Association processing system and method for network security events
By combining the extraction matrix and the association processing matrix, the problem that traditional technology cannot effectively analyze the correlation characteristics of network security events is solved, and the correlation analysis and multi-dimensional correlation representation of network security events are realized.
Patent Information
- Application Number
- CN202510528278.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-25
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2045-04-25
AI Technical Summary
Traditional network security incident correlation processing cannot effectively analyze the correlation between correlation characteristics, resulting in the inability to accurately determine the target of the attack.
By extracting the matrix and the association processing matrix, identifying the identification features and generating correlation numbers, determining the reference sequence segments, and adjusting the identification rules to improve the accuracy of the correlation analysis.
The