Service alarm method and device
By introducing a log audit module into the security management platform, the business alarm data of each security service is received and processed in real time, and using a target timing task to capture and push data, the problems of large number of timing tasks, large performance consumption and poor scalability in traditional solutions are solved, and efficient and real-time alarm data processing and push are achieved.
Patent Information
- Application Number
- CN202510161855.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-13
- Publication Date
- 2025-05-27
AI Technical Summary
When traditional security management platforms process business alarm data for multiple security services, they need to set up a large number of timing tasks, resulting in large performance consumption and poor scalability, making it difficult to effectively push and process real-time alarm data.
By introducing a log audit module into the security management platform, the business alarm data of each security service is received in real time, and the business alarm data of all security services is captured from the log audit module through a target timing task and pushed to the corresponding user terminal.
It reduces the number of timing tasks, avoids performance consumption, improves the real-time and sensitivity of alarm data, simplifies the configuration process when adding new security services, and improves the scalability of the entire alarm solution.
Smart Images

Figure CN120050154A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and in particular, to a service alarm method and apparatus. Background Art
[0002] The security management platform supports security services such as bastion hosts, endpoint security, database auditing, and firewalls. In order for users to timely understand the operation status of each security service, the security management platform needs to timely obtain the service alarm data of each security service and push it to users.
[0003] In traditional alarm solutions, the security management platform sets a timing task for each security service to capture the service alarm data of the security service. In the case of a large number of security services, many timing tasks consume the performance of the security management platform to a large extent. How to overcome this problem is the key research objective in this field. Summary of the Invention
[0004] To overcome the problems in the related art, this application provides a service alarm method and apparatus.
[0005] According to the first aspect of the embodiments of this application, a service alarm method is provided. The method is applied to a security management platform, and the method includes:
[0006] Execute a target timing task to capture the service alarm data of all security services managed by the security management platform from a log audit module, where the log audit module is used to receive the service alarm data pushed in real time by each security service managed by the security management platform;
[0007] Query an alarm policy to determine the alarm recipient information of each security service managed by the security management platform;
[0008] Push the captured service alarm data of each security service to the user terminal corresponding to the alarm recipient information of the security service.
[0009] According to the second aspect of the embodiments of this application, a service alarm apparatus is provided. The apparatus is applied to a security management platform, and the apparatus includes:
[0010] A capture module, configured to execute a target timing task to capture the service alarm data of all security services managed by the security management platform from a log audit module, where the log audit module is used to receive the service alarm data pushed in real time by each security service managed by the security management platform;
[0011] A query module, configured to query an alarm policy to determine the alarm recipient information of each security service managed by the security management platform;
[0012] A push module, configured to push the service alarm data of each captured security service to the user terminal corresponding to the alarm recipient information of the security service.
[0013] According to a third aspect of the embodiments of the present application, there is provided a computer-readable storage medium, including computer instructions, which, when running on an electronic device, cause the electronic device to execute the method as described above.
[0014] According to a fourth aspect of the embodiments of the present application, there is provided a computer program product, which, when running on a computer, causes the computer to execute the method as described above.
[0015] The technical solutions provided by the embodiments of the present application may include the following beneficial effects:
[0016] In the embodiments of the present application, the log audit module can receive the service alarm data of each security service managed by the security management platform. Therefore, the security management platform only needs to set one target timing task to capture the service alarm data of all security services from the log audit module. It can be seen that the security management platform of the present application does not need to set a timing task for each security service separately, reducing the number of timing tasks and avoiding the performance degradation of the security management platform caused by a large number of timing tasks. In addition, since the security management platform only needs to set one target timing task, the execution period of the target timing task can be set shorter to improve the sensitivity of alarm triggering. Moreover, since each security service directly pushes the service alarm data to the log audit module, the problem of failed capture or partial loss of service alarm data can be avoided. Finally, if a new security service needs to be added to the security management platform, only the configuration of the log audit module needs to be modified, without developing new timing tasks, improving the scalability of the entire alarm solution.
