chain corresponding to the data source analysis rule" of the same data source device type, and so on, to obtain the effectiveness result of the first analysis rule;

[0166] Specifically: compare the first event name and the second event name to perform the following Figure 3 The “event name evaluation” shown obtains the event name matching result, and the event name matching result includes event name matching and event name mismatching;

[0167] Further, if the event name matching result is that the event name does not match, the first analysis rule failure result is generated; if the event name matching result is that the event name matches, the first event field set and the second event field set are compared to perform the following steps: Figure 3 The "field evaluation" in the (event) field set shown obtains the event field set matching result, and the event field set matching result includes the event field set matching (i.e., satisfying) and the event field set not matching (i.e., not satisfying);

[0168] If the event field set matching result is that the event field set does not match (that is, it does not satisfy), then the first analysis rule failure result is generated; if the event field set matching result is that the event field set matches (that is, it satisfies), then the first event field value set and the second event field value set are continued to be compared as follows: Figure 3 The “field value evaluation” shown is used to evaluate the event field value set to obtain the event field value set matching result, and the event field value set matching result includes the event field value set matching and the event field value set mismatching;

[0169] If the event field value set matching result is a field value set match, the first analysis rule effectiveness result is generated; if the event field value set matching result is a field value set mismatch, the first analysis rule failure result is generated, and the analysis rule failure reason of the first analysis rule failure result is determined, and the analysis rule failure reason reflects which event elements do not match and the specific detailed information of the mismatch.

[0170] Indicatively, event name evaluation: If the analysis rule item depends on event name A, and all resolution chains of the data source do not support resolution of event name A, then the analysis rule is determined to be ineffective for the data source. The reason for ineffectiveness is: event name A is not resolved in the resolution chain; if there is a resolution chain in the resolution rule of the data source that supports resolution of event name A, then continue to evaluate.

[0171] Indicatively, field evaluation: If the analysis rule item depends on the B field set of event name A, and all the resolution chains that support resolution of event name A in the resolution rules of the data source do not contain the B field set, then the analysis rule is judged to be ineffective for the data source. The reason for ineffectiveness is: there is no B field for resolving event name A in the resolution chain; among the resolution chains that support resolution of event name A in the resolution rules of the data source, there is a resolution chain that satisfies the B field set, then the evaluation continues.

[0172] Indicatively, field value evaluation: if the analysis rule item depends on the B field set and the C field value set of the A event name, and all the analysis chains that support the analysis of the A event name and the B field set in the analysis rules of the data source do not contain the C field value set, then the analysis rule is judged to be ineffective for the data source. The reason for ineffectiveness is: there is no C field set value that satisfies the B field set of the analysis event name A in the analysis chain; if a certain analysis chain that supports the analysis of the A event name and the B field set in the analysis rules of the data source satisfies the C field set, then the analysis rule is judged to be effective for the data source.

[0173] Optional: Value matching supports equal, not equal, regular matching and other conditional judgment methods.

[0174] S210: If the association analysis effectiveness evaluation method is a complex association analysis effectiveness evaluation method, then detect whether the data source device type corresponding to the data source log data matches the event source device type corresponding to the association analysis rule to obtain a device type matching result; according to the device type matching result, perform a second association analysis effectiveness evaluation on the parsing chain corresponding to the data source parsing rule and the association analysis rule item corresponding to the association analysis rule based on the data source device type to obtain a second analysis rule effectiveness result.

[0175] The effectiveness evaluation method of complex correlation analysis can be understood as targeting two or more event sources. The effectiveness evaluation method of complex correlation analysis involves two or more event sources, and is usually an analysis rule for a correlation analysis (event) correlation template.

[0176] The data source device type is the device type of the data source server parsed from the data source log data.

[0177] Specifically, a complex rule evaluation process is performed for a data source log analysis of a data source vendor. First, the data source device type corresponding to the data source log data is detected to see whether it matches the event source device type corresponding to each correlation analysis rule to obtain a device type matching result.

[0178] Indicatively, since two or more event sources are involved, the device type matching results can be divided into two cases:

[0179] ① If the device type of the event source is consistent with the device type of the data source (the corresponding device types match), it means that it falls within the evaluation scope of the complex association analysis effectiveness evaluation method.

