Security policy adjustment method and device, equipment and storage medium
Patent Information
- Application Number
- CN202510138307.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-07
- Publication Date
- 2025-05-13
AI Technical Summary
The manually configured security policies in the prior art cannot adapt to the changing network environment, resulting in a decrease in the protection effect of the security protection system.
By obtaining security-related data of the current device, analyzing whether there is a security threat. If it exists, obtain historical security events, call pre-trained security policies to generate models to process data, generate target security policies, and adjust the security policies of the current device according to this policy.
This method can dynamically adjust security strategies according to the changing network environment and improve the protection effect of the security protection system.
Smart Images

Figure CN119995981A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to a security policy adjustment method, apparatus, device and storage medium. Background Art
[0002] As cyber attacks become more complex and diverse, the demand for cyber security from enterprises and individuals continues to rise. To prevent cyber attacks, security policies are usually configured in security protection systems. Security policies are composed of a set of rules, guidelines and measures to ensure the security of systems, networks and data. They cover access control, identity authentication, data encryption, vulnerability management, emergency response and other aspects, aiming to ensure that corporate and personal information assets are properly protected and resist various security threats.
[0003] In the prior art, technicians manually configure security policies in the security protection system based on their own experience.
[0004] However, with the development of technology, security threats and attack methods are evolving rapidly, and manually configured security policies cannot adapt to the changing network environment, which in turn leads to a decline in the protection effect of the security protection system. Summary of the invention
[0005] The present application provides a security policy adjustment method, apparatus, device and storage medium, which can adapt to a changing network environment and improve the protection effect of a security protection system.
[0006] In a first aspect, the present application provides a security policy adjustment method, the method comprising:
[0007] Get security-related data of the current device;
[0008] Analyzing the security-related data to detect whether there is a security threat in the current device;
[0009] In the case where there is a security threat to the current device, obtaining a pre-stored historical security event, calling a pre-trained security policy generation model, processing the historical security event and the security-related data, and obtaining a target security policy;
[0010] Based on the target security policy, the security policy of the current device is adjusted.
[0011] Optionally, when the security-related data includes network traffic data, analyzing the security-related data to detect whether there is a security threat includes:
[0012] Extracting network request features from the network traffic data;
[0013] Inputting the network request features into a clustering algorithm to obtain at least one set;
[0014] In the case that there is a set corresponding to the preset mode in the set, it is determined that there is a security threat in the current device.
[0015] Optionally, when the security-related data includes a user behavior log, analyzing the security-related data to detect whether there is a security threat in the current device includes:
[0016] Using a pre-trained behavior analysis model, analyzing the user behavior log, detecting whether there is abnormal behavior data in the user behavior log, and obtaining an analysis result;
[0017] When the analysis result is that abnormal behavior data exists in the user behavior log, it is determined that there is a security threat in the current device.
[0018] Optionally, when the security-related data includes an endpoint security log, analyzing the security-related data to detect whether there is a security threat in the current device includes:
[0019] Based on the endpoint security log, determine the process behavior characteristics of the process related to the endpoint security log;
[0020] The process behavior feature is input into a pre-trained process analysis model, so that the process analysis model detects whether there is an abnormal process through the process behavior feature, and obtains an analysis result;
[0021] When the identification result is that an abnormal process exists, it is determined that a security threat exists in the current device.
[0022] Optionally, when there is a security threat, the method further includes:
[0023] Obtain the correspondence between pre-created security threats and alarm levels;
[0024] Determining the alarm level of the current device according to the security threats existing in the current device and the corresponding relationship;
[0025] Execute corresponding operations according to the alarm level of the current device.
[0026] Optionally, in the event of a security threat, the method further includes:
[0027] Determining whether there is a target security threat of a corresponding reference security policy among the security threats;
[0028] When there is a target security threat corresponding to the reference security policy, obtaining the reference security policy corresponding to the target security threat and the corresponding target security policy;
[0029] When the reference security policy corresponding to the target security threat is the same as the corresponding target security policy, adjusting the security policy of the current device based on the target security policy;
[0030] In the case that the reference security policy corresponding to the target security threat is different from the corresponding target security policy, an optimization suggestion is generated according to the target security policy and the reference security policy, and the optimization suggestion is displayed.
[0031] Optionally, calling a pre-trained security policy generation model to process the historical security events and the security-related data to obtain a target security policy includes:
[0032] Preprocessing the historical security events and the security-related data to obtain preprocessed target data;
[0033] Extracting target features from the target data;
[0034] The target features are input into a pre-trained security policy generation model to obtain a target security policy.
