Security event tracing method and device, storage medium and electronic equipment

By searching for attack association information associated with alarm data in the event database, security events are generated, and the problem of difficult security incidents in the prior art is solved, and the analysis efficiency and response speed of attack behavior are improved.

CN119995910APending Publication Date: 2025-05-13BEIJING HONGTENG INTELLIGENT TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202311511624.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-13
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The existing technology is difficult to effectively trace security incidents, resulting in the inability to efficiently analyze and respond to attack behaviors.

Method used

By obtaining the alarm data generated by the attack behavior, determining the alarm type, obtaining the attack search data, and searching for the associated attack association information in the event database to generate security events to complete traceability.

Benefits of technology

It improves the efficiency of analyzing attack behavior, shortens the response time, and realizes complete traceability of security incidents and effective display of associated information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995910A_ABST
    Figure CN119995910A_ABST
Patent Text Reader

Abstract

The invention discloses a security event traceability method and device, a storage medium and electronic equipment, and the method comprises the steps: obtaining alarm data generated for an attack behavior, determining the alarm type of the alarm data, obtaining attack search data in the alarm data based on the alarm type, and storing the attack search data in the alarm data; and searching attack association information associated with the attack search data in an event database, and generating a security event based on the attack association information and the alarm data. According to the application, the information search is performed on the alarm data generated by the attack behavior to obtain the security event comprising the attack association information associated with the alarm data, so that the source tracing of the security event is completed, the analysis efficiency of the attack behavior is improved, and the time consumed for responding to the attack behavior is shortened.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a security event tracing method, device, storage medium and electronic device. Background Art

[0002] Nowadays, with the continuous development of computer technology, security incidents caused by attacks on terminal devices are also constantly changing. Therefore, it is very important to trace the source of security incidents, restore the complete attack process of security incidents, and determine the degree of harm of security incidents. Summary of the invention

[0003] The present application provides a security incident tracing method, device, storage medium and electronic device, which conducts information search on alarm data generated by attack behavior to obtain security events including attack-related information associated with the alarm data, so as to complete the tracing of security events, thereby improving the efficiency of attack behavior analysis and shortening the time spent on responding to attack behavior.

[0004] In a first aspect, an embodiment of the present application provides a security event tracing method, including:

[0005] Obtaining warning data generated for attack behaviors;

[0006] Determine an alarm type of the alarm data, obtain attack search data in the alarm data based on the alarm type, and search an event database for attack association information associated with the attack search data;

[0007] A security event is generated based on the attack association information and the alarm data.

[0008] In a second aspect, an embodiment of the present application provides a security event tracing device, the device comprising:

[0009] An acquisition unit, used to acquire warning data generated for attack behaviors;

[0010] A search unit, configured to determine an alarm type of the alarm data, obtain attack search data in the alarm data based on the alarm type, and search an event database for attack association information associated with the attack search data;

[0011] A generating unit is used to generate a security event based on the attack association information and the alarm data.

[0012] In a third aspect, an embodiment of the present application provides a computer storage medium, wherein the computer storage medium stores a plurality of instructions, wherein the instructions are suitable for being loaded by a processor and executing the above-mentioned method steps.

[0013] In a fourth aspect, an embodiment of the present application provides an electronic device, comprising: a processor and a memory; wherein the memory stores a computer program, and the computer program is suitable for being loaded by the processor and executing the above-mentioned method steps.

[0014] In an embodiment of the present application, attack search data is obtained by determining the alarm type of the acquired alarm data, attack correlation information associated with the attack search data is searched, and a security event is generated based on the attack correlation information and the alarm data, thereby realizing information search for the alarm data generated by the attack behavior, and obtaining a security event including the attack correlation information associated with the alarm data, so as to complete the tracing of the security event, thereby improving the efficiency of the analysis of the attack behavior and shortening the time spent on responding to the attack behavior. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without paying any creative work.

[0016] Figure 1 A system architecture diagram for tracing the source of a security incident provided in an embodiment of the present application;

[0017] Figure 2 A schematic diagram of a process for tracing the source of a security incident provided in an embodiment of the present application;

[0018] Figure 3 An example schematic diagram of displaying attack association information provided by an embodiment of the present application;

[0019] Figure 4 A schematic diagram of a process for tracing the source of a security incident provided in an embodiment of the present application;

[0020] Figure 5 A flowchart of another security incident tracing method provided in an embodiment of the present application;

[0021] Figure 6 A schematic diagram of the structure of a security event tracing device provided in an embodiment of the present application;

[0022] Figure 7 A schematic diagram of the structure of a search unit provided in an embodiment of the present application;

[0023] Figure 8 A schematic diagram of the structure of a security event tracing device provided in an embodiment of the present application;

[0024] Fig. 9A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0025] In order to make the features and advantages of the present application more obvious and easy to understand, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present application.

[0026] In the prior art, when tracing the source of a security incident, the method used is unable to trace the various types of security data corresponding to the security incident, making tracing difficult. The incomplete data makes it impossible to restore the complete attack process of the security incident, making it impossible to conduct an efficient and comprehensive analysis of the security incident.

[0027] Based on this, an embodiment of the present application provides a security incident tracing method, which obtains attack search data by determining the alarm type of the acquired alarm data, searches for attack correlation information associated with the attack search data, and generates a security incident based on the attack correlation information and the alarm data, thereby realizing information search for the alarm data generated by the attack behavior, and obtaining a security incident including the attack correlation information associated with the alarm data, so as to complete the tracing of the security incident, thereby improving the efficiency of the analysis of the attack behavior and shortening the time spent on responding to the attack behavior.

[0028] See also Figure 1 , which is a system structure diagram of a security incident tracing method provided in an embodiment of the present application. Figure 1 As shown, the security event tracing method provided in the embodiment of the present application can be applied to the terminal device 10 to realize the process of security event tracing. The system structure provided in the embodiment of the present application mainly includes the terminal device 10 and the event database 20. Among them, the terminal device 10 can be a terminal device with a network connection function, including but not limited to conference tablets, mobile phones, personal computers, laptops, smart furniture, vehicle-mounted devices, wearable devices, etc., which have terminal application installation, operation and other functions; the event database 20 can be a server with data information related to the attack behavior stored, which can be implemented with an independent server or a server cluster composed of multiple servers, including but not limited to hardware servers, virtual servers, cloud servers, etc.

