Entity relationship determination method and computing device

By automatically extracting and determining IP entity data and its relationships, the inefficiency problem caused by changes in IP address format in the prior art is solved, and efficient and accurate acquisition of IP entity data is achieved.

CN119996373APending Publication Date: 2025-05-13HENAN QINWEI DIGITAL TECHNOLOGY CO LTD
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
CN202411944609.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-26
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

In the prior art, when the IP address format is changed, regular expressions need to be re-written, resulting in inefficient, high labor costs and high error rates.

Method used

By obtaining server log data, the IP entity data and its relationships are automatically extracted and determined based on the preset relationship between the target IP entity and the target IP entity, and avoid manually writing regular expressions.

Benefits of technology

Improve the efficiency and accuracy of IP entity data and entity relationships, and reduce labor costs and error rates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996373A_ABST
    Figure CN119996373A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides an entity relationship determination method and computing equipment. The method comprises the following steps: acquiring log data generated in the running process of a server; extracting IP entity data in the log data based on a preset target IP entity; determining an entity relationship between the IP entity data based on a preset target IP entity relationship; wherein the preset IP entity relationship is used for indicating the relationship between the two target IP entities. Through the above mode, the acquisition efficiency and accuracy of the entity relationship between the IP entity data and the IP entity data are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of computing devices, and in particular to a method for determining entity relationships and a computing device. Background Art

[0002] With the rapid development of the Internet, the scale of the global network is growing exponentially. The number of Internet Protocol (IP) addresses, which are used as the identification of devices on the Internet, is also increasing. On the Internet, the allocation and use of IP addresses involve many entities (such as enterprises, individual users, etc.). Attackers can attack other IP addresses through malicious IP addresses. Therefore, in order to prevent network attacks, it is crucial to quickly and accurately extract IP addresses from log data to accurately identify the source of malicious IP addresses.

[0003] In the related art, the administrator needs to know the format of the IP address in advance and manually write a regular expression that matches the format of the IP address, so as to use the regular expression to extract and process the IP address in the log data.

[0004] However, the method in the related art needs to spend time and effort to write a regular expression again when the format of the IP address changes, which leads to the problem of low efficiency of the method in the related art. Summary of the invention

[0005] The embodiment of the present application provides a method for determining IP entity data and a computing device, which improves the efficiency of obtaining IP entity data and entity relationships between IP entity data.

[0006] In a first aspect, an embodiment of the present application provides a method for determining an entity relationship, including:

[0007] Get the log data generated during the server operation;

[0008] Based on the preset target IP entity, extract the IP entity data in the log data;

[0009] Based on a preset target IP entity relationship, an entity relationship between IP entity data is determined; wherein the preset target IP entity relationship is used to indicate a relationship between two target IP entities.

[0010] In this solution, the computing device can obtain the log data generated during the operation of the server. The computing device can extract the IP entity data in the log data based on the preset target IP entity, and determine the entity relationship between the IP entity data based on the preset target IP entity relationship (used to indicate the relationship between two target IP entities). Through the above method, the IP entity data can be automatically extracted from the log data using the preset target IP entity, which improves the efficiency and accuracy of obtaining the IP entity data, avoids the problem of high labor cost, high error rate and low efficiency caused by manually arranging regular expressions to extract IP addresses. In addition, through the above method, the entity relationship between the IP entity data can also be automatically determined using the preset target IP entity relationship, thereby realizing accurate and rapid acquisition of the entity relationship between the IP entity data.

[0011] In one implementation, the method further includes:

[0012] Get sample logs;

[0013] Based on the sample log, determine the IP entity and the relationship between the two IP entities associated in the sample log;

[0014] The relationship between two associated IP entities is recorded as an IP entity relationship.

[0015] In this solution, the computing device can obtain the sample log. The computing device can determine the IP entity based on the sample log, and determine the relationship between the two IP entities associated in the sample log. The computing device can record the relationship between the two associated IP entities as an IP entity relationship. In the above manner, the computing device can obtain the IP entity and the IP entity relationship in advance, so that after obtaining the log data, the computing device can directly determine the IP entity data and the entity relationship between the IP entity data based on the selected target IP entity and the target IP entity relationship, thereby improving the efficiency of obtaining the IP entity data and the entity relationship between the IP entity data.

[0016] In one implementation, the sample log includes a plurality of sub-sample logs; based on the sample log, determining the IP entity, and determining the relationship between two IP entities associated in the sample log, including:

[0017] For any sub-sample log, based on the IP entity model, the sample log data is extracted and processed to obtain two IP entities; wherein multiple attribute fields in the IP entity match multiple model fields in the IP entity model;

[0018] Determine the relationship between two IP entities based on the relationship field in the sub-sample log.

[0019] In this solution, the sample log includes multiple sub-sample logs. For any sub-sample log, based on the IP entity model, the sample log data is extracted and processed to obtain two IP entities (multiple attribute fields in the IP entity match multiple model fields in the IP entity model), and the relationship between the two IP entities is determined based on the relationship field in the sub-sample log. Through the above method, the rapid, automatic, and large-scale acquisition of IP entities is achieved, and the accuracy and efficiency of IP entity acquisition are improved.

[0020] In one implementation, the method further includes:

[0021] Record the correspondence between IP entities, IP entity relationships and sample logs.

[0022] In this solution, the computing device can also record the correspondence between the IP entities and the IP entity relationships and the sample logs after extracting the IP entities and the IP entity relationships from the sample logs, thereby realizing data traceability, improving the transparency and reliability of data management, and realizing the effective establishment of a comprehensive security monitoring system.

[0023] In one implementation, before extracting IP entity data from the log data based on a preset target IP entity, the method further includes:

[0024] Determine the corresponding target sample log according to the log type of the log data;

[0025] According to the target sample log, find the corresponding relationship and determine the target IP entity and the target IP entity relationship.

[0026] In this solution, the computing device can determine the corresponding target sample log according to the log type of the log data, and find the corresponding relationship according to the target sample log to determine the target IP entity and the target IP entity relationship. In this way, the target IP entity and the target IP entity relationship that match the log type of the log data can be accurately obtained, thereby improving the efficiency of extracting the IP entity data and the entity relationship between the IP entity data based on the target IP entity and the target IP entity relationship.

[0027] In one implementation, the log data includes at least one sub-log data; based on a preset target IP entity, extracting IP entity data from the log data includes:

[0028] Determine multiple attribute fields in the target IP entity;

[0029] For any sub-log data, according to multiple attribute fields in the target IP entity and multiple attribute fields in the sub-log data, determine a first target IP entity and a second target IP entity from multiple target IP entities;

[0030] According to the multiple attribute fields in the first target IP entity and the multiple attribute fields in the second target IP entity, the sub-log data is extracted and processed to obtain two IP entity data.

[0031] In this solution, the computing device can determine multiple attribute fields in the target IP entity. For any sub-log data, the computing device can determine the first target IP entity and the second target IP entity among multiple target IP entities based on the multiple attribute fields in the target IP entity and the multiple attribute fields in the sub-log data, and extract and process the sub-log data based on the multiple attribute fields in the first target IP entity and the multiple attribute fields in the second target IP entity to obtain two IP entity data. The above method can be used to automatically and quickly extract two IP entity data from the log data using the preset target IP entity, thereby improving the efficiency and accuracy of obtaining IP entity data and avoiding the problem of high labor cost, high error rate and low efficiency caused by manually arranging regular expressions to extract IP addresses.