[0035] In a second aspect, the present application provides a security policy adjustment device, the device comprising:
[0036] An acquisition unit, used to acquire security-related data of the current device;
[0037] A detection unit, configured to analyze the security-related data and detect whether there is a security threat in the current device;
[0038] A processing unit, configured to obtain, when there is a security threat to the current device, a pre-stored historical security event, call a pre-trained security policy generation model, process the historical security event and the security-related data, and obtain a target security policy;
[0039] An adjusting unit is used to adjust the security policy of the current device based on the target security policy.
[0040] Optionally, when the security-related data includes network traffic data, the detection unit is configured to:
[0041] Extracting network request features from the network traffic data;
[0042] Inputting the network request features into a clustering algorithm to obtain at least one set;
[0043] In the case that there is a set corresponding to the preset mode in the set, it is determined that there is a security threat in the current device.
[0044] Optionally, when the security-related data includes a user behavior log, the detection unit is configured to:
[0045] Using a pre-trained behavior analysis model, analyzing the user behavior log, detecting whether there is abnormal behavior data in the user behavior log, and obtaining an analysis result;
[0046] When the analysis result is that abnormal behavior data exists in the user behavior log, it is determined that there is a security threat in the current device.
[0047] Optionally, when the security-related data includes an endpoint security log, the detection unit is configured to:
[0048] Based on the endpoint security log, determine the process behavior characteristics of the process related to the endpoint security log;
[0049] The process behavior feature is input into a pre-trained process analysis model, so that the process analysis model detects whether there is an abnormal process through the process behavior feature, and obtains an analysis result;
[0050] When the identification result is that an abnormal process exists, it is determined that a security threat exists in the current device.
[0051] Optionally, when there is a security threat, the device further includes an alarm unit, wherein the alarm unit is used to:
[0052] Obtain the correspondence between pre-created security threats and alarm levels;
[0053] Determining the alarm level of the current device according to the security threats existing in the current device and the corresponding relationship;
[0054] Execute corresponding operations according to the alarm level of the current device.
[0055] Optionally, in the case of a security threat, the device further comprises an optimization unit, the optimization unit being configured to:
[0056] Determining whether there is a target security threat of a corresponding reference security policy among the security threats;
[0057] When there is a target security threat corresponding to the reference security policy, obtaining the reference security policy corresponding to the target security threat and the corresponding target security policy;
[0058] When the reference security policy corresponding to the target security threat is the same as the corresponding target security policy, adjusting the security policy of the current device based on the target security policy;
[0059] In the case that the reference security policy corresponding to the target security threat is different from the corresponding target security policy, an optimization suggestion is generated according to the target security policy and the reference security policy, and the optimization suggestion is displayed.
[0060] Optionally, the processing unit is used to:
[0061] Preprocessing the historical security events and the security-related data to obtain preprocessed target data;
[0062] Extracting target features from the target data;
[0063] The target features are input into a pre-trained security policy generation model to obtain a target security policy.
[0064] In a third aspect, the present application provides a security policy adjustment device, comprising: at least one communication interface; at least one bus connected to the at least one communication interface; at least one processor connected to the at least one bus; at least one memory connected to the at least one bus, wherein the processor is configured to:
[0065] Get security-related data of the current device;
[0066] Analyzing the security-related data to detect whether there is a security threat in the current device;
[0067] In the case where there is a security threat to the current device, obtaining a pre-stored historical security event, calling a pre-trained security policy generation model, processing the historical security event and the security-related data, and obtaining a target security policy;
[0068] Based on the target security policy, the security policy of the current device is adjusted.
[0069] In a fourth aspect, the present application provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program implements the above-mentioned security policy adjustment method when executed by a processor.
[0070] The above technical solution provided by the embodiment of the present application has the following advantages over the prior art: In the embodiment of the present application, by obtaining the security-related data of the current device and analyzing the security-related data, it is detected whether there is a security threat in the current device. In the case of a security threat to the current device, the pre-stored historical security events are obtained, the pre-trained security policy generation model is called, the historical security events and security-related data are processed, the target security policy is obtained, and then the security policy of the current device is adjusted based on the target security policy. Since the security-related data can reflect the various security issues and risk conditions existing in the network, that is, the security-related data reflects the network environment to a certain extent, therefore, the present application can regenerate the policy according to the changed network environment, and use the policy to adjust the existing security policy to adapt to the changing network environment, thereby improving the protection effect of the security protection system. BRIEF DESCRIPTION OF THE DRAWINGS
[0071] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the invention and, together with the description, serve to explain the principles of the invention.
[0072] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.
[0073] One or more embodiments are exemplarily described by pictures in the corresponding drawings, and these exemplified descriptions do not constitute limitations on the embodiments. Elements with the same reference numerals in the drawings represent similar elements, and unless otherwise stated, the figures in the drawings do not constitute proportional limitations.
