Method and system for eliminating security alarm influence caused by simulated attack

By establishing a linkage mechanism between the security effectiveness verification platform and the situation awareness platform, using the time sliding window for log correlation analysis, eliminating the impact of security alarms caused by simulated attacks, solving the problems of misjudgment and unnecessary emergency response caused by simulated attacks in the existing technology, and improving the efficiency of network security management operations.

CN119996038APending Publication Date: 2025-05-13THREE GORGES JINSHAJIANG CHUANYUN HYDROPOWER DEV CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510267417.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-07
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

When the existing network security management platform simulates attacks, the security alarm impact caused by the existing network security management platform is difficult to eliminate, resulting in misjudgment and unnecessary emergency response, and affecting the promotion and application of the security effectiveness verification platform in large network subsidiaries and branches.

Method used

By establishing a linkage mechanism between the security effectiveness verification platform and the situation awareness platform, the security effectiveness verification platform sends simulated attack logs to the situation awareness platform when launching a simulated attack. The situation awareness platform establishes a time sliding window, correlates the simulated attack log and the security protection device response log, and marks the security alarms caused by the simulated attack, thereby eliminating the impact of security alarms.

Benefits of technology

It realizes automatic identification of security simulation attack behavior, avoids unnecessary security response, and improves the efficiency of overall network security management operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996038A_ABST
    Figure CN119996038A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, and discloses a method and a system for eliminating security alarm influence caused by simulated attacks, and the method comprises the following steps: when a security validity verification platform initiates simulated attacks, a simulated attack log is sent to a situation awareness platform, and the simulated attack log comprises feature information of the simulated attacks; and the situation awareness platform identifies a simulation attack log sent by the security validity verification platform, establishes a time sliding window, performs association analysis on the simulation attack log and a security protection equipment response log in the corresponding time sliding window, and marks a security alarm caused by a simulation attack, so that the influence of the security alarm is eliminated. Therefore, when the security effectiveness verification platform evaluates the network security protection capability through the automatic simulation attack, the simulation attack behavior can be automatically identified on the situation awareness platform, the attack misjudgment and unnecessary emergency response caused by the security alarm are avoided, and the efficiency of the overall network security management operation is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a method and system for eliminating the impact of security alarms caused by simulated attacks. Background Art

[0002] In network security operations, simulated attacks on target networks can be conducted through network security automated verification tools to verify the protective effects of security protection devices in the network. The attack may trigger security alarms from network security protection devices, which will be collected and aggregated to the network-wide situation awareness platform. Since the situation awareness platform may be managed by different network security management levels or different teams, simulated attacks on some subnets may cause security emergencies for the security management and operation team. Therefore, it is necessary to establish task linkage between the situation awareness system and the automated security verification system to automatically identify the team's own simulated attack behaviors and reduce misjudgments in security operations.

[0003] The security effectiveness verification platform is a commonly used tool to verify network security protection capabilities based on automated attack simulation technology. The platform can verify the protection capabilities of security products such as firewalls, network gates, intrusion detection, EDR, AV, etc. in actual working environments. The security effectiveness verification platform verifies whether security products have completed threat interception by launching simulated attacks and monitoring security protection device logs.

[0004] like Figure 1 As shown in the figure, in the existing security management platform, the security alarms of the entire network are centrally sent to the situation awareness platform of the headquarters, and the security management and operation personnel of the headquarters conduct the monitoring of the entire network and emergency response. When the security effectiveness verification platform performs penetration testing and simulates attacks, the alarm logs of the security protection equipment triggered will also be sent to the situation awareness platform of the headquarters, causing the headquarters to initiate an emergency response to security threats. The existence of this problem has affected the promotion and application of the security effectiveness verification platform in large network subsidiaries and branches. Summary of the invention

[0005] In order to solve the above problems, the present invention proposes a method and system for eliminating the impact of security alarms caused by simulated attacks, and solves the above problems by establishing a linkage mechanism between a security effectiveness verification platform and a situation awareness platform.

[0006] The technical solution adopted by the present invention is as follows:

[0007] A method for eliminating the impact of a security alarm caused by a simulated attack, comprising:

[0008] When the security effectiveness verification platform initiates a simulated attack, it sends a simulated attack log to the situation awareness platform, wherein the simulated attack log includes characteristic information of the simulated attack;

[0009] The situation awareness platform identifies the simulated attack logs sent by the security effectiveness verification platform, establishes a time sliding window, correlates and analyzes the simulated attack logs with the security protection equipment response logs within the corresponding time sliding window, and marks the security alarms caused by the simulated attacks, thereby eliminating the impact of security alarms.

