Machine frame type equipment attack message collection method, query method and computer device
Patent Information
- Application Number
- CN202510292342.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-12
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-03-12
AI Technical Summary
When chassis-type devices handle large-scale network attacks, they have slow response speed and low processing efficiency, and the dispersed storage of attack packets leads to time-consuming and labor-intensive information query.
By detecting data surface attack information on the service board, obtaining attack messages and attack logs, and configuring the index relationship between the message name and the message source slot. Attack messages and logs are sent to the main control board and backup control board through inter-board channels, and are stored in the corresponding data tables to achieve centralized management and backup.
It improves the response speed and processing efficiency of frame-type devices when dealing with large-scale network attacks, reduces the time for information query, and reduces the complexity of message aggregation and the delay in information display.
Smart Images

Figure CN119996048A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of data communication technology, and in particular to a collection method, a query method, and a computer device for frame-type equipment attack messages. Background Art
[0002] As a high-performance network device, the core of the frame-type firewall is composed of a control service board and a service board. The control board is the management unit of the device and is usually configured as a primary and a backup board to ensure high stability and reliability of the system. The control board is mainly responsible for system management, configuration maintenance and network service processing; the service board is a service processing unit, focusing on network forwarding, security service processing and log data recording.
[0003] When an attack is detected in network traffic, the chassis device can record the attack log and display the log information to the user through a visual interface. In addition, the business board can detect and record attack messages and store them in a local database for subsequent query and analysis.
[0004] However, in actual applications, when collecting log information, the main control board needs to connect to the database of each business board for repeated queries. This process is time-consuming and affects the efficiency of obtaining log information. In addition, when attack information is stored in different business boards, the main control board needs to summarize and display this information, which not only increases the complexity of message aggregation, but also causes delays in information display, resulting in slow response speed and low processing efficiency of the frame-type firewall when dealing with large-scale network attacks. Summary of the invention
[0005] In view of this, the embodiments of the present disclosure provide a method for collecting attack messages of frame-type devices, a query method, and a computer device, which can solve the problem in the prior art that attack messages of frame-type devices are stored in a scattered manner, resulting in slow response speed and low processing efficiency of frame-type firewalls when handling large-scale network attacks, and time-consuming and labor-intensive when information query and call are required.
[0006] In a first aspect, an embodiment of the present disclosure provides a method for collecting attack messages of a frame-type device, wherein the frame-type device includes a main control board, a standby control board, and several service boards, including:
[0007] In response to the data plane attack information detected by the service board, obtain the attack message and attack log;
[0008] Based on the attack message and the attack log, configure an index association relationship between the attack message name and the message source slot, and store the index association relationship in an index association table;
[0009] The attack message and the attack log are respectively sent to the attack message receiving main process and the log receiving main process of the main control board through the inter-board channel through the attack detection process;
[0010] The attack message and the attack log are respectively sent to the attack message receiving standby process and the log receiving standby process of the standby control board through the inter-board channel by the attack detection process;
[0011] In response to the message reception messages of the attack message receiving main process and the attack message receiving standby process, the attack message is stored in the main control board message data table and the standby control board message data table respectively;
[0012] In response to the log receiving messages of the log receiving main process and the log receiving standby process, the attack log is stored in the main control board log data table and the standby control board log data table respectively.
[0013] Optionally, obtaining attack messages and attack logs in response to data plane attack information detected by the service board includes: monitoring the attack information in real time through a data plane attack detection process of the frame-type security device service board, and generating attack messages and attack logs in response to the attack information.
[0014] Optionally, in response to the message reception message of the attack message receiving main process and the attack message receiving standby process, storing the attack message in the main control board message data table and the standby control board message data table respectively includes:
[0015] In response to a message receiving message of the attack message receiving main process, the attack message is stored in a first message buffer area, and the data in the first message buffer area is stored into the main control board message data table one by one through the main control board attack message storage process;
[0016] In response to the message reception message of the standby attack message receiving process, the attack message is stored in the second message buffer area, and the data in the second message buffer area is stored in the standby control board message data table one by one through the standby control board attack message storage process.
[0017] Optionally, in response to the log receiving messages of the log receiving main process and the log receiving standby process, storing the attack log in the main control board log data table and the standby control board log data table respectively includes:
[0018] In response to a log receiving message from the log receiving main process, the attack log is stored in a first log buffer area, and the data in the first log buffer area is stored in a main control board log data table one by one through a main control board log storage process;
[0019] In response to the log receiving message of the log receiving standby process, the attack log is stored in the second log buffer area, and the data in the second log buffer area is stored one by one in the standby control board log data table through the standby control board log storage process.
[0020] Optionally, when the data plane attack information is set attack information, the set attack information is collected according to a maximum number of message records configured for the chassis device.
[0021] In a second aspect, the present application discloses a method for querying attack messages of a frame-type device, storing attack messages based on the method for collecting attack messages of a frame-type device, and the query method includes:
[0022] Receive attack message data query requirements;
[0023] According to the attack message data query requirement, obtain the target attack message name and the target message source slot, and use the target attack message name and the target message source slot as the target index;
[0024] When the target index exists in the index association table, obtaining the actual attack log corresponding to the attack message data query requirement from the main control board log data table;
[0025] Based on the actual attack log, the corresponding actual attack message is obtained from the main control board message data table, and the actual attack log and the actual attack message are fed back to the client corresponding to the attack message data query instruction.
[0026] In a third aspect, the present application discloses a method for querying attack messages of a frame-type device, storing attack messages based on the method for collecting attack messages of a frame-type device, and the query method includes:
[0027] Receive attack message data query instructions;
[0028] According to the attack message data query requirement, obtain the target attack message name and the target message source slot, and use the target attack message name and the target message source slot as the target index;
[0029] When the target index exists in the index association table, obtaining the first actual attack log corresponding to the attack message data query requirement from the main control board log data table;
[0030] Based on the first actual attack log, obtaining a corresponding first actual attack message from the main control board message data table;
[0031] Recording the first actual attack message and the first actual attack log as first information;
[0032] Obtaining a second actual attack log corresponding to the attack message data query requirement from the standby control board log data table;
[0033] Based on the second actual attack log, obtaining a corresponding second actual attack message from the standby control board message data table;
[0034] Recording the second actual attack message and the second actual attack log as second information;
[0035] When the first information is consistent with the second information, target attack message display information is generated, and the target attack message display information is fed back to the client corresponding to the attack message data query instruction.