[0074] Figure 1 A flowchart of a security policy adjustment method provided in an embodiment of the present application;
[0075] Figure 2 A flowchart of a network traffic data analysis method provided in an embodiment of the present application;
[0076] Figure 3 A flowchart of a user behavior log analysis method provided in an embodiment of the present application;
[0077] Figure 4 A flowchart of an endpoint security log analysis method provided in an embodiment of the present application;
[0078] Figure 5 A schematic diagram of a safety alarm method provided in an embodiment of the present application;
[0079] Figure 6 A schematic diagram of a process flow of a security policy optimization method provided in an embodiment of the present application;
[0080] Figure 7 A flowchart of another method for preprocessing data provided in an embodiment of the present application;
[0081] Figure 8 A schematic diagram of a process flow of a security policy adjustment device provided in an embodiment of the present application;
[0082] Fig. 9 A schematic diagram of a security policy adjustment device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0083] In order to make the purpose, technical solution and advantages of the embodiments of the present application clearer, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application.
[0084] The disclosure below provides many different embodiments or examples to implement different structures of the present invention. In order to simplify the disclosure of the present invention, the parts and settings of specific examples are described below. Of course, they are only examples, and the purpose is not to limit the present invention. In addition, the present invention can repeat reference numbers and / or letters in different examples. This repetition is for the purpose of simplification and clarity, and does not itself indicate the relationship between the various embodiments and / or settings discussed.
[0085] In related technologies, technicians manually configure security policies in security protection systems based on their own experience. However, with the development of science and technology, security threats and attack methods are evolving rapidly, and manually configured security policies cannot adapt to the changing network environment, which in turn leads to a decline in the protection effect of the security protection system.
[0086] In order to solve the above problems, the embodiments of the present application provide a security policy adjustment method, which can adapt to the changing network environment and improve the protection effect of the security protection system. Figure 1 As shown, the specific steps include:
[0087] Step 101, obtaining security-related data of the current device.
[0088] Among them, security-related data include network traffic data, user log data, endpoint security logs, external threat intelligence data, etc. Among them, network traffic data includes traffic logs from firewalls, routers, intrusion detection systems (IDS), and intrusion prevention systems (IPS). Endpoint security logs include host security logs, process data logs, application behavior logs, etc. User behavior logs include login, file access, API call and other behavior logs. External threat intelligence data includes known IP addresses, domain names, malware samples, etc.
[0089] In this step, the security protection system can periodically obtain security-related data of the current device.
[0090] Step 102: Analyze the security-related data to detect whether there is a security threat in the current device.
[0091] In this step, since the security protection system adopts different analysis strategies for different types of security-related data, the corresponding analysis strategy can be determined according to the type of security-related data, and then the security-related data is analyzed using the analysis strategy to obtain the analysis result. As long as there is an analysis result that there is a security threat, it is determined that there is a security threat in the current device. When all analysis results show that there is no security threat, it is determined that there is no security threat in the current device.
[0092] It should be noted that since the security protection system manages multiple devices, when there is no security threat in the current device, the next device is checked until a device with a security threat is detected or all devices are checked. When a device with a security threat is detected, the device is used as the current device to execute the following steps.
[0093] Step 103, when there is a security threat to the current device, obtain pre-stored historical security events, call the pre-trained security policy generation model, process the historical security events and security-related data, and obtain the target security policy.
[0094] In this step, historical security events are security events that occurred on the current device in the historical period. Since the current device has experienced a security event in the historical event period, the security event may occur repeatedly. Therefore, in order to make the generated target security policy more in line with the needs of the current device, the pre-trained security policy generation model can be used to process the historical security events. At the same time, in order to make the generated target security policy more comprehensive, it is also necessary to use the pre-trained security policy generation model to process security-related data.
[0095] In addition, when the security protection system manages multiple devices, these devices may experience the same security events. Therefore, this step can also set the historical security events as the security events that occurred in the historical period for all devices managed by the security protection system.
[0096] Furthermore, since the security policy generation model is a machine learning model, it is necessary to first obtain the sample set required for training the security policy generation model. The sample set includes multiple samples, each sample includes sample security-related data, sample security events and sample security policies, and then the security policy generation model is trained based on each sample in the sample set to obtain the trained security policy generation model.
[0097] It should be noted that by collecting security-related data of various devices under security threats, it is determined as sample security-related data. After the data is collected, it can also be cleaned, redundancy removed and other related operations to remove noise data in the data, thereby obtaining sample security-related data.
[0098] Step 104: Adjust the security policy of the current device based on the target security policy.