[0017] It should be understood that the above general description and subsequent detailed description are only exemplary and explanatory, and cannot limit the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] The accompanying drawings herein are incorporated into the specification and constitute a part of the present application, showing embodiments consistent with the present application and used together with the specification to explain the principles of the present application.
[0019] Figure 1 It is a schematic diagram of the implementation of the alarm solution for the traditional security management platform;
[0020] Figure 2 It is a schematic diagram of the implementation of the alarm solution for the security management platform provided by the embodiments of the present application;
[0021] Figure 3 It is a flowchart of the service alarm method provided by the embodiments of the present application;
[0022] Figure 4 This is the structural diagram of the service alarm device provided by the embodiment of the present application. Detailed implementation manners
[0023] Next, in combination with the accompanying drawings in the embodiments of the present application, the technical solutions in the embodiments of the present application will be described. Among them, in the description of the embodiments of the present application, the terms used in the following embodiments are only for the purpose of describing specific embodiments, and are not intended to limit the present application.
[0024] It should be noted that "at least one" in the present application means one or more, and "a plurality" means two or more than two. "And / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone, where A and B can be singular or plural. The terms "first", "second", "third", etc. (if any) in the specification, claims and drawings of the present application are used to distinguish similar objects, rather than to describe a specific order or sequence.
[0025] In the embodiments of the present application, words such as "exemplary" or "for example" are used to represent examples, illustrations or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other embodiments or design solutions. Exactly, using words such as "exemplary" or "for example" is intended to present relevant concepts in a specific manner.
[0026] The traditional security management platform alarm solution is as follows Figure 1 As shown, a timing task is created for each security service on the security management platform, and the interval time of the timing task can be set to half an hour. Taking the timing task of the firewall as an example, the execution process of this timing task is as follows: query the instance list of the firewall, call the API interface of the firewall according to the IP address, username, and password of the firewall, and grab the latest service alarm data of the firewall; push the grabbed service alarm data of the firewall to the corresponding firewall users through the push module.
[0027] The above alarm solution has the following problems:
[0028] (1) Each security service in the security management platform corresponds to a timing task, resulting in a large number of timing tasks, which consumes the performance of the security management platform. Moreover, when a new security service is expanded later, new timing tasks will be added, further reducing the performance of the security management platform.
[0029] (2) When the number of devices managed by a certain security service is large, even if the interval of the scheduled task is set to half an hour, it may happen that the next round of scraping task starts before all the business alarm data in this round has been fully scraped, resulting in the failure or partial loss of the business alarm data scraping.
[0030] (3) Every time the security management platform expands to support the management of one more security service, new scheduled task code and business alarm scraping code need to be developed, and the scalability is poor.
[0031] In view of the above problems, the present application provides a business alarm method and device, which can solve the performance consumption problem caused by a large number of scheduled tasks, can also solve the problem that the business alarm data may be scraped unsuccessfully or partially lost, and in addition allows setting a shorter execution cycle to improve the sensitivity of the alarm. Finally, it also solves the problem of poor scalability of security services and supports flexible and convenient expansion of security services.
[0032] Next, the embodiments of the present application will be described in detail.
[0033] The embodiment of the present application provides a business alarm method, and the method is applied to a security management platform, as Figure 2 shown, and the method may include the following steps:
[0034] Step 210: Execute a target scheduled task to scrape the business alarm data of all security services managed by the security management platform from the log audit module, where the log audit module is used to receive the business alarm data pushed in real time by each security service managed by the security management platform;
[0035] Step 220: Query the alarm policy to determine the alarm recipient information of each security service managed by the security management platform;
[0036] Step 230: Push the scraped business alarm data of each security service to the user terminal corresponding to the alarm recipient information of the security service.
[0037] As Figure 3 shown, in this embodiment, the security management platform manages multiple security services, which may specifically include any one or more of WAF (Web Application Firewall), operation and maintenance audit, database audit, Internet access behavior audit, firewall, and terminal security.
[0038] In this embodiment, a target scheduled task is set on the security management platform. During operation, each security service managed by the security management platform will push service alarm data to the log audit module in real time. When the system time reaches the start time of the target scheduled task, the security management platform executes the target scheduled task and grabs the service alarm data of all security services managed by the security management platform from the log audit module.