[0010] Furthermore, the establishment of a time sliding window, correlation analysis of the simulated attack log and the security protection device response log within the corresponding time sliding window, and marking of the security alarm caused by the simulated attack include:

[0011] The situation awareness platform establishes a time sliding window to cache the simulated attack logs sent by the security effectiveness verification platform, and extracts key information from the security protection device response logs in the time sliding window;

[0012] When the key information of the simulated attack log matches the response log of the security protection device, it is determined that the attack alarm sent by the security protection device is caused by the simulated attack sent by the security effectiveness verification platform, and the security threat of the attack alarm is eliminated.

[0013] Furthermore, the situation awareness platform caches the simulated attack logs sent by the security effectiveness verification platform by establishing a time sliding window, including: establishing a cache queue with time attributes based on a log matching method based on a time sliding window; marking the reception time of each simulated attack log sent by the security effectiveness verification platform when receiving the log; and performing loss processing on the simulated attack log when the difference between the current time and the reception time of the simulated attack log exceeds a threshold.

[0014] Furthermore, the simulated attack log sent by the security effectiveness verification platform includes attack feature data and attack traffic features. The attack feature data includes the source IP address, source port, destination IP address, destination port and traffic protocol of the attack. The attack traffic features include the requested URL address, file name and load keywords.

[0015] Furthermore, when the security protection device detects attack traffic, it triggers an alarm log, that is, a security protection device response log; the security protection device response log includes the source IP address, source port, destination IP address, destination port and traffic protocol of the attack, and the attack traffic characteristics include the requested URL address, file name and load keywords.

[0016] A system for eliminating the impact of security alarms caused by simulated attacks, comprising:

[0017] The security effectiveness verification platform is configured to send a simulated attack log to the situation awareness platform when launching a simulated attack, wherein the simulated attack log includes characteristic information of the simulated attack;

[0018] The situation awareness platform is configured to identify the simulated attack logs sent by the security effectiveness verification platform, establish a time sliding window, correlate and analyze the simulated attack logs with the security protection device response logs within the corresponding time sliding window, and mark the security alarms caused by the simulated attacks, thereby eliminating the impact of the security alarms.

[0019] Furthermore, the situational awareness platform establishes a time sliding window, caches the simulated attack logs sent by the security effectiveness verification platform, and extracts key information from the security protection device response logs in the time sliding window; when the key information of the simulated attack log matches the security protection device response log, it is determined that the attack alarm sent by the security protection device is caused by the simulated attack sent by the security effectiveness verification platform, and the security threat of the attack alarm is eliminated.

[0020] Furthermore, the situation awareness platform caches the simulated attack logs sent by the security effectiveness verification platform by establishing a time sliding window, including: establishing a cache queue with time attributes based on a log matching method based on a time sliding window; marking the reception time of each simulated attack log sent by the security effectiveness verification platform when receiving the log; and performing loss processing on the simulated attack log when the difference between the current time and the reception time of the simulated attack log exceeds a threshold.

[0021] Furthermore, the simulated attack log sent by the security effectiveness verification platform includes attack feature data and attack traffic features. The attack feature data includes the source IP address, source port, destination IP address, destination port and traffic protocol of the attack. The attack traffic features include the requested URL address, file name and load keywords.

[0022] Furthermore, when the security protection device detects attack traffic, it triggers an alarm log, that is, a security protection device response log; the security protection device response log includes the source IP address, source port, destination IP address, destination port and traffic protocol of the attack, and the attack traffic characteristics include the requested URL address, file name and load keywords.

[0023] The beneficial effects of the present invention are:

[0024] In the present invention, when the security effectiveness verification platform launches a simulated attack, it extracts the simulated attack features to form a simulated attack log, which is actively sent to the situation awareness platform; the situation awareness platform performs correlation analysis on the simulated attack log and the response log of the security protection device, automatically identifies the simulated attack behavior and the response log, and performs log marking and eliminates the security threat record, thereby realizing the identification of the security simulated attack behavior and avoiding unnecessary security response. Therefore, when the security effectiveness verification platform evaluates the network security protection capability through automated simulated attacks, it can automatically identify the simulated attack behavior on the situation awareness platform, avoid attack misjudgment and unnecessary emergency response caused by security alarms, and improve the efficiency of the overall network security management and operation. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] Figure 1 This is a schematic diagram of existing security alarms caused by simulated attacks.