[0099] In this step, the security protection system may send the target security policy to the current device, so that the current device adjusts the security policy of the current device based on the received target security policy.
[0100] The security policies generated in step 103 mainly include preventive policies, responsive policies, and remedial policies, among which the preventive policies are to prevent the occurrence of security incidents, for example, restricting the access of specific IPs or users, increasing the authentication level, enabling endpoint protection and other related security policies to avoid the occurrence of corresponding security incidents. Responsive policies are corresponding measures taken in a timely manner when a security incident occurs to prevent the spread of security incidents in multiple devices. For example, related security policies such as automatically generating alarms, isolating infected devices, and starting traffic cleaning services. Remedial policies are remedial measures taken after a security incident occurs. For example, related policies such as automatically updating signature libraries, fixing vulnerabilities, and restoring systems.
[0101] In an embodiment of the present application, by obtaining security-related data of the current device and analyzing the security-related data, it is detected whether there is a security threat in the current device. In the case of a security threat to the current device, a pre-stored historical security event is obtained, a pre-trained security policy generation model is called, the historical security events and security-related data are processed, and a target security policy is obtained, and then the security policy of the current device is adjusted based on the target security policy. Since security-related data can reflect various security issues and risk conditions in the network, that is, security-related data reflects the network environment to a certain extent, the present application can regenerate a policy according to the changed network environment, and use the policy to adjust the existing security policy to adapt to the changing network environment, thereby improving the protection effect of the security protection system.
[0102] In the embodiment of the present application, since the typical characteristics of DDoS attacks are a surge in traffic and the number of requests far exceeds the normal user behavior pattern, and there are usually multiple network request patterns in the network traffic data of a device, it is necessary to detect whether there is a high-frequency, sudden network request pattern in the current device based on the network traffic data. When such a network request pattern exists, it is determined that there is a security threat in the current device. Therefore, the embodiment of the present application provides a network traffic data analysis method, which is a further limitation of step 102, such as Figure 2 As shown, the specific steps are:
[0103] Step 201: extract network request features from network traffic data.
[0104] Among them, network request characteristics are characteristics related to the network mode, such as request frequency, time distribution, proportion of request types, size of data volume, etc.
[0105] In this step, in order to more accurately identify the network request pattern, network request features can be extracted from the network traffic data, and then data identification is performed based on the network request features.
[0106] Step 202: Input the network request features into a clustering algorithm to obtain at least one set.
[0107] The clustering algorithm can mine the similarities hidden in the network request features and divide them into multiple sets, each set corresponding to a network request pattern. The clustering algorithm used can be the DBSCAN algorithm.
[0108] In this step, the network request features are input into a clustering algorithm to obtain a clustering result, which includes at least one set.
[0109] Step 203: If there is a set corresponding to the preset mode in the set, it is determined that there is a security threat.
[0110] Among them, the preset mode is an abnormal mode, which is generally a high-frequency, sudden network request mode.
[0111] In this step, the network request pattern corresponding to each set in the clustering result is first obtained, and then these network request patterns are detected to see if there are high-frequency and sudden situations. Once a set is found to have a network request pattern that meets the preset pattern, it can be determined that the current device has a security threat.
[0112] In the embodiment of the present application, when the security-related data includes a user behavior log, the user behavior log is analyzed to determine whether there is an abnormal event in the user behavior log to determine whether there is a security threat in the current device. Therefore, the embodiment of the present application provides a user behavior log analysis method, which is a further limitation of step 102, such as Figure 3 As shown, the specific steps are:
[0113] Step 301: Use a pre-trained behavior analysis model to analyze the user behavior log, detect whether there is abnormal behavior data in the user behavior log, and obtain an analysis result.
[0114] Among them, user behavior generally includes user login, operation, access, etc. User behavior log is a log that records user behavior. The behavior analysis model can be a K-means model or other machine learning models. The behavior analysis model can analyze normal behavior data and abnormal behavior data in the user behavior log. Abnormal behavior includes users accessing a large amount of sensitive data in a short period of time, frequently trying to log in to multiple system accounts, etc.
[0115] In this step, the security protection system can directly input the user behavior log into the pre-trained behavior analysis model to obtain the analysis result. The security protection system can also first extract the key behavior features in the user behavior log, input the key behavior features into the pre-trained behavior analysis model, and obtain the analysis result.
[0116] Among them, the key behavior characteristics are data on the characteristics of the reaction behavior, which may be relevant data such as the frequency, time, and type of the behavior.
[0117] Step 302: When the analysis result shows that there is abnormal behavior data in the user behavior log, it is determined that there is a security threat in the current device.
[0118] In this step, when the analysis result shows that there is abnormal behavior data in the user behavior log, the security protection system determines that there is a security threat in the current device.