[0029] In an embodiment of the present application, the terminal device 10 obtains alarm data generated for the attack behavior, obtains attack search data in the alarm data, searches the event database 20 for attack association information associated with the attack search data, and generates a security event based on the attack association information and the alarm data.

[0030] In an embodiment of the present application, attack search data is obtained by determining the alarm type of the acquired alarm data, attack correlation information associated with the attack search data is searched, and a security event is generated based on the attack correlation information and the alarm data, thereby realizing information search for the alarm data generated by the attack behavior, and obtaining a security event including the attack correlation information associated with the alarm data, so as to complete the tracing of the security event, thereby improving the efficiency of the analysis of the attack behavior and shortening the time spent on responding to the attack behavior.

[0031] based on Figure 1 The system architecture shown below will be combined with Figure 2-Figure 3 , a security incident tracing method provided in an embodiment of the present application is introduced in detail.

[0032] See also Figure 2 , which is a flowchart of a security incident tracing method provided in an embodiment of the present application. Figure 2 As shown, the method may include the following steps S101-S103.

[0033] S101, obtaining warning data generated for attack behavior;

[0034] In one embodiment, when an attack behavior is received, alarm data generated for the attack behavior is obtained.

[0035] Furthermore, the attack behavior may be a data flow attack or information theft directed at a terminal device or information data. When defense measures of a system such as a firewall detect the attack behavior, alarm data is generated for the attack behavior.

[0036] Furthermore, the alarm data may be data indicating attack behavior, and the alarm data may include basic information of the terminal device and operation behavior, and the types of alarm data may be network alarms and terminal alarms, so that different methods can be used for tracing according to different alarm types.

[0037] S102, determining an alarm type of the alarm data, acquiring attack search data in the alarm data based on the alarm type, and searching an event database for attack association information associated with the attack search data;

[0038] In one embodiment, based on an identifier in the alarm data, the identifier is identified to determine the alarm type of the alarm data, an attack search field corresponding to the alarm type is obtained, attack search data corresponding to the attack search field is obtained in the alarm data, and attack association information associated with the attack search data is searched in an event database.

[0039] Furthermore, the identifier in the alarm data may be an identifier generated corresponding to specific information of the alarm data during the process of generating the alarm data, and the identifier is used to indicate the alarm type of the alarm data.

[0040] Further, the attack search field may be a field to be obtained according to the alarm type of the alarm data, and then based on the search mode or abnormal type of the alarm data, the attack search data corresponding to the attack search field is obtained in the alarm data according to the attack search field. For example, the attack search field corresponding to the network alarm is information such as the source address, the destination address, and the four-tuple, and the attack search data is information such as the source address obtained in the alarm data.

[0041] Furthermore, the event database may be a database related to attack behaviors obtained according to the big data architecture, and may include information such as network alarms, terminal alarms, network logs, and terminal logs. Attack-related information associated with the attack search data is obtained in the event database according to different alarm types. It should be noted that since there is a large amount of invalid data in the network log, the network log is not obtained in the actual process of obtaining the attack-related information.

[0042] Exemplarily, if the alarm type of the alarm data is a network alarm, and the search mode is a network alarm mode, the source address and the destination address in the attack search data are obtained, and the attack association information associated with the source address and the destination address is searched in the event database.

[0043] S103, generating a security event based on the attack association information and the alarm data;

[0044] In one embodiment, a security event is generated based on the acquired attack correlation information and alarm data, and when a viewing instruction for the security event is received, the attack correlation information is displayed.

[0045] Furthermore, a security event can be a collection of information for collecting and displaying alarm data, etc., and the attack-related information corresponding to the alarm data can be obtained by viewing the security event. It should be noted that in the process of generating a security event, various types of data are classified and displayed according to categories, so as to restore the attack information of the security event.

[0046] Exemplarily, the terminal device determines that the alarm type of the "mining software communication detected" alarm data generated by the "mining software" is a network alarm, obtains attack search data such as the source address, destination address, attack direction and quadruple in the alarm data, and obtains attack correlation information associated with the attack search data in the event database based on the attack search data, generates a security event based on the attack correlation information and the alarm data, and displays the attack correlation information on the display interface when a viewing instruction is received.

[0047] For example, Figure 3 As shown, Figure 3 The attack-related information associated with "Mining software communication detected" is displayed, namely "Host implanted with mining software", "Mining software process", "Contextual behavior of mining software process" and "Attack alert before mining software implantation", and each attack-related information displayed in the figure is a folder. By clicking the folder, you can view the specific information in each folder. Among them, the specific information can be the ID corresponding to the host in "Host implanted with mining software" and other information.

[0048] Furthermore, when alarm data for attack behavior is obtained, the alarm data is parsed based on preset rules to obtain a parsing result corresponding to the alarm data. If the parsing result indicates that the alarm data matches an existing security event, the alarm data is added to the existing security event; if the parsing result indicates that the alarm data does not match the existing security event, steps S101 to S103 are executed.

[0049] Furthermore, another feasible method for generating security events may be, after obtaining the alarm data, generating an initial event including the alarm data, and after obtaining the attack-related information corresponding to the alarm data, adding all the obtained attack-related information to the initial event to obtain the security event corresponding to the alarm data.

[0050] It should be noted that security events have a life cycle. If no attack-related information is added to the security event within a preset period of time, the security event will be expired. The life cycle can be a period of time set during the generation process, for example, two days. If no new attack-related information is added to the security event within the life cycle, which is a preset period of two days, the security event will be expired.

[0051] It should be noted that, when a security event is generated, the attack correlation information used to generate the security event is all the attack correlation information searched based on the alarm data.