[0032] In one implementation, for any first IP entity data, the method further includes:

[0033] Display the first IP entity data and the viewing control of the first IP entity data; the viewing control is used to trigger the display of the entity relationship between the first IP entity data and at least one second IP entity data.

[0034] In this solution, for any first IP entity data, the computing device can display the first IP entity data and the viewing control of the first IP entity data. The viewing control is used to trigger the display of the entity relationship between the first IP entity data and at least one second IP entity data. By displaying the first IP entity data and the viewing control of the first IP entity data, the management personnel can intuitively identify security threats (such as abnormal IP addresses, abnormal behaviors, etc.) based on the entity relationship between the IP entity data and the IP entity data, thereby improving network security.

[0035] In one implementation, the method further includes:

[0036] In response to an operation on a viewing control of the first IP entity data, a target page is displayed; the target page includes a network graph corresponding to the first IP entity data;

[0037] The network graph is used to indicate the entity relationship between the first IP entity data and at least one second IP entity data.

[0038] In this solution, the computing device can display a target page in response to an operation on a viewing control of the first IP entity data; the target page includes a network map corresponding to the first IP entity data; wherein the network map is used to indicate the entity relationship between the first IP entity data and at least one second IP entity data. By displaying the target page in the above manner, the administrator can intuitively view the entity relationship between the first IP entity data and at least one second IP entity data, that is, the communication path and communication behavior between each entity data can be intuitively viewed, thereby enabling the administrator to quickly identify security threats (such as abnormal IP addresses, abnormal behaviors, etc.), thereby improving network security.

[0039] In one implementation, the network graph includes: a first entity node corresponding to the first IP entity data, a second entity node corresponding to each second IP entity data, and entity connection type information between the first entity node and each second entity node;

[0040] Among them, the first entity node includes the IP address and port number of the first IP entity data, the second entity node includes the IP address and port number of the second IP entity data, and the entity connection type information includes: entity connection, entity relationship, and communication times; the communication times correspond to the first IP entity data and the second IP entity data.

[0041] In this solution, the network map includes: a first entity node corresponding to the first IP entity data, a second entity node corresponding to each second IP entity data, and entity connection type information between the first entity node and each second entity node; wherein the first entity node includes the IP address and port number of the first IP entity data, the second entity node includes the IP address and port number of the second IP entity data, and the entity connection type information includes: entity connection, entity relationship, and communication times; the communication times correspond to the first IP entity data and the second IP entity data. Through the above method, the management personnel can intuitively view the communication path and communication behavior between the entity data, and then the management personnel can quickly identify security threats (such as abnormal IP addresses, abnormal behaviors, etc.), thereby improving network security.

[0042] In a second aspect, an embodiment of the present application provides a device for determining an entity relationship, including:

[0043] The acquisition module is used to obtain the log data generated during the operation of the server;

[0044] A processing module, used for extracting IP entity data from log data based on a preset target IP entity;

[0045] The processing module is also used to determine the entity relationship between the IP entity data based on a preset target IP entity relationship; wherein the preset target IP entity relationship is used to indicate the relationship between two target IP entities.

[0046] The entity relationship determination device provided in the embodiment of the present application can execute the technical solution shown in the above method embodiment, and its implementation principle and beneficial effects are similar, which will not be repeated here.

[0047] In this scheme,

[0048] In one implementation,

[0049] The acquisition module is also used to obtain sample logs;

[0050] The processing module is further used to determine the IP entity based on the sample log, and determine the relationship between two IP entities associated in the sample log;

[0051] The processing module is further used to record the relationship between two associated IP entities as an IP entity relationship.

[0052] The entity relationship determination device provided in the embodiment of the present application can execute the technical solution shown in the above method embodiment, and its implementation principle and beneficial effects are similar, which will not be repeated here.

[0053] In one implementation, the sample log includes a plurality of sub-sample logs; and the processing module is specifically configured to:

[0054] For any sub-sample log, based on the IP entity model, the sample log data is extracted and processed to obtain two IP entities; wherein multiple attribute fields in the IP entity match multiple model fields in the IP entity model;

[0055] Determine the relationship between two IP entities based on the relationship field in the sub-sample log.

[0056] The entity relationship determination device provided in the embodiment of the present application can execute the technical solution shown in the above method embodiment, and its implementation principle and beneficial effects are similar, which will not be repeated here.

[0057] In one implementation, the processing module is further configured to:

[0058] Record the correspondence between IP entities, IP entity relationships and sample logs.

[0059] The entity relationship determination device provided in the embodiment of the present application can execute the technical solution shown in the above method embodiment, and its implementation principle and beneficial effects are similar, which will not be repeated here.

[0060] In one implementation, the processing module is further configured to:

[0061] Determine the corresponding target sample log according to the log type of the log data;

[0062] According to the target sample log, find the corresponding relationship and determine the target IP entity and the target IP entity relationship.

[0063] The entity relationship determination device provided in the embodiment of the present application can execute the technical solution shown in the above method embodiment, and its implementation principle and beneficial effects are similar, which will not be repeated here.

[0064] In one implementation, the log data includes at least one sub-log data; the processing module is specifically applied to:

[0065] Determine multiple attribute fields in the target IP entity;

[0066] For any sub-log data, according to multiple attribute fields in the target IP entity and multiple attribute fields in the sub-log data, determine a first target IP entity and a second target IP entity from multiple target IP entities;

[0067] According to the multiple attribute fields in the first target IP entity and the multiple attribute fields in the second target IP entity, the sub-log data is extracted and processed to obtain two IP entity data.

[0068] The entity relationship determination device provided in the embodiment of the present application can execute the technical solution shown in the above method embodiment, and its implementation principle and beneficial effects are similar, which will not be repeated here.

[0069] In one implementation, for any first IP entity data, the display module is used to:

[0070] Display the first IP entity data and the viewing control of the first IP entity data; the viewing control is used to trigger the display of the entity relationship between the first IP entity data and at least one second IP entity data.

[0071] The entity relationship determination device provided in the embodiment of the present application can execute the technical solution shown in the above method embodiment, and its implementation principle and beneficial effects are similar, which will not be repeated here.

[0072] In one implementation, the display module is further configured to:

[0073] In response to an operation on a viewing control of the first IP entity data, a target page is displayed; the target page includes a network graph corresponding to the first IP entity data;

[0074] The network graph is used to indicate the entity relationship between the first IP entity data and at least one second IP entity data.

[0075] The entity relationship determination device provided in the embodiment of the present application can execute the technical solution shown in the above method embodiment, and its implementation principle and beneficial effects are similar, which will not be repeated here.

[0076] In one implementation, the network graph includes: a first entity node corresponding to the first IP entity data, a second entity node corresponding to each second IP entity data, and entity connection type information between the first entity node and each second entity node;

[0077] Among them, the first entity node includes the IP address and port number of the first IP entity data, the second entity node includes the IP address and port number of the second IP entity data, and the entity connection type information includes: entity connection, entity relationship, and communication times; the communication times correspond to the first IP entity data and the second IP entity data.

[0078] The entity relationship determination device provided in the embodiment of the present application can execute the technical solution shown in the above method embodiment, and its implementation principle and beneficial effects are similar, which will not be repeated here.

[0079] In a third aspect, an embodiment of the present application provides a computing device, the computing device comprising a memory and a processor;

[0080] The memory is coupled to the processor;

[0081] Memory is used to store computer instructions;

[0082] The processor is used to execute computer instructions to enable the computing device to implement the method of the first aspect.

