Data reporting method, device, equipment and medium
The network security data reporting system analyzes and filters traffic data, generates alarm events based on pre-configured policies and field management information, and reports it, solving the problems of low efficiency and poor accuracy of data reporting in the existing technology, and realizing customized and efficient data reporting.
Patent Information
- Application Number
- CN202510170275.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-17
- Publication Date
- 2025-05-13
AI Technical Summary
The existing data reporting methods are inefficient and have poor accuracy when processing abnormal data, and are difficult to achieve user customization needs, resulting in data processing interruptions and data discarding.
Through the network security data reporting system, the traffic data of the target data source is analyzed and filtered, and alarm events are generated based on pre-configured reporting policies and field management information, and reported according to server information, realizing automatic mapping and conversion from traffic data to standardized reporting data.
Customized data reporting is realized, improving the efficiency and accuracy of data processing, ensuring the accuracy and completeness of reporting, and ensuring that the data complies with customer specifications and standards.
Smart Images

Figure CN119996156A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a data reporting method, device, equipment and medium. Background Art
[0002] In order to achieve network and information security situation awareness, it is necessary to monitor and analyze the network security status within the industry, and report security incidents when encountering network attacks, abnormal behaviors and other security incidents. It is suitable for industries that are highly dependent on network security, data-sensitive and have significant security risks, such as the financial industry, medical industry, etc.
[0003] Existing data reporting methods generally implement reporting functions based on scripts or open source software. If a script is used for reporting, when encountering abnormal data, the script may terminate abnormally, thereby interrupting the reporting and making it difficult for users to quickly discover the problem of abnormal script termination. If open source software is used for reporting, data will only be processed and reported according to the set process, and if abnormal data is encountered, it will be directly discarded.
[0004] Whether using scripts or open source software for reporting, to achieve the user's customized reporting needs, more complex configuration operations are required and the real-time performance is poor. Summary of the invention
[0005] The present invention provides a data reporting method, device, equipment and medium, which can perform reporting configuration according to user needs, realize customized data reporting, improve the efficiency and accuracy of data processing, and ensure the accuracy and completeness of reporting.
[0006] According to one aspect of the present invention, there is provided a data reporting method, which is executed by a network security data reporting system, comprising:
[0007] Analyze and filter the traffic data of the target data source to obtain the target traffic data to be reported;
[0008] According to a pre-configured reporting strategy, determine a first event type corresponding to the target traffic data, and obtain multiple first field names in the first event type and field values corresponding to each first field name;
[0009] Determine, according to the pre-configured field management information, the field English names corresponding to the first field names respectively, and generate an alarm event according to the field English names and the field values;
[0010] According to the pre-configured server information, the alarm event is reported to the target server.
[0011] According to another aspect of the present invention, there is provided a data reporting device, which is executed by a network security data reporting system and includes:
[0012] The target flow data acquisition module is used to parse and filter the flow data of the target data source to obtain the target flow data to be reported;
[0013] A field value acquisition module, used to determine a first event type corresponding to the target traffic data according to a pre-configured reporting strategy, and obtain a plurality of first field names in the first event type and field values corresponding to each first field name;
[0014] An alarm event generation module, used to determine the field English names corresponding to the first field names according to the pre-configured field management information, and generate an alarm event according to the field English names and field values;
[0015] The data sending module is used to report the alarm event to the target server according to the pre-configured server information.
[0016] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising:
[0017] at least one processor; and
[0018] a memory communicatively connected to the at least one processor; wherein,
[0019] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the data reporting method described in any embodiment of the present invention.
[0020] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the data reporting method described in any embodiment of the present invention when executed.
[0021] The technical solution of the embodiment of the present invention parses and filters the traffic data of the target data source to obtain the target traffic data to be reported, determines the first event type corresponding to the target traffic data according to a pre-configured reporting strategy, and obtains multiple first field names in the first event type and field values corresponding to each first field name, determines the field English names corresponding to each first field name according to the pre-configured field management information, and generates an alarm event according to the English name of each field and each field value, and reports the alarm event to the target server according to the pre-configured server information. The reporting configuration can be performed according to user needs, supports data template customization, realizes customized data reporting, realizes automatic mapping and conversion from traffic data to standardized reporting data, improves the efficiency and accuracy of data processing, and ensures the accuracy and completeness of reporting. By configuring the field management information, it can ensure that the reported data meets the specifications and standards required by the customer, and ensures the accuracy and completeness of reporting.