[0052] In an embodiment of the present application, attack search data is obtained by determining the alarm type of the acquired alarm data, attack correlation information associated with the attack search data is searched, and a security event is generated based on the attack correlation information and the alarm data, thereby realizing information search for the alarm data generated by the attack behavior, and obtaining a security event including the attack correlation information associated with the alarm data, so as to complete the tracing of the security event, thereby improving the efficiency of the analysis of the attack behavior and shortening the time spent on responding to the attack behavior.

[0053] See also Figure 4, which is a flowchart of a security incident tracing method provided in an embodiment of the present application. Figure 4 As shown, the method may include the following steps S201-S207.

[0054] S201, obtaining warning data generated for attack behavior;

[0055] In one embodiment, when an attack behavior is received, alarm data generated for the attack behavior is obtained.

[0056] Furthermore, the attack behavior may be a data flow attack or information theft directed at a terminal device or information data. When defense measures of a system such as a firewall detect the attack behavior, alarm data is generated for the attack behavior.

[0057] Furthermore, the alarm data may be data for indicating attack behavior, and the alarm data may include basic information of the terminal device and operation behavior and other information.

[0058] S202, obtaining an identifier in the alarm data, and identifying the identifier to determine an alarm type corresponding to the alarm data;

[0059] In an embodiment, the identifier in the alarm data may be an identifier generated corresponding to specific information of the alarm data during the process of generating the alarm data, and the identifier is used to indicate the alarm type of the alarm data.

[0060] Furthermore, the alarm type may be a network alarm or a terminal alarm, so that the method corresponding to the alarm type is used to trace the source according to the alarm type of the alarm data to obtain specific behavior information of the attack behavior of the alarm data.

[0061] S203, obtaining an attack search field corresponding to the alarm type, and obtaining attack search data corresponding to the attack search field in the alarm data;

[0062] In one embodiment, after the alarm type of the alarm data is determined according to the identifier, an attack search field corresponding to the alarm type is obtained, and attack search data corresponding to the attack search field is obtained in the alarm data.

[0063] The attack search field may be a field to be obtained according to the alarm type of the alarm data, and then based on the search mode or abnormal type of the alarm data, the attack search data corresponding to the attack search field is obtained in the alarm data according to the attack search field.

[0064] Exemplarily, it is determined that the alarm type of the alarm data is a network alarm, and the attack search field corresponding to the network alarm is information such as the source address, the destination address, and the four-tuple, then the attack search data is the source address and other information obtained in the alarm data. For example, the alarm data includes the source address (192.168.0.1), the destination address (192.168.0.2) and the file data, and the attack search field of the network alarm is the source address, the destination address and the four-tuple, then the attack search data is the source address (192.168.0.1) and the destination address (192.168.0.2) and the four-tuple information, but does not include the file data.

[0065] S204, if the alarm type of the alarm data is a network alarm, based on the search pattern of the network alarm, obtaining first search data corresponding to the search pattern in the attack search data, and obtaining attack association information associated with the first search data in the event database;

[0066] In one embodiment, if the alarm type of the alarm data is determined to be a network alarm based on the identifier, and the attack search data of the alarm data is obtained, then based on the search pattern of the network alarm, the first search data corresponding to the search pattern is obtained in the alarm search data, and the attack association information associated with the first search data is obtained in the event database.

[0067] Furthermore, if the alarm type of the alarm data is a network alarm, the search mode of the network alarm is determined; if the search mode is a network alarm mode, the source address and the destination address in the first search data are obtained, and the first attack association information associated with the source address and the destination address is obtained in the event database; if the search mode is a terminal alarm mode, the second attack association information associated with the first search data is obtained in the event database based on the attack direction of the network alarm; if the search mode is a terminal log mode, the quadruple data in the first search data is obtained, and the third attack association information associated with the quadruple data is obtained in the event database; based on the first attack association information, the second attack association information and the third attack association information, the attack association information associated with the first search data is generated.

[0068] The first attack-related information may be network alarm data, the second attack-related information may be terminal alarm data, and the third attack-related information may be terminal logs.

[0069] Exemplarily, if the search mode is a network alarm mode, the source address (192.168.0.1) and the destination address (192.168.0.2) in the first search data are obtained, and the alarm data with the source address "192.168.0.1" and the destination address "192.168.0.2" is obtained in the event database as the first attack association information.

[0070] Furthermore, a feasible method for obtaining the second attack-related information may be to obtain the second attack-related information in the event database according to the attack direction of the network alarm. The specific implementation method may be: if the attack direction is an intranet attacking an extranet, then the source address in the first search data is obtained, and the first historical alarm data with the network identifier as the source address is obtained in the event database, and the first historical alarm data is determined as the second associated information associated with the first search field; if the attack direction is an intranet attacking an intranet, then the source address and the destination address in the first search data are obtained, and the second historical alarm data with the network identifier as the source address or the destination address is obtained in the event database, and the second historical alarm data is determined as the second associated information associated with the first search field; if the attack direction is an extranet attacking an intranet, then the destination address in the first search data is obtained, and the third historical alarm data with the network identifier as the destination address is obtained in the event database, and the third historical alarm data is determined as the second associated information associated with the first search field.

[0071] It should be noted that the intranet may be a local area network where the terminal device for obtaining alarm data is located, and the extranet may be a network in a different area from the intranet, such as the Internet, or another local area network in a different area from the intranet.

[0072] S205, if the alarm type of the alarm data is a terminal alarm, based on the abnormal type of the terminal alarm, obtaining second search data corresponding to the abnormal type in the attack search data, and obtaining attack association information associated with the second search data in the event database;

[0073] In one embodiment, if the alarm type of the alarm data is determined to be a terminal alarm based on the identifier, and the attack search data of the alarm data is obtained, the abnormal type of the terminal alarm is determined, the second search data corresponding to the abnormal type is obtained in the attack search data, and the attack association information associated with the second search data is obtained in the event database.