[0083] The computing device provided in the embodiment of the present application can execute the technical solution shown in the above method embodiment, and its implementation principle and beneficial effects are similar, which will not be repeated here.

[0084] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, they are used to implement the method of the first aspect.

[0085] When the computer-executable instructions in the computer-readable storage medium provided in the embodiment of the present application are executed by the processor, the technical solution shown in the above method embodiment can be implemented. The implementation principle and beneficial effects are similar and will not be repeated here.

[0086] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program, which is used to implement the method of the first aspect when the computer program is executed by a processor.

[0087] When the computer program in the computer program product provided in the embodiment of the present application is executed by a processor, the technical solution shown in the above method embodiment can be implemented. The implementation principle and beneficial effects are similar and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0088] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, a brief introduction will be given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0089] Figure 1 A schematic diagram of a scenario of a method for determining an entity relationship provided in an embodiment of the present application;

[0090] Figure 2 A flowchart of a method for determining an entity relationship according to an embodiment of the present application;

[0091] Figure 3a A flowchart of a second embodiment of a method for determining an entity relationship provided in an embodiment of the present application;

[0092] Figure 3b A schematic diagram showing entity relationships provided in an embodiment of the present application;

[0093] Figure 3c A schematic diagram showing an IP entity model provided in an embodiment of the present application;

[0094] Figure 4a A flowchart of a third embodiment of a method for determining an entity relationship provided in an embodiment of the present application;

[0095] Figure 4b A schematic diagram of a display of at least two IP entity data and a viewing control of each IP entity data provided by an embodiment of the present application;

[0096] Figure 5a A flowchart of a fourth embodiment of a method for determining an entity relationship provided in an embodiment of the present application;

[0097] Figure 5b A schematic diagram of displaying a target page provided in an embodiment of the present application;

[0098] Figure 6A schematic diagram of the structure of an entity relationship determination device provided in an embodiment of the present application;

[0099] Figure 7 A schematic diagram of the structure of a computing device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0100] In order to make the purpose, technical solution and advantages of the embodiments of the present application clearer, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments made by ordinary technicians in this field under the enlightenment of the embodiments belong to the scope of protection of the present application.

[0101] The terms "first", "second", "third", "fourth", etc. (if any) in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0102] With the rapid development of the Internet, the scale of the global network is growing exponentially. The number of IP addresses, which are used to identify devices on the Internet, is also increasing. On the Internet, the allocation and use of IP addresses involve many entities. Attackers can attack other IP addresses through malicious IP addresses. Therefore, in order to prevent network attacks, it is crucial to quickly and accurately extract IP addresses from log data to accurately identify the source of malicious IP addresses.

[0103] In the related art, the administrator needs to know the format of the IP address in advance and manually write a regular expression that matches the format of the IP address, so as to use the regular expression to extract and process the IP address in the log data.

[0104] However, the method in the related art needs to spend time and effort to write a regular expression again when the format of the IP address changes, which leads to the problem of low efficiency of the method in the related art.

[0105] Based on the above technical problems, the embodiment of the present application provides a method for determining entity relationships, and a computing device can obtain log data generated during the operation of a server. The computing device can extract IP entity data in the log data based on a preset target IP entity, and determine the entity relationship between the IP entity data based on a preset target IP entity relationship (used to indicate the relationship between two target IP entities).

[0106] Through the above method, the efficiency of obtaining IP entity data and entity relationships between IP entity data is improved.

[0107] The following is a detailed description of the method for determining the entity relationship of the embodiment of the present application.

[0108] Figure 1 A schematic diagram of a scenario of a method for determining an entity relationship provided in an embodiment of the present application. Figure 1 As shown, the scenario includes a computing device 10 and a terminal device 20 , a database server 30 , and a server 40 .

[0109] The computing device 10 may be a terminal device, a server, or a server cluster.

[0110] When the computing device 10 is a server, from an architectural point of view, the server can be a rack server, a high-density server, a tower server or a whole cabinet server; from a functional point of view, the server can be a general-purpose server or an artificial intelligence server (AI (artificial intelligence) server), etc. For example, the artificial intelligence server can be a graphics processing server (GPU (graphics processing unit) server).

[0111] When the computing device 10 is a terminal device, the terminal device may be, but is not limited to, various personal computers, laptops, smart phones, and tablet computers.

[0112] It should be noted that, when the computing device 10 is a terminal device, the computing device 10 and the terminal device 20 may be the same device or different devices.

[0113] It should be noted that, when the computing device 10 is a server, the computing device 10, the database server 30, and the server 40 may be the same server or different servers, and the embodiment of the present application does not limit this. When the computing device 10 is a server cluster, the database server 30 and the server 40, and at least one server in the computing device 10, may be the same server or different servers, and the embodiment of the present application does not limit this.

[0114] In this scenario, the computing device 10 may obtain log data generated during the operation of the server 40. In one implementation, the log data may be sent by the database server 30. In one implementation, the log data may be sent directly by the server 40.

[0115] The computing device 10 may extract IP entity data from the log data based on preset target IP entity data.

[0116] The computing device 10 may determine the entity relationship between the IP entity data based on a preset target IP entity relationship; wherein the preset target IP entity relationship is used to indicate the relationship between two target IP entities.

[0117] It should be noted that Figure 1 This is a schematic diagram of the scenario provided by the embodiment of the present application. The embodiment of the present application is not Figure 1 The actual form of the various devices included in the Figure 1 The interaction mode between devices is limited, and in the application of the solution, it can be set according to actual needs.

[0118] The technical solution of the present application is described in detail below through specific embodiments. It should be noted that the following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described in detail in some embodiments.

[0119] Figure 2 A flowchart of a method for determining an entity relationship provided in an embodiment of the present application. Figure 2 , the method specifically comprises the following steps:

[0120] S201: Obtain log data generated during the operation of the server.

[0121] In this embodiment, the server may generate log data during operation.

[0122] The computing device can obtain the log data generated during the operation of the server.

[0123] In one implementation, the database server may obtain the log data sent by the server. The database server may store the log data. The computing device may obtain the log data sent by the database server.

[0124] In one implementation, the server stores log data generated during the operation of the server, and the computing device can obtain the log data sent by the server.

[0125] It should be noted that the computing device can also obtain log data in other ways, and the embodiments of the present application are not limited to this.

[0126] S202: Extracting IP entity data from log data based on a preset target IP entity.

[0127] In this embodiment, the computing device may extract IP entity data from the log data based on a preset target IP entity.

[0128] In one implementation,

[0129] After acquiring the log data generated during the operation of the server, the computing device can determine the corresponding target sample log according to the log type of the log data. For example, the computing device can determine that the corresponding target sample log is an alarm sample log according to the log type of the log data being an alarm log type.

[0130] The computing device can search for a corresponding relationship based on the target sample log to determine the target IP entity and the target IP entity relationship, wherein the corresponding relationship is a corresponding relationship between the IP entity and the IP entity relationship and the sample log.

[0131] It should be noted that an IP entity relationship is a relationship between two associated IP entities. It should also be noted that an IP entity refers to an object that has independent existence, distinguishability, and some association with other IP entities. An IP entity may include multiple attribute fields. It should be noted that the attribute field is used to describe the characteristics of the IP entity during the communication process. Exemplarily, an IP entity may include four attribute fields, namely src_ip (source IP address), ip_protocol (IP protocol), src_port (source port number), and alarm_content (alarm content).