[0022] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present invention, nor are they intended to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0024] Figure 1 is a flow chart of a data reporting method provided according to Embodiment 1 of the present invention;
[0025] Figure 2 is a schematic diagram of a configuration page of a reporting strategy provided according to an embodiment of the present invention;
[0026] Figure 3 It is a schematic diagram of server information configuration in a reporting configuration function unit provided in an embodiment of the present invention;
[0027] Figure 4 is a flow chart of another data reporting method provided according to Embodiment 2 of the present invention;
[0028] Figure 5 is a schematic diagram of a reporting overview unit provided according to an embodiment of the present invention;
[0029] Figure 6 is a schematic diagram of an editing box provided according to an embodiment of the present invention;
[0030] Figure 7 is a structural diagram of a data reporting device provided according to Embodiment 3 of the present invention;
[0031] Figure 8 It is a structural schematic diagram of an electronic device for implementing the data reporting method of an embodiment of the present invention. DETAILED DESCRIPTION
[0032] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.
[0033] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0034] Embodiment 1
[0035] Figure 1 This is a flow chart of a data reporting method provided in the first embodiment of the present invention. This embodiment can be applied to the case where an alarm event is generated and reported to a target server when network data is abnormal. The method can be executed by a data reporting device, which can be implemented in the form of hardware and / or software and can generally be configured in a computer or processor with data processing capabilities. Figure 1 As shown, the method includes:
[0036] S110: Analyze and filter the traffic data of the target data source to obtain the target traffic data to be reported.
[0037] Optionally, the data reporting method described in the present invention can be integrated into a network security data reporting system, and the user can configure and obtain relevant information of the data reporting through the network security data reporting system.
[0038] Optionally, data reporting is for reporting security incidents such as network attacks and abnormal behaviors to the customer platform in order to display and remind customers of security incidents. The target data source can be a data source specified by the customer platform and with an open traffic data acquisition interface. Taking the financial field as an example, the target data source can be the transaction server of the securities trading platform, the interaction interface between financial institutions and third-party payment platforms, etc.
[0039] Optionally, traffic data may refer to a collection of data packets transmitted in the network, including information such as source address, destination address, transmission time, data content, etc., which can reflect the situation of network activities. Parsing traffic data may refer to disassembling and analyzing the traffic data generated by the target data source to extract valuable information, such as separating key elements such as source IP address, destination IP address, port number, data type, etc. from complex network data packets.
[0040] Optionally, in the network security data reporting system, multiple functional units may be pre-configured, such as reporting overview, reporting list, data type management, reporting policy management, reporting configuration, and monitoring and analysis.
[0041] Optionally, users can set filtering rules for traffic data in advance, and by filtering traffic data, they can exclude some known normal traffic, duplicate data, or data that does not meet the characteristics of specific security events, and only retain traffic data related to network security events and with quoted values, that is, target traffic data to be reported, to improve data processing efficiency and the quality of reported data.
[0042] S120. Determine a first event type corresponding to the target traffic data according to a preconfigured reporting strategy, and obtain a plurality of first field names in the first event type and field values corresponding to the first field names.
[0043] Optionally, in the reporting policy management function unit, the user can set multiple event types and edit the reporting policy for each event type according to the user's reporting requirements.
[0044] Optionally, event types may include, but are not limited to, alarm statistical verification data, DDOS (Distributed Denial of Service) attack data, malicious code infection data, malicious email data, counterfeit / phishing website data, counterfeit APP data, internal network attack data, external network attack data, website tampering data, abnormal external connection data, and network access security alarm data.
[0045] Optionally, for each event type, configure multiple field names of the event type, a mapping method for each field name, a mapping value, and sample data in the reporting strategy.
[0046] Optionally, field names can be customized by users. Taking the event type of counterfeit / phishing website data as an example, field names can include but are not limited to alarm ID, occurrence time, organization code, organization abbreviation, counterfeit website domain name, counterfeit website URL (Uniform Resource Locator), counterfeit website IP, counterfeited website domain name, counterfeit website business type, and reported data type.
