Automatic network security operation management integrated system and method based on security event driving
By adopting an integrated automated network security operation and management system driven by security events in network security management, the problems of poor timeliness, accuracy and efficiency of network security management in the existing technology are solved, and the effects of rapid response and effective protection are achieved.
Patent Information
- Application Number
- CN202411955062.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-27
- Publication Date
- 2025-05-27
AI Technical Summary
In the prior art, network security management has problems of poor timeliness, accuracy and efficiency, and it is difficult to quickly detect and deal with security incidents in complex networks, especially unknown attack methods.
The integrated system of automated network security operation and management based on security event-driven is adopted, including security event perception unit, security event analysis unit, decision-making and response unit, and operation management and feedback optimization unit. Through real-time data collection, association analysis, automated decision-making and visual display, rapid response and effective protection are achieved.
It significantly shortens the time interval between the occurrence of security incidents and the system is detected, improves the timeliness and accuracy of network security management, reduces the time delay in the response process, and can promptly curb the further development of security incidents and reduce possible losses.
Smart Images

Figure CN120050061A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security operation and management, and particularly to an integrated system and method for automated network security operation and management driven by security events. Background Art
[0002] With the wide application of the Internet in daily life and work and the stable and rapid development of information technology, network systems are facing increasingly complex and diverse security threats. For example, security incidents such as malicious hacker attacks, virus propagation, and internal unauthorized operations occur frequently.
[0003] In the prior art, log processing is scattered for collection and storage. Various devices in the network, such as servers, firewalls, switches, etc., generate logs respectively and usually store the logs in local devices. For example, a server with a Windows system will record the logs in the local event viewer. Network administrators need to log in to different devices separately to view the corresponding logs, which is inefficient. Facing a large amount of scattered log data, the method of manual viewing and analysis is time-consuming and laborious, and it is difficult to quickly discover potential security problems. For example, in an enterprise with numerous network devices and servers, administrators need to spend a lot of time switching between different devices to view the logs and may miss some security incidents with strong timeliness.
[0004] The filtering method based on rules and features can only identify known attack patterns and malicious traffic, and cannot protect against new and unknown attack means, such as zero-day attacks, in a timely and effective manner. Because these attacks have not been defined in the rule library, they can easily bypass the traditional traffic filtering mechanism. Due to the complexity and diversity of network traffic, the filtering based on simple rules may generate more false positives or false negatives.
[0005] That is to say, the traditional network security management methods mostly rely on manual monitoring, analysis, and manual response, and have many defects such as lagging response, high misjudgment rate, and difficulty in integrating multi-source information for comprehensive decision-making, and can no longer meet the requirements of timeliness, accuracy, and efficiency of security management in the current complex network environment. Summary of the Invention
[0006] The technical problem to be solved by the present invention is to overcome the defects of poor timeliness, accuracy, and efficiency in network security management in the prior art, and provide an integrated system and method for automated network security operation and management driven by security events.
[0007] The present invention solves the above technical problems through the following technical solutions:
[0008] The present invention provides an integrated system and method for automated network security operation and management based on security event-driven, including a security event perception unit, a security event analysis unit, a decision-making and response unit, and an operation management and feedback optimization unit. The security event perception unit, the security event analysis unit, the decision-making and response unit, and the operation management and feedback optimization unit are connected in sequence;
[0009] The security event perception unit collects network traffic data in real time by deploying traffic sensors at key network nodes. The security event analysis unit receives the trigger data from the security event perception unit and uses the correlation analysis algorithm to correlate and integrate the data from different data sources. The decision-making and response unit automatically matches a pre-set set of response strategies according to the security event risk level and type determined by the security event analysis unit. The operation management and feedback optimization unit displays the overall network security situation of the system in a visual manner.
[0010] In this technical solution, the security event perception unit can collect multi-source data in real time and quickly detect abnormal situations that may indicate security events. Once an anomaly is detected, the subsequent analysis process is triggered in a timely manner. Compared with the traditional method that relies on manual regular inspections or post-event analysis, the time interval from the occurrence of a security event to its detection by the system is greatly shortened, gaining a head start for rapid response;
[0011] The use of structures such as the decision-making and response unit realizes automated risk assessment, strategy formulation, and execution coordination. When a security event is triggered, it can quickly determine the risk level according to pre-set rules and algorithms, generate and immediately execute the corresponding response strategies, without the need for manual configuration of security devices or formulation of response measures one by one, effectively reducing the time delay in the response process, and can timely contain the further development of security events and reduce the possible losses.