[0036] In a fourth aspect, the embodiments of the present disclosure further provide a computer device, which adopts the following technical solution:
[0037] The computer device comprises:
[0038] at least one processor; and,
[0039] a memory communicatively connected to the at least one processor; wherein,
[0040] The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute any of the above-mentioned methods for collecting attack messages of frame-type devices or methods for querying attack messages of frame-type devices.
[0041] In a fifth aspect, an embodiment of the present disclosure further provides a computer-readable storage medium, which stores computer instructions, and the computer instructions are used to enable a computer to execute any of the above-mentioned methods for collecting attack messages of frame-type devices or methods for querying attack messages of frame-type devices.
[0042] In a sixth aspect, an embodiment of the present disclosure further provides a computer program product, comprising a computer program / instruction, which implements the steps of any of the above methods when executed by a processor.
[0043] The present application discloses a method for collecting attack messages of a frame-type device. In response to data plane attack information detected by a business board, an attack message and an attack log are obtained; based on the message information and the attack log, an index association relationship between the attack message name and the message source slot is configured; the attack message and the attack log are respectively sent to the attack message receiving main process and the log receiving main process of the main control board through the attack detection process through the inter-board channel; the attack message and the attack log are respectively sent to the attack message receiving standby process and the log receiving standby process of the standby control board through the attack detection process through the inter-board channel; in response to the message reception message of the attack message receiving main process and the attack message receiving standby process, the attack message is respectively stored in the message data table of the main control board and the message data table of the standby control board; in response to the log reception message of the log receiving main process and the log receiving standby process, the attack log is respectively stored in the log data table of the main control board and the log data table of the standby control board. Through this method, the attack messages and attack logs scattered on various business boards are collected and managed on the main control board and the standby control board, which is convenient for security managers to conduct unified analysis and processing; the reliability and availability of attack messages and attack logs are ensured through the backup mechanism of the main and standby control boards. Even if the main control board fails, the standby control board can continue to process data, avoiding the risk of data loss; by establishing an index association between the attack message name and the message source slot, and storing the data in a data table, it is convenient for security experts to conduct data analysis and mining, so as to better understand the attacker's attack methods and intentions and take corresponding preventive measures; the detailed attack log records the time, type and related information of the attack, providing strong support for subsequent security audits and tracing.
[0044] The above description is only an overview of the technical solution of the present invention. In order to more clearly understand the technical means of the present invention, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present invention more obvious and easy to understand, the following preferred embodiments are specifically cited and described in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] In order to more clearly illustrate the technical solutions of the embodiments of the present disclosure, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0046] Figure 1 A schematic diagram of a flow chart of a method for collecting attack messages of a frame-type device provided in an embodiment of the present disclosure.
[0047] Figure 2A schematic flow chart of a first embodiment of a method for querying attack messages of a frame-type device provided in an embodiment of the present disclosure.
[0048] Figure 3 A schematic flow chart of a second embodiment of a method for querying attack messages of a frame-type device provided in an embodiment of the present disclosure.
[0049] Figure 4 A schematic diagram of the structure of a computer device provided in an embodiment of the present disclosure. DETAILED DESCRIPTION
[0050] The embodiments of the present disclosure are described in detail below with reference to the accompanying drawings.
[0051] It should be clear that the following embodiments of the present disclosure are described by specific specific examples, and those skilled in the art can easily understand other advantages and effects of the present disclosure from the contents disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all of the embodiments. The present disclosure can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present disclosure. It should be noted that the following embodiments and features in the embodiments can be combined with each other in the absence of conflict. Based on the embodiments in the present disclosure, all other embodiments obtained by ordinary technicians in the field without making creative work are within the scope of protection of the present disclosure.
[0052] It should be noted that various aspects of the embodiments within the scope of the appended claims are described below. It should be apparent that the aspects described herein may be embodied in a wide variety of forms, and any specific structure and / or function described herein is merely illustrative. Based on the present disclosure, it should be understood by those skilled in the art that an aspect described herein may be implemented independently of any other aspect, and two or more of these aspects may be combined in various ways. For example, any number of aspects described herein may be used to implement the device and / or practice the method. In addition, other structures and / or functionalities other than one or more of the aspects described herein may be used to implement this device and / or practice this method.
[0053] It should also be noted that the illustrations provided in the following embodiments are only schematic illustrations of the basic concept of the present disclosure. The drawings only show components related to the present disclosure rather than being drawn according to the number, shape and size of components in actual implementation. In actual implementation, the type, quantity and proportion of each component may be changed arbitrarily, and the component layout may also be more complicated.
[0054] Additionally, in the following description, specific details are provided to facilitate a thorough understanding of the examples. However, it will be understood by those skilled in the art that the aspects described may be practiced without these specific details.
[0055] Reference Figure 1 The present application discloses a method for collecting attack messages of a frame-type device, wherein the frame-type device includes a main control board, a standby control board, and several service boards, including:
[0056] S100, in response to the data plane attack information detected by the service board, acquiring the attack message and the attack log.
[0057] Specifically, the attack information is monitored in real time through the attack detection process of the data plane of the service board of the frame-type security device, and an attack message and an attack log are generated in response to the attack information.
[0058] In this embodiment, the attack message includes attack message information, an attack message name, and a message source slot, and the attack log includes an attack message name and a message source slot.
[0059] Specifically, the data traffic flowing through the service board can be monitored in real time through the intrusion detection system (IDS) or intrusion prevention system (IPS) deployed on the service board. For example, when an abnormally high frequency of TCP connection requests is detected, or malicious port scanning behavior is found, it will be determined that data plane attack information is detected, or when information with attack characteristics is detected, it can be determined as attack information.
[0060] Once the attack information is detected, the business board will immediately capture the relevant messages being transmitted. Specifically, the attack message can be captured from the network interface through a network packet capture tool, such as the tcpdump tool under the Linux system, and stored in the temporary buffer of the business board. When the business board detects an attack, it will record a detailed attack log. The log content includes the time when the attack occurred, the type of attack (such as DDoS attack, SQL injection attack, etc.), the source IP address and destination IP address of the attack, etc. These logs will be stored in the log file of the business board.