[0074] Furthermore, the method for obtaining the second search data according to the anomaly type can be: if the anomaly type is a file anomaly, the behavior data and file data in the second attack search data are obtained, and the fourth attack association information associated with the behavior data and the file data is obtained in the event database; if the anomaly type is a network anomaly, the behavior data and address data in the second attack search data are obtained, and the fifth attack association information associated with the behavior data and the address data is obtained in the event database; if the anomaly type is not a file anomaly or a network anomaly, the behavior data in the second attack search data is obtained, and the sixth attack association information associated with the behavior data is obtained in the event database; based on the fourth attack association information, the fifth attack association information and the sixth attack association information, the attack association information associated with the second attack search data is generated.

[0075] Among them, the behavior data can be the host IP (Internet Protocol), host ID, process PID (Process Identification) or process path of the terminal device; the file data can be the file path, file name, file MD5 (Message-Digest Algorithm) and other information in the alarm data; the address data can be the source address, destination address and other information.

[0076] Among them, the fourth attack association information may be the terminal alarm data and terminal log obtained when the abnormality type of the alarm data is a file abnormality, the fifth attack association information may be the network alarm data, terminal alarm data and terminal log obtained when the abnormality type of the alarm data is a network abnormality, and the sixth attack association information may be the terminal alarm data and terminal log obtained when the abnormality type of the alarm data is an abnormality type other than file abnormality and network abnormality.

[0077] Furthermore, by obtaining associated attack-related information in the event database based on the behavior data, file data or address data, a process tree can be constructed for contextual behavior logs and alarm data including the parent process, grandparent process, child process, process behavior, etc. of the host process, so as to construct a complete attack chain corresponding to the attack behavior of the alarm data.

[0078] S206, generating a security event based on the attack association information and the alarm data;

[0079] In one embodiment, the acquired attack correlation information is detected based on preset rules. If the attack correlation information does not contain attack correlation data satisfying the preset rules, a security event is generated based on the acquired attack correlation information and alarm data.

[0080] Furthermore, a security event can be a collection of information for collecting and displaying alarm data, etc., and the attack-related information corresponding to the alarm data can be obtained by viewing the security event. It should be noted that in the process of generating a security event, various types of data are classified and displayed according to categories, so as to restore the attack information of the security event.

[0081] Further, the acquired attack association information is detected based on the preset rules. If the attack association information contains attack association data that satisfies the preset rules, the attack association data is used as the attack search data, and step S204 or step S205 is executed. It should be noted that when the attack association information contains attack association data that satisfies the preset rules based on the preset rules, the alarm type corresponding to the attack association information is determined, so as to determine whether to specifically execute step S204 or step S205 based on the alarm type. For example, if the attack association information contains attack association data that satisfies the preset rules based on the preset rules, and the alarm type corresponding to the attack association data is a terminal alarm, step S205 is executed.

[0082] Furthermore, when alarm data for attack behavior is obtained, the alarm data is parsed based on preset rules to obtain a parsing result corresponding to the alarm data. If the parsing result indicates that the alarm data matches an existing security event, the alarm data is added to the existing security event; if the parsing result indicates that the alarm data does not match the existing security event, steps S201 to S206 are executed.

[0083] Further, another feasible method for generating security events may be, after obtaining the alarm data, generating an initial event including the alarm data, and after obtaining the attack-related information corresponding to the alarm data, adding all the acquired attack-related information to the initial event, so as to obtain the security event corresponding to the alarm data. The initial event may be a blank security event including the alarm data generated for the alarm data, and then, according to the acquired attack-related information, all the attack-related information acquired in the event database is added to the blank security event, so as to continuously enrich the blank security event, and obtain the security event corresponding to the alarm data.

[0084] It should be noted that security events have a life cycle. If no attack-related information is added to the security event within a preset period of time, the security event will be expired. The life cycle can be a period of time set during the generation process, for example, two days. If no new attack-related information is added to the security event within the life cycle, which is a preset period of two days, the security event will be expired.

[0085] It should be noted that when generating a security event, the attack-related information used to generate the security event is all the attack-related information searched based on the alarm data. If there is attack-related data that meets the preset rules in the searched attack-related information, then the related attack-related information is searched based on the attack-related data until there is no attack-related data that meets the preset rules in the attack-related information. The attack-related information searched based on the attack-related data is also used to generate the security event.

[0086] S207, when receiving a viewing instruction for a security event, displaying the attack-related information;

[0087] In one embodiment, after a security event is generated based on attack correlation information and alarm data, upon receiving a viewing instruction for the security event, the attack correlation information included in the security event is displayed on a display interface of the terminal device to facilitate analysis of the security event.

[0088] Exemplarily, the terminal device determines that the alarm type of the "mining software communication detected" alarm data generated by the "mining software" is a network alarm, obtains attack search data such as the source address, destination address, attack direction and quadruple in the alarm data, and obtains attack correlation information associated with the attack search data in the event database based on the attack search data, generates a security event based on the attack correlation information and the alarm data, and displays the attack correlation information on the display interface when a viewing instruction is received.

[0089] For example, Figure 3 As shown, Figure 3 The attack-related information associated with "Mining software communication detected" is displayed, namely "Host implanted with mining software", "Mining software process", "Contextual behavior of mining software process" and "Attack alert before mining software implantation", and each attack-related information displayed in the figure is a folder. By clicking the folder, you can view the specific information in each folder. Among them, the specific information can be the ID corresponding to the host in "Host implanted with mining software" and other information.

[0090] In an embodiment of the present application, by acquiring alarm data generated by the attack behavior, determining the attack search field corresponding to the alarm type of the acquired alarm data, acquiring the attack search data corresponding to the attack search field in the alarm data, searching for attack-related information associated with the attack search data, generating a security event based on all the searched attack-related information and alarm data, and displaying the attack-related information in the security event when a viewing instruction is received, thereby realizing information search for the alarm data generated by the attack behavior, and obtaining a security event including the attack-related information associated with the alarm data, so as to complete the tracing of the security event and the display of the related information, thereby improving the efficiency of the analysis of the attack behavior and shortening the time spent on responding to the attack behavior.