[0012] Preferably, the security event perception unit includes a network traffic collection module, a log collection module, and an event trigger module.
[0013] In this technical solution, the security event perception unit deploys traffic sensors at key network nodes to collect network traffic data in real time for monitoring abnormal communication behaviors in the network.
[0014] Preferably, the security event analysis unit includes a data correlation analysis module and a behavior modeling and risk assessment module.
[0015] In this technical solution, the security event analysis unit receives the trigger data from the security event perception module and uses the correlation analysis algorithm to correlate and integrate the data from different data sources.
[0016] Preferably, the data association analysis module includes a network traffic sub-module, a system log sub-module, an endpoint data collection sub-module, and a threat intelligence knowledge base.
[0017] Preferably, the behavior modeling and risk assessment module includes a normal behavior data sub-module, an abnormal behavior data sub-module, an event feature sub-module, and an operation and path feature sub-module.
[0018] Preferably, the decision-making and response unit includes a risk assessment information receiving module, a mining analysis platform, a data integration platform, a risk level output module, and an execution scheduling module.
[0019] In this technical solution, the decision-making and response unit automatically matches a pre-set set of response strategies according to the risk level and type of security events determined by the security event analysis module.
[0020] Preferably, the mining analysis platform includes agenda behavior feature definition, known high-hazard supply technologies, and the importance of affected assets;
[0021] The data integration platform includes a data model.
[0022] Preferably, the execution scheduling module includes execution component management and integration, policy disassembly and task allocation, and execution monitoring and coordination.
[0023] Preferably, the operation management and feedback optimization unit includes a log module, a database module, an external data module, a log collection agent module, a database real-time synchronization module, a batch data extraction module, an external data collection service module, and a data display platform.
[0024] In this technical solution, the operation management and feedback optimization unit displays the overall network security situation of the system through intuitive visualizations such as dashboards and charts.
[0025] Preferably, the method includes the following operating steps:
[0026] Step 1, security event detection and perception: Use the security event perception unit to deploy traffic sensors at key network nodes, collect network traffic data in real time, monitor abnormal communication behaviors in the network in real time, and collect relevant data from various network devices at the same time, and access external threat intelligence sources to provide a data basis for subsequent perception of security events;
[0027] Step 2, security event analysis: The security event analysis unit receives the trigger data from the security event perception unit in Step 1, uses the association analysis algorithm to associate and integrate the data from different data sources, and determines the risk level and type of security events;
[0028] Step 3: Security incident decision-making and response. According to the risk level and type of the security incident determined in Step 2, automatically match the pre-set set of response strategies.
[0029] Step 4: Security incident operation management and feedback optimization. Display the overall network security situation of the system in a visual way, enabling security management personnel to quickly understand the overall situation and specific incident situations, and assisting them in making decision judgments.
[0030] Based on common knowledge in the field, the above preferred conditions can be combined arbitrarily to obtain various preferred embodiments of the present invention.
[0031] The positive and progressive effects of the present invention are as follows:
[0032] Through the security incident perception unit, the present invention can collect multi-source data in real time and quickly detect abnormal situations that may indicate security incidents. Once an abnormality is found, the subsequent analysis process is triggered in a timely manner. Compared with the traditional method that relies on manual regular inspections or post-event analysis, the time interval from the occurrence of a security incident to its detection by the system is greatly shortened, gaining a head start for rapid response.
[0033] Utilize structures such as the decision-making and response unit to achieve automated risk assessment, strategy formulation, and execution coordination. When a security incident is triggered, it can quickly determine the risk level according to preset rules and algorithms, generate and immediately execute the corresponding response strategy, without the need for manual configuration of security devices or formulation of response measures one by one, effectively reducing the time delay in the response process, promptly curbing the further development of security incidents, and reducing possible losses.