[0132] The computing device may extract IP entity data from the log data based on the target IP entity.

[0133] In one implementation,

[0134] After acquiring the log data generated during the operation of the server, the computing device can search for a corresponding relationship according to the log type of the log data to determine the target IP entity and the target IP entity relationship, wherein the corresponding relationship is the corresponding relationship between the IP entity and the IP entity relationship and the log type.

[0135] The computing device may extract IP entity data from the log data based on the target IP entity.

[0136] The following describes a process in which a computing device extracts IP entity data from log data based on a target IP entity.

[0137] In one implementation,

[0138] The log data includes at least one sub-log data.

[0139] The computing device may determine multiple attribute fields in the target IP entity. It should be noted that the attribute fields are used to describe the characteristics of the target IP entity during the communication process. Exemplarily, a target IP entity may include four attribute fields, namely dst_ip, ip_protocol, dst_port, and alarm_content.

[0140] For any sub-log data, the computing device can determine the first target IP entity and the second target IP entity from among the multiple target IP entities according to the multiple attribute fields in the target IP entity and the multiple attribute fields in the sub-log data. It should be noted that the first target IP entity and the second target IP entity are target IP entities whose attribute fields are the same as the attribute fields in the sub-log data.

[0141] The computing device can extract and process the sub-log data according to the multiple attribute fields in the first target IP entity and the multiple attribute fields in the second target IP entity to obtain two IP entity data. In one implementation, the computing device can extract multiple first keywords in the sub-log data according to the multiple attribute fields in the first target IP entity, and generate an IP entity data according to the multiple first keywords. It should be noted that the attribute field corresponding to the first keyword in the sub-log data is the same as the attribute field in the first target IP entity. The computing device can extract multiple second keywords in the sub-log data according to the multiple attribute fields in the second target IP entity, and generate an IP entity data according to the multiple second keywords. It should be noted that the attribute field corresponding to the second keyword in the sub-log data is the same as the attribute field in the second target IP entity.

[0142] The following describes a process in which a computing device extracts IP entity data from log data based on a preset target IP entity through a specific example.

[0143] For example, there are five target IP entities, namely target IP entity 1, target IP entity 2, target IP entity 3, target IP entity 4, and target IP entity 5.

[0144] The computing device may determine a plurality of attribute fields in the target IP entity.

[0145] For a sub-log data in the log data:

[0146] {"name":"li1","record_time":"1698049107312","start_time":"1698049107312","alarm_le vel":1,"is_ipv6":0,"src_ip":"10.223.1.24","src_port":"42784","src_country":"901","src_provin ce":"901001","src_city":"90664","dst_ip":"183.220.108.39","dst_port":"34448","dst_country":"156","dst_province":"15 6032","dst_city":"15286","ip_protocol":"TCP","alarm_rule":"warn","alarm_content":"warn","rule_id":2,"send_mail":0}.

[0147] Based on the fact that multiple attribute fields (src_ip, ip_protocol, src_port, and alarm_content) in the target IP entity 3 are the same as the multiple attribute fields in the sub-log data, and multiple attribute fields (dst_ip, ip_protocol, dst_port, and alarm_content) in the target IP entity 4 are the same as the multiple attribute fields in the sub-log data, the computing device can determine that the target IP entity 3 is the first target IP entity, and determine that the target IP entity 4 is the second target IP entity.

[0148] The computing device may extract and process the sub-log data according to multiple attribute fields in the first target IP entity and multiple attribute fields in the second target IP entity to obtain two IP entity data.

[0149] For example, in the process of extracting an IP entity data,

[0150] For the attribute field src_ip in the first target IP entity, the computing device can extract the first keyword 10.223.1.24 in the sub-log data. It should be noted that in the sub-log data "…"src_ip":"10.223.1.24"…", the attribute field (src_ip) corresponding to the first keyword (10.223.1.24) is the same as the attribute field (src_ip) in the first target IP entity.

[0151] With respect to the attribute field ip_protocol in the first target IP entity, the computing device may extract the first keyword TCP from the sub-log data.

[0152] For the attribute field src_port in the first target IP entity, the computing device may extract the first keyword 42784 from the sub-log data.

[0153] For the attribute field alarm_content in the first target IP entity, the computing device may extract the first keyword warm from the sub-log data.

[0154] The computing device may generate an IP entity data—first IP entity data—based on 10.223.1.24, TCP, 42784, and warm.

[0155] In the process of extracting data from another IP entity,

[0156] For the attribute field dst_ip in the second target IP entity, the computing device may extract the second keyword 183.220.108.39 from the sub-log data.

[0157] With respect to the attribute field ip_protocol in the second target IP entity, the computing device may extract the second keyword TCP from the sub-log data.

[0158] For the attribute field dst_port in the second target IP entity, the computing device may extract the second keyword 34448 from the sub-log data.

[0159] For the attribute field alarm_content in the second target IP entity, the computing device may extract the second keyword warm from the sub-log data.

[0160] The computing device may generate an IP entity data—second IP entity data—based on 183.220.108.39, TCP, 34448, and warm.

[0161] In addition, it should be noted that the computing device can determine that each IP entity data can also include at least one or more of the following: IP entity model, discovery time, last update time, discovery method, label, and log type of log data.

[0162] It should be noted that, taking the first IP entity data as an example, the discovery time refers to the time when the multiple first keywords included in the first IP entity data are extracted for the first time; the last update time refers to the time when the multiple first keywords included in the first IP entity data are extracted for the last time; the discovery method includes automatic discovery or manual discovery; the label can be a label manually set by the administrator for the IP entity data; the log type of the log data is the log type of the log data to which the sub-log data from which the multiple first keywords are extracted belongs.

[0163] In addition, in one implementation, the IP entity data may also include whether to join the blacklist. Through the above method, the workload of the management personnel is reduced and the management efficiency is improved.

[0164] S203: Determine the entity relationship between IP entity data based on the preset target IP entity relationship.

[0165] In this embodiment, the computing device may determine the entity relationship between IP entity data based on a preset target IP entity relationship.

[0166] The preset target IP entity relationship is used to indicate the relationship between two target IP entities.

[0167] In one implementation,

[0168] For any sub-log data, the computing device can determine the first target IP entity and the second target IP entity in the process of extracting and processing the sub-log data to obtain two IP entity data. After determining the first target IP entity and the second target IP entity, the computing device can determine the relationship between the first target IP entity and the second target IP entity as the entity relationship between the two IP entity data.

[0169] In addition, in one implementation, the computing device may also, after determining the entity relationship between the two IP entity data, add 1 to the number of communications corresponding to the two IP entity data. For example, after determining the entity relationship between the first IP entity data and the second IP entity data, the computing device may add 1 to the number of communications corresponding to the first IP entity data and the second IP entity data.

[0170] In addition, it should be noted that, in one implementation,

[0171] The computing device may determine abnormal IP addresses and abnormal behaviors based on entity relationships between IP entity data and the number of communications between IP entity data.

[0172] Next, a process of determining abnormal IP addresses and abnormal behaviors by a computing device based on entity relationships between IP entity data and the number of communications between IP entity data is described.

[0173] For example, any IP entity data is the first IP entity data, and the IP entity data having a relationship with the first IP entity data is the second IP entity data.