[0026] Figure 2 It is a schematic diagram of a method for eliminating the impact of security alarms caused by simulated attacks according to Example 1 of the present invention.

[0027] Figure 3 This is a situation awareness platform processing flow chart of Example 1 of the present invention.

[0028] Figure 4 This is a flow chart of a log matching method based on a time sliding window in Example 1 of the present invention. DETAILED DESCRIPTION

[0029] In order to have a clearer understanding of the technical features, purposes and effects of the present invention, the specific implementation methods of the present invention are now described. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention, that is, the embodiments described are only part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without making creative work are within the scope of protection of the present invention.

[0030] Example 1

[0031] In the existing security management platform, the security alarms of the entire network are centrally sent to the situational awareness platform of the headquarters, and the security management and operation personnel of the headquarters conduct the monitoring of the entire network and emergency response. When the security effectiveness verification platform conducts penetration testing and simulates attacks, the alarm logs of the security protection equipment triggered will also be sent to the situational awareness platform of the headquarters, causing the headquarters to initiate an emergency response to security threats. The existence of this problem has affected the promotion and application of the security effectiveness verification platform in large network subsidiaries and branches.

[0032] Based on this, this embodiment provides a method for eliminating the impact of security alarms caused by simulated attacks, such as Figure 2 As shown, including:

[0033] When the security effectiveness verification platform initiates a simulated attack, it sends a simulated attack log to the situation awareness platform. The simulated attack log includes characteristic information of the simulated attack.

[0034] The situation awareness platform identifies the simulated attack logs sent by the security effectiveness verification platform, establishes a time sliding window, correlates and analyzes the simulated attack logs with the security protection equipment response logs within the corresponding time sliding window, and marks the security alarms caused by the simulated attacks, thereby eliminating the impact of security alarms.

[0035] In this embodiment, the security effectiveness verification platform extracts the characteristic information of each simulated attack when it is launched, forms a simulated attack log, and sends the simulated attack log to the situation awareness platform. Specifically, the characteristic word defining the simulated attack in the simulated attack log may be Breach_and_Attack_Simulation, indicating that the log is a simulated attack log.

[0036] Preferably, the simulated attack log sent by the security effectiveness verification platform includes attack feature data and attack traffic features. The attack feature data includes the attack source IP address, source port, destination IP address, destination port and traffic protocol. The attack traffic features include the requested URL address, file name and load keywords. For example:

[0037] "Flag":"Breach_and_Attack_Simulation","device":"qdbas","level":30,"id":"152518901","type":"InfoLog","time":1578909976995,"source":{"ip":"192.168.10.230","port":14893},"destination":{"ip":"192.168.10.231","port":80},"count":83,"protocol":"HTTP","securityid":"9","attackid":"1004","subject":"HTTP_ICQ_web server accesses arbitrary files","url":"= / .html / ............* / config.sys;"}

[0038] It should be noted that when the security protection device detects attack traffic, an alarm log is triggered, that is, the security protection device response log. Depending on the type of device, manufacturer, and attack type, the security protection device response log will be different, but basically it will contain key information of the attack, such as source IP address, source port, destination IP address, destination port, traffic protocol, and attack traffic characteristics such as requested URL address, file name, and load keyword information. Taking the above simulated attack as an example, the log example triggered by the security protection device is as follows:

[0039] "dt":"VENUS_IDS_0700R0400B20190109101512","level":30,"id":"152518901","type":"AlertLog","time":15789099769 95,"source":{"ip":"192.168.10.230","port":14893,"mac":"02-90-27-a1-97-03"},"destination":{"ip":"192.168.10 .231","port":80,"mac":"00-30-48-21-ad-d6"},"count":83,"protocol":"HTTP","securityid":"9","attackid":"1004","subject":"HTTP_ICQ_web server accesses arbitrary files","message":"nic=1;Host name=;URL length=31;URL name= / .html / ............* / config.sys;"}

[0040] Preferably, a time sliding window is established, the simulated attack log is correlated with the security protection device response log within the corresponding time sliding window, and the security alarm caused by the simulated attack is marked, such as Figure 3 As shown, including:

[0041] The situation awareness platform establishes a time sliding window to cache the simulated attack logs sent by the security effectiveness verification platform, and extracts key information from the security protection device response logs in the time sliding window;

[0042] When the key information of the simulated attack log matches the response log of the security protection device, it is determined that the attack alarm sent by the security protection device is caused by the simulated attack sent by the security effectiveness verification platform, and the security threat of the attack alarm is eliminated.