[0119] It should be noted that this step can also use data statistical analysis methods to determine whether there is abnormal behavior data in the user behavior log, for example, determine the frequency of occurrence of various user behaviors in the user behavior log, and determine the normal frequency range corresponding to each behavior based on each user behavior. When the frequency of a certain behavior is not within the corresponding normal frequency range, it means that the frequency of the behavior is abnormal, that is, there is abnormal behavior data in the user behavior log. For example, there are two behaviors in the user behavior log: accessing sensitive data and attempting to log in to a system account. If the frequency of accessing sensitive data is not within the normal range, the behavior is abnormal behavior, and the corresponding data is abnormal behavior data; similarly, if the frequency of attempting to log in to a system account is abnormal, it can also be determined as abnormal behavior and abnormal behavior data.
[0120] In an embodiment of the present application, when the security-related data includes an endpoint security log of the current device, the endpoint security log is analyzed to detect whether there is a security threat in the current device. Therefore, an embodiment of the present application provides an endpoint security log analysis method, which is a further limitation of step 102, such as Figure 4 As shown, the specific steps are:
[0121] Step 401: Determine process behavior characteristics of processes related to the endpoint security log according to the endpoint security log.
[0122] The endpoint security log is a record file that contains detailed information about security-related events on the endpoint device.
[0123] In this step, the security protection system first pre-processes the endpoint security log to remove noise data and invalid information in the endpoint security log. Since the endpoint security log may include multiple events, each event has different characteristics. Therefore, before extracting features from the endpoint security log, all events in the endpoint security log can be obtained first, and these events are classified according to the type of each event to obtain multiple event sets. Afterwards, for each event set, according to the feature extraction method corresponding to the event set, feature extraction is performed on each event in the event set to obtain the behavior features corresponding to each event. Since different processes will generate corresponding events, according to the process to which each event belongs and the behavior features corresponding to each event, the process behavior features of the process to which each event belongs are obtained, and then the process behavior features of the process related to the endpoint security log are obtained.
[0124] For example, network connection events focus more on data such as source address, destination address, protocol, etc. Therefore, for network connection events, it is necessary to extract features such as source address, destination address, protocol, etc. File operation events focus more on data such as file name and operation type, so for file operation events, it is necessary to extract features such as file name and operation type.
[0125] Step 402: input the process behavior feature into a pre-trained process analysis model, so that the process analysis model detects whether there is an abnormal process through the process behavior feature, and obtains an analysis result.
[0126] The analysis result is whether there is an abnormal process. An abnormal process is a process with abnormal events.
[0127] In this step, the behavior characteristics are input into a pre-trained process analysis model, which analyzes the process behavior characteristics to determine whether there are abnormal processes and outputs the analysis results.
[0128] Step 403: When the identification result shows that an abnormal process exists, it is determined that a security threat exists in the current device.
[0129] In this step, when the identification result is that an abnormal process exists, it is determined that a security threat exists in the current device.
[0130] It should be noted that when the identification result is that there is no abnormal process, it only means that there is no security threat in the security endpoint data, and it does not mean that there is no security threat on the current device. Only when there is no security threat in the security-related data can it be said that there is no security threat on the current device.
[0131] In the embodiment of the present application, when a security threat is detected, an alarm can also be issued to the user to remind relevant personnel to deal with the security threat. Therefore, the embodiment of the present application provides a security alarm method, such as Figure 5 As shown, the specific steps are:
[0132] Step 501: Acquire a pre-created correspondence between security threats and alarm levels.
[0133] In this step, for some security threats that are easy to handle and have relatively small impacts, the security protection system can process the security threats according to a preset processing method, for example, using a security policy generation model to process security-related data and obtain a target security policy to be used, so that the security protection system can process the existing security threats based on the target security policy. For some security threats that have a relatively large impact and are difficult to handle, in order to avoid economic losses caused by improper machine handling, technical personnel can be notified to intervene. In order to achieve the above, the technician can set the alarm level corresponding to each security threat according to the impact of each security threat, and then obtain the corresponding relationship between the security threat and the alarm level, and store the corresponding relationship in the security protection system. When the security protection system needs to execute step 501, the corresponding relationship is obtained in the storage space.
[0134] Step 502: Determine the alarm level of the current device according to the security threats existing in the current device and the corresponding relationship.
[0135] In this step, when there is only one security threat in the current device, the alarm level corresponding to the security threat is determined according to the security threat and the corresponding relationship, and the alarm level is determined as the alarm level of the current device. When there are multiple security threats in the current device, the alarm level corresponding to each security threat is determined according to each security threat and the corresponding relationship, and among these alarm levels, the highest alarm level is determined as the alarm level of the current device.