[0174] In one implementation,

[0175] For the first IP entity data, the computing device may determine whether the entity relationship between the first IP entity data and a second IP entity data is an abnormal connection.

[0176] If yes, the computing device may determine whether the number of communications is greater than a preset number of communications, wherein the number of communications corresponds to the first IP entity data and the second IP entity data.

[0177] If yes, the computing device may determine the number of IP entity data that has an entity relationship with the first IP entity data as a first number. The computing device may determine the number of IP entity data that has an entity relationship with the second entity data as a second number.

[0178] In one implementation, the computing device may determine that the IP address in the first IP entity data is an abnormal IP address and determine that the communication behavior corresponding to the IP address is an abnormal behavior when determining that the first number is greater than a preset number. Exemplarily, the preset number may be 100.

[0179] In one implementation, the computing device may determine that the IP address in the second IP entity data is an abnormal IP address and determine that the communication behavior corresponding to the IP address is an abnormal behavior when it is determined that the second number is greater than a preset number.

[0180] In one implementation, the computing device may determine that the IP address in the first IP entity data is an abnormal IP address and determine that the communication behavior corresponding to the IP address is an abnormal behavior when determining that the difference between the first number and the second number is greater than a preset threshold. For example, the preset threshold may be 80.

[0181] In one implementation, the computing device may determine that the IP address in the second IP entity data is an abnormal IP address and determine that the communication behavior corresponding to the IP address is abnormal behavior when it is determined that the difference between the second number and the first number is greater than a preset threshold.

[0182] In addition, it should be noted that, in one implementation, the computing device can run a distributed data flow management system to create multiple workflows. The computing device can use the workflow to obtain log data generated during the operation of the server, and then extract IP entity data in the log data based on the target IP entity, and determine the entity relationship between the IP entity data based on the preset target IP entity relationship.

[0183] By using the above-mentioned method of data extraction using a distributed data flow management system, when the computing device is a server cluster, the number of servers used can be dynamically adjusted based on the network environment and data extraction requirements of each server, thereby improving data extraction efficiency.

[0184] Beneficial effects of this embodiment: In this embodiment, the computing device can obtain the log data generated during the operation of the server. The computing device can extract the IP entity data in the log data based on the preset target IP entity, and determine the entity relationship between the IP entity data based on the preset target IP entity relationship (used to indicate the relationship between two target IP entities). Through the above method, the IP entity data can be automatically extracted from the log data using the preset target IP entity, which improves the efficiency and accuracy of obtaining the IP entity data (including the actual IP address), and avoids the problem of high labor cost, high error rate and low efficiency caused by manually arranging regular expressions to extract IP addresses. In addition, through the above method, the entity relationship between the IP entity data can also be automatically determined using the preset target IP entity relationship, which improves the speed and accuracy of obtaining the entity relationship between the IP entity data.

[0185] The following describes a process in which a computing device obtains IP entities and IP entity relationships in advance through a second method embodiment.

[0186] Figure 3a This is a flow chart of a second embodiment of a method for determining an entity relationship provided in an embodiment of the present application. Figure 3a , the method specifically comprises the following steps:

[0187] S301: Obtain sample logs.

[0188] In this embodiment, the computing device may obtain a sample log.

[0189] In one implementation, the database server may store the sample logs, and the computing device may obtain the sample logs sent by the database server.

[0190] In one implementation, the server stores the sample logs, and the computing device can obtain the sample logs sent by the server.

[0191] It should be noted that the computing device can also obtain sample logs in other ways, and the embodiments of the present application are not limited to this.

[0192] It should also be noted that different log types correspond to different sample logs. For example, the sample log corresponding to the alarm log type is the alarm sample log, the sample log corresponding to the audit log type is the audit sample log, the sample log corresponding to the system log type is the system sample log, and the sample log corresponding to the security log type is the security sample log.

[0193] It should also be noted that, in one implementation, the sample log is obtained by filtering and processing the log data by the computing device. In one implementation, the sample log is obtained by filtering and processing the historical log data by the computing device. In one implementation, the sample log is input into the computing device by the user. The computing device can also obtain the sample log in other ways, and the embodiments of the present application are not limited to this.

[0194] S302: Based on the sample log, determine the IP entity, and determine the relationship between two IP entities associated in the sample log.

[0195] In this embodiment, the computing device may determine the IP entity based on the sample log, and determine the relationship between two IP entities associated in the sample log.

[0196] In one implementation,

[0197] The computing device stores an IP entity model. It should be noted that the IP entity model includes multiple model fields (also referred to as business fields). Exemplarily, the multiple model fields included in the IP entity model may be an IP address (ip_addr), a protocol (protocol), a port number (server_port), and an alert content (alert_content).

[0198] The sample log includes multiple sub-sample logs. It can be understood that the sub-sample log records the communication behavior between two IP addresses.

[0199] For any sub-sample log, the computing device can extract and process the sub-sample log based on the IP entity model to obtain two IP entities. Among them, multiple attribute fields in the IP entity match multiple model fields in the IP entity model. In one implementation, the computing device can store the matching relationship between the model field and the attribute field, and the computing device can extract and process the sub-sample log based on the IP entity model (including multiple model fields) and the matching relationship to obtain two IP entities.

[0200] The computing device may determine the relationship between the two IP entities based on the relationship field in the sub-sample log.

[0201] Among them, the relationship field records the relationship between the two IP entities. In one implementation, the relationship field can also record the type of the relationship. Exemplarily, the type of the relationship can be connection, inclusion, association, or other types, and the embodiments of the present application do not limit this. Exemplarily, when the type of the relationship is connection, the relationship can be a network connection, a DNS request, an abnormal connection, or other relationships, and the embodiments of the present application do not limit this. Figure 3b A schematic diagram showing entity relationships provided in an embodiment of the present application. Figure 3b As shown, the relationship between the two IP entities may be an abnormal connection.

[0202] Next, the process of obtaining the IP entity model is described.

[0203] In one implementation, the computing device may extract and process the sample log to obtain multiple attributes. The computing device may determine the multiple attributes as multiple model fields in the IP entity model. Figure 3c A schematic diagram showing an IP entity model provided in an embodiment of the present application. Figure 3c As shown, the IP model includes multiple model fields, which may include IP address, port number, alarm content, and protocol. It can be understood that the process of the computing device determining multiple model fields in the IP entity model is a modeling process.

[0204] In one implementation, the computing device may extract and process the sample log to obtain multiple attributes. The computing device may display the multiple attributes and determine some or all of the multiple attributes as multiple model fields in the IP entity model based on the user's selection request.

[0205] In one implementation, the computing device may obtain multiple attributes input by the user, and determine the multiple attributes as multiple model fields in the IP entity model.

[0206] The following describes a process in which a computing device obtains two IP entities through a specific example.

[0207] For example, for a sub-sample log in the sample log:

[0208] {"name":"mor","record_time":"1698049107000","start_time":"1698049107000","alarm_level" :1,"is_ipv6":0,"src_ip":"10.223.1.18","src_port":"42684","src_country":"912","src_provi nce":"901002","src_city":"90663","dst_ip":"183.220.108.30","dst_port":"34447","dst_country":"155","dst_province":"1 56031","dst_city":"15282","ip_protocol":"TCP","alarm_rule":"warn","alarm_content":"warn","rule_id":2,"send_mail":0}

[0209] The computing device may extract and process the sub-sample log based on the IP entity model to obtain an IP entity, namely, a first IP entity (also referred to as a source IP entity). For example, Table 1 is a first IP entity.