[0047] Figure 2 The following is a schematic diagram of a configuration page for an optional reporting strategy. Figure 2 As shown, the mapping method of the field name can be selected by the user in the drop-down selection box. When the mapping method is a log field, the mapping value can be a specified field identifier. According to the field identifier, the field value corresponding to the field name can be extracted from the traffic data; when the mapping method is fixed data such as the organization code and the organization abbreviation, the mapping value is pre-configured, and the mapping value is the field value of the field name; when the mapping method is an alarm ID, the mapping value is configured to be automatically generated, that is, when an alarm event is generated, an ID value can be automatically generated according to the predefined generation rules as the field value of the alarm ID; when the mapping method is a standard enumeration item, one of the standard enumeration items can be determined according to the traffic data as the field value of the field name.
[0048] In a specific example, the mapping method of the occurrence time is a log field, and the mapping value is timestamp. When obtaining the field value of the occurrence time, the field identifier timestamp can be identified in the log, and the data identified by the timestamp is determined as the field value of the occurrence time.
[0049] Optionally, the sample data is a sample of the form of the field value of the field name. For example, for the occurrence time, its field value should be a specific date and time. If the field value is different from the sample form, it may indicate an error in field value extraction.
[0050] Optionally, by configuring the mapping method and the mapping value method, the extractable fields in the traffic data can be directly extracted according to the field value, which effectively improves the efficiency and accuracy of data processing.
[0051] Optionally, the first event type is a security event category determined after matching target traffic data through a reporting policy, and the first field name is a name of each field in a predefined first event type, used to describe and define specific attributes of the event.
[0052] S130. Determine, according to pre-configured field management information, field English names corresponding to the first field names, and generate an alarm event according to the field English names and field values.
[0053] Optionally, the user can pre-configure field management information for each event type in the data type management function unit. The field management information includes but is not limited to the field name, field English name, field type, whether it is a required item, and sample data.
[0054] Optionally, based on the field name, the English name of the field that matches the field name can be determined in the field management information. For example, when the first event type is counterfeit / phishing website data, the first field name under the event type includes the occurrence time, and its field value is 2024-10-0910:35:09. Based on the field management information, it can be determined that the English name of the field corresponding to the occurrence time is time.
[0055] Optionally, according to the field management information, the field value corresponding to the first field name may also be checked, and the field type includes but is not limited to an enumeration type (Enum), a string type (String), and a date and time type (Datatime).
[0056] Optionally, after determining the field English names corresponding to the first field names respectively according to the pre-configured field management information, the following may also be included:
[0057] Determine whether the field value corresponding to the first field name conforms to the field type corresponding to the first field name; if so, determine that the data of the field name conforms to the standard, and generate an alarm event based on the English name of each field and each field value; if not, determine the alarm event as an abnormal alarm event.
[0058] S140: Report the alarm event to the target server according to the pre-configured server information.
[0059] Optionally, in the reporting strategy management function unit, the user can also set the reporting timing. According to the reporting timing, the time point when the alarm time is reported to the target server can be determined, and when the event point is reached, the alarm time is reported to the target server.
[0060] Optionally, in the reporting configuration function unit, the user can configure the server information.
[0061] Figure 3 FIG. 1 is a schematic diagram of an optional configuration of server information in a reporting configuration function unit. Figure 3As shown, in the reporting configuration function unit, multiple data such as HTTP (HyperText Transfer Protocol) configuration name, request type, request path parameters, etc. can be configured. After generating an alarm event, the alarm event can be directly uploaded to the target server according to the configured server information. Then, the user can view the network security data of the target data source through the target server.
[0062] Optionally, also include:
[0063] The SSL protocol is used to encrypt data transmission between the network security data reporting system and the target server.
[0064] Optionally, encryption through the SSL (Secure Sockets Layer) protocol can ensure data security and reliability.
[0065] The technical solution of the embodiment of the present invention parses and filters the traffic data of the target data source to obtain the target traffic data to be reported, determines the first event type corresponding to the target traffic data according to a pre-configured reporting strategy, and obtains multiple first field names in the first event type and field values corresponding to each first field name, determines the field English names corresponding to each first field name according to the pre-configured field management information, and generates an alarm event according to the English name of each field and each field value, and reports the alarm event to the target server according to the pre-configured server information. The reporting configuration can be performed according to user needs, supports data template customization, realizes customized data reporting, realizes automatic mapping and conversion from traffic data to standardized reporting data, improves the efficiency and accuracy of data processing, and ensures the accuracy and completeness of reporting. By configuring the field management information, it can ensure that the reported data meets the specifications and standards required by the customer, and ensures the accuracy and completeness of reporting.