[0091] See also Figure 5 , which is a flowchart of a security incident tracing method provided in an embodiment of the present application. Figure 5 As shown, the method may include the following contents.

[0092] In one embodiment, according to another security incident tracing method described in step S206, the specific implementation method may be:

[0093] When the alarm data generated for the attack behavior is obtained, the alarm data is matched according to the preset rules to determine whether the alarm data matches the existing security event. If it matches the existing security event, the alarm data is added to the existing security event to enrich the existing security event; if there is no existing security event matching the alarm data, a new security event is created, and the alarm data is identified according to the identifier in the alarm data to determine whether the alarm type of the alarm data is a network alarm or a terminal alarm.

[0094] Furthermore, if the alarm data is a network alarm, the attack search data in the alarm data is obtained, and the attack search data includes information such as the source address, the destination address, and a four-tuple. The network alarm data associated with the attack search data is obtained based on the source address, the destination address, and other information, and the network alarm data is added to the attack association information corresponding to the network alarm; the terminal log associated with the attack search data is obtained based on the four-tuple, and the terminal log is added to the attack association information; the associated terminal alarm is obtained based on the attack direction information corresponding to the alarm data, and the associated terminal alarm is added to the attack association information.

[0095] Furthermore, while obtaining the associated terminal alarm based on the attack direction information, a cascade search is started to build a complete attack chain. The specific implementation method can be to obtain the parent process, grandparent process, child process, process behavior and other context behavior logs and alarm data of the host process based on the host ID, host IP, and process PID information to build a process tree, and add the behavior logs and alarm data to the attack-related information; if the abnormality type of the alarm data is a file abnormality, the file path, file name, file MD5 and other information are synchronously extracted to obtain the host file operation related context logs and alarm data, and add them to the attack-related information; if the abnormality type is a network abnormality, the source address, destination address and other information are synchronously extracted to obtain the terminal device network connection related context logs and alarm data, and add them to the attack-related information.

[0096] Furthermore, if the alarm data is a terminal alarm, the abnormal type of the alarm data is determined. If the alarm data is neither a file abnormality nor a network abnormality, the alarm data and the log are contextually associated based on the host ID, host IP, and process PID information to obtain the parent process, grandparent process, child process, process behavior and other context logs and alarm data of the host process, build a process tree, and add the obtained logs and alarm data to the attack association information; if the abnormal type of the alarm data is a file abnormality, the alarm data and the log are contextually associated based on the host ID, host IP, process PID, file path, file name, file MD5 and other information. The process tree is constructed to obtain the context behavior logs and alarm data of the host process, such as the process chain, process behavior, and file operation, and the obtained logs and alarm data are added to the attack correlation information; if the abnormal type of the alarm data is a network abnormality, the alarm data and logs are contextually associated according to the host ID, host IP, process PID, alarm source address, and / or destination address information to obtain the parent process, grandparent process, child process, process behavior, and other context logs and terminal alarm data of the host process, and then obtain the associated network alarm data, and add the obtained logs, terminal alarm data, and network alarm data to the attack correlation information.

[0097] Furthermore, the acquired attack association information is detected according to preset rules. If there is no attack association data satisfying the preset rules in the attack association information, the attack association information is added to the created security event to obtain the security event corresponding to the alarm data.

[0098] Furthermore, if it is detected that there is attack-related data that meets the preset rules in the alarm-related information, after determining the alarm type corresponding to the attack-related data, a cascade search is performed again in the event database based on the attack-related data as attack search data to obtain the attack-related information associated with the attack-related data. It should be noted that each time after the step of obtaining the attack-related information is performed, the obtained attack-related information is tested according to the preset rules until there is no attack-related data that meets the preset rules in the obtained attack-related information, and all the obtained attack-related information is added to the created security event, thereby obtaining the security event corresponding to the alarm data.

[0099] In an embodiment of the present application, by creating a security event corresponding to the alarm data, determining the alarm type of the acquired alarm data to obtain attack search data, searching for attack-related information associated with the attack search data, and adding the acquired attack-related information and alarm data to the security event, information search is performed on the alarm data generated by the attack behavior, and a security event including the attack-related information associated with the alarm data is obtained, so as to complete the tracing of the security event, thereby improving the efficiency of the analysis of the attack behavior and shortening the time spent on responding to the attack behavior.

[0100] based on Figure 1 The system architecture shown below will be combined with Figure 6 , the security event tracing device provided in the embodiment of the present application is introduced in detail. It should be noted that, Figure 6-Figure 8 The security event tracing device in this manual is used to execute Figure 2-Figure 5 For the convenience of explanation, only the part related to the embodiment of the present application is shown. For the specific technical details not disclosed, please refer to this specification. Figure 2-Figure 5 The embodiment shown.

[0101] See also Figure 6 , which is a schematic diagram of the structure of a security event tracing device according to an embodiment of the present application. Figure 6 As shown, the security event tracing device 1 in the embodiment of the present application may include: an acquisition unit 11, a search unit 12 and a generation unit 13.

[0102] An acquisition unit 11 is used to acquire warning data generated for attack behaviors;

[0103] A search unit 12, configured to determine an alarm type of the alarm data, obtain attack search data in the alarm data based on the alarm type, and search an event database for attack association information associated with the attack search data;

[0104] The generating unit 13 is configured to generate a security event based on the attack association information and the alarm data.

[0105] Optional, such as Figure 7 As shown, the search unit 12 includes:

[0106] The type determination subunit 121 is used to obtain the identifier in the alarm data, identify the identifier to determine the alarm type corresponding to the alarm data, and the alarm type includes a network alarm and a terminal alarm;

[0107] The data acquisition subunit 122 is used to acquire the attack search field corresponding to the alarm type, and acquire the attack search data corresponding to the attack search field in the alarm data;

[0108] The information search subunit 123 is used to search the event database for attack-related information associated with the attack search data.