[0210] The first IP entity includes multiple attribute fields (src_ip, ip_protocol, src_port, and alarm_content). Among them, src_ip (attribute field) matches the IP address (model field); ip_protocol (attribute field) matches the protocol (model field); src_port matches the port number (model field); alarm_content (attribute field) matches the alarm content (model field).

[0211] Table 1 First Entity

[0212]

[0213] The computing device may extract and process the sub-sample log based on the IP entity model to obtain another IP entity, namely, a second IP entity (also referred to as a target IP entity). For example, Table 2 is the second IP entity.

[0214] The second IP entity includes a plurality of attribute fields (dst_ip, ip_protocol, dst_port, and alarm_content). Among them, dst_ip (attribute field) corresponds to the IP address (model field); ip_protocol (attribute field) corresponds to the protocol (model field); dst_port (attribute field) corresponds to the port number (model field); and alarm_content (attribute field) corresponds to the alarm content (model field).

[0215] Table 2 Second Entity

[0216]

[0217] S303: Record the relationship between the two associated IP entities as an IP entity relationship.

[0218] In this embodiment, the computing device can record the relationship between the two associated IP entities as an IP entity relationship. It can be understood that the process of the computing device determining the IP entity and the IP entity relationship is the process of assigning values ​​to the model.

[0219] In addition, in one implementation, after obtaining the IP entity and the IP entity relationship based on the sample log, the computing device may record the corresponding relationship between the IP entity and the IP entity relationship and the sample log.

[0220] By establishing the correspondence between IP entities, IP entity relationships and sample logs, data traceability is achieved, the transparency and reliability of data management are improved, and the effective establishment of a comprehensive security monitoring system is achieved.

[0221] In addition, in one implementation, after obtaining the IP entity and the IP entity relationship based on the sample log, the computing device may establish a correspondence between the IP entity and the IP entity relationship and the log type based on the log type corresponding to the sample log.

[0222] By establishing the correspondence between IP entities and IP entity relationships and log types, rapid search of IP entities and IP entity relationships is achieved, and a comprehensive security monitoring system is effectively established.

[0223] Beneficial effects of this embodiment: In this embodiment, the computing device can obtain sample logs. The computing device can determine the IP entity based on the sample logs, and determine the relationship between two IP entities associated in the sample logs. The computing device can record the relationship between the two associated IP entities as an IP entity relationship. In the above manner, the computing device can obtain the IP entity and the IP entity relationship based on the sample log in advance, so that the computing device can quickly determine the entity relationship between the IP entity data and the IP entity data based on the selected target IP entity and the target IP entity relationship after obtaining the log data, thereby improving the efficiency of obtaining the IP entity data and the entity relationship between the IP entity data.

[0224] Figure 4a This is a flow chart of a third embodiment of a method for determining an entity relationship provided in an embodiment of the present application. Figure 4a , the method specifically comprises the following steps:

[0225] S401: Obtain log data generated during the operation of the server.

[0226] In this embodiment, the computing device can obtain log data generated during the operation of the server.

[0227] The specific implementation process is the same as S201 and will not be repeated here.

[0228] S402: Extracting IP entity data from log data based on a preset target IP entity.

[0229] In this embodiment, the computing device may extract IP entity data from the log data based on a preset target IP entity.

[0230] The specific implementation process is the same as S202 and will not be repeated here.

[0231] S403: Determine the entity relationship between IP entity data based on the preset target IP entity relationship.

[0232] In this embodiment, the computing device may determine the entity relationship between the IP entity data based on a preset target IP entity relationship, wherein the preset target IP entity relationship is used to indicate the relationship between two target IP entities.

[0233] The specific implementation process is the same as S203 and will not be repeated here.

[0234] S404: Display the first IP entity data and a viewing control of the first IP entity data.

[0235] In this embodiment, for any first IP entity data, the computing device may display the first IP entity data and a viewing control of the first IP entity data, wherein the viewing control is used to trigger the display of an entity relationship between the first IP entity data and at least one second IP entity data.

[0236] In other words, the computing device may display at least two IP entity data (all IP entity data) and a viewing control for each IP entity data.

[0237] In one implementation, the computing device may control a display interface of the computing device to display at least two IP entity data and a viewing control for each IP entity data. Figure 4b A schematic diagram of displaying at least two IP entity data and a viewing control for each IP entity data provided by an embodiment of the present application. For example, Figure 4b As shown, the display interface of the computing device can display two IP entity data and viewing controls for each IP entity data.

[0238] In one implementation, the computing device may control the display interface of the terminal device to display at least two IP entity data and a viewing control for each IP entity data.

[0239] In one implementation, at least two IP entity data and a viewing control for each IP entity data are displayed in the form of a target IP entity list.

[0240] In addition, it should be noted that, in one implementation,

[0241] After obtaining the IP entity data and the entity relationship between the IP entity data, the computing device can determine whether there is an IP entity list. In other words, the computing device can determine whether the computing device stores the IP entity list.

[0242] If the IP entity list does not exist, the computing device may generate a target IP entity list based on the IP entity data and the entity relationships between the IP entity data. The computing device may display the target IP entity list.

[0243] It should be noted that the target IP entity list includes at least two IP entity data and a viewing control for each IP entity data. Figure 4b As shown, the computing device can display the target IP entity list. Each row of information in the target IP entity list can include IP entity data and a viewing control for the IP entity data.

[0244] If the IP entity list already exists, the computing device may update the IP entity list according to the IP entity data and the entity relationship between the IP entity data to obtain the target IP entity list. The computing device may display the target IP entity list.

[0245] Next, the process of updating the IP entity list according to the IP entity data and the entity relationship between the IP entity data by the computing device is described.

[0246] In one implementation,

[0247] For any IP entity data, the computing device can determine whether the IP entity data exists in the IP entity list.

[0248] If not, then the IP entity data and the viewing controls corresponding to the IP entity data are added to the IP entity list.

[0249] Beneficial effects of this embodiment: For any first IP entity data, the computing device can display the first IP entity data and the viewing control of the first IP entity data. The viewing control is used to trigger the display of the entity relationship between the first IP entity data and at least one second IP entity data. Through the above method, the administrator can intuitively view the IP entity data and the entity relationship between the IP entity data, and then the administrator can quickly identify security threats (such as abnormal IP addresses, abnormal behaviors, etc.) based on the IP entity data and the entity relationship between the IP entity data, thereby improving network security.

[0250] Figure 5a This is a flow chart of a fourth embodiment of a method for determining an entity relationship provided in an embodiment of the present application. Figure 5a , the method specifically comprises the following steps:

[0251] S501: Obtain log data generated during the operation of the server.

[0252] In this embodiment, the computing device can obtain log data generated during the operation of the server.

[0253] The specific implementation process is the same as S201 and will not be repeated here.

[0254] S502: Extracting IP entity data from log data based on a preset target IP entity.

[0255] In this embodiment, the computing device may extract IP entity data from the log data based on a preset target IP entity.

[0256] The specific implementation process is the same as S202 and will not be repeated here.

[0257] S503: Determine the entity relationship between IP entity data based on the preset target IP entity relationship.

[0258] In this embodiment, the computing device may determine the entity relationship between the IP entity data based on a preset target IP entity relationship, wherein the preset target IP entity relationship is used to indicate the relationship between two target IP entities.