[0034] With security incidents as the driving core, the present invention realizes automated network security operation management, improves the timeliness, accuracy, and efficiency of the system, and is convenient for meeting various requirements of security management in the current complex network environment. Brief Description of the Drawings
[0035] Figure 1 It is a schematic structural diagram of an integrated system and method for automated network security operation management based on security incident drive according to an embodiment of the present invention.
[0036] Figure 2 is Figure 1 A schematic structural diagram of the specific operation process of the security incident perception unit of the integrated system and method for automated network security operation management based on security incident drive shown in the figure.
[0037] Figure 3 is Figure 1 A schematic structural diagram of the specific operation process of the security incident analysis unit of the integrated system and method for automated network security operation management based on security incident drive shown in the figure.
[0038] Figure 4 For Figure 1 The schematic diagram of the specific operation process structure of the decision-making and response unit of the automated network security operation management integration system and method driven by security events as shown in the figure.
[0039] Figure 5 For Figure 1 The schematic diagram of the specific operation process structure of the operation management and feedback optimization unit of the automated network security operation management integration system and method driven by security events as shown in the figure.
[0040] Description of the reference numerals in the drawings
[0041] 1. Security event perception unit; 11. Network traffic collection module; 12. Log collection module; 13. Event trigger module;
[0042] 2. Security event analysis unit; 21. Data correlation analysis module; 211. Network traffic sub-module; 212. System log sub-module; 213. Endpoint data collection sub-module; 214. Threat intelligence knowledge base; 22. Behavior modeling and risk assessment module; 221. Normal behavior data sub-module; 222. Abnormal behavior data sub-module; 223. Event feature sub-module; 224. Operation and path feature sub-module;
[0043] 3. Decision-making and response unit; 31. Risk assessment information receiving module; 32. Mining analysis platform; 33. Data integration platform; 34. Risk level output module; 35. Execution scheduling module;
[0044] 4. Operation management and feedback optimization unit; 41. Log module; 42. Database module; 43. External data module; 44. Log collection proxy module; 45. Database real-time synchronization module; 46. Batch data extraction module; 47. External data collection service module; 48. Data display platform. Detailed implementation manners
[0045] The present invention will be further described below by way of embodiments, but the present invention is not limited to the scope of the described embodiments.
[0046] Figures 1 to 5 The schematic diagram of the structure of the embodiment of the automated network security operation management integration system and method driven by security events according to the present invention is shown. The automated network security operation management integration system and method driven by security events includes a security event perception unit 1, a security event analysis unit 2, a decision-making and response unit 3, and an operation management and feedback optimization unit 4, and the security event perception unit 1, the security event analysis unit 2, the decision-making and response unit 3, and the operation management and feedback optimization unit 4 are connected in sequence;
[0047] The security event perception unit 1 collects network traffic data in real time by deploying traffic sensors at key network nodes. The security event analysis unit 2 receives the trigger data from the security event perception unit 1 and uses the correlation analysis algorithm to correlate and integrate the data from different data sources. The decision-making and response unit 3 automatically matches the pre-set response strategy set according to the security event risk level and type determined by the security event analysis unit 2. The operation management and feedback optimization unit 4 displays the overall network security situation of the system in a visual manner.
[0048] In this technical solution, the security event perception unit 1 can collect multi-source data in real time and quickly detect abnormal situations that may indicate security events. Once an anomaly is detected, the subsequent analysis process is triggered in a timely manner. Compared with the traditional method that relies on manual regular inspections or post-event analysis, the time interval from the occurrence of a security event to its detection by the system is greatly shortened, gaining a head start for rapid response.
[0049] The use of structures such as the decision-making and response unit 3 realizes automated risk assessment, strategy formulation, and execution coordination. When a security event is triggered, it can quickly determine the risk level according to the preset rules and algorithms, generate and immediately execute the corresponding response strategy, without the need for manual configuration of security devices or formulation of response measures one by one, effectively reducing the time delay in the response process, and can timely contain the further development of security events and reduce the possible losses.
[0050] The security event perception unit 1 includes a network traffic collection module 11, a log collection module 12, and an event trigger module 13.
[0051] In this technical solution, the security event perception unit 1 is used to deploy traffic sensors at key network nodes to collect network traffic data in real time for monitoring abnormal communication behaviors in the network.