[0180] ② If the device type of the event source is inconsistent with the device type of the data source (the corresponding device types do not match), it means that it does not fall within the evaluation scope, and there is no need to perform a second association analysis effectiveness evaluation based on the data source device type on the parsing chain corresponding to the data source parsing rule and the association analysis rule item corresponding to the association analysis rule to obtain the second analysis rule effectiveness result.

[0181] In a feasible implementation manner, according to the device type matching result, based on the data source device type, a second association analysis effectiveness evaluation is performed on the parsing chain corresponding to the data source parsing rule and the association analysis rule item corresponding to the association analysis rule to obtain the second analysis rule effectiveness result, which may be:

[0182] B2: if the device type matching result is a device type mismatch, generating a second analysis rule failure result, and determining an analysis rule failure reason of the second analysis rule failure result;

[0183] The reason for the failure of the analysis rule is that the device type corresponding to a certain event source is inconsistent with the device type of all data sources.

[0184] B4: If the device type matching result is a device type match, determine the reference event source corresponding to the device type match, determine the association analysis rule item associated with the reference event source device type from the association analysis rule, and determine the parsing chain corresponding to the data source parsing rule, and sequentially take the reference event source as a benchmark and perform a second association analysis effectiveness evaluation on the parsing chain based on at least one event dependency element in the association analysis rule item to obtain the reference analysis rule effectiveness result corresponding to the reference event source;

[0185] B6: Based on the reference analysis rule effectiveness result corresponding to each of the reference event sources, obtain a second analysis rule effectiveness result.

[0186] At this time, the association analysis rule item contains at least two event sources. Event source 1, event source 2...event source n all meet condition ① "The device type of the event source is consistent with the device type of the data source (the corresponding device type matches)", then n effectiveness evaluations are required. If n event sources are effective for one or more resolution chains, then the analysis rule is effective for the data source and effectiveness evaluation is required; if none of "event source 1, event source 2...event source n" is effective, then the analysis rule item is not effective for the data source.

[0187] For example, Figure 5 As shown, Figure 5 It is a scenario diagram of the second association analysis effectiveness evaluation. Assuming that association analysis rule item 1 contains two event sources, event source 1 and event source 2 both meet condition ① "the device type of the event source is consistent with the device type of the data source (the corresponding device types match)", then two effectiveness evaluations are required (taking the reference event source as the benchmark, and performing a second association analysis effectiveness evaluation on the parsing chain based on at least one event dependency element in the association analysis rule item to obtain the reference analysis rule effectiveness result corresponding to the reference event source). If both reference analysis rule effectiveness results are effective, the analysis rule is effective for the data source, otherwise the analysis rule is not effective for the data source.

[0188] For example, taking reference event source 1 as a benchmark, a second management analysis effectiveness evaluation is performed based on the "event name A, field set, field value set" in the associated analysis rule item and the "event name, field set, field value combination" in each parsing chain to obtain reference analysis rule effectiveness result 1 of reference event source 1, and, taking reference event source 2 as a benchmark, a second management analysis effectiveness evaluation is performed based on the "event name B, field set, field value set" in the associated analysis rule item and the "event name, field set, field value combination" in each parsing chain to obtain reference analysis rule effectiveness result 2 of reference event source 1. If both reference analysis rule effectiveness result 1 and reference analysis rule effectiveness result 2 are effective, then the analysis rule is effective for the data source; otherwise, the analysis rule is not effective for the data source.

[0189] Furthermore, the association analysis rule item contains at least two event sources, event source 1, event source 2... event source n, and i (i is a positive integer less than n) event sources all meet condition ① "the device type of the event source is consistent with the device type of the data source (the corresponding device types match)", then i effectiveness evaluations are required. In the i effectiveness evaluations, the event sources currently participating in the evaluation are effective for one or more resolution chains, then the analysis rule is effective for the data source. In the i effectiveness evaluations, the event sources currently participating in the evaluation are not effective for one or more resolution chains, then the analysis rule item is not effective for the data source.

[0190] Assuming that association analysis rule item 1 contains two event sources, and one of event source 1 and event source 2 meets condition ① "the device type of the event source is consistent with the device type of the data source (the corresponding device types match)", then it is necessary to perform an effectiveness evaluation (taking the reference event source as the benchmark, and performing a second association analysis effectiveness evaluation on the parsing chain based on at least one event dependency element in the association analysis rule item to obtain the reference analysis rule effectiveness result corresponding to the reference event source). If the reference analysis rule effectiveness results are all effective, then the analysis rule is effective for the data source, otherwise the analysis rule is not effective for the data source.