[0259] The specific implementation process is the same as S203 and will not be repeated here.

[0260] S504: Display the first IP entity data and the viewing control of the first IP entity data.

[0261] In this embodiment, for any first IP entity data, the computing device may display the first IP entity data and a viewing control of the first IP entity data.

[0262] The viewing control is used to trigger the display of the entity relationship between the first IP entity data and at least one second IP entity data.

[0263] The specific implementation process is the same as S404 and will not be repeated here.

[0264] S505: In response to the operation of the viewing control of the first IP entity data, display the target page.

[0265] In this embodiment, the computing device may display a target page in response to an operation on a viewing control of the first IP entity data.

[0266] The target page includes a network graph corresponding to the first IP entity data. The network graph is used to indicate the entity relationship between the first IP entity data and at least one second IP entity data. It should also be noted that the second IP entity data is the IP entity data that has a relationship with the first IP entity data.

[0267] In one implementation, the target page may also include first IP entity data. Figure 5b A schematic diagram of a target page displayed in an embodiment of the present application is provided, such as Figure 5b As shown, the target page includes the network map corresponding to the first IP entity data and the first IP entity data.

[0268] Next, the contents of the network map are explained.

[0269] In one implementation,

[0270] The network map includes the following contents: a first entity node corresponding to the first IP entity data, a second entity node corresponding to each second IP entity data, and entity connection type information between the first entity node and each second entity node.

[0271] The first entity node includes: the IP address and port number of the first IP entity data. It should be noted that the first entity node is an element in the network graph, which is used to identify the IP address and port number of the first IP entity data. Exemplarily, the first entity node can be 10.223.1.24@42784. 10.223.1.24 is the IP address and 42784 is the port number.

[0272] The second entity node includes: the IP address and port number of the second IP entity data. It should be noted that the second entity node is an element in the network map, which is used to identify the IP address and port number of the second IP entity data. Exemplarily, the second entity node can be 183.220.108.39@34448. Among them, 183.220.108.39 is the IP address and 34448 is the port number.

[0273] The entity connection type information includes: entity connection, entity relationship, and communication times. It should be noted that the communication times correspond to the first IP entity data and the second IP entity data. It should also be noted that the communication times are the number of times the IP address in the first IP entity data and the IP address of the second IP entity data communicate with each other.

[0274] The following is an explanation of the network graph using specific examples.

[0275] like Figure 5b As shown, the target page includes the network map corresponding to the first IP entity data and the first IP entity data.

[0276] The network map includes:

[0277] A first entity node corresponding to the first IP entity data; wherein the first entity node includes an IP address (10.223.1.24) and a port number (42784) of the first IP entity data;

[0278] The second entity node 1 corresponding to the second IP entity data 1; wherein the second entity node 1 includes the IP address (183.220.108.39) and the port number (34448) of the second IP entity data 1;

[0279] Physical connection type information between the first physical node and the second physical node 1; the physical connection type information includes: a physical connection between the first physical node and the second physical node 1, a physical relationship between the first physical node and the second physical node 1 (abnormal connection), and a communication number (1);

[0280] A second entity node 2 corresponding to the second IP entity data 2; wherein the second entity node 2 includes the IP address (192.168.3.11) and the port number (54368) of the second IP entity data 2;

[0281] Physical connection type information between the first physical node and the second physical node 2; the physical connection type information includes: a physical connection between the first physical node and the second physical node 2, a physical relationship (DNS request) between the first physical node and the second physical node 2, and a communication number (1);

[0282] A second entity node 3 corresponding to the second IP entity data 3; wherein the second entity node 3 includes the IP address (180.220.3.178) and the port number (9563) of the second IP entity data 3;

[0283] Physical connection type information between the first physical node and the second physical node 3; the physical connection type information includes: the physical connection between the first physical node and the second physical node 3, the physical relationship (network connection) between the first physical node and the second physical node 3, and the number of communications (1).

[0284] The first IP entity data includes:

[0285] IP address: 10.223.1.24;

[0286] Port number: 42784;

[0287] Geographical location: It should be noted that Figure 3b The geographical location is not shown;

[0288] Warning content: warn;

[0289] Protocol: TCP;

[0290] Discovery time: 2024-12-01 10:01:55;

[0291] Last updated: 2024-12-01 10:03:28;

[0292] Tags: It should be noted that Figure 3b Labels not shown;

[0293] IP entity data source (also known as log type of log data): alarm log type.

[0294] Beneficial effects of this embodiment: In this embodiment, the computing device can display a target page in response to an operation on a viewing control of the first IP entity data; the target page includes a network map corresponding to the first IP entity data; wherein the network map is used to indicate the entity relationship between the first IP entity data and at least one second IP entity data. By displaying the target page in the above manner, the administrator can intuitively view the entity relationship between the first IP entity data and at least one second IP entity data, that is, the communication path and communication behavior (entity relationship) between each entity data can be intuitively viewed, thereby enabling the administrator to quickly identify security threats (such as abnormal IP addresses, abnormal behaviors, etc.), thereby improving network security.

[0295] The following is an embodiment of the device of the present application, which can be used to execute the embodiment of the method of the present application. For details not disclosed in the embodiment of the device of the present application, please refer to the embodiment of the method of the present application.

[0296] Figure 6 A schematic diagram of a structure of an entity relationship determination device provided in an embodiment of the present application. The entity relationship determination device 60 is applied to a computing device. The entity relationship determination device 60 includes an acquisition module 61, a processing module 62, and a display module 63.

[0297] The acquisition module 61 is used to acquire the log data generated during the operation of the server;

[0298] The processing module 62 is used to extract IP entity data in the log data based on a preset target IP entity;

[0299] The processing module 62 is further used to determine the entity relationship between the IP entity data based on a preset target IP entity relationship; wherein the preset target IP entity relationship is used to indicate the relationship between two target IP entities.

[0300] The entity relationship determination device provided in the embodiment of the present application can execute the technical solution shown in the above method embodiment, and its implementation principle and beneficial effects are similar, which will not be repeated here.

[0301] In this scheme,

[0302] In one implementation,

[0303] The acquisition module 61 is also used to obtain sample logs;

[0304] The processing module 62 is further used to determine the IP entity based on the sample log, and determine the relationship between two IP entities associated in the sample log;

[0305] The processing module 62 is further configured to record the relationship between the two associated IP entities as an IP entity relationship.

[0306] The entity relationship determination device provided in the embodiment of the present application can execute the technical solution shown in the above method embodiment, and its implementation principle and beneficial effects are similar, which will not be repeated here.

[0307] In one implementation, the sample log includes a plurality of sub-sample logs; the processing module 62 is specifically configured to:

[0308] For any sub-sample log, based on the IP entity model, the sample log data is extracted and processed to obtain two IP entities; wherein multiple attribute fields in the IP entity match multiple model fields in the IP entity model;

[0309] Determine the relationship between two IP entities based on the relationship field in the sub-sample log.

[0310] The entity relationship determination device provided in the embodiment of the present application can execute the technical solution shown in the above method embodiment, and its implementation principle and beneficial effects are similar, which will not be repeated here.

[0311] In one implementation, the processing module 62 is further configured to:

[0312] Record the correspondence between IP entities, IP entity relationships and sample logs.

[0313] The entity relationship determination device provided in the embodiment of the present application can execute the technical solution shown in the above method embodiment, and its implementation principle and beneficial effects are similar, which will not be repeated here.