[0052] The security event perception unit 1 collects network traffic data in real time by deploying traffic sensors at key network nodes, including IP addresses, port information, protocol types, packet payloads, etc., for monitoring abnormal communication behaviors in the network;
[0053] At the same time, system log information is collected from various network devices such as firewalls, servers, and terminal devices such as computers and mobile terminals, recording system operations, login situations, error messages, etc., and endpoint-related data such as process activities, file changes, and network requests are collected by means of lightweight proxy programs installed on endpoint devices;
[0054] In addition, external authoritative threat intelligence sources are also accessed to obtain the latest malicious IP lists, virus signatures, vulnerability bulletins, etc., forming an all-round data collection system to provide a rich data basis for subsequent security event perception.
[0055] The security event analysis unit 2 includes a data association analysis module 21 and a behavior modeling and risk assessment module 22 .
[0056] In this technical solution, the security event analysis unit 2 is used to receive the trigger data from the security event perception module, and the association analysis algorithm is used to associate and integrate the data from different data sources.
[0057] The data correlation analysis module 21 includes a network traffic submodule 211 , a system log submodule 212 , an endpoint data collection submodule 213 and a threat intelligence knowledge base 214 .
[0058] The behavior modeling and risk assessment module 22 includes a normal behavior data submodule 221 , an abnormal behavior data submodule 222 , an event feature submodule 223 , and an operation and path feature submodule 224 .
[0059] The security event analysis unit 2 receives the trigger data from the security event perception module and uses the correlation analysis algorithm to correlate and integrate the data from different data sources;
[0060] For example, the abnormal IP appearing in the network traffic is associated with the login behavior corresponding to the IP in the system log, as well as the abnormal process related to it on the endpoint device, so as to deeply explore the complete security event chain hidden behind the multi-source data, accurately restore the full picture of the security event, avoid misjudgment or omission caused by isolated data, and improve the ability to identify complex attack behaviors.
[0061] The decision and response unit 3 includes a risk assessment information receiving module 31 , a mining and analysis platform 32 , a data integration platform 33 , a risk level output module 34 and an execution scheduling module 35 .
[0062] In this technical solution, the decision and response unit 3 is used to automatically match a pre-set response strategy set according to the risk level and type of the security incident determined by the security incident analysis module.
[0063] The mining and analysis platform 32 includes the definition of agenda behavior characteristics, known high-risk supply technologies and the importance of affected assets;
[0064] The data integration platform 33 includes a data model.
[0065] The execution scheduling module 35 includes execution component management and integration, strategy disassembly and task allocation, and execution monitoring and coordination.
[0066] The decision-making and response unit 3 automatically matches the pre-set set of response strategies according to the security event risk level and type determined by the security event analysis module, and generates different response strategies for events with different risk levels;
[0067] For example, for high-risk external malicious attack events, the strategies may include immediately blocking the network access of the attack source IP, isolating the infected endpoint devices, notifying relevant security management personnel, etc.;
[0068] For medium-risk internal privilege violation events, the strategies can be sending reminder and warning messages to the involved personnel, recording the details of the violation operations and temporarily restricting some of their privileges, etc.;
[0069] For low-risk regular abnormal events, operations such as automatic simple repair or continuous observation can be selected.
[0070] The operation management and feedback optimization unit 4 includes a log module 41, a database module 42, an external data module 43, a log collection agent module 44, a database real-time synchronization module 45, a batch data extraction module 46, an external data collection service module 47, and a data display platform 48.
[0071] In this technical solution, the operation management and feedback optimization unit 4 uses intuitive dashboards, charts and other visualization methods to display the overall network security situation of the system.
[0072] The operation management and feedback optimization unit 4 uses intuitive dashboards, charts and other visualization methods to display the overall network security situation of the system, including macroscopic information such as the number of real-time security events, the distribution of events with different risk levels, and the affected assets;
[0073] At the same time, for each specific security event, its detailed information is displayed, such as the event occurrence time, the devices and systems involved, the risk level, the response measures taken, and the event handling progress, etc., which is convenient for security management personnel to quickly understand the overall situation and specific event situations and assist them in making decision-making judgments.