[0061] Taking port scanning attacks as an example, when the attack detection process monitors network traffic, it finds that a certain IP address frequently attempts to connect to multiple ports in a short period of time, which meets the characteristics of port scanning. At this time, the system will capture the message sent by the IP address as an attack message and record the time of the attack, source IP address and other information as an attack log.
[0062] In this step, timely capture of attack messages and logs can provide raw data for subsequent analysis and processing; attack messages can help security experts analyze the attacker's attack methods and intentions, while attack logs can record the time and related information of the attack, facilitating subsequent tracing and auditing.
[0063] S200, based on the attack message and the attack log, configure an index association relationship between the attack message name and the message source slot, and store the index association relationship in an index association table.
[0064] The source slot of the message refers to the board number of the service board.
[0065] In this embodiment, the acquired attack message name may be directly associated with the message source slot to establish an index association relationship.
[0066] In another embodiment, key information such as source IP address, destination IP address, protocol type, etc. can also be extracted from the attack message, and the timestamp of the attack can be obtained from the attack log. Based on the extracted information, a unique name is generated for the attack message. For example, the naming method of "source IP-destination IP-timestamp" can be used, such as "192.168.1.1-10.0.0.1-20250306100000".
[0067] The attack message name is associated with the slot number of the message source and stored in the index table of the service board. For example, if the attack message comes from slot 3 of the service board, the corresponding relationship between "192.168.1.1-10.0.0.1-20250306100000" and "slot 3" is recorded in the index table.
[0068] By indexing the association relationship, the source slot of the attack message can be quickly located, which improves the efficiency of data processing. At the same time, the unique attack message name also avoids the problem of message naming conflicts.
[0069] S300, the attack detection process sends the attack message and the attack log to the attack message receiving main process and the log receiving main process of the main control board through the inter-board channel respectively.
[0070] S400, the attack detection process sends the attack message and the attack log to the attack message receiving standby process and the log receiving standby process of the standby control board through the inter-board channel respectively.
[0071] Specifically, for the establishment of inter-board channels: inter-board channels are established between the business board, main control board and backup control board in the frame-type device through a high-speed inter-board communication interface (such as PCIe, Ethernet, etc.); when the device starts, the inter-board channels will be initialized and configured to ensure that data can be transmitted stably between different boards.
[0072] For data transmission: the attack detection process on the business board will encapsulate the attack message and attack log into a specific data packet format and send them to the main control board and the standby control board through the inter-board channel. For example, the UDP protocol can be used for data transmission to improve transmission efficiency. The attack message receiving main process, log receiving main process, attack message receiving standby process and log receiving standby process on the main control board and the standby control board will monitor the corresponding ports to receive data from the business board.
[0073] Through this step, centralized management of attack messages and attack logs can be achieved; data is sent to the main control board and the standby control board in a unified manner to facilitate subsequent data analysis and processing; at the same time, the backup mechanism of the standby control board improves data reliability and availability. Even if the main control board fails, the standby control board can continue to process attack messages and logs.
[0074] S500 , in response to message reception messages of the attack message receiving master process and the attack message receiving standby process, respectively store the attack message in the master control board message data table and the standby control board message data table.
[0075] Specifically, in response to a message receiving message of the attack message receiving main process, the attack message is stored in the first message buffer area, and the data in the first message buffer area is stored into the main control board message data table one by one through the main control board attack message storage process;
[0076] In response to the message reception message of the standby attack message receiving process, the attack message is stored in the second message buffer area, and the data in the second message buffer area is stored into the standby control board message data table one by one through the standby control board attack message storage process.
[0077] S600 , in response to log receiving messages from the log receiving master process and the log receiving standby process, respectively store attack logs in the master control board log data table and the standby control board log data table.
[0078] Specifically, in response to the log receiving message of the log receiving main process, the attack log is stored in the first log buffer area, and the data in the first log buffer area is stored in the main control board log data table one by one through the main control board log storage process.
[0079] In response to the log receiving message of the log receiving standby process, the attack log is stored in the second log buffer area, and the data in the second log buffer area is stored in the standby control board log data table one by one through the standby control board log storage process.
[0080] In this embodiment, after receiving the attack message, the attack message receiving main process and the attack message receiving standby process on the main control board and the standby control board can send a message reception message to the business board. After receiving the message, the business board confirms that the attack message has been successfully sent; the main control board and the standby control board will store the received attack message in their respective message data tables (i.e., the main control board message data table and the standby control board message data table), and further, a database (such as MySQL, SQLite, etc.) can be used to store the attack message for subsequent query and analysis; when storing, the attack message name and related index information will be stored together to facilitate subsequent associated queries.
[0081] After receiving the attack log, the log receiving main process and log receiving standby process on the main control board and the standby control board can send a log receiving message to the business board. After receiving the message, the business board confirms that the attack log has been successfully sent; the main control board and the standby control board will store the received attack log in their respective log data tables (i.e., the main control board log data table and the standby control board log data table). A database can also be used to store the attack log, and the storage content includes detailed information of the attack log and related index information.
[0082] Through the above steps, the persistent storage of attack messages and attack logs can be guaranteed; the data is stored in the data table to facilitate subsequent data analysis, statistics and query; at the same time, the dual storage mechanism of the main control board and the standby control board further improves the reliability and security of the data.
[0083] The present application discloses a method for collecting attack messages of a frame-type device. In response to data plane attack information detected by a business board, an attack message and an attack log are obtained; based on the message information and the attack log, an index association relationship between the attack message name and the message source slot is configured; the attack message and the attack log are respectively sent to the attack message receiving main process and the log receiving main process of the main control board through the attack detection process through the inter-board channel; the attack message and the attack log are respectively sent to the attack message receiving standby process and the log receiving standby process of the standby control board through the attack detection process through the inter-board channel; in response to the message reception message of the attack message receiving main process and the attack message receiving standby process, the attack message is respectively stored in the message data table of the main control board and the message data table of the standby control board; in response to the log reception message of the log receiving main process and the log receiving standby process, the attack log is respectively stored in the log data table of the main control board and the log data table of the standby control board. Through this method, the attack messages and attack logs scattered on various business boards are collected and managed on the main control board and the standby control board, which is convenient for security managers to conduct unified analysis and processing; the reliability and availability of attack messages and attack logs are ensured through the backup mechanism of the main and standby control boards. Even if the main control board fails, the standby control board can continue to process data, avoiding the risk of data loss; by establishing an index association between the attack message name and the message source slot, and storing the data in a data table, it is convenient for security experts to conduct data analysis and mining, so as to better understand the attacker's attack methods and intentions and take corresponding preventive measures; the detailed attack log records the time, type and related information of the attack, providing strong support for subsequent security audits and tracing.