[0136] Step 503: Execute corresponding operations according to the alarm level of the current device.
[0137] In this step, when the alarm level of the current device is relatively high, the relevant technical personnel can be notified to handle the security threat existing in the current device. When the alarm level of the current device is relatively low, the security policy generation model can be used to handle the security threat.
[0138] In addition, when there are multiple security threats in the current device, in order to reduce the workload of technicians, corresponding operations can also be performed based on the alarm level of each security threat. For example, for security threats with relatively low alarm levels, the security threats are processed based on the security policy generation model. For security threats with relatively high alarm levels, the security threats are notified to relevant technicians so that the relevant technicians can process the security threats.
[0139] Furthermore, when there are multiple security threats with relatively low alarm levels, the security policy generation model needs to be used multiple times based on the above method to process security-related data, and each use will increase the processing burden of the security protection system. Therefore, in order to reduce the processing burden of the security protection system, as long as there is a relatively low alarm level, the security policy generation model is used for processing.
[0140] In the embodiment of the present application, since the target security policy is machine-generated, the target security policy may not completely resolve the security threats in the current device. Therefore, the target security policy can also be optimized. Therefore, the embodiment of the present application provides a security policy optimization method. Figure 6 As shown, the specific steps include:
[0141] Step 601: Determine whether there is a target security threat corresponding to a reference security policy among security threats.
[0142] In this step, relevant personnel will pre-set some security policies in the security protection system according to some security threats. When these security threats occur, these security policies need to be used first. Therefore, the security protection system can determine whether there is a target security threat corresponding to the reference security policy in the security threat.
[0143] Step 602: When there is a target security threat corresponding to the reference security policy, obtain the reference security policy and the corresponding target security policy corresponding to the target security threat.
[0144] In this step, when there is a target security threat corresponding to a reference security policy, the target security threat is analyzed, and in the target security policy, the target policy corresponding to the target security threat is determined, and the reference security policy corresponding to the target security threat is obtained.
[0145] Step 603: When the reference security policy corresponding to the target security threat is the same as the corresponding target security policy, the security policy of the current device is adjusted based on the target security policy.
[0146] In this step, if the reference security policy corresponding to the target security threat is the same as the corresponding target security policy, it means that the target security policy corresponding to the target security threat is correct, and the security policy of the current device can be adjusted based on the target security policy.
[0147] Step 604: When the reference security policy corresponding to the target security threat is different from the corresponding target security policy, an optimization suggestion is generated according to the target security policy and the reference security policy, and the optimization suggestion is displayed.
[0148] In this step, when the reference security policy corresponding to the target security threat is different from the corresponding target security policy, an optimization suggestion is generated based on the target security policy and the reference security policy, and the optimization suggestion is displayed so that the user can select the security policy to be used.
[0149] In addition, since the reference security policy corresponding to the target security threat is manually set, it has higher reliability. Therefore, this step can also update the target security policy based on the reference security policy corresponding to the target security threat to obtain an updated target security policy, so as to set the current device based on the updated target security policy.
[0150] It should be noted that the embodiment of the present application can also generate optimization suggestions based only on the target security policy, specifically, generate an optimization policy based on the target security policy, send the optimization message to the current device, and the current device obtains the target security policy in the optimization message. Afterwards, the current device generates an optimization suggestion page based on the target security policy, and the optimization suggestion page displays relevant information of the target security policy, a security policy adjustment entry, and an OK button. The user can adjust the security policy adjustment entry according to the relevant information of the target security policy to set the security policy required by the user, for example, set the target security policy to the security policy of the current device, or fine-tune the target security policy according to the security policy adjustment entry to obtain the security policy of the current device. When the user clicks the OK button, the current device is set based on the security policy on the optimization page.
[0151] In this step, before the data is input into the pre-trained security policy generation model, the data needs to be pre-processed and feature extracted, and then the processed data can be input into the pre-trained security policy generation model. Therefore, the embodiment of the present application provides a method for pre-processing data, such as Figure 7 As shown, the specific steps include:
[0152] Step 701, pre-processing historical security events and security-related data to obtain pre-processed target data.
[0153] In this step, the security protection system preprocesses historical security events and security-related data, such as data standardization, removal of redundant data, outlier processing, data format conversion, filling in missing values, and other related preprocessing, and then obtains the preprocessed target data.
[0154] Step 702: extract target features from the target data.
[0155] Among them, target features are data used to represent the characteristics or attributes of target data. For example, traffic features include traffic size, protocol type, source IP and destination IP, port number, etc., behavior features include login time, frequent access patterns, abnormal operation behaviors, etc., and time features include whether the behavior occurs in an abnormal time period (late at night, a large number of failed login attempts, etc.).