[0074] The method includes the following operation steps:
[0075] Step 1, security event detection and perception. Use the security event perception unit 1 to deploy traffic sensors at key network nodes, collect network traffic data in real time, monitor abnormal communication behaviors in the network in real time, and at the same time collect relevant data from various network devices and access external threat intelligence sources to provide a data basis for subsequent perception of security events;
[0076] Step 2: Security incident analysis. The security incident analysis unit 2 receives the trigger data from the security incident perception unit 1 in Step 1, and uses the correlation analysis algorithm to correlate and integrate the data from different data sources to determine the risk level and type of the security incident;
[0077] Step 3: Security incident decision-making and response. According to the risk level and type of the security incident determined in Step 2, automatically match the pre-set set of response strategies;
[0078] Step 4: Security incident operation management and feedback optimization. Display the overall network security situation of the system in a visual way, so that security managers can quickly understand the overall situation and specific event situations, and assist them in making decision-making judgments.
[0079] The data collection and processing process of the security incident perception unit 1 for multi-source data is as follows:
[0080] Step 1: Deploy the network traffic collection module 11 and the log collection module 12 for data collection, that is, deploy the sensor recognition module for network traffic and logs for data collection;
[0081] Step 2: The network traffic collection module 11 and the log collection module 12 format the data and then pass it into the data message queue cluster;
[0082] Step 3: Data label adaptation judgment process. Different processing logics are performed for the adapter judgment of data formats and types and the corresponding business processes;
[0083] Step 4: If "yes" is matched, enter the queue for processing by the corresponding type adapter, that is, enter the message processing queue for the corresponding adaptation;
[0084] Step 5: If "no" is matched, enter the default general configuration process for general data processing;
[0085] Step 6: According to the type identified in the previous step, match different intelligence rules for tagging;
[0086] Step 7: Classify the data types according to the tagged data, such as login type, network connection, process creation, etc.
[0087] The security incident analysis unit 2 performs the next step of processing through the data received from the security incident perception unit 1. The specific operation process is as follows:
[0088] Step 1: Receive the data of the security incident perception unit 1, that is, monitor the data queue of the security incident perception unit 1;
[0089] Step 2: Perform correlation integration analysis and processing on different types of data, such as traffic information, log information, process information, etc.;
[0090] Step 3: Analyze the login behavior based on the identified abnormal IPs.
[0091] Step 4: Conduct process association analysis of the terminal / server based on the identified abnormal IPs.
[0092] Step 5: Analyze the network operation behavior based on the identified abnormal IPs, including DNS queries, domain names, IPs
[0093] Step 6: Identify the behavior attack and add it to the next processing flow queue.
[0094] In the decision-making and response unit 3, for the identified security incidents, risk levels are evaluated. The specific operation process is as follows:
[0095] Step 1: Receive risk assessment data.
[0096] Step 2: Evaluate the risk levels of the security incidents based on the data in Step 1.
[0097] Step 3: Generate different response strategies according to the risk levels evaluated in Step 2. For high-risk events, the disposal strategies include blocking network connections, isolating devices, etc.; for medium-risk events, the disposal strategy is to send notification alerts; for low-risk events, the disposal strategy is to save data evidence.
[0098] Step 5: Notify relevant operation and maintenance personnel for follow-up review and disposal.
[0099] The operation management and feedback optimization unit 4 mainly focuses on model deployment, actual application, and performance monitoring. The specific operation process is as follows:
[0100] Step 1: Display platform deployment, the unified entry of the platform backend management system.
[0101] Step 2: Analyze strategy management, including traffic, logs, and terminal strategies.
[0102] Step 3: Alarm management, including alarm types, alarm details, alarm event generation paths, and risk levels.
[0103] Step 4: Acquisition and adaptation source management, including traffic sensor adaptation and log sensor adaptation.
[0104] Step 5: Dashboard statistics display, for information disposal and prompts on the same day.
[0105] Step 6: Report management, regularly generate different types of summary analysis reports according to different dimensions such as IPs, hosts, and networks for policy adjustment and optimization.
[0106] In addition, the system also includes a system integration and expansion unit, which uses standardized interfaces and protocols to ensure the compatibility of the system with other security tools. At the same time, it provides a flexible expansion mechanism to facilitate enterprises to add new security modules or functions according to actual needs;
[0107] The system integration and expansion unit seamlessly integrates with existing security tools such as firewalls, intrusion detection systems, security information and event management solutions, etc., to achieve data sharing and collaborative work. At the same time, it supports the expansion and upgrade of the system to meet the changing security needs of enterprises.