[0039] As a specific implementation manner, the security management platform grabs the service alarm data of all security services managed by the security management platform by calling the target interface of the log audit module. The above target interface is used to filter service alarm data according to the target filtering condition, and the target filtering condition can be specifically set as: the generation time of the service alarm data is between the end time of the last grab and the current time.
[0040] This embodiment sets an alarm policy, which records the alarm recipient information of each security service of different platform tenants. Therefore, after the security management platform grabs the service alarm data of all security services, it can query the alarm policy and push the service alarm data of each security service to the user terminal corresponding to the corresponding alarm recipient information.
[0041] As a specific implementation manner, after grabbing the service alarm data of all security services, the security management platform parses the service alarm data of each grabbed security service to determine the security service identifier and the platform tenant identifier; then, according to the security service identifier and the platform tenant identifier, it queries the alarm policy to determine the alarm recipient information of the security service.
[0042] On this basis, as a specific implementation manner, as Figure 3 shown, this embodiment selects the SMS and email module as the push module. During actual operation, the security management platform sends the service alarm data of each grabbed security service and the alarm recipient information of the security service to the SMS and email module, so that the SMS and email module pushes the service alarm data of the security service to the user terminal corresponding to the alarm recipient information of the security service.
[0043] To ensure the implementation of the alarm solution, this embodiment makes the following configurations at the sending end and the receiving end of the service alarm data: on each security service managed by the security management platform, the target address of the Syslog log is configured as the IP address of the log audit module, and the Syslog log includes service alarm data; on the log audit module, the source address of the Syslog log is configured as the IP addresses of all security services managed by the security management platform.
[0044] In addition, the present embodiment can also perform the following configurations on the security management platform: according to the setting instruction, set the execution period and / or start time of the target scheduled task.
[0045] Furthermore, the present embodiment can also perform the following configurations on the security management platform: according to the adjustment instruction, adjust the execution period of the target scheduled task.
[0046] The following takes an actual application as an example to introduce in detail the implementation steps of the service alarm method of the present application:
[0047] Step 1: Through the configuration page of the alarm policy, configure the alarm policy to determine the alarm recipient information of each security service under the platform tenant;
[0048] Step 2: Create the target tenant omp_alert_tenant on the log audit module; create the administrator account omp_alert_tenant_manager within the target tenant omp_alert_tenant;
[0049] Step 3: Configure the default collector of the log audit module to allow the default collector to receive the Syslog logs of the target tenant omp_alert_tenant; log in to the log audit module using the administrator account omp_alert_tenant_manager, and configure the source address of the Syslog logs as the IP addresses of all security services managed by the security management platform;
[0050] Step 4: On all security services, configure the target address of the Syslog logs as the IP address of the log audit module;
[0051] Step 5: The execution period of the target scheduled task can be set to 5 minutes, and the target scheduled task is started;
[0052] Step 6: The target scheduled task includes the following steps:
[0053] (1) Call the API interface of the log audit module, authenticate using the administrator account omp_alert_tenant_manager, and grab the Syslog logs under this account according to the filtering condition. The filtering condition is from the end time of the previous grab to the current time;
[0054] (2) Parse the Syslog logs, determine the platform tenant identifier of the security management platform according to the tenant name information in the Syslog logs, and determine the security service identifier;
[0055] (3) Query the alarm policy according to the platform tenant identifier and the security service identifier to determine the alarm recipient information;
[0056] (4) Send the service alarm data and the alarm recipient information to the SMS and email module together.
[0057] (5) Record the end time point of this round of scraping into the Redis database as the start time point for the next scrape.
[0058] Step 7: The SMS and email module sends the service alarm data to the user terminals corresponding to the alarm recipient information.
[0059] It can be seen from the above technical solutions that the service alarm method of this application has at least the following advantages:
[0060] First, this application uses the log audit module to receive the service alarm data of each security service managed by the security management platform. Only one target scheduled task needs to be set to scrape the service alarm data of all security services from the log audit module, without setting a scheduled task for each security service separately. The number of scheduled tasks is reduced. Therefore, no matter how many security services are managed by the security management platform, the performance of the security management platform will not decay due to the increase in the number of security services.