[0109] Optionally, the information search subunit 123 is further used for:

[0110] If the alarm type of the alarm data is a network alarm, based on the search mode of the network alarm, obtaining first search data corresponding to the search mode in the attack search data, and obtaining attack association information associated with the first search data in the event database;

[0111] If the alarm type of the alarm data is a terminal alarm, based on the abnormal type of the terminal alarm, second search data corresponding to the abnormal type is obtained in the attack search data, and attack association information associated with the second search data is obtained in the event database.

[0112] Optionally, the information search subunit 123 is further used for:

[0113] If the alarm type of the alarm data is a network alarm, determining a search mode for the network alarm;

[0114] If the search mode is a network alarm mode, obtaining a source address and a destination address in the first search data, and obtaining first attack association information associated with the source address and the destination address in an event database;

[0115] If the search mode is a terminal alarm mode, acquiring second attack association information associated with the first search data in the event database based on the attack direction of the network alarm;

[0116] If the search mode is a terminal log mode, obtaining the four-tuple data in the first search data, and obtaining the third attack association information associated with the four-tuple data in the event database;

[0117] Attack-related information associated with the first search data is generated based on the first attack-related information, the second attack-related information, and the third attack-related information.

[0118] Optionally, the information search subunit 123 is further used for:

[0119] If the attack direction is an intranet attacking an extranet, obtaining a source address in the first search data, obtaining first historical alarm data with a network identifier as the source address in the event database, and determining the first historical alarm data as second associated information associated with the first search field;

[0120] If the attack direction is an intranet attacking an intranet, obtaining a source address and a destination address in the first search data, obtaining second historical alarm data with a network identifier as the source address or the destination address in the event database, and determining the second historical alarm data as second associated information associated with the first search field;

[0121] If the attack direction is an external network attacking an internal network, obtain the destination address in the first search data, obtain the third historical alarm data with the network identifier as the destination address in the event database, and determine the third historical alarm data as the second association information associated with the first search field.

[0122] Optionally, the information search subunit 123 is further used for:

[0123] If the alarm type of the alarm data is a terminal alarm, determining the abnormal type of the terminal alarm;

[0124] If the anomaly type is a file anomaly, obtaining the behavior data and the file data in the second attack search data, and obtaining fourth attack association information associated with the behavior data and the file data in an event database;

[0125] If the anomaly type is a network anomaly, obtaining the behavior data and the address data in the second attack search data, and obtaining fifth attack association information associated with the behavior data and the address data in an event database;

[0126] If the anomaly type is not a file anomaly or a network anomaly, obtaining behavior data in the second attack search data, and obtaining sixth attack association information associated with the behavior data in an event database;

[0127] Attack-related information associated with the second attack search data is generated based on the fourth attack-related information, the fifth attack-related information, and the sixth attack-related information.

[0128] Optionally, the security event tracing device 1 is also used for:

[0129] If the attack association information contains attack association data satisfying a preset rule, the attack association data is used as attack search data, and the step of searching the database for attack association information associated with the attack search data is performed;

[0130] If the attack association information does not contain attack association data that meets the preset rule, the step of generating a security event based on the attack association information and the alarm data is performed.

[0131] Optionally, the acquiring unit 11 is further used for:

[0132] Analyze the alarm data based on preset rules to obtain analysis results corresponding to the alarm data;

[0133] If the analysis result indicates that the alarm data matches an existing security event, adding the alarm data to the existing security event;

[0134] If the analysis result indicates that the alarm data does not match the existing security event, a step of determining an alarm type of the alarm data is performed.

[0135] Optional, such as Figure 8 As shown, the security event tracing device 1 also includes:

[0136] The viewing unit 14 is configured to display the attack-related information if a viewing instruction for the security event is received.

[0137] Optionally, the security event tracing device 1 is further used to generate an initial event including the alarm data;

[0138] Optionally, the generating unit 13 includes:

[0139] The adding subunit 131 is used to add the attack association information to the initial event to obtain the security event corresponding to the alarm data.

[0140] Optional, such as Figure 8 As shown, the security event tracing device 1 also includes:

[0141] Expiration unit 15, used to expire the security event if the attack-related information is not added to the security event within a preset time period

[0142] In an embodiment of the present application, by acquiring alarm data generated by the attack behavior, determining the attack search field corresponding to the alarm type of the acquired alarm data, acquiring the attack search data corresponding to the attack search field in the alarm data, searching for attack-related information associated with the attack search data, generating a security event based on all the searched attack-related information and alarm data, and displaying the attack-related information in the security event when a viewing instruction is received, thereby realizing information search for the alarm data generated by the attack behavior, and obtaining a security event including the attack-related information associated with the alarm data, so as to complete the tracing of the security event and the display of the related information, thereby improving the efficiency of the analysis of the attack behavior and shortening the time spent on responding to the attack behavior.

[0143] The present application also provides a computer storage medium, which can store multiple program instructions, and the program instructions are suitable for being loaded and executed by a processor as described above. Figure 2-Figure 5 The method steps of the embodiment shown in the figure can be found in the specific execution process. Figure 2-Figure 5 The specific description of the illustrated embodiment will not be repeated here.

[0144] See also Fig. 9 , is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. Fig. 9 As shown, the electronic device 1000 may include: at least one processor 1001, such as a CPU, at least one network interface 1004, an input / output interface 1003, a memory 1005, and at least one communication bus 1002. The communication bus 1002 is used to realize the connection and communication between these components. The network interface 1004 may optionally include a standard wired interface, a wireless interface (such as a WI-FI interface). The memory 1005 may be a high-speed RAM memory, or a non-volatile memory (non-volatile memory), such as at least one disk storage. The memory 1005 may optionally also be at least one storage device located away from the aforementioned processor 1001. As shown in FIG. Fig. 9 As shown, the memory 1005 as a computer storage medium may include an operating system, a network communication module, an input and output interface module, and a security event tracing application.

[0145] exist Fig. 9 In the electronic device 1000 shown, the input-output interface 1003 is mainly used to provide an input interface for the user and obtain data input by the user.