[0191] For example, Figure 6 As shown, Figure 6This is another scenario diagram of the effectiveness evaluation of the second association analysis. The association analysis rule 1 contains two event sources. Event source 1 meets condition ①, and event source 2 does not. In this case, only one simple evaluation is required. With reference to event source 1 as the benchmark, the effectiveness evaluation of the second management analysis is performed based on the "event name A, field set, field value set" in the association analysis rule item and the "event name, field set, field value combination" in each parsing chain. If the evaluation is effective as the reference analysis rule effectiveness result, the analysis rule is effective for the data source to generate the second analysis rule effectiveness result. Otherwise, the analysis rule is not effective for the data source to generate the second analysis rule failure result, and the analysis rule failure reason of the second analysis rule failure result is determined.

[0192] That is, when the service platform executes the reference analysis rule effectiveness result corresponding to each reference event source to obtain the second analysis rule effectiveness result, it can:

[0193] If the reference analysis rule validity result corresponding to each of the reference event sources is a reference analysis rule validity result, generating a second analysis rule validity result;

[0194] If the reference analysis rule validity result corresponding to at least one of the reference event sources is a reference analysis rule failure result, a second analysis rule failure result is generated, and an analysis rule failure reason of the second analysis rule failure result is determined.

[0195] like Figure 7 As shown, Figure 7 This is another flow chart of effectiveness evaluation, as follows:

[0196] S4002: Based on the reference event source, determine the third event name, the third event field set and the third event field value set in the association analysis rule item, and determine the fourth event name, the fourth event field set and the fourth event field value set in the resolution chain;

[0197] Several association analysis rule items include corresponding event elements, and a third event name, a third event field set, and a third event field value set in the association analysis rule item can be determined;

[0198] A plurality of resolution chains include corresponding event elements, and a fourth event name, a fourth event field set, and a fourth event field value set in the resolution chain can be determined;

[0199] Based on this, after determining the data source device type, the same data source device type can be used as an evaluation reference to compare whether the third event name matches the fourth event name, whether the third event field set matches the fourth event field set, and whether the third event field value set matches the fourth event field value set.

[0200] S4004: Performing an event name evaluation based on the third event name and the fourth event name to obtain an event name matching result, performing a field evaluation based on the third event field set and the fourth event field set to obtain an event field set matching result, and performing a field value evaluation based on the third event field value set and the fourth event field value set to obtain an event field set matching result;

[0201] Compare the third event name and the fourth event name to perform event name evaluation and obtain an event name matching result, where the event name matching result includes an event name match and an event name mismatch;

[0202] Comparing the third event field set and the fourth event field set to perform event field set evaluation, and obtaining an event field set matching result, wherein the event field set matching result includes an event field set match and an event field set mismatch;

[0203] Compare the third event field value set and the fourth event field value set to perform event field value set evaluation, and obtain an event field value set matching result, where the event field value set matching result includes an event field value set match and an event field value set mismatch;

[0204] S4006: If the event name matching result, the event field set matching result and the event field value matching result are all matching types, generating a reference analysis rule effectiveness result;

[0205] S4008: If at least one of the event name matching result, the event field set matching result and the event field value matching result is a mismatch type, a reference analysis rule failure result is generated, and the analysis rule failure reason of the reference analysis rule failure result is determined.

[0206] like Figure 4 As shown, after determining the data source device type and performing the above steps, taking each reference event source as a benchmark, the same data source device type can be used as an evaluation reference to determine the "association analysis rule items corresponding to the association analysis rules" and the "analysis chains corresponding to the data source analysis rules" involving the same data source device type, and then the "association analysis rule items corresponding to the association analysis rules" of the same data source device type and each "analysis chain corresponding to the data source analysis rule" are evaluated one by one to perform event element adaptation detection, and so on, for example, the association analysis rules are compared with each "analysis chain corresponding to the data source analysis rule" of the same data source device type, and so on, to obtain the second analysis rule effectiveness result;

[0207] Specifically: compare the third event name and the fourth event name to perform the following Figure 3The “event name evaluation” shown obtains the event name matching result, and the event name matching result includes event name matching and event name mismatching;

[0208] Further, if the event name matching result is that the event name does not match, a second analysis rule failure result is generated; if the event name matching result is that the event name matches, the third event field set and the fourth event field set are compared to perform the following steps: Figure 3 The "field evaluation" in the (event) field set shown obtains the event field set matching result, and the event field set matching result includes the event field set matching (i.e., satisfying) and the event field set not matching (i.e., not satisfying);