[0043] Preferably, the situation awareness platform caches the simulated attack logs sent by the security effectiveness verification platform by establishing a time sliding window, such as Figure 4 As shown, it includes: a log matching method based on a time sliding window to establish a cache queue with time attributes; for each simulated attack log sent by a security effectiveness verification platform, the receiving time of the simulated attack log is marked when it is received; when the difference between the current time and the receiving time of the simulated attack log exceeds a threshold, the simulated attack log is lost.

[0044] To sum up, when the security effectiveness verification platform of this embodiment initiates a simulated attack, it extracts the simulated attack features to form a simulated attack log, and actively sends it to the situation awareness platform; the situation awareness platform performs correlation analysis on the simulated attack log and the security protection equipment response log, automatically identifies the simulated attack behavior and response log, and marks the log and eliminates the security threat record, thereby realizing the identification of security simulated attack behavior and avoiding unnecessary security response.

[0045] Example 2

[0046] This embodiment provides a system for eliminating the impact of security alarms caused by simulated attacks, including:

[0047] The security effectiveness verification platform is configured to send a simulated attack log to the situation awareness platform when launching a simulated attack, wherein the simulated attack log includes characteristic information of the simulated attack;

[0048] The situation awareness platform is configured to identify the simulated attack logs sent by the security effectiveness verification platform, establish a time sliding window, correlate and analyze the simulated attack logs with the security protection device response logs within the corresponding time sliding window, and mark the security alarms caused by the simulated attacks, thereby eliminating the impact of the security alarms.

[0049] Preferably, the situation awareness platform establishes a time sliding window, caches the simulated attack logs sent by the security effectiveness verification platform, and extracts key information from the security protection device response logs in the time sliding window; when the key information of the simulated attack log matches the security protection device response log, it is determined that the attack alarm sent by the security protection device is caused by the simulated attack sent by the security effectiveness verification platform, and the security threat of the attack alarm is eliminated.

[0050] Preferably, the situation awareness platform caches the simulated attack logs sent by the security effectiveness verification platform by establishing a time sliding window, including: establishing a cache queue with time attributes based on a log matching method based on a time sliding window; marking the reception time of each simulated attack log sent by the security effectiveness verification platform when receiving the log; when the difference between the current time and the reception time of the simulated attack log exceeds a threshold, the simulated attack log is processed as lost.

[0051] Preferably, the simulated attack log sent by the security effectiveness verification platform includes attack feature data and attack traffic features. The attack feature data includes the source IP address, source port, destination IP address, destination port and traffic protocol of the attack. The attack traffic features include the requested URL address, file name and load keywords.

[0052] Preferably, when the security protection device detects attack traffic, an alarm log is triggered, i.e., a security protection device response log; the security protection device response log includes the source IP address, source port, destination IP address, destination port and traffic protocol of the attack, and the attack traffic characteristics include the requested URL address, file name and load keywords.

[0053] To sum up, when the security effectiveness verification platform of this embodiment evaluates network security protection capabilities through automated simulated attacks, it can automatically identify simulated attack behaviors on the situational awareness platform, avoid misjudgments of attacks and unnecessary emergency responses caused by security alarms, and improve the efficiency of overall network security management operations.

[0054] Example 3

[0055] This embodiment is based on embodiment 1:

[0056] This embodiment provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the method for eliminating the impact of the security alarm caused by the simulated attack in Embodiment 1 is implemented. The computer program may be in source code form, object code form, executable file, or some intermediate form.

[0057] Example 4

[0058] This embodiment is based on embodiment 1:

[0059] This embodiment provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the method of eliminating the impact of security alerts caused by simulated attacks in Embodiment 1. The computer program may be in source code form, object code form, executable file, or some intermediate form, etc. The storage medium includes: any entity or device capable of carrying computer program code, recording medium, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signal, telecommunication signal, and software distribution medium, etc. It should be noted that the content contained in the storage medium may be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the storage medium does not include electric carrier signals and telecommunication signals.

[0060] It should be noted that, for the aforementioned method embodiments, for the sake of simplicity of description, they are expressed as a series of action combinations, but those skilled in the art should be aware that the present application is not limited by the order of the actions described, because according to the present application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by the present application.