[0084] In this embodiment, the main control board log data table and the standby control board log data table are displayed externally, while the main control board message data table and the standby control board message data table are not displayed externally.
[0085] The method for collecting attack messages of a frame-type device disclosed in the present application also includes: before obtaining the attack message and the attack log, determining whether the data plane attack information has been marked, and if not, marking the data plane attack information and recording it as set attack information, that is, attack information in a set state;
[0086] If so, the data plane attack information is no longer marked, and the attack message and attack log are obtained.
[0087] The method for collecting attack messages of a frame-type device disclosed in the present application also includes: when the data plane attack information is in a set state, collecting the set attack information according to the maximum number of message records configured for the frame-type device. Specifically, when the same data plane attack information in the set state (referring to the message name and the same message source slot) appears twice in succession, for subsequent information collection, only the set attack information is collected, and other attack information is no longer collected.
[0088] Specifically, the frame-type device can be pre-configured with a maximum number of message records, which is an upper limit. When collecting attack information in the set state, the system will collect relevant attack information messages according to this pre-set maximum number. For example, if the maximum number of message records is set to 5, the system will only collect a maximum of 5 attack information in the set state.
[0089] When the system detects that the same set attack information has appeared twice in a row, it will enter a special collection mode; in the subsequent information collection process, the system will focus on collecting this set attack information that has appeared twice in a row, which means that the system will continue to pay attention to and collect messages related to this specific attack information, and further analyze the characteristics and rules of this attack. Once entering the above special collection mode, the system will temporarily ignore other types of attack information, that is, for other attack information that is not this set attack information that appears twice in a row, the system will not perform collection operations until certain specific conditions are met (such as the collection reaches the maximum number of message records, the attack information no longer appears, etc.), and then it may resume the collection of other attack information.
[0090] Assume that the maximum number of message records configured for a chassis-type device is 50, and the system detects that the set attack information "SYN flood attack" appears twice in succession, then in the subsequent collection process, the system will only collect messages related to "SYN flood attack", and will not collect other types of attack information such as "ICMP flood attack" and "SQL injection attack" until 50 "SYN flood attack" messages are collected.
[0091] In this embodiment, the attack message and the attack log are respectively stored in the data tables of the main control board and the standby control board. Storing them in the standby control board has many important purposes, mainly reflected in improving the reliability, availability, data integrity of the system and coping with special situations. The following is a detailed description: the main control board may be damaged due to hardware aging, overheating, power failure, etc. For example, bad sectors appear on the hard disk of the main control board, which may cause the loss of data stored in the message data table and log data table of the main control board; and the data storage of the standby control board can be used as a backup. Even if the hardware of the main control board fails, the attack message and log can still be obtained from the data table of the standby control board to ensure that data is not lost and to ensure the system's continuous analysis and processing capabilities for attack events.
[0092] The operating system, database management system and other software of the main control board may crash or become abnormal. For example, if the database software is deadlocked, the data table of the main control board cannot be accessed normally. At this time, the data storage of the standby control board is not affected and can continue to provide data support for security managers to ensure the normal operation of the system.
[0093] In addition, when performing software upgrades and hardware maintenance on the main control board, the main control board may need to temporarily stop service. For example, upgrading the version of the main control board's database may take several hours or even longer. During this period, the data storage of the standby control board can continue to provide query and analysis services for attack messages and logs, ensuring that the system can still maintain the ability to monitor and respond to attack events during maintenance and upgrades, thereby improving system availability.
[0094] When a large number of security managers access the data table of the main control board for data analysis at the same time, the main control board may be overloaded, resulting in access delays or even failure to respond. The data storage of the standby control board can share some of the access pressure, allowing some personnel to obtain the required data from the data table of the standby control board, thereby ensuring the availability of the system under high concurrency.
[0095] In the process of transmitting attack messages and logs from the business board to the main control board through the inter-board channel, data transmission errors may occur due to network interference, signal attenuation, etc. As another independent receiving and storage node, the standby control board can re-verify and store the transmitted data. If the data received by the main control board is erroneous, but the data received by the standby control board is complete, the data of the standby control board can be used as the standard to ensure data integrity. When the main control board stores and processes attack messages and logs, data corruption may occur due to program logic errors, data conflicts, etc. The data storage of the standby control board can be used as an independent data source to restore and verify the data of the main control board to ensure data integrity.
[0096] In the prior art, when collecting log information, the main control board needs to connect to the database of each business board for repeated query, and this process is time-consuming. In the method for collecting attack messages of frame-type equipment disclosed in the present application, after the business board detects the data plane attack information, it actively sends the attack message and the attack log to the main control board and the standby control board through the inter-board channel. Specifically, after the business board detects the attack information, it obtains the attack message and the attack log; through the attack detection process, the attack message and the attack log are sent to the main attack message receiving process and the log receiving process of the main control board, as well as the attack message receiving standby process and the log receiving standby process of the standby control board through the inter-board channel. In this way, the main control board and the standby control board do not need to actively connect to the database of each business board for repeated query, which reduces the query link, thereby shortening the time for collecting log information and improving the efficiency of obtaining log information.
[0097] In the prior art, when the attack information is scattered and stored on different business boards, the main control board needs to summarize and display this information, which increases the complexity of message aggregation and also causes a delay in information display. The present application scheme solves this problem in the following ways: Based on message information and attack logs, an index association relationship between the attack message name and the message source slot is configured. This association relationship enables the main control board and the standby control board to clearly know the source of the message and log when receiving the attack message and attack log, which is convenient for subsequent aggregation and processing; the main control board and the standby control board respectively store the received attack message and attack log in the corresponding data table, namely the main control board message data table, the standby control board message data table, the main control board log data table, and the standby control board log data table, so that the attack message and the attack log are centrally stored on the control board, avoiding the situation where the information is scattered on different business boards and reducing the complexity of message aggregation. At the same time, since the data has been centrally stored, there is no need to perform complex aggregation operations when displaying information, thereby reducing the delay of information display.