[0209] If the event field set matching result is that the event field set does not match (that is, it does not satisfy), then the second analysis rule failure result is generated; if the event field set matching result is that the event field set matches (that is, it satisfies), then the third event field value set and the fourth event field value set are compared as follows: Figure 3 The “field value evaluation” shown is used to evaluate the event field value set to obtain the event field value set matching result, and the event field value set matching result includes the event field value set matching and the event field value set mismatching;

[0210] If the event field value set matching result is a field value set match, the second analysis rule effectiveness result is generated; if the event field value set matching result is a field value set mismatch, the second analysis rule failure result is generated, and the analysis rule failure reason of the second analysis rule failure result is determined, which reflects which event elements do not match and the specific detailed information of the mismatch.

[0211] Indicatively, event name evaluation: If the analysis rule item depends on event name A, and all resolution chains of the data source do not support resolution of event name A, then the analysis rule is determined to be ineffective for the data source. The reason for ineffectiveness is: event name A is not resolved in the resolution chain; if there is a resolution chain in the resolution rule of the data source that supports resolution of event name A, then continue to evaluate.

[0212] Indicatively, field evaluation: If the analysis rule item depends on the B field set of event name A, and all the resolution chains that support resolution of event name A in the resolution rules of the data source do not contain the B field set, then the analysis rule is judged to be ineffective for the data source. The reason for ineffectiveness is: there is no B field for resolving event name A in the resolution chain; among the resolution chains that support resolution of event name A in the resolution rules of the data source, there is a resolution chain that satisfies the B field set, then the evaluation continues.

[0213] Indicatively, field value evaluation: if the analysis rule item depends on the B field set and the C field value set of the A event name, and all the analysis chains that support the analysis of the A event name and the B field set in the analysis rules of the data source do not contain the C field value set, then the analysis rule is judged to be ineffective for the data source. The reason for ineffectiveness is: there is no C field set value that satisfies the B field set of the analysis event name A in the analysis chain; if a certain analysis chain that supports the analysis of the A event name and the B field set in the analysis rules of the data source satisfies the C field set, then the analysis rule is judged to be effective for the data source.

[0214] Optional: Value matching supports equal, not equal, regular matching and other conditional judgment methods.

[0215] In one or more embodiments of the present specification, the service platform obtains data source log data from multiple data source servers in a multi-source heterogeneous security management scenario, detects the rule maintenance status of the data source parsing rule corresponding to the data source log data, and if the rule maintenance status is the rule update status, performs an association analysis effectiveness evaluation on the data source parsing rule based on the association analysis rule and the data source log data to obtain the effectiveness result of the analysis rule. After the log parsing rule is updated, the association analysis rule adaptation effect evaluation can be performed for the log parsing rule of each data source server, and the adaptation status between the association analysis rule and the log parsing rule can be determined in time, the effectiveness of the association analysis rule can be determined, and the reason why the rule is not effective can be determined based on the effectiveness result of the analysis rule, which can be used for subsequent guidance and optimization of log parsing or the analysis rule itself, and the effectiveness of the rule can be detected in advance before the real threat arrives to ensure the security management effect.

[0216] The following will be combined Figure 8 , the adaptation evaluation device provided in the embodiment of the present application is introduced in detail. It should be noted that, Figure 8 The adaptation evaluation device shown is used to implement this application Figure 1 to Figure 7 For the convenience of explanation, only the part related to the embodiment of the present application is shown. For the specific technical details not disclosed, please refer to the present application. Figure 1 to Figure 7 The embodiment shown.

[0217] See also Figure 8 , which shows a schematic diagram of the structure of the adaptation evaluation device of the embodiment of the present application. The adaptation evaluation device 1 can be implemented as all or part of the user terminal through software, hardware or a combination of both. According to some embodiments, the adaptation evaluation device 1 includes a data acquisition module 11, a state detection module 12 and a validation evaluation module 13, which are specifically used to:

[0218] The data acquisition module 11 is used to acquire data source log data of multiple data source service terminals in a multi-source heterogeneous security management scenario, wherein the data source log data is used to instruct the service platform to generate standard storage log data for the data source log data based on the data source parsing rule, and the standard storage log data is used to instruct the service platform to use the association analysis rule to perform security alarm processing based on the standard storage log data;

[0219] A state detection module 12, used to detect the rule maintenance state of the data source parsing rule corresponding to the data source log data;

[0220] The effectiveness evaluation module 13 is used to perform an effectiveness evaluation of the data source parsing rule based on the association analysis rule and the data source log data to obtain the effectiveness result of the analysis rule if the rule maintenance state is the rule update state.