[0108] Although the specific implementation manners of the present invention have been described above, those skilled in the art should understand that this is only an example. The protection scope of the present invention is defined by the appended claims. Without departing from the principle and essence of the present invention, those skilled in the art can make various changes or modifications to these implementation manners, but these changes and modifications all fall within the protection scope of the present invention.
Claims
1. An integrated automated network security operation and management system driven by security events, characterized by: It comprises a security event perception unit (1), a security event analysis unit (2), a decision and response unit (3) and an operation management and feedback optimization unit (4), wherein the security event perception unit (1), the security event analysis unit (2), the decision and response unit (3) and the operation management and feedback optimization unit (4) are connected in sequence; The security event perception unit (1) collects network traffic data in real time by deploying traffic sensors at key network nodes; the security event analysis unit (2) receives trigger data from the security event perception unit (1) and uses a correlation analysis algorithm to correlate and integrate data from different data sources; the decision and response unit (3) automatically matches a pre-set response strategy set according to the risk level and type of the security event determined by the security event analysis unit (2); and the operation management and feedback optimization unit (4) displays the overall network security situation of the system in a visual manner.
2. The integrated system for automated network security operation and management based on security event drive according to claim 1, characterized in that: The security event sensing unit (1) comprises a network traffic collection module (11), a log collection module (12) and an event triggering module (13).
3. The integrated system for automated network security operation and management based on security event drive according to claim 1, characterized in that: The security event analysis unit (2) comprises a data association analysis module (21) and a behavior modeling and risk assessment module (22).
4. The security event-driven integrated automated network security operation and management system according to claim 3, characterized in that: The data association analysis module (21) includes a network traffic submodule (211), a system log submodule (212), an endpoint data collection submodule (213) and a threat intelligence knowledge base (214).
5. The security event-driven integrated automated network security operation and management system according to claim 3, characterized in that: The behavior modeling and risk assessment module (22) comprises a normal behavior data submodule (221), an abnormal behavior data submodule (222), an event feature submodule (223), and an operation and path feature submodule (224).
6. The security event-driven integrated automated network security operation and management system according to claim 1, characterized in that: The decision-making and response unit (3) comprises a risk assessment information receiving module (31), a mining and analysis platform (32), a data integration platform (33), a risk level output module (34) and an execution scheduling module (35).
7. The integrated system for automated network security operation and management based on security event drive according to claim 6, characterized in that: The mining and analysis platform (32) includes the definition of agenda behavior characteristics, known high-risk supply technologies and the importance of affected assets; The data integration platform (33) includes a data model.
8. The security event-driven integrated automated network security operation and management system according to claim 6, characterized in that: The execution scheduling module (35) includes execution component management and integration, strategy disassembly and task allocation, and execution monitoring and coordination.
9. The security event-driven integrated automated network security operation and management system according to claim 1, characterized in that: The operation management and feedback optimization unit (4) comprises a log module (41), a database module (42), an external data module (43), a log collection agent module (44), a database real-time synchronization module (45), a batch data extraction module (46), an external data collection service module (47) and a data display platform (48).
10. A method for obtaining an automated network security operation and management integrated system based on security event drive according to any one of claims 1 to 9, characterized in that: The method comprises the following steps: Step 1: Detect and perceive security events. Use the security event perception unit (1) to deploy flow sensors at key network nodes to collect network flow data in real time, monitor abnormal communication behaviors in the network in real time, collect relevant data from various network devices, and access external threat intelligence sources to provide a data basis for subsequent perception of security events. Step 2: security incident analysis: the security incident analysis unit (2) receives the trigger data of the security incident sensing unit (1) in step 1, and uses the correlation analysis algorithm to correlate and integrate the data from different data sources to determine the risk level and type of the security incident; Step 3: Security incident decision and response: automatically matching a pre-set response strategy set based on the risk level and type of the security incident determined in step 2; Step 4: Security incident operational management and feedback optimization, through visual display of the overall network security situation of the system, so that security managers can quickly understand the overall and specific incident situation, to assist them in decision-making.
Citation Information
Cited By
Network security supervision method, system and device, storage medium and program product
CN121644141A