[0061] Second, because only one target scheduled task needs to be set in the security management platform of this application, the execution period of the target scheduled task can be set shorter to improve the sensitivity of alarm triggering. Moreover, since the security service directly pushes the service alarm data to the log audit module, the problem of failed scraping or partial loss of service alarm data can be avoided.
[0062] Third, when adding a new security service to the security management platform, this application only needs to configure the source address of the new Syslog log on the log audit module, without developing a new scheduled task, which improves the scalability of the entire alarm solution.
[0063] Based on the same inventive concept, this application also provides a service alarm device, which is applied to the security management platform. The schematic structural diagram is as Figure 4 shown and specifically includes:
[0064] A scraping module 410, configured to execute a target scheduled task to scrape the service alarm data of all security services managed by the security management platform from the log audit module, where the log audit module is used to receive the service alarm data pushed in real time by each security service managed by the security management platform;
[0065] A query module 420, configured to query the alarm policy to determine the alarm recipient information of each security service managed by the security management platform;
[0066] A pushing module 430, configured to push the service alarm data of each security service captured to the user terminals corresponding to the alarm recipient information of this security service.
[0067] As a specific implementation manner, the grabbing module 410 grabs the business alarm data of all the security services managed by the security management platform from the log auditing module in the following specific way:
[0068] Call the target interface of the log auditing module, and grab the business alarm data of all the security services managed by the security management platform from the log auditing module according to the target filtering condition, where the target filtering condition is that the generation time of the business alarm data is between the last grabbing end time and the current time.
[0069] As a specific implementation manner, the query module 420 determines the alarm recipient information of each security service managed by the security management platform in the following specific way:
[0070] Analyze the business alarm data of each grabbed security service to determine the security service identifier and the platform tenant identifier; according to the security service identifier and the platform tenant identifier, query the alarm policy to determine the alarm recipient information of this security service.
[0071] As a specific implementation manner, the pushing module 430 pushes the business alarm data of each grabbed security service to the user terminal corresponding to the alarm recipient information of this security service in the following specific way:
[0072] Send the grabbed business alarm data of each security service and the alarm recipient information of this security service to the SMS and email module, so that the SMS and email module pushes the business alarm data of this security service to the user terminal corresponding to the alarm recipient information of this security service.
[0073] As a specific implementation manner, the device further includes:
[0074] A sending end configuration module, configured to configure the target address of the Syslog log as the IP address of the log auditing module on each of the security services managed by the security management platform, where the Syslog log includes business alarm data;
[0075] A receiving end configuration module, configured to configure the source address of the Syslog log as the IP addresses of all the security services managed by the security management platform on the log auditing module.
[0076] As a specific implementation manner, the device further includes:
[0077] An adjustment module, configured to adjust the execution period of the target timing task according to an adjustment instruction.
[0078] An embodiment of the present application also provides a computer-readable storage medium, which includes computer instructions. When the computer instructions run on an electronic device, the electronic device is caused to execute each function or step of the above method embodiment.
[0079] The above computer-readable storage medium includes, but is not limited to, any of the following: USB flash drive, mobile hard disk, read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disc, etc., various media that can store program codes.
[0080] An embodiment of the present application also provides a computer program product. When the computer program product runs on a computer, the computer is caused to execute each function or step of the above method embodiment.
[0081] Among them, the electronic device, computer-readable storage medium, and computer program product provided by the embodiments of the present application are all used to execute the corresponding method provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding method provided above, and will not be elaborated here.
[0082] Through the description of the above embodiments, those skilled in the art can clearly understand that for the convenience and simplicity of description, only the above division of each functional module is used as an example. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above.
[0083] In several embodiments provided by the present application, it should be understood that the disclosed method can be implemented in other ways. The device embodiments described above are only illustrative. For example, the division of the module or unit is only a logical function division, and there may be other division methods in actual implementation; for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces, indirect coupling or communication connection of modules or units, and can be in electrical, mechanical or other forms.