[0098] The present application scheme avoids the process of the main control board actively querying the databases of each business board. The business board actively pushes attack messages and attack logs, which reduces the query time and enables the log information to be obtained by the main control board and the standby control board more quickly, thereby improving the timeliness of the system in obtaining key information and providing faster data support for subsequent analysis and processing; by configuring the index association relationship between the attack message name and the message source slot, and centrally storing the attack messages and attack logs in the data table of the control board, the message aggregation process is clearer and simpler; the main control board and the standby control board can accurately process the messages and logs according to the index association relationship, thereby reducing errors and confusion in the aggregation process and improving the reliability and stability of the system.
[0099] Reference Figure 2In a second aspect, the present application discloses a method for querying attack messages of a frame-type device, storing attack messages based on the method for collecting attack messages of the frame-type device, and the query method includes:
[0100] A100 receives the attack message data query request.
[0101] For example, a client (such as a management terminal used by a network administrator) sends a query request to the query service interface of a chassis device through the network. This request can be a POST request based on the HTTP protocol, and the request body contains key information required for the query, such as the query time range, attack type, etc.; after receiving the request, the query service module of the chassis device parses it and extracts key query conditions.
[0102] By receiving the query requirements from the client, we can clearly know what kind of attack message data the user wants to query, providing a clear direction for subsequent query operations; allowing the client to actively initiate queries to meet the diverse query needs of different users in different scenarios.
[0103] A200 obtains the target attack message name and the target message source slot according to the attack message data query requirement, and uses the target attack message name and the target message source slot as the target index.
[0104] After receiving the query request, the chassis device first searches for information matching the query criteria in the internal metadata storage area. Assume that based on the attack type and time range queried, the system determines from the metadata that the target attack message name is "PortScan_20250305" and the target message source slot is "Slot5".
[0105] The two pieces of information are then combined into a target index, for example, by concatenating them using a specific separator (such as “@”) to form “PortScan_20250305@Slot5” as a key identifier for subsequent queries.
[0106] In this step, the target attack message name and the target message source slot are obtained, laying the foundation for the subsequent accurate search for related attack messages and logs, so that the query can be focused on specific attack events and device locations; these two key information are combined into a target index, which simplifies the subsequent search process in the data table, improves query efficiency, and reduces the complexity of data processing.
[0107] A300, when the target index exists in the index association table, obtain the actual attack log corresponding to the attack message data query requirement from the main control board log data table.
[0108] The frame-type device maintains an index association table, which records the correspondence between the target index and the records in the main control board log data table. The system first searches the index association table for the target index generated in step A200 (such as "PortScan_20250305@Slot5"). If the target index exists, the corresponding record in the main control board log data table is located according to the mapping relationship recorded in the index association table. The main control board log data table may store basic information about the attack, such as the attack start time, end time, attack source IP, etc.
[0109] In this step, through the screening mechanism of the index association table, subsequent log data acquisition operations are performed only when the target index exists, avoiding unnecessary data queries and saving system resources; the index association table is used to associate the target index with the records in the main control board log data table to ensure that the actual attack logs matching the query requirements can be accurately obtained, thereby improving the accuracy and relevance of the data.
[0110] A400 obtains the corresponding actual attack message from the message data table of the main control board based on the actual attack log, and feeds back the actual attack log and the actual attack message to the client corresponding to the attack message data query instruction.
[0111] According to the key information (such as attack name, time, etc.) in the actual attack log obtained in step A300, search in the main control board message data table. The main control board message data table stores detailed attack message content. For example, through the attack name "PortScan_20250305" and the attack time range, the corresponding actual attack message is located, and its content may be a series of network data packet information; the system integrates the actual attack log and the actual attack message, and then sends it back to the client through the network interface in a suitable format (such as JSON or XML).
[0112] In this step, complete attack information can be provided to the client, including attack logs and detailed attack message content, so that the user can fully understand the situation of the attack event and facilitate in-depth analysis and processing; the query results are fed back to the client in a timely manner, which improves the efficiency of users in obtaining information, enhances the user experience, and helps users make decisions quickly.
[0113] In this embodiment, through a series of steps, using the target index and index association table, it is possible to quickly and accurately locate and obtain the required attack log and message information from a large amount of data, greatly improving the query efficiency and reducing the query time; ensuring that the attack information obtained by the client is complete and accurate, from the basic log of the attack to the detailed message content, it can be provided, which helps network security managers to conduct comprehensive analysis and judgment and take corresponding protective measures in a timely manner; allowing users to obtain the required information through simple query requests, the entire query process is transparent to the user, improving the system's ease of use and user satisfaction, and facilitating use by users of different technical levels.
[0114] Reference Figure 3 In a third aspect, the present application discloses a method for querying attack messages of a frame-type device, storing attack messages based on the method for collecting attack messages of the frame-type device, and the query method includes:
[0115] B100, receives the attack message data query instruction.
[0116] Through this step, the specific scope and characteristics of the attack message data that the user wants to query can be clearly understood, providing an accurate direction for subsequent query operations; allowing users to actively initiate queries, meeting the diverse needs of different users for attack message data in different scenarios, and improving the practicality of the system.
[0117] B200, according to the attack message data query requirement, obtains the target attack message name and the target message source slot, and uses the target attack message name and the target message source slot as the target index.
[0118] Combining the two key information into a target index simplifies the search process in the data table, improves query efficiency, and reduces the complexity of data processing.
[0119] B300, when the target index exists in the index association table, the first actual attack log corresponding to the attack message data query requirement is obtained from the main control board log data table.
[0120] Through the screening mechanism of the index association table, subsequent log data acquisition operations are performed only when the target index exists, avoiding unnecessary data queries and saving system resources; the index association table is used to associate the target index with the records in the main control board log data table to ensure that the actual attack logs matching the query requirements can be accurately obtained, thereby improving the accuracy and relevance of the data.
[0121] B400, based on the first actual attack log, obtain the corresponding first actual attack message from the main control board message data table.