[0314] In one implementation, the processing module 62 is further configured to:

[0315] Determine the corresponding target sample log according to the log type of the log data;

[0316] According to the target sample log, find the corresponding relationship and determine the target IP entity and the target IP entity relationship.

[0317] The entity relationship determination device provided in the embodiment of the present application can execute the technical solution shown in the above method embodiment, and its implementation principle and beneficial effects are similar, which will not be repeated here.

[0318] In one implementation, the log data includes at least one sub-log data; the processing module 62 is specifically applied to:

[0319] Determine multiple attribute fields in the target IP entity;

[0320] For any sub-log data, according to multiple attribute fields in the target IP entity and multiple attribute fields in the sub-log data, determine a first target IP entity and a second target IP entity from multiple target IP entities;

[0321] According to the multiple attribute fields in the first target IP entity and the multiple attribute fields in the second target IP entity, the sub-log data is extracted and processed to obtain two IP entity data.

[0322] The entity relationship determination device provided in the embodiment of the present application can execute the technical solution shown in the above method embodiment, and its implementation principle and beneficial effects are similar, which will not be repeated here.

[0323] In one implementation, for any first IP entity data, the display module 63 is used to:

[0324] Display the first IP entity data and the viewing control of the first IP entity data; the viewing control is used to trigger the display of the entity relationship between the first IP entity data and at least one second IP entity data.

[0325] The entity relationship determination device provided in the embodiment of the present application can execute the technical solution shown in the above method embodiment, and its implementation principle and beneficial effects are similar, which will not be repeated here.

[0326] In one implementation, the display module 63 is further configured to:

[0327] In response to an operation on a viewing control of the first IP entity data, a target page is displayed; the target page includes a network graph corresponding to the first IP entity data;

[0328] The network graph is used to indicate the entity relationship between the first IP entity data and at least one second IP entity data.

[0329] The entity relationship determination device provided in the embodiment of the present application can execute the technical solution shown in the above method embodiment, and its implementation principle and beneficial effects are similar, which will not be repeated here.

[0330] In one implementation, the network graph includes: a first entity node corresponding to the first IP entity data, a second entity node corresponding to each second IP entity data, and entity connection type information between the first entity node and each second entity node;

[0331] Among them, the first entity node includes the IP address and port number of the first IP entity data, the second entity node includes the IP address and port number of the second IP entity data, and the entity connection type information includes: entity connection, entity relationship, and communication times; the communication times correspond to the first IP entity data and the second IP entity data.

[0332] The entity relationship determination device provided in the embodiment of the present application can execute the technical solution shown in the above method embodiment, and its implementation principle and beneficial effects are similar, which will not be repeated here.

[0333] Figure 7 A schematic diagram of the structure of a computing device provided in an embodiment of the present application. Figure 7 As shown, the computing device 70 includes: a processor 71 and a memory 72; wherein the processor 71 is coupled to the memory 72, and the memory 72 is used to store computer instructions; the processor 71 is used to execute computer instructions to enable the computing device 70 to execute the technical solution in the aforementioned method embodiment.

[0334] Optionally, the memory 72 may be independent or integrated with the processor 71. Optionally, when the memory 72 is a device independent of the processor 71, the computing device 70 may further include: a bus 73 for connecting the above devices.

[0335] The processor is used to execute the technical solution in the aforementioned method embodiment, and its implementation principle and technical effect are similar and will not be repeated here.

[0336] An embodiment of the present application provides a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, they are used to implement the technical solution provided by the aforementioned method embodiment.

[0337] An embodiment of the present application provides a computer program product, including a computer program, which is used to implement the technical solution provided by the aforementioned method embodiment when executed by a processor.

[0338] Those skilled in the art can understand that all or part of the steps of implementing the above-mentioned method embodiments can be completed by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, the steps of the above-mentioned method embodiments are executed; and the aforementioned storage medium includes: volatile memory, non-volatile memory and other media that can store program codes.

[0339] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit it. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or replace some or all of the technical features therein with equivalents. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present application.

Claims

1. A method for determining entity relationships, characterized in that: include: Get the log data generated during the server operation; Based on a preset target IP entity, extracting IP entity data in the log data; Based on a preset target IP entity relationship, the entity relationship between the IP entity data is determined; wherein the preset target IP entity relationship is used to indicate the relationship between two target IP entities.

2. The method according to claim 1, characterized in that: The method further comprises: Get sample logs; Based on the sample log, determine the IP entity, and determine the relationship between two IP entities associated in the sample log; The relationship between the two associated IP entities is recorded as an IP entity relationship.

3. The method according to claim 2, characterized in that The sample log includes a plurality of sub-sample logs; and determining the IP entity based on the sample log, and determining the relationship between two IP entities associated in the sample log, includes: For any sub-sample log, based on the IP entity model, the sample log data is extracted and processed to obtain two IP entities; wherein multiple attribute fields in the IP entity match multiple model fields in the IP entity model; The relationship between the two IP entities is determined according to the relationship field in the sub-sample log.

4. The method according to claim 2, characterized in that: The method further comprises: The correspondence between the IP entity and the IP entity relationship and the sample log is recorded.

5. The method according to claim 4, characterized in that Before extracting the IP entity data in the log data based on the preset target IP entity, the method further includes: Determine a corresponding target sample log according to the log type of the log data; According to the target sample log, the corresponding relationship is searched to determine the target IP entity and the target IP entity relationship.

6. The method according to any one of claims 1 to 5, characterized in that: The log data includes at least one sub-log data; the extracting IP entity data in the log data based on the preset target IP entity includes: Determining a plurality of attribute fields in the target IP entity; For any sub-log data, according to a plurality of attribute fields in the target IP entity and a plurality of attribute fields in the sub-log data, determine a first target IP entity and a second target IP entity among a plurality of the target IP entities; According to the multiple attribute fields in the first target IP entity and the multiple attribute fields in the second target IP entity, the sub-log data is extracted and processed to obtain two IP entity data.

7. The method according to any one of claims 1 to 6, characterized in that: For any first IP entity data, the method further includes: The first IP entity data and a viewing control for the first IP entity data are displayed; the viewing control is used to trigger the display of an entity relationship between the first IP entity data and at least one second IP entity data.

8. The method according to claim 7, characterized in that The method further comprises: In response to an operation on a viewing control of the first IP entity data, a target page is displayed; the target page includes a network graph corresponding to the first IP entity data; The network map is used to indicate the entity relationship between the first IP entity data and at least one of the second IP entity data.

9. The method according to claim 8, characterized in that The network graph includes: a first entity node corresponding to the first IP entity data, a second entity node corresponding to each second IP entity data, and entity connection type information between the first entity node and each second entity node; Among them, the first entity node includes the IP address and port number of the first IP entity data, the second entity node includes the IP address and port number of the second IP entity data, and the entity connection type information includes: entity connection, entity relationship, and communication times; the communication times correspond to the first IP entity data and the second IP entity data.

10. A computing device, characterized in that: include: A processor, and a memory communicatively connected to the processor; The memory is used to store computer-executable instructions; The processor is used to execute the computer-executable instructions stored in the memory to implement the method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Security event log processing method and device and storage medium

    CN110933101A

  • Log anomaly detection method and device

    CN112579414A

  • Knowledge graph construction method for log data

    CN112579707A

  • Medical log processing method and device, edge node and storage medium

    CN114913967A

  • Network attack detection method and device, equipment, storage medium and product

    CN116319077A