[0084] In addition, each functional unit in the various embodiments of the present application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0085] As described above, it is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions within the technical scope disclosed in the present application should be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims described.
Claims
1. A service alarm method, characterized in that: The method is applied to a security management platform, and the method comprises: Execute the target scheduled task to capture the business alarm data of all security services managed by the security management platform from the log audit module, wherein the log audit module is used to receive the business alarm data pushed in real time by each security service managed by the security management platform; Query the alarm strategy to determine the alarm recipient information of each security service managed by the security management platform; The captured business alarm data of each security service is pushed to the user terminal corresponding to the alarm recipient information of the security service.
2. The method according to claim 1, characterized in that The method specifically captures the business alarm data of all security services managed by the security management platform from the log audit module in the following manner: The target interface of the log audit module is called, and the business alarm data of all security services managed by the security management platform are captured from the log audit module according to the target filtering conditions, wherein the target filtering conditions are that the generation time of the business alarm data is between the last capture end time and the current time.
3. The method according to claim 1, characterized in that: The method specifically determines the alarm recipient information of each security service managed by the security management platform in the following manner: Parse the captured business alarm data of each security service to determine the security service ID and platform tenant ID; According to the security service identifier and the platform tenant identifier, the alarm policy is queried to determine the alarm recipient information of the security service.
4. The method according to claim 1, characterized in that: The method specifically pushes the captured business alarm data of each security service to the user terminal corresponding to the alarm recipient information of the security service in the following manner: The captured business alarm data of each security service and the alarm recipient information of the security service are sent to the SMS and email module, so that the SMS and email module pushes the business alarm data of the security service to the user terminal corresponding to the alarm recipient information of the security service.
5. The method according to claim 1, characterized in that The method further comprises: On each security service managed by the security management platform, a target address of a Syslog log is configured as an IP address of a log audit module, wherein the Syslog log includes service alarm data; On the log audit module, the source address of the Syslog log is configured as the IP addresses of all security services managed by the security management platform.
6. The method according to claim 1, characterized in that The method further comprises: The execution period of the target scheduled task is adjusted according to the adjustment instruction.
7. A service alarm device, characterized in that: The device is applied to a security management platform, and comprises: A capture module, used to execute a target scheduled task to capture the business alarm data of all security services managed by the security management platform from the log audit module, wherein the log audit module is used to receive the business alarm data pushed in real time by each security service managed by the security management platform; A query module, used to query the alarm strategy to determine the alarm recipient information of each security service managed by the security management platform; The push module is used to push the captured business alarm data of each security service to the user terminal corresponding to the alarm recipient information of the security service.
8. The device according to claim 7, characterized in that The capture module specifically captures the business alarm data of all security services managed by the security management platform from the log audit module in the following manner: The target interface of the log audit module is called, and the business alarm data of all security services managed by the security management platform are captured from the log audit module according to the target filtering conditions, wherein the target filtering conditions are that the generation time of the business alarm data is between the last capture end time and the current time.
9. The device according to claim 7, characterized in that The query module specifically determines the alarm recipient information of each security service managed by the security management platform in the following manner: Parse the captured business alarm data of each security service to determine the security service ID and platform tenant ID; According to the security service identifier and the platform tenant identifier, the alarm policy is queried to determine the alarm recipient information of the security service.
10. The device according to claim 7, characterized in that The device also includes: A sending end configuration module, configured to configure the target address of the Syslog log as the IP address of the log audit module on each security service managed by the security management platform, wherein the Syslog log includes business alarm data; The receiving end configuration module is used to configure the source address of the Syslog log on the log audit module to the IP addresses of all security services managed by the security management platform.
11. A computer-readable storage medium comprising computer instructions, characterized in that: When the computer instructions are executed on an electronic device, the electronic device is caused to execute the method according to any one of claims 1 to 6.
12. A computer program product, characterized in that When the computer program product is executed on a computer, the computer is caused to execute the method according to any one of claims 1 to 6.