[0122] According to the key information (such as attack name, time range, source IP and destination IP, etc.) in the first actual attack log obtained in step B300, a search is performed in the main control board message data table. The main control board message data table stores detailed attack message content, which may be a series of network data packet information. For example, through the attack name "SQL_Injection_20250308" and the attack time range, the corresponding first actual attack message is located, and its content may contain detailed information such as the specific statement of SQL injection.
[0123] Obtaining detailed attack message content from the main control board message data table and combining it with the first actual attack log can provide users with more comprehensive attack event information, which helps to deeply analyze the principles and processes of the attack; searching based on the key information in the first actual attack log ensures that the acquired attack message accurately matches the query requirements and log information.
[0124] B500, record the first actual attack message and the first actual attack log as first information.
[0125] Combining the attack log and the attack message together facilitates subsequent processing and comparison operations and improves data management efficiency; representing the first information in a unified format ensures the integrity and consistency of the data and facilitates subsequent analysis and presentation.
[0126] B600, obtains the second actual attack log corresponding to the attack message data query requirement from the log data table of the standby control board.
[0127] Similar to the main control board, the standby control board also has its own log data table. The system searches directly in the standby control board log data table according to the attack message data query requirements received in step B100. For example, according to the query attack type, time range and other conditions, the corresponding second actual attack log is located, and its content may be similar to the first actual attack log, containing basic information of the attack.
[0128] The data in the backup control board log data table can be used as a backup and verification of the main control board data. By obtaining the second actual attack log, the consistency of the data of the main control board and the backup control board can be checked to improve the reliability of the data; in the event of a failure or data loss on the main control board, the log data of the backup control board can be used as a backup data source to ensure that the system can still provide effective query services.
[0129] B700, based on the second actual attack log, obtain the corresponding second actual attack message from the message data table of the standby control board.
[0130] According to the key information (such as attack name, time range, etc.) in the second actual attack log obtained in step B600, a search is performed in the standby control board message data table. The standby control board message data table stores the detailed attack message content corresponding to the standby control board log. For example, by the attack name and time range, the corresponding second actual attack message is located, and its content should correspond to the first actual attack message.
[0131] Similar to step B400, obtaining the second actual attack message can ensure that the data of the standby control board is complete and matches the log information. At the same time, by comparing with the first actual attack message, the accuracy of the data can be further verified; the data in the standby control board message data table is used as a backup of the main control board message data, and can provide alternative data when the main control board has problems, ensuring the normal operation of the system.
[0132] B800, record the second actual attack message and the second actual attack log as second information.
[0133] The system integrates the second actual attack log obtained in step B600 and the second actual attack message obtained in step B700 to form a unified data structure, which is recorded as the second information. They are also combined in JSON format, and the format is similar to the first information.
[0134] Similar to step B500, the attack log and attack message of the standby control board are combined together to facilitate subsequent comparison operations, improve data management efficiency, represent the second information in a unified format, ensure the integrity and consistency of the standby control board data, and facilitate comparison with the first information.
[0135] B900, when the first information is consistent with the second information, target attack message display information is generated, and the target attack message display information is fed back to the client corresponding to the attack message data query instruction.
[0136] The system makes a detailed comparison of the first information and the second information, including various information in the attack log (such as attack name, time, source IP, destination IP, etc.) and the content of the attack message. By writing a special comparison algorithm, each field in the JSON data structure can be compared one by one. If the first information and the second information are consistent, the system will generate the target attack message display information based on this information. The display information can be further formatted and organized to present it to the user in a more user-friendly way, such as adding some descriptive text, charts, etc. The target attack message display information is then sent back to the client through the network interface (such as HTTP response).
[0137] By comparing the consistency of the first information and the second information, the accuracy and reliability of the query results can be ensured. If the two are inconsistent, it means that there may be data errors or system failures, which require further investigation; generating target attack message display information and feeding it back to the client in a friendly manner improves the efficiency and experience of users in obtaining information, allowing users to understand the situation of the attack incident more intuitively.
[0138] In this embodiment, by simultaneously acquiring data from the main control board and the standby control board and performing consistency verification, the accuracy and reliability of the query results are ensured. In the event of a failure in the main control board or data anomalies, the data of the standby control board can be used as a backup to ensure the normal operation of the system; at the same time, complete attack information is provided, including attack logs and detailed attack message content, which helps network security managers to fully understand the situation of the attack incident and conduct in-depth analysis and processing. The entire query process is transparent to the user. The user only needs to send a simple query command to obtain the verified and formatted target attack message display information, which improves the ease of use of the system and user satisfaction.
[0139] Furthermore, when the first information is consistent with the second information and there are multiple groups of first information, the multiple groups of first information can be combined in order of storage time, and a fused attack message information can be output, and the fused attack message information is used as the target attack message display information.
[0140] In this embodiment, the target attack message display information may be a pcap format file.
[0141] Furthermore, when the first information is inconsistent with the second information, union information of the first information and the second information may be obtained, and the union information may be used as target attack message display information.
[0142] In a fourth aspect, the present application discloses a system for collecting attack messages of a frame-type device, which is used to execute a method for collecting attack messages of a frame-type device, wherein the frame-type device includes a main control board, a standby control board, and several service boards, including:
[0143] An acquisition module, used to obtain attack messages and attack logs in response to data plane attack information detected by the service board;
[0144] A configuration module, used to configure an index association relationship between an attack message name and a message source slot based on message information and attack logs;
[0145] The first sending module is used to send the attack message and the attack log to the attack message receiving main process and the log receiving main process of the main control board through the inter-board channel through the attack detection process;
[0146] The second sending module is used to send the attack message and the attack log to the attack message receiving standby process and the log receiving standby process of the standby control board through the inter-board channel through the attack detection process;
[0147] A first storage module is used to store attack messages to a main control board message data table and a standby control board message data table in response to message reception messages of an attack message reception main process and an attack message reception standby process, respectively;
[0148] The second storage module is used to store the attack logs in the main control board log data table and the standby control board log data table respectively in response to the log receiving messages of the log receiving main process and the log receiving standby process.
[0149] In a fifth aspect, the present application discloses a query system for frame-type device attack messages, which is used to execute a query method for frame-type device attack messages. The query system includes:
[0150] A receiving module, used for receiving attack message data query requirements;
[0151] The query module is used to obtain the actual attack message name and the actual message source slot corresponding to the attack message data query requirement from the main control board log data table according to the attack message data query requirement and the index association relationship;
[0152] A determination module, used to use the actual attack message name and the actual message source slot as a target index;
[0153] The analysis feedback module is used to obtain the attack message information corresponding to the target index from the main control board message data table, and feed back the attack message information to the client corresponding to the attack message data query instruction.