[0221] Optionally, the effectiveness evaluation module 13 is used to:

[0222] Determine at least one event source correlation analysis template type corresponding to the correlation analysis rule, and determine a correlation analysis effectiveness evaluation method corresponding to the event source correlation analysis model type;

[0223] The association analysis effectiveness evaluation method is adopted to perform association analysis effectiveness evaluation on the data source parsing rule based on the association analysis rule and the data source log data to obtain the analysis rule effectiveness result.

[0224] Optionally, the effectiveness evaluation module 13 is used to:

[0225] Determining the number of associated events of at least one association analysis rule item in the association analysis rule;

[0226] If the number of associated data is one event source, determining that the event source association analysis template type is an independent event source association analysis template type, and determining an independent association analysis effectiveness evaluation method corresponding to the independent event source association analysis template type;

[0227] If the number of associated data is at least two event sources, the event source association analysis template type is determined to be a complex event source association analysis template type, and a complex association analysis effectiveness evaluation method corresponding to the complex event source association analysis template type is determined.

[0228] Optionally, the effectiveness evaluation module 13 is used to:

[0229] If the association analysis effectiveness evaluation method is an independent association analysis effectiveness evaluation method, the data source device type is determined based on the data source log data, and based on the data source device type, a first association analysis effectiveness evaluation is performed on the parsing chain corresponding to the data source parsing rule and the association analysis rule item corresponding to the association analysis rule to obtain a first analysis rule effectiveness result;

[0230] If the association analysis effectiveness evaluation method is a complex association analysis effectiveness evaluation method, then detect whether the data source device type corresponding to the data source log data matches the event source device type corresponding to the association analysis rule to obtain a device type matching result; according to the device type matching result, perform a second association analysis effectiveness evaluation on the parsing chain corresponding to the data source parsing rule and the association analysis rule item corresponding to the association analysis rule based on the data source device type to obtain a second analysis rule effectiveness result.

[0231] Optionally, the effectiveness evaluation module 13 is used to:

[0232] Determining an association analysis rule item associated with the data source device type from the association analysis rule, and determining a parsing chain corresponding to the data source parsing rule;

[0233] A first association analysis effectiveness evaluation is performed on the analysis chain based on at least one event dependency element in the association analysis rule item to obtain a first analysis rule effectiveness result.

[0234] Optionally, the effectiveness evaluation module 13 is used to:

[0235] Determine a first event name, a first event field set, and a first event field value set in the association analysis rule item, and determine a second event name, a second event field set, and a second event field value set in the resolution chain;

[0236] An event name is evaluated based on the first event name and the second event name to obtain an event name matching result, a field evaluation is performed based on the first event field set and the second event field set to obtain an event field set matching result, and a field value evaluation is performed based on the first event field value set and the second event field value set to obtain an event field set matching result;

[0237] If the event name matching result, the event field set matching result and the event field value matching result are all matching types, generating a first analysis rule effectiveness result;

[0238] If at least one of the event name matching result, the event field set matching result and the event field value matching result is a mismatch type, a first analysis rule failure result is generated, and an analysis rule failure reason of the first analysis rule failure result is determined.

[0239] Optionally, the effectiveness evaluation module 13 is used to:

[0240] If the device type matching result is that the device type does not match, generating a second analysis rule failure result, and determining an analysis rule failure reason of the second analysis rule failure result;

[0241] If the device type matching result is a device type match, determine the reference event source corresponding to the device type match, determine the association analysis rule item associated with the reference event source device type from the association analysis rule, and determine the parsing chain corresponding to the data source parsing rule, and sequentially take the reference event source as a benchmark and perform a second association analysis effectiveness evaluation on the parsing chain based on at least one event dependency element in the association analysis rule item to obtain a reference analysis rule effectiveness result corresponding to the reference event source;

[0242] Based on the reference analysis rule effectiveness result corresponding to each of the reference event sources, a second analysis rule effectiveness result is obtained.