[0156] In this step, target features corresponding to various security-related data are extracted from the target data.
[0157] Step 703: Input the target features into a pre-trained security policy generation model to obtain a target security policy.
[0158] In this step, the target features are input into a pre-trained security policy generation model, so that the security policy generation model analyzes the target features and outputs target security policy data.
[0159] like Figure 8 As shown, an embodiment of the present application provides a security policy adjustment device, which corresponds to the method embodiment and specifically includes:
[0160] An acquisition unit 801 is used to acquire security-related data of the current device;
[0161] A detection unit 802 is used to analyze the security-related data to detect whether there is a security threat in the current device;
[0162] A processing unit 803 is used to obtain a pre-stored historical security event when there is a security threat to the current device, call a pre-trained security policy generation model, process the historical security event and the security-related data, and obtain a target security policy;
[0163] The adjusting unit 804 is configured to adjust the security policy of the current device based on the target security policy.
[0164] Optionally, when the security-related data includes network traffic data, the detecting unit 802 is configured to:
[0165] Extracting network request features from the network traffic data;
[0166] Inputting the network request features into a clustering algorithm to obtain at least one set;
[0167] In the case that there is a set corresponding to the preset mode in the set, it is determined that there is a security threat in the current device.
[0168] Optionally, when the security-related data includes a user behavior log, the detection unit 802 is configured to:
[0169] Using a pre-trained behavior analysis model, analyzing the user behavior log, detecting whether there is abnormal behavior data in the user behavior log, and obtaining an analysis result;
[0170] When the analysis result is that abnormal behavior data exists in the user behavior log, it is determined that there is a security threat in the current device.
[0171] Optionally, when the security-related data includes an endpoint security log, the detecting unit 802 is configured to:
[0172] Based on the endpoint security log, determine the process behavior characteristics of the process related to the endpoint security log;
[0173] The process behavior feature is input into a pre-trained process analysis model, so that the process analysis model detects whether there is an abnormal process through the process behavior feature, and obtains an analysis result;
[0174] When the identification result is that an abnormal process exists, it is determined that a security threat exists in the current device.
[0175] Optionally, when there is a security threat, the device further includes an alarm unit 805, and the alarm unit 805 is used to:
[0176] Obtain the correspondence between pre-created security threats and alarm levels;
[0177] Determining the alarm level of the current device according to the security threats existing in the current device and the corresponding relationship;
[0178] Execute corresponding operations according to the alarm level of the current device.
[0179] Optionally, in the case of a security threat, the device further includes 806, where the optimization unit 806 is configured to:
[0180] Determining whether there is a target security threat of a corresponding reference security policy among the security threats;
[0181] When there is a target security threat corresponding to the reference security policy, obtaining the reference security policy corresponding to the target security threat and the corresponding target security policy;
[0182] When the reference security policy corresponding to the target security threat is the same as the corresponding target security policy, adjusting the security policy of the current device based on the target security policy;
[0183] In the case that the reference security policy corresponding to the target security threat is different from the corresponding target security policy, an optimization suggestion is generated according to the target security policy and the reference security policy, and the optimization suggestion is displayed.
[0184] Optionally, the processing unit 804 is configured to:
[0185] Preprocessing the historical security events and the security-related data to obtain preprocessed target data;
[0186] Extracting target features from the target data;
[0187] The target features are input into a pre-trained security policy generation model to obtain a target security policy.
[0188] like Fig. 9As shown, the embodiment of the present application provides a security policy adjustment device, including a processor 901, a communication interface 902, a memory 903 and a communication bus 904, wherein the processor 901, the communication interface 902, and the memory 903 communicate with each other through the communication bus 904.
[0189] Memory 903, used for storing computer programs;
[0190] In one embodiment of the present application, the processor 901 is used to implement the security policy adjustment method provided by any one of the aforementioned method embodiments when executing the program stored in the memory 903, including:
[0191] Get security-related data of the current device;
[0192] Analyzing the security-related data to detect whether there is a security threat in the current device;
[0193] In the case where there is a security threat to the current device, obtaining a pre-stored historical security event, calling a pre-trained security policy generation model, processing the historical security event and the security-related data, and obtaining a target security policy;
[0194] Based on the target security policy, the security policy of the current device is adjusted.
[0195] An embodiment of the present application further provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the steps performed by the security policy adjustment method provided in any of the aforementioned method embodiments are implemented.