[0154] In a sixth aspect, the present application discloses a query system for a frame-type device attack message, which is used to execute a query method for a frame-type device attack message. The query system includes:
[0155] An instruction receiving module, used for receiving an attack message data query instruction;
[0156] The first information query module is used to obtain the actual attack message name and the actual message source slot corresponding to the attack message data query requirement from the main control board log data table according to the attack message data query instruction and the index association relationship, and record them as the first name and the first slot respectively;
[0157] A first target index determination module, configured to use the first name and the first slot as a first target index;
[0158] A first information acquisition module, used to acquire attack message information corresponding to a first target index from a main control board message data table, recorded as first information;
[0159] The second information query module is used to obtain the actual attack message name and the actual message source slot corresponding to the attack message data query requirement from the standby control board log data table according to the attack message data query instruction and the index association relationship, and record them as the second name and the second slot respectively;
[0160] The target index determination module is used to use the second name and the second slot as the second target index;
[0161] A second information acquisition module is used to obtain attack message information corresponding to the second target index from the standby control board message data table, recorded as second information;
[0162] The display module is used to determine whether the first information is consistent with the second information. If so, generate target attack message display information and feed back the target attack message display information to the client corresponding to the attack message data query instruction.
[0163] The computer device according to the embodiment of the present disclosure includes a memory and a processor. The memory is used to store non-temporary computer-readable instructions. Specifically, the memory may include one or more computer program products, and the computer program product may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may, for example, include a random access memory (RAM) and / or a cache memory (cache), etc. The non-volatile memory may, for example, include a read-only memory (ROM), a hard disk, a flash memory, etc.
[0164] The processor may be a central processing unit (CPU) or other forms of processing units with data processing capabilities and / or instruction execution capabilities, and may control other components in the computer device to perform desired functions. In one embodiment of the present disclosure, the processor is used to run the computer-readable instructions stored in the memory, so that the computer device executes all or part of the steps of the aforementioned frame device attack message collection method or frame device attack message query method of each embodiment of the present disclosure.
[0165] Those skilled in the art should be able to understand that in order to solve the technical problem of how to obtain a good user experience, the present embodiment may also include well-known structures such as a communication bus and an interface, and these well-known structures should also be included in the protection scope of the present disclosure.
[0166] like Figure 4 A schematic diagram of the structure of a computer device provided in an embodiment of the present disclosure is shown, which is a schematic diagram of the structure of a computer device suitable for implementing the embodiment of the present disclosure. Figure 4 The computer device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.
[0167] like Figure 4 As shown, the computer device may include a processor (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) or a program loaded from a storage device into a random access memory (RAM). In the RAM, various programs and data required for the operation of the computer device are also stored. The processor, ROM, and RAM are connected to each other via a bus. An input / output (I / O) interface is also connected to the bus.
[0168] Typically, the following devices can be connected to the I / O interface: input devices such as sensors or visual information acquisition devices; output devices such as display screens; storage devices such as tapes, hard disks, etc.; and communication devices. The communication device can allow the computer device to communicate with other devices (such as edge computing devices) wirelessly or by wire to exchange data. Figure 4 A computer device having various devices is shown, but it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed instead.
[0169] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program contains program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through a communication device, or installed from a storage device, or installed from a ROM. When the computer program is executed by a processor, all or part of the steps of the method for collecting attack messages of a frame device or the method for querying attack messages of a frame device of an embodiment of the present disclosure are executed.
[0170] For detailed description of this embodiment, reference may be made to the corresponding descriptions in the aforementioned embodiments, which will not be repeated here.
[0171] According to the computer-readable storage medium of the embodiment of the present disclosure, non-transitory computer-readable instructions are stored thereon. When the non-transitory computer-readable instructions are executed by a processor, all or part of the steps of the method for collecting attack messages of a frame-type device or the method for querying attack messages of a frame-type device in the aforementioned embodiments of the present disclosure are executed.
[0172] The above-mentioned computer-readable storage media include, but are not limited to: optical storage media (e.g., CD-ROM and DVD), magneto-optical storage media (e.g., MO), magnetic storage media (e.g., magnetic tape or mobile hard disk), media with built-in rewritable non-volatile memory (e.g., memory card) and media with built-in ROM (e.g., ROM box).
[0173] For detailed description of this embodiment, reference may be made to the corresponding descriptions in the aforementioned embodiments, which will not be repeated here.
[0174] The basic principles of the present disclosure are described above in conjunction with specific embodiments. However, it should be noted that the advantages, strengths, effects, etc. mentioned in the present disclosure are only examples and not limitations, and it cannot be considered that these advantages, strengths, effects, etc. are required by each embodiment of the present disclosure. In addition, the specific details disclosed above are only for the purpose of illustration and ease of understanding, and are not limitations. The above details do not limit the present disclosure to the necessity of adopting the above specific details to be implemented.
[0175] In the present disclosure, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply that there is any such actual relationship or order between these entities or operations. The block diagrams of the devices, devices, equipment, and systems involved in the present disclosure are only illustrative examples and are not intended to require or imply that they must be connected, arranged, and configured in the manner shown in the block diagram. As will be appreciated by those skilled in the art, these devices, devices, equipment, and systems can be connected, arranged, and configured in any manner. Words such as "including", "comprising", "having", etc. are open words, referring to "including but not limited to", and can be used interchangeably with them. The words "or" and "and" used here refer to the words "and / or" and can be used interchangeably with them, unless the context clearly indicates otherwise. The words "such as" used here refer to the phrase "such as but not limited to", and can be used interchangeably with them.
[0176] Additionally, as used herein, "or" used in a list of items beginning with "at least one" indicates a separate list, so that, for example, a list of "at least one of A, B, or C" means A or B or C, or AB or AC or BC, or ABC (i.e., A and B and C). Furthermore, the word "exemplary" does not mean that the example described is preferred or better than other examples.
[0177] It should also be noted that in the system and method of the present disclosure, each component or each step can be decomposed and / or recombined. Such decomposition and / or recombination should be regarded as equivalent solutions of the present disclosure.