[0243] Optionally, the effectiveness evaluation module 13 is used to:

[0244] Based on the reference event source, determine the third event name, the third event field set and the third event field value set in the association analysis rule item, and determine the fourth event name, the fourth event field set and the fourth event field value set in the resolution chain;

[0245] An event name evaluation is performed based on the third event name and the fourth event name to obtain an event name matching result, a field evaluation is performed based on the third event field set and the fourth event field set to obtain an event field set matching result, and a field value evaluation is performed based on the third event field value set and the fourth event field value set to obtain an event field set matching result;

[0246] If the event name matching result, the event field set matching result and the event field value matching result are all matching types, generating a reference analysis rule effectiveness result;

[0247] If at least one of the event name matching result, the event field set matching result and the event field value matching result is a mismatch type, a reference analysis rule failure result is generated, and an analysis rule failure reason of the reference analysis rule failure result is determined.

[0248] Optionally, the effectiveness evaluation module 13 is used to:

[0249] If the reference analysis rule validity result corresponding to each of the reference event sources is a reference analysis rule validity result, generating a second analysis rule validity result;

[0250] If the reference analysis rule validity result corresponding to at least one of the reference event sources is a reference analysis rule failure result, a second analysis rule failure result is generated, and an analysis rule failure reason of the second analysis rule failure result is determined.

[0251] It should be noted that the adaptation evaluation device provided in the above embodiment only uses the division of the above functional modules as an example when executing the adaptation evaluation method. In actual applications, the above functional distribution can be completed by different functional modules as needed, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In addition, the adaptation evaluation device provided in the above embodiment and the adaptation evaluation method embodiment belong to the same concept, and the implementation process thereof is detailed in the method embodiment, which will not be repeated here.

[0252] The serial numbers of the above-mentioned embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.

[0253] The present application also provides a computer storage medium, which can store multiple instructions, and the instructions are suitable for being loaded and executed by a processor as described above. Figure 1 to Figure 7 The specific implementation process of the adaptation evaluation method in the embodiment shown can be found in Figure 1 to Figure 7 The specific description of the illustrated embodiment will not be repeated here.

[0254] The present application also provides a computer program product, which stores at least one instruction, and the at least one instruction is loaded and executed by the processor as described above. Figure 1 to Figure 7 The specific implementation process of the adaptation evaluation method in the embodiment shown can be found in Figure 1 to Figure 7 The specific description of the illustrated embodiment will not be repeated here.

[0255] Please refer to Fig. 9 , is a structural block diagram of an electronic device provided in an embodiment of this specification. The electronic device in this specification may include one or more of the following components: a processor 110, a memory 120, an input device 130, an output device 140, and a bus 150. The processor 110, the memory 120, the input device 130, and the output device 140 may be connected via a bus 150.

[0256] The processor 110 may include one or more processing cores. The processor 110 uses various interfaces and lines to connect various parts of the entire terminal, and executes various functions and processes data of the terminal 100 by running or executing instructions, programs, code sets or instruction sets stored in the memory 120, and calling data stored in the memory 120. Optionally, the processor 110 can be implemented in at least one hardware form of digital signal processing (DSP), field-programmable gate array (FPGA), and programmable logic array (PLA). The processor 110 can integrate one or a combination of a central processing unit (CPU), a graphics processing unit (GPU), and a modem. Among them, the CPU mainly processes the operating system, user interface, and application programs; the GPU is responsible for rendering and drawing display content; and the modem is used to process wireless communications. It can be understood that the above-mentioned modem may not be integrated into the processor 110, but may be implemented separately through a communication chip.

[0257] The memory 120 may include a random access memory (RAM) or a read-only memory (ROM). Optionally, the memory 120 includes a non-transitory computer-readable storage medium. The memory 120 may be used to store instructions, programs, codes, code sets, or instruction sets.

[0258] The input device 130 is used to receive input commands or data, and the input device 130 includes but is not limited to a keyboard, a mouse, a camera, a microphone, or a touch device. The output device 140 is used to output commands or data, and the output device 140 includes but is not limited to a display device and a speaker. In the embodiment of this specification, the input device 130 may be a temperature sensor for obtaining the operating temperature of the terminal. The output device 140 may be a speaker for outputting audio signals.