[0146] In one embodiment, the processor 1001 may be used to call the security event tracing application stored in the memory 1005, and specifically perform the following operations:

[0147] Obtaining warning data generated for attack behaviors;

[0148] Determine an alarm type of the alarm data, obtain attack search data in the alarm data based on the alarm type, and search an event database for attack association information associated with the attack search data;

[0149] A security event is generated based on the attack association information and the alarm data.

[0150] Optionally, when the processor 1001 determines the alarm type of the alarm data, obtains the attack search field in the alarm data based on the alarm type, and searches the event database for attack association information associated with the attack search data, the processor 1001 specifically performs the following operations:

[0151] Obtaining an identifier in the alarm data, identifying the identifier to determine an alarm type corresponding to the alarm data, the alarm type including a network alarm and a terminal alarm;

[0152] Acquire an attack search field corresponding to the alarm type, and acquire attack search data corresponding to the attack search field in the alarm data;

[0153] The event database is searched for attack-related information associated with the attack search data.

[0154] Optionally, when searching the event database for attack association information associated with the attack search data, the processor 1001 specifically performs the following operations:

[0155] If the alarm type of the alarm data is a network alarm, based on the search mode of the network alarm, obtaining first search data corresponding to the search mode in the attack search data, and obtaining attack association information associated with the first search data in the event database;

[0156] If the alarm type of the alarm data is a terminal alarm, based on the abnormal type of the terminal alarm, second search data corresponding to the abnormal type is obtained in the attack search data, and attack association information associated with the second search data is obtained in the event database.

[0157] Optionally, when the processor 1001 executes, if the alarm type of the alarm data is a network alarm, obtaining, based on the search mode of the network alarm, first search data corresponding to the search mode in a first search field, and obtaining attack association information associated with the first search data in an event database, specifically performs the following operations:

[0158] If the alarm type of the alarm data is a network alarm, determining a search mode for the network alarm;

[0159] If the search mode is a network alarm mode, obtaining a source address and a destination address in the first search data, and obtaining first attack association information associated with the source address and the destination address in an event database;

[0160] If the search mode is a terminal alarm mode, acquiring second attack association information associated with the first search data in the event database based on the attack direction of the network alarm;

[0161] If the search mode is a terminal log mode, obtaining the four-tuple data in the first search data, and obtaining the third attack association information associated with the four-tuple data in the event database;

[0162] Attack-related information associated with the first search data is generated based on the first attack-related information, the second attack-related information, and the third attack-related information.

[0163] Optionally, when the processor 1001 acquires second association information associated with the first search field in the event database based on the attack direction of the terminal alarm mode, the processor 1001 specifically performs the following operations:

[0164] If the attack direction is an intranet attacking an extranet, obtaining a source address in the first search data, obtaining first historical alarm data with a network identifier as the source address in the event database, and determining the first historical alarm data as second associated information associated with the first search field;

[0165] If the attack direction is an intranet attacking an intranet, obtaining a source address and a destination address in the first search data, obtaining second historical alarm data with a network identifier as the source address or the destination address in the event database, and determining the second historical alarm data as second associated information associated with the first search field;

[0166] If the attack direction is an external network attacking an internal network, obtain the destination address in the first search data, obtain the third historical alarm data with the network identifier as the destination address in the event database, and determine the third historical alarm data as the second association information associated with the first search field.

[0167] Optionally, when the processor 1001 executes the following operations: if the alarm type of the alarm data is a terminal alarm, based on the abnormal type of the terminal alarm, obtaining second attack search data corresponding to the abnormal type in a second attack search field, and obtaining attack association information associated with the second attack search data in an event database, specifically performing the following operations:

[0168] If the alarm type of the alarm data is a terminal alarm, determining the abnormal type of the terminal alarm;

[0169] If the anomaly type is a file anomaly, obtaining the behavior data and the file data in the second attack search data, and obtaining fourth attack association information associated with the behavior data and the file data in an event database;

[0170] If the anomaly type is a network anomaly, obtaining the behavior data and the address data in the second attack search data, and obtaining fifth attack association information associated with the behavior data and the address data in an event database;

[0171] If the anomaly type is not a file anomaly or a network anomaly, obtaining behavior data in the second attack search data, and obtaining sixth attack association information associated with the behavior data in an event database;

[0172] Attack-related information associated with the second attack search data is generated based on the fourth attack-related information, the fifth attack-related information, and the sixth attack-related information.

[0173] Optionally, after searching the event database for attack association information associated with the attack search field, the processor 1001 further performs the following operations:

[0174] If the attack association information contains attack association data satisfying a preset rule, the attack association data is used as attack search data, and the step of searching the database for attack association information associated with the attack search data is performed;

[0175] If the attack association information does not contain attack association data that meets the preset rule, the step of generating a security event based on the attack association information and the alarm data is performed.

[0176] Optionally, after acquiring the warning data generated for the attack behavior, the processor 1001 further performs the following operations:

[0177] Analyze the alarm data based on preset rules to obtain analysis results corresponding to the alarm data;

[0178] If the analysis result indicates that the alarm data matches an existing security event, adding the alarm data to the existing security event;

[0179] If the analysis result indicates that the alarm data does not match the existing security event, a step of determining an alarm type of the alarm data is performed.

[0180] Optionally, after generating a security event based on the attack association information and the alarm data, the processor 1001 further performs the following operations:

[0181] If a viewing instruction for the security event is received, the attack-related information is displayed.

[0182] Optionally, after acquiring the warning data generated for the attack behavior, the processor 1001 further performs the following operations:

[0183] generating an initial event including the alarm data;

[0184] The generating a security event based on the attack association information and the alarm data includes:

[0185] The attack association information is added to the initial event to obtain a security event corresponding to the alarm data.

[0186] Optionally, the processor 1001 further performs the following operations:

[0187] If the attack-related information is not added to the security event within a preset period of time, the security event will be expired.