[0066] Embodiment 2
[0067] Figure 4 This is a flow chart of a data reporting method provided by Embodiment 2 of the present invention. Based on the above embodiments, this embodiment specifically describes a method for reporting data statistics and abnormal alarm event processing. Figure 4 As shown, the method includes:
[0068] S210: Analyze and filter the traffic data of the target data source to obtain the target traffic data to be reported.
[0069] S220: Determine a first event type corresponding to the target traffic data according to a preconfigured reporting strategy.
[0070] Optionally, after obtaining the target traffic data, the system will compare and analyze each key information in the data one by one according to the preset reporting strategy. For example, for a securities trading platform, the source IP address is one of the important factors in determining whether the traffic data is abnormal. If it is found that a source IP address does not come from a legitimate trading terminal or an authorized network range, but frequently sends transaction requests to the trading server, this may trigger the relevant rules in the reporting strategy.
[0071] S230. Determine a mapping relationship between each first field name and the target traffic data according to the reporting strategy, and determine a field value corresponding to each first field name according to the mapping relationship.
[0072] S240. Determine, according to pre-configured field management information, field English names corresponding to the first field names, and generate an alarm event according to the field English names and field values.
[0073] S250: Store the alarm event and the reporting status of the alarm event in a database of the network security data reporting system.
[0074] Optionally, the reporting status may include but is not limited to reported, pending for reporting, reporting failure, and abnormal situations.
[0075] The data reporting method may further include:
[0076] When responding to the data reporting overview request sent by the user, multiple statistical results within the target time interval are generated according to the historical alarm events stored in the database and the reporting status of each historical alarm event, and the statistical results are displayed.
[0077] Optionally, all alarm events stored in the database may be used as historical alarm events. After generating multiple statistical results, the statistical results may be displayed in the reporting overview function unit.
[0078] Figure 5 is a schematic diagram of an optional reporting overview unit. Figure 5 As shown, the statistical results may include the statistical count values of reported data, data to be reported, failed data and abnormal data within the specified time range, and may also display the number of historical alarm events of each event type within the specified time range in the form of a chart. Below the chart, the historical alarm event details of the reported data, data to be reported, failed data and abnormal data are displayed in a paged form. The alarm event details include at least event time, alarm ID, data type, source address, destination address, and may also include event status.
[0079] The advantage of this setting is that it can count and display the data reporting status within the specified time range, provide users with an intuitive global view, and realize visual management of data.
[0080] Optionally, the present invention provides a variety of statistical methods. In addition to the above-mentioned display in the form of quantitative statistics, it also provides display by setting filtering conditions.
[0081] The data reporting method may further include:
[0082] When responding to the report list query request sent by the user, obtaining the second event type and the filtering information in the report list query request;
[0083] According to the second event type and the screening information, a matching target historical alarm event is determined in the database, and according to the target historical alarm event and the reporting status of the target historical alarm event, a classification list is generated and displayed.
[0084] Optionally, the user can select a second event type in the reporting list function unit and fill in the filtering information under the second event type. When a reporting list query request sent by the user is received, the second event type and the filtering information can be determined according to the reporting list query request, and the historical alarm events belonging to the second event type can be determined in the database, and then the matching target historical alarm events can be further determined according to the filtering information, and the target historical alarm events can be displayed in the form of a list.
[0085] Optionally, the filtering information may include but is not limited to reporting ID, reporting method, alarm ID, event time, reporting time and creation time. After generating the classification list, the classification list may be further filtered through the reporting status option.
[0086] Optionally, in the classification list, the display information of the target historical alarm event includes but is not limited to the reporting ID, alarm ID, event time, reporting time, creation time, reporting method, reporting status, etc.
[0087] The advantage of this setting is that it classifies alarm events and provides detailed content display for user query and management.
[0088] S260: Report the alarm event to the target server according to the pre-configured server information.
[0089] The data reporting method may further include:
[0090] Real-time monitoring of the query interface provided by the target server;
[0091] According to the pre-configured notification information, when it is determined that an abnormal alarm event is monitored and meets the notification conditions, a notification email is generated and sent to the recipient at the specified notification time.