[0259] In addition, those skilled in the art will appreciate that the structure of the terminal shown in the above drawings does not constitute a limitation on the terminal, and the terminal may include more or fewer components than shown, or combine certain components, or arrange the components differently. For example, the terminal also includes a radio frequency circuit, an input unit, a sensor, an audio circuit, a wireless fidelity (WIFI) module, a power supply, a Bluetooth module, and other components, which will not be described in detail here.

[0260] In the embodiments of this specification, the execution subject of each step may be the terminal described above. Optionally, the execution subject of each step is the operating system of the terminal. The operating system may be an Android system, an IOS system, or other operating systems, which is not limited in the embodiments of this specification.

[0261] exist Fig. 9 In the electronic device, the processor 110 can be used to call the program stored in the memory 120 and execute it to implement the adaptation evaluation method as described in the various method embodiments of this specification.

[0262] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing related hardware through a computer program, and the program can be stored in a computer-readable storage medium, and when the program is executed, it can include the processes of the embodiments of the above-mentioned methods. The storage medium can be a disk, an optical disk, a read-only storage memory, or a random access memory, etc.

[0263] The above disclosure is only the preferred embodiment of the present application, which certainly cannot be used to limit the scope of rights of the present application. Therefore, equivalent changes made according to the claims of the present application are still within the scope covered by the present application.

Claims

1. A method for adapting and evaluating, characterized in that: Applied to a service platform, the method comprises: Acquire data source log data of multiple data source service ends in a multi-source heterogeneous security management scenario, wherein the data source log data is used by the service platform to generate standard storage log data for the data source log data based on the data source parsing rule, and the standard storage log data is used by the service platform to perform security alarm processing based on the standard storage log data using association analysis rules; Detecting a rule maintenance status of the data source parsing rule corresponding to the data source log data; If the rule maintenance state is the rule update state, then the data source parsing rule is evaluated for association analysis effectiveness based on the association analysis rule and the data source log data to obtain an analysis rule effectiveness result.

2. The method according to claim 1, characterized in that: The performing association analysis effectiveness evaluation on the data source parsing rule based on the association analysis rule and the data source log data to obtain the analysis rule effectiveness result includes: Determine at least one event source correlation analysis template type corresponding to the correlation analysis rule, and determine a correlation analysis effectiveness evaluation method corresponding to the event source correlation analysis model type; The association analysis effectiveness evaluation method is adopted to perform association analysis effectiveness evaluation on the data source parsing rule based on the association analysis rule and the data source log data to obtain the analysis rule effectiveness result.

3. The method according to claim 2, characterized in that The determining of at least one event source correlation analysis template type corresponding to the correlation analysis rule and the determining of a correlation analysis effectiveness evaluation method corresponding to the event source correlation analysis model type include: Determining the number of associated events of at least one association analysis rule item in the association analysis rule; If the number of associated data is one event source, determining that the event source association analysis template type is an independent event source association analysis template type, and determining an independent association analysis effectiveness evaluation method corresponding to the independent event source association analysis template type; If the number of associated data is at least two event sources, the event source association analysis template type is determined to be a complex event source association analysis template type, and a complex association analysis effectiveness evaluation method corresponding to the complex event source association analysis template type is determined.

4. The method according to claim 2, characterized in that: The method of evaluating the effectiveness of the association analysis is used to evaluate the effectiveness of the data source parsing rule based on the association analysis rule and the data source log data, and obtain the effectiveness result of the analysis rule, including: If the association analysis effectiveness evaluation method is an independent association analysis effectiveness evaluation method, the data source device type is determined based on the data source log data, and based on the data source device type, a first association analysis effectiveness evaluation is performed on the parsing chain corresponding to the data source parsing rule and the association analysis rule item corresponding to the association analysis rule to obtain a first analysis rule effectiveness result; If the association analysis effectiveness evaluation method is a complex association analysis effectiveness evaluation method, then detect whether the data source device type corresponding to the data source log data matches the event source device type corresponding to the association analysis rule to obtain a device type matching result; according to the device type matching result, perform a second association analysis effectiveness evaluation on the parsing chain corresponding to the data source parsing rule and the association analysis rule item corresponding to the association analysis rule based on the data source device type to obtain a second analysis rule effectiveness result.

5. The method according to claim 4, characterized in that The performing a first association analysis effectiveness evaluation on the parsing chain corresponding to the data source parsing rule and the association analysis rule item corresponding to the association analysis rule based on the data source device type to obtain a first analysis rule effectiveness result includes: Determining an association analysis rule item associated with the data source device type from the association analysis rule, and determining a parsing chain corresponding to the data source parsing rule; A first association analysis effectiveness evaluation is performed on the analysis chain based on at least one event dependency element in the association analysis rule item to obtain a first analysis rule effectiveness result.