[0188] In an embodiment of the present application, by acquiring alarm data generated by the attack behavior, determining the attack search field corresponding to the alarm type of the acquired alarm data, acquiring the attack search data corresponding to the attack search field in the alarm data, searching for attack-related information associated with the attack search data, generating a security event based on all the searched attack-related information and alarm data, and displaying the attack-related information in the security event when a viewing instruction is received, thereby realizing information search for the alarm data generated by the attack behavior, and obtaining a security event including the attack-related information associated with the alarm data, so as to complete the tracing of the security event and the display of the related information, thereby improving the efficiency of the analysis of the attack behavior and shortening the time spent on responding to the attack behavior.

[0189] A person skilled in the art can understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program, and the program can be stored in a computer-readable storage medium, and when the program is executed, it can include the processes of the embodiments of the above-mentioned methods. The storage medium can be a disk, an optical disk, a read-only memory (ROM) or a random access memory (RAM), etc.

[0190] The above disclosure is only the preferred embodiment of the present application, which certainly cannot be used to limit the scope of rights of the present application. Therefore, equivalent changes made according to the claims of the present application are still within the scope covered by the present application.

Claims

1. A security incident tracing method, characterized in that: include: Obtaining warning data generated for attack behaviors; Determine an alarm type of the alarm data, obtain attack search data in the alarm data based on the alarm type, and search an event database for attack association information associated with the attack search data; A security event is generated based on the attack association information and the alarm data.

2. The method according to claim 1, characterized in that The determining the alarm type of the alarm data, acquiring the attack search field in the alarm data based on the alarm type, and searching the event database for attack association information associated with the attack search data, includes: Obtaining an identifier in the alarm data, identifying the identifier to determine an alarm type corresponding to the alarm data, the alarm type including a network alarm and a terminal alarm; Acquire an attack search field corresponding to the alarm type, and acquire attack search data corresponding to the attack search field in the alarm data; The event database is searched for attack-related information associated with the attack search data.

3. The method according to claim 2, characterized in that The step of searching the event database for attack-related information associated with the attack search data includes: If the alarm type of the alarm data is a network alarm, based on the search mode of the network alarm, obtaining first search data corresponding to the search mode in the attack search data, and obtaining attack association information associated with the first search data in the event database; If the alarm type of the alarm data is a terminal alarm, based on the abnormal type of the terminal alarm, second search data corresponding to the abnormal type is obtained in the attack search data, and attack association information associated with the second search data is obtained in the event database.

4. The method according to claim 3, characterized in that If the alarm type of the alarm data is a network alarm, based on the search mode of the network alarm, obtaining first search data corresponding to the search mode in a first search field, and obtaining attack association information associated with the first search data in an event database, including: If the alarm type of the alarm data is a network alarm, determining a search mode for the network alarm; If the search mode is a network alarm mode, obtaining a source address and a destination address in the first search data, and obtaining first attack association information associated with the source address and the destination address in an event database; If the search mode is a terminal alarm mode, acquiring second attack association information associated with the first search data in the event database based on the attack direction of the network alarm; If the search mode is a terminal log mode, obtaining the four-tuple data in the first search data, and obtaining the third attack association information associated with the four-tuple data in the event database; Attack-related information associated with the first search data is generated based on the first attack-related information, the second attack-related information, and the third attack-related information.

5. The method according to claim 4, characterized in that The acquiring, in the event database, second association information associated with the first search field, the attack direction based on the terminal alarm mode includes: If the attack direction is an intranet attacking an extranet, obtaining a source address in the first search data, obtaining first historical alarm data with a network identifier as the source address in the event database, and determining the first historical alarm data as second associated information associated with the first search field; If the attack direction is an intranet attacking an intranet, obtaining a source address and a destination address in the first search data, obtaining second historical alarm data with a network identifier as the source address or the destination address in the event database, and determining the second historical alarm data as second associated information associated with the first search field; If the attack direction is an external network attacking an internal network, obtain the destination address in the first search data, obtain the third historical alarm data with the network identifier as the destination address in the event database, and determine the third historical alarm data as the second association information associated with the first search field.

6. The method according to claim 3, characterized in that If the alarm type of the alarm data is a terminal alarm, based on the abnormal type of the terminal alarm, obtaining second attack search data corresponding to the abnormal type in a second attack search field, and obtaining attack association information associated with the second attack search data in an event database, including: If the alarm type of the alarm data is a terminal alarm, determining the abnormal type of the terminal alarm; If the anomaly type is a file anomaly, obtaining the behavior data and the file data in the second attack search data, and obtaining fourth attack association information associated with the behavior data and the file data in an event database; If the anomaly type is a network anomaly, obtaining the behavior data and the address data in the second attack search data, and obtaining fifth attack association information associated with the behavior data and the address data in an event database; If the anomaly type is not a file anomaly or a network anomaly, obtaining behavior data in the second attack search data, and obtaining sixth attack association information associated with the behavior data in an event database; Attack-related information associated with the second attack search data is generated based on the fourth attack-related information, the fifth attack-related information, and the sixth attack-related information.

7. The method according to claim 1, characterized in that After the security event is generated based on the attack association information and the alarm data, the method further includes: If a viewing instruction for the security event is received, the attack-related information is displayed.

8. A security event tracing device, characterized in that: The device comprises: An acquisition unit, used to acquire warning data generated for attack behaviors; A search unit, configured to determine an alarm type of the alarm data, obtain attack search data in the alarm data based on the alarm type, and search an event database for attack association information associated with the attack search data; A generating unit is used to generate a security event based on the attack association information and the alarm data.

9. A computer storage medium, characterized in that The computer storage medium stores a plurality of instructions, and the instructions are suitable for being loaded by a processor and executing the steps of the method according to any one of claims 1 to 7.

10. An electronic device, characterized in that: include: A processor and a memory; wherein the memory stores a computer program, and the computer program is suitable for being loaded by the processor and executing the steps of the method according to any one of claims 1 to 7.

Citation Information

Cited By

  • A method for detecting abnormalities in agricultural product quality traceability

    CN120410342B