[0092] Optionally, in the monitoring and analysis unit, the interface address of the query interface can be pre-configured, and the network security data reporting system can monitor the query interface in real time. When the target server detects an abnormal alarm event, it can be returned through the query interface.
[0093] Optionally, in the monitoring and analysis unit, you can also pre-configure information such as recipients, monitoring conditions, notification time, email subject, and email format preview. Based on the monitoring conditions and notification time, you can determine whether the notification conditions are met. If they are met, a notification email is generated based on the abnormal alarm event, email format preview, and email subject, and sent to the designated recipient. For example, when the notification time is set to the hour, when the detected abnormal alarm event meets the monitoring conditions, a notification email is sent to the recipient at the hour.
[0094] The advantage of this setting is that the platform monitors abnormal situations in data reporting, such as data omissions and duplicate reporting, in real time, and prompts users through an automatic notification mechanism, which can promptly remind relevant persons in charge and ensure network data security.
[0095] The data reporting method may further include:
[0096] When responding to the user's editing operation on the target abnormal alarm event, determining each second field name of the target abnormal alarm event, the field value of each second field name, and the sample data of each second field name according to the target abnormal alarm event and the pre-configured reporting strategy;
[0097] An edit box is generated according to each second field name, the field value of each second field name and the sample data of each second field name, and the target field value that causes the reporting exception in the edit box is marked.
[0098] Optionally, if open source software is used for data reporting, the data will only be processed and reported according to the set process. If abnormal data is encountered, it will be discarded directly, and the content of the abnormal data cannot be modified again before reporting.
[0099] Optionally, the user can query the reporting status of each historical alarm event in the reporting overview function unit or the reporting list function unit. If an abnormal alarm event is found, the abnormal alarm event can be edited and the alarm event that meets the standard after editing can be reported again.
[0100] Optionally, the target abnormal alarm event may refer to the alarm event that the user is currently editing. According to the reporting strategy, the second field names in the target abnormal alarm event and the sample data corresponding to each second field name can be determined, and the field values corresponding to each second field name can be determined in the target abnormal alarm event, and an edit box can be generated according to the second field name, field value and sample data.
[0101] Figure 6 is a schematic diagram of an optional editing box. Figure 6 In the example shown, in this abnormal alarm event, the data abnormality is caused by the missing alarm device name. At this time, the field value position corresponding to the alarm device name can be prompted with text or the color of the fill box can be modified to prompt the user. The user can determine the reporting requirements based on the prompts of the sample data. After the supplement is completed according to the reporting requirements, the data can be reported again.
[0102] The technical solution of the embodiment of the present invention parses and filters the traffic data of the target data source to obtain the target traffic data to be reported, determines the first event type corresponding to the target traffic data according to the pre-configured reporting strategy, obtains multiple first field names in the first event type and the field values corresponding to each first field name, determines the field English name corresponding to each first field name according to the pre-configured field management information, generates an alarm event according to each field English name and each field value, and reports the alarm event to the target server according to the pre-configured server information. The method provides full-process management from data template customization, server configuration to data transmission, covers the core links of data reporting, supports users to customize data templates and configure reporting strategies through multiple functional units, and realizes visual management of data through reporting overviews and reporting lists, can monitor abnormal situations in data reporting in real time, and prompt users through automatic notification mechanisms, and support secondary modification of abnormal data before reporting, which can ensure that the reported data meets the specifications and standards required by customers and ensure the accuracy and completeness of the reporting.
[0103] Embodiment 3
[0104] Figure 7 This is a schematic diagram of the structure of a data reporting device provided in Embodiment 3 of the present invention. Figure 7 As shown, the device includes: a target traffic data acquisition module 310, a field value acquisition module 320, an alarm event generation module 330 and a data sending module 340.
[0105] The target flow data acquisition module 310 is used to parse and filter the flow data of the target data source to obtain the target flow data to be reported.
[0106] The field value acquisition module 320 is used to determine the first event type corresponding to the target traffic data according to a pre-configured reporting strategy, and obtain multiple first field names in the first event type and field values corresponding to each first field name.
[0107] The alarm event generation module 330 is used to determine the field English names corresponding to the first field names according to the pre-configured field management information, and generate an alarm event according to the field English names and field values.