6. The method according to claim 5, characterized in that The step of performing a first association analysis effectiveness evaluation on the parsing chain based on at least one event dependency element in the association analysis rule item to obtain a first analysis rule effectiveness result includes: Determine a first event name, a first event field set, and a first event field value set in the association analysis rule item, and determine a second event name, a second event field set, and a second event field value set in the resolution chain; An event name is evaluated based on the first event name and the second event name to obtain an event name matching result, a field evaluation is performed based on the first event field set and the second event field set to obtain an event field set matching result, and a field value evaluation is performed based on the first event field value set and the second event field value set to obtain an event field set matching result; If the event name matching result, the event field set matching result and the event field value matching result are all matching types, generating a first analysis rule effectiveness result; If at least one of the event name matching result, the event field set matching result and the event field value matching result is a mismatch type, a first analysis rule failure result is generated, and an analysis rule failure reason of the first analysis rule failure result is determined.

7. The method according to claim 4, characterized in that According to the device type matching result, based on the data source device type, a second association analysis effectiveness evaluation is performed on the parsing chain corresponding to the data source parsing rule and the association analysis rule item corresponding to the association analysis rule to obtain a second analysis rule effectiveness result, including: If the device type matching result is that the device type does not match, generating a second analysis rule failure result, and determining an analysis rule failure reason of the second analysis rule failure result; If the device type matching result is a device type match, determine the reference event source corresponding to the device type match, determine the association analysis rule item associated with the reference event source device type from the association analysis rule, and determine the parsing chain corresponding to the data source parsing rule, and sequentially take the reference event source as a benchmark and perform a second association analysis effectiveness evaluation on the parsing chain based on at least one event dependency element in the association analysis rule item to obtain a reference analysis rule effectiveness result corresponding to the reference event source; Based on the reference analysis rule effectiveness result corresponding to each of the reference event sources, a second analysis rule effectiveness result is obtained.

8. The method according to claim 7, characterized in that The step of sequentially taking the reference event source as a benchmark and performing a second association analysis effectiveness evaluation on the analysis chain based on at least one event dependency element in the association analysis rule item to obtain a reference analysis rule effectiveness result corresponding to the reference event source includes: Based on the reference event source, determine the third event name, the third event field set and the third event field value set in the association analysis rule item, and determine the fourth event name, the fourth event field set and the fourth event field value set in the resolution chain; An event name evaluation is performed based on the third event name and the fourth event name to obtain an event name matching result, a field evaluation is performed based on the third event field set and the fourth event field set to obtain an event field set matching result, and a field value evaluation is performed based on the third event field value set and the fourth event field value set to obtain an event field set matching result; If the event name matching result, the event field set matching result and the event field value matching result are all matching types, generating a reference analysis rule effectiveness result; If at least one of the event name matching result, the event field set matching result and the event field value matching result is a mismatch type, a reference analysis rule failure result is generated, and an analysis rule failure reason of the reference analysis rule failure result is determined.

9. The method according to claim 8, characterized in that The obtaining of the second analysis rule effectiveness result based on the reference analysis rule effectiveness result corresponding to each reference event source includes: If the reference analysis rule validity result corresponding to each of the reference event sources is a reference analysis rule validity result, generating a second analysis rule validity result; If the reference analysis rule validity result corresponding to at least one of the reference event sources is a reference analysis rule failure result, a second analysis rule failure result is generated, and an analysis rule failure reason of the second analysis rule failure result is determined.

10. An adaptation evaluation device, characterized in that: The device comprises: A data acquisition module, used to acquire data source log data of multiple data source service terminals in a multi-source heterogeneous security management scenario, wherein the data source log data is used to instruct the service platform to generate standard storage log data for the data source log data based on the data source parsing rule, and the standard storage log data is used to instruct the service platform to use the association analysis rule to perform security alarm processing based on the standard storage log data; A status detection module, used to detect the rule maintenance status of the data source parsing rule corresponding to the data source log data; The effectiveness evaluation module is used to perform an effectiveness evaluation of the data source parsing rule based on the association analysis rule and the data source log data if the rule maintenance state is the rule update state, and obtain the analysis rule effectiveness result.