[0178] Various changes, substitutions, and modifications of the techniques described herein may be made without departing from the teachings defined by the appended claims. Furthermore, the scope of the claims of the present disclosure is not limited to the specific aspects of the processes, machines, manufactures, compositions of events, means, methods, and actions described above. Currently existing or later to be developed processes, machines, manufactures, compositions of events, means, methods, or actions that perform substantially the same functions or achieve substantially the same results as the corresponding aspects described herein may be utilized. Thus, the appended claims include such processes, machines, manufactures, compositions of events, means, methods, or actions within their scope.
[0179] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use the present disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects without departing from the scope of the present disclosure. Therefore, the present disclosure is not intended to be limited to the aspects shown herein, but rather to the widest scope consistent with the principles and novel features disclosed herein.
[0180] The above description has been given for the purpose of illustration and description. In addition, this description is not intended to limit the embodiments of the present disclosure to the forms disclosed herein. Although multiple example aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, changes, additions and sub-combinations thereof.
Claims
1. A method for collecting attack messages of a frame-type device, wherein the frame-type device includes a main control board, a standby control board, and several service boards, characterized in that: include: In response to the data plane attack information detected by the service board, obtain the attack message and attack log; Based on the attack message and the attack log, configure an index association relationship between the attack message name and the message source slot, and store the index association relationship in an index association table; The attack message and the attack log are respectively sent to the attack message receiving main process and the log receiving main process of the main control board through the inter-board channel through the attack detection process; The attack message and the attack log are respectively sent to the attack message receiving standby process and the log receiving standby process of the standby control board through the inter-board channel by the attack detection process; In response to the message reception messages of the attack message receiving main process and the attack message receiving standby process, the attack message is stored in the main control board message data table and the standby control board message data table respectively; In response to the log receiving messages of the log receiving main process and the log receiving standby process, the attack log is stored in the main control board log data table and the standby control board log data table respectively.
2. The method for collecting attack messages of a frame-type device according to claim 1, characterized in that: The method of obtaining attack messages and attack logs in response to data plane attack information detected by the service board includes: real-time monitoring of attack information through a data plane attack detection process of the service board of the frame-type security device, and generating attack messages and attack logs in response to the attack information.
3. The method for collecting attack messages of a frame-type device according to claim 1, characterized in that: The method of responding to the message reception message of the attack message receiving main process and the attack message receiving standby process, storing the attack message in the main control board message data table and the standby control board message data table respectively, comprises: In response to a message receiving message of the attack message receiving main process, the attack message is stored in a first message buffer area, and the data in the first message buffer area is stored into the main control board message data table one by one through the main control board attack message storage process; In response to the message reception message of the standby attack message receiving process, the attack message is stored in the second message buffer area, and the data in the second message buffer area is stored in the standby control board message data table one by one through the standby control board attack message storage process.
4. The method for collecting attack messages of a frame-type device according to claim 3, characterized in that: The method of responding to the log receiving messages of the log receiving main process and the log receiving standby process, storing the attack log in the main control board log data table and the standby control board log data table respectively, comprises: In response to a log receiving message from the log receiving main process, the attack log is stored in a first log buffer area, and the data in the first log buffer area is stored in a main control board log data table one by one through a main control board log storage process; In response to the log receiving message of the log receiving standby process, the attack log is stored in the second log buffer area, and the data in the second log buffer area is stored one by one in the standby control board log data table through the standby control board log storage process.
5. The method for collecting attack messages of a frame-type device according to claim 1, characterized in that: When the data plane attack information is set attack information, the set attack information is collected according to the maximum message record quantity configured for the frame-type device.
6. A method for querying attack messages of a frame-type device, characterized in that: Based on the method for collecting attack messages of a frame-type device according to any one of claims 1 to 5, the attack messages are stored, and the query method includes: Receive attack message data query requirements; According to the attack message data query requirement, obtain the target attack message name and the target message source slot, and use the target attack message name and the target message source slot as the target index; When the target index exists in the index association table, obtaining the actual attack log corresponding to the attack message data query requirement from the main control board log data table; Based on the actual attack log, the corresponding actual attack message is obtained from the main control board message data table, and the actual attack log and the actual attack message are fed back to the client corresponding to the attack message data query instruction.
7. A method for querying attack messages of a frame-type device, characterized in that: Based on the method for collecting attack messages of a frame-type device according to any one of claims 1 to 5, the attack messages are stored, and the query method includes: Receive attack message data query instructions; According to the attack message data query requirement, obtain the target attack message name and the target message source slot, and use the target attack message name and the target message source slot as the target index; When the target index exists in the index association table, obtaining the first actual attack log corresponding to the attack message data query requirement from the main control board log data table; Based on the first actual attack log, obtaining a corresponding first actual attack message from the main control board message data table; Recording the first actual attack message and the first actual attack log as first information; Obtaining a second actual attack log corresponding to the attack message data query requirement from the standby control board log data table; Based on the second actual attack log, obtaining a corresponding second actual attack message from the standby control board message data table; Recording the second actual attack message and the second actual attack log as second information; When the first information is consistent with the second information, target attack message display information is generated, and the target attack message display information is fed back to the client corresponding to the attack message data query instruction.
8. A computer device, characterized in that: The computer device comprises: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the method for collecting attack messages of a frame device described in any one of claims 1-5 or the method for querying attack messages of a frame device described in claim 6 or the method for querying attack messages of a frame device described in claim 7.
9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, which are used to enable a computer to execute the method for collecting attack messages of a frame device as described in any one of claims 1-5, the method for querying attack messages of a frame device as described in claim 6, or the method for querying attack messages of a frame device as described in claim 7.
10. A computer program product comprising computer instructions, characterized in that: When the computer instruction is executed by the processor, the steps of the method for collecting attack messages of frame-type devices described in any one of claims 1 to 5, the method for querying attack messages of frame-type devices described in claim 6, or the method for querying attack messages of frame-type devices described in claim 7 are implemented.
Citation Information
Patent Citations
Log processing method and system, storage medium and computer equipment
CN111930886A
APT attack analysis method and system, and server
CN112165451A
Attack detection method and related device
CN113886814A
Large-scale network attack-oriented tracing system and method
CN114584401A
Analysis method and system for host abnormal program detection
CN117834198A