[0108] The data sending module 340 is used to report the alarm event to the target server according to the pre-configured server information.
[0109] The technical solution of the embodiment of the present invention parses and filters the traffic data of the target data source to obtain the target traffic data to be reported, determines the first event type corresponding to the target traffic data according to a pre-configured reporting strategy, and obtains multiple first field names in the first event type and field values corresponding to each first field name, determines the field English names corresponding to each first field name according to the pre-configured field management information, and generates an alarm event according to the English name of each field and each field value, and reports the alarm event to the target server according to the pre-configured server information. The reporting configuration can be performed according to user needs, supports data template customization, realizes customized data reporting, realizes automatic mapping and conversion from traffic data to standardized reporting data, improves the efficiency and accuracy of data processing, and ensures the accuracy and completeness of reporting. By configuring the field management information, it can ensure that the reported data meets the specifications and standards required by the customer, and ensures the accuracy and completeness of reporting.
[0110] Based on the above embodiments, the field value acquisition module 320 can be specifically used for:
[0111] According to the reporting strategy, a mapping relationship between each first field name and the target traffic data is determined, and according to the mapping relationship, a field value corresponding to each first field name is determined.
[0112] Based on the above embodiments, a data storage module may also be included for:
[0113] The alarm event and the reporting status of the alarm event are stored in a database of the network security data reporting system.
[0114] Based on the above embodiments, a statistical overview module may also be included, which is used to:
[0115] When responding to the data reporting overview request sent by the user, multiple statistical results within the target time interval are generated according to the historical alarm events stored in the database and the reporting status of each historical alarm event, and the statistical results are displayed.
[0116] Based on the above embodiments, a query display module may also be included, which is used to:
[0117] When responding to the report list query request sent by the user, obtaining the second event type and the filtering information in the report list query request;
[0118] According to the second event type and the screening information, a matching target historical alarm event is determined in the database, and according to the target historical alarm event and the reporting status of the target historical alarm event, a classification list is generated and displayed.
[0119] Based on the above embodiments, an abnormality notification module may be further included, which is used to:
[0120] Real-time monitoring of the query interface provided by the target server;
[0121] According to the pre-configured notification information, when it is determined that an abnormal alarm event is monitored and meets the notification conditions, a notification email is generated and sent to the recipient at the specified notification time.
[0122] On the basis of the above embodiments, an abnormal alarm event editing module may also be included, which is used to:
[0123] When responding to the user's editing operation on the target abnormal alarm event, determining each second field name of the target abnormal alarm event, the field value of each second field name, and the sample data of each second field name according to the target abnormal alarm event and the pre-configured reporting strategy;
[0124] An edit box is generated according to each second field name, the field value of each second field name and the sample data of each second field name, and the target field value that causes the reporting exception in the edit box is marked.
[0125] The data reporting device provided in the embodiment of the present invention can execute the data reporting method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0126] Embodiment 4
[0127] Figure 8A schematic diagram of the structure of an electronic device 10 that can be used to implement an embodiment of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or required herein.
[0128] like Figure 8 As shown, the electronic device 10 includes at least one processor 11, and a memory connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., wherein the memory stores a computer program that can be executed by at least one processor, and the processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 to the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0129] A number of components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0130] The processor 11 may be a variety of general and / or special processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, digital signal processors (DSPs), and any appropriate processors, controllers, microcontrollers, etc. The processor 11 executes the various methods and processes described above, such as the data reporting method described in the embodiment of the present invention. That is:
[0131] Analyze and filter the traffic data of the target data source to obtain the target traffic data to be reported;
[0132] According to a pre-configured reporting strategy, determine a first event type corresponding to the target traffic data, and obtain multiple first field names in the first event type and field values corresponding to each first field name;
[0133] Determine, according to the pre-configured field management information, the field English names corresponding to the first field names respectively, and generate an alarm event according to the field English names and the field values;
[0134] According to the pre-configured server information, the alarm event is reported to the target server.
[0135] In some embodiments, the data reporting method may be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as a storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the data reporting method described above may be performed. Alternatively, in other embodiments, the processor 11 may be configured to perform the data reporting method in any other appropriate manner (e.g., by means of firmware).