Claims

1. A method for eliminating the impact of security alarms caused by simulated attacks, characterized in that: include: When the security effectiveness verification platform initiates a simulated attack, it sends a simulated attack log to the situation awareness platform, wherein the simulated attack log includes characteristic information of the simulated attack; The situation awareness platform identifies the simulated attack logs sent by the security effectiveness verification platform, establishes a time sliding window, correlates and analyzes the simulated attack logs with the security protection equipment response logs within the corresponding time sliding window, and marks the security alarms caused by the simulated attacks, thereby eliminating the impact of security alarms.

2. A method for eliminating the impact of security alarms caused by simulated attacks according to claim 1, characterized in that: The establishing of the time sliding window, correlating and analyzing the simulated attack log with the security protection device response log within the corresponding time sliding window, and marking the security alarm caused by the simulated attack, includes: The situation awareness platform establishes a time sliding window to cache the simulated attack logs sent by the security effectiveness verification platform, and extracts key information from the security protection device response logs in the time sliding window; When the key information of the simulated attack log matches the response log of the security protection device, it is determined that the attack alarm sent by the security protection device is caused by the simulated attack sent by the security effectiveness verification platform, and the security threat of the attack alarm is eliminated.

3. A method for eliminating the impact of security alarms caused by simulated attacks according to claim 2, characterized in that: The situation awareness platform caches the simulated attack logs sent by the security effectiveness verification platform by establishing a time sliding window, including: A log matching method based on a time sliding window is used to establish a cache queue with time attributes. For each simulated attack log sent by the security effectiveness verification platform, the receiving time of the simulated attack log is marked when it is received. When the difference between the current time and the receiving time of the simulated attack log exceeds a threshold, the simulated attack log is processed as lost.

4. A method for eliminating the impact of security alarms caused by simulated attacks according to claim 1, characterized in that: The simulated attack log sent by the security effectiveness verification platform includes attack feature data and attack traffic features. The attack feature data includes the source IP address, source port, destination IP address, destination port and traffic protocol of the attack. The attack traffic features include the requested URL address, file name and load keywords.

5. The method for eliminating the impact of security alarms caused by simulated attacks according to claim 1, characterized in that: When the security protection device detects attack traffic, it triggers an alarm log, that is, a security protection device response log; the security protection device response log includes the source IP address, source port, destination IP address, destination port and traffic protocol of the attack, and the attack traffic characteristics include the requested URL address, file name and load keywords.

6. A system for eliminating the impact of security alarms caused by simulated attacks, characterized in that: include: The security effectiveness verification platform is configured to send a simulated attack log to the situation awareness platform when launching a simulated attack, wherein the simulated attack log includes characteristic information of the simulated attack; The situation awareness platform is configured to identify the simulated attack logs sent by the security effectiveness verification platform, establish a time sliding window, correlate and analyze the simulated attack logs with the security protection device response logs within the corresponding time sliding window, and mark the security alarms caused by the simulated attacks, thereby eliminating the impact of the security alarms.

7. A system for eliminating the impact of security alarms caused by simulated attacks according to claim 6, characterized in that: The situation awareness platform establishes a time sliding window, caches the simulated attack logs sent by the security effectiveness verification platform, and extracts key information from the security protection device response logs in the time sliding window; when the key information of the simulated attack log matches the security protection device response log, it is determined that the attack alarm sent by the security protection device is caused by the simulated attack sent by the security effectiveness verification platform, and the security threat of the attack alarm is eliminated.

8. A system for eliminating the impact of security alarms caused by simulated attacks according to claim 7, characterized in that: The situation awareness platform caches the simulated attack logs sent by the security effectiveness verification platform by establishing a time sliding window, including: establishing a cache queue with time attributes based on a log matching method based on the time sliding window; marking the receiving time of each simulated attack log sent by the security effectiveness verification platform when receiving the log; when the difference between the current time and the receiving time of the simulated attack log exceeds a threshold, the simulated attack log is lost.

9. A system for eliminating the impact of security alarms caused by simulated attacks according to claim 6, characterized in that: The simulated attack log sent by the security effectiveness verification platform includes attack feature data and attack traffic features. The attack feature data includes the source IP address, source port, destination IP address, destination port and traffic protocol of the attack. The attack traffic features include the requested URL address, file name and load keywords.

10. A system for eliminating the impact of security alarms caused by simulated attacks according to claim 6, characterized in that: When the security protection device detects attack traffic, it triggers an alarm log, that is, a security protection device response log; the security protection device response log includes the source IP address, source port, destination IP address, destination port and traffic protocol of the attack, and the attack traffic characteristics include the requested URL address, file name and load keywords.

Citation Information

Cited By

  • Network security situation awareness and emergency response system based on digital twinning

    CN121841762A