[0196] The device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0197] Through the description of the above implementation methods, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a general hardware platform, and of course, by hardware. Based on this understanding, the above technical solution is essentially or the part that contributes to the relevant technology can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0198] It should be understood that the terms used herein are only for the purpose of describing specific example embodiments and are not intended to be limiting. Unless the context clearly indicates otherwise, the singular forms "one", "an" and "said" as used herein may also be meant to include plural forms. The terms "include", "comprise", "contain", and "have" are inclusive, and therefore specify the existence of stated features, steps, operations, elements and / or parts, but do not exclude the existence or addition of one or more other features, steps, operations, elements, parts, and / or combinations thereof. The method steps, processes, and operations described herein are not interpreted as necessarily requiring them to be performed in the specific order described or illustrated, unless the execution order is clearly indicated. It should also be understood that additional or alternative steps may be used.
[0199] The foregoing is merely a specific embodiment of the present invention, which enables those skilled in the art to understand or implement the present invention. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but rather to the widest scope consistent with the principles and novel features claimed herein.
Claims
1. A security policy adjustment method, characterized in that: The method comprises: Obtain security-related data of the current device; Analyzing the security-related data to detect whether there is a security threat in the current device; In the case where there is a security threat to the current device, obtaining a pre-stored historical security event, calling a pre-trained security policy generation model, processing the historical security event and the security-related data, and obtaining a target security policy; Based on the target security policy, the security policy of the current device is adjusted.
2. The method according to claim 1, characterized in that: In the case where the security-related data includes network traffic data, analyzing the security-related data to detect whether there is a security threat includes: Extracting network request features from the network traffic data; Inputting the network request features into a clustering algorithm to obtain at least one set; In the case that there is a set corresponding to the preset mode in the set, it is determined that there is a security threat in the current device.
3. The method according to claim 1, characterized in that: In the case where the security-related data includes a user behavior log, analyzing the security-related data to detect whether there is a security threat in the current device includes: Using a pre-trained behavior analysis model, analyzing the user behavior log, detecting whether there is abnormal behavior data in the user behavior log, and obtaining an analysis result; When the analysis result is that abnormal behavior data exists in the user behavior log, it is determined that there is a security threat in the current device.
4. The method according to claim 1, characterized in that: In a case where the security-related data includes an endpoint security log, analyzing the security-related data to detect whether there is a security threat in the current device includes: Based on the endpoint security log, determine the process behavior characteristics of the process related to the endpoint security log; The process behavior feature is input into a pre-trained process analysis model, so that the process analysis model detects whether there is an abnormal process through the process behavior feature, and obtains an analysis result; When the identification result is that an abnormal process exists, it is determined that a security threat exists in the current device.
5. The method according to claim 1, characterized in that: When there is a security threat, the method further includes: Obtain the correspondence between pre-created security threats and alarm levels; Determine the alarm level of the current device according to the security threat existing in the current device and the corresponding relationship; Execute corresponding operations according to the alarm level of the current device.
6. The method according to claim 1, characterized in that: In the event of a security threat, the method further comprises: Determining whether there is a target security threat of a corresponding reference security policy among the security threats; When there is a target security threat corresponding to the reference security policy, obtaining the reference security policy and the corresponding target security policy corresponding to the target security threat; When the reference security policy corresponding to the target security threat is the same as the corresponding target security policy, adjusting the security policy of the current device based on the target security policy; In the case that the reference security policy corresponding to the target security threat is different from the corresponding target security policy, an optimization suggestion is generated according to the target security policy and the reference security policy, and the optimization suggestion is displayed.
7. The method according to claim 1, characterized in that The calling of the pre-trained security policy generation model to process the historical security events and the security-related data to obtain a target security policy includes: Preprocessing the historical security events and the security-related data to obtain preprocessed target data; Extracting target features from the target data; The target features are input into a pre-trained security policy generation model to obtain a target security policy.
8. A security policy adjustment device, characterized in that: The device comprises: An acquisition unit, used to acquire security-related data of the current device; A detection unit, configured to analyze the security-related data and detect whether there is a security threat in the current device; A processing unit, configured to obtain, when there is a security threat to the current device, a pre-stored historical security event, call a pre-trained security policy generation model, process the historical security event and the security-related data, and obtain a target security policy; An adjusting unit is used to adjust the security policy of the current device based on the target security policy.
9. A security policy adjustment device, characterized in that: include: at least one communication interface; at least one bus connected to the at least one communication interface; at least one processor connected to the at least one bus; at least one memory connected to the at least one bus, wherein the processor is configured to: Obtain security-related data of the current device; Analyzing the security-related data to detect whether there is a security threat in the current device; In the case where there is a security threat to the current device, obtaining a pre-stored historical security event, calling a pre-trained security policy generation model, processing the historical security event and the security-related data, and obtaining a target security policy; Based on the target security policy, the security policy of the current device is adjusted.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the security policy adjustment method according to any one of claims 1 to 7 is implemented.