[0136] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), load programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0137] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that when the computer program is executed by the processor, the functions / operations specified in the flow chart and / or block diagram are implemented. The computer program may be executed entirely on the machine, partially on the machine, partially on the machine and partially on a remote machine as a stand-alone software package, or entirely on a remote machine or server.
[0138] In the context of the present invention, a computer-readable storage medium may be a tangible medium that may contain or store a computer program for use by or in combination with an instruction execution system, device or equipment. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0139] To provide interaction with a user, the systems and techniques described herein may be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices may also be used to provide interaction with the user; for example, the feedback provided to the user may be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user may be received in any form (including acoustic input, voice input, or tactile input).
[0140] The systems and techniques described herein may be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system may be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0141] A computing system may include a client and a server. The client and the server are generally remote from each other and usually interact through a communication network. The client and server relationship is generated by computer programs running on the corresponding computers and having a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system to solve the defects of difficult management and weak business scalability in traditional physical hosts and VPS services.
[0142] It should be understood that the various forms of processes shown above can be used to reorder, add or delete steps. For example, the steps described in the present invention can be executed in parallel, sequentially or in different orders, as long as the desired results of the technical solution of the present invention can be achieved, and this document does not limit this.
[0143] The above specific implementations do not constitute a limitation on the protection scope of the present invention. It should be understood by those skilled in the art that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modification, equivalent substitution and improvement made within the spirit and principle of the present invention should be included in the protection scope of the present invention.
Claims
1. A data reporting method, executed by a network security data reporting system, characterized in that: include: Analyze and filter the traffic data of the target data source to obtain the target traffic data to be reported; According to a pre-configured reporting strategy, determine a first event type corresponding to the target traffic data, and obtain multiple first field names in the first event type and field values corresponding to each first field name; Determine, according to the pre-configured field management information, the field English names corresponding to the first field names respectively, and generate an alarm event according to the field English names and the field values; According to the pre-configured server information, the alarm event is reported to the target server.
2. The method according to claim 1, characterized in that Acquiring multiple first field names in the first event type and field values corresponding to each first field name, including: According to the reporting strategy, a mapping relationship between each first field name and the target traffic data is determined, and according to the mapping relationship, a field value corresponding to each first field name is determined.
3. The method according to claim 1, characterized in that After generating an alarm event based on the English name of each field and the value of each field, it also includes: The alarm event and the reporting status of the alarm event are stored in a database of the network security data reporting system.
4. The method according to claim 3, characterized in that Also includes: When responding to the data reporting overview request sent by the user, multiple statistical results within the target time interval are generated according to the historical alarm events stored in the database and the reporting status of each historical alarm event, and the statistical results are displayed.
5. The method according to claim 3, characterized in that: Also includes: When responding to the report list query request sent by the user, obtaining the second event type and the filtering information in the report list query request; According to the second event type and the screening information, a matching target historical alarm event is determined in the database, and according to the target historical alarm event and the reporting status of the target historical alarm event, a classification list is generated and displayed.
6. The method according to claim 1, characterized in that Also includes: Real-time monitoring of the query interface provided by the target server; According to the pre-configured notification information, when it is determined that an abnormal alarm event is monitored and meets the notification conditions, a notification email is generated and sent to the recipient at the specified notification time.
7. The method according to claim 6, characterized in that Also includes: When responding to the user's editing operation on the target abnormal alarm event, determining each second field name of the target abnormal alarm event, the field value of each second field name, and the sample data of each second field name according to the target abnormal alarm event and the pre-configured reporting strategy; An edit box is generated according to each second field name, the field value of each second field name and the sample data of each second field name, and the target field value that causes the reporting exception in the edit box is marked.
8. A data reporting device, executed by a network security data reporting system, characterized in that: include: The target flow data acquisition module is used to parse and filter the flow data of the target data source to obtain the target flow data to be reported; A field value acquisition module, used to determine a first event type corresponding to the target traffic data according to a pre-configured reporting strategy, and obtain a plurality of first field names in the first event type and field values corresponding to each first field name; An alarm event generation module, used to determine the field English names corresponding to the first field names according to the pre-configured field management information, and generate an alarm event according to the field English names and field values; The data sending module is used to report the alarm event to the target server according to the pre-configured server information.
9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the data reporting method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the data reporting method according to any one of claims 1 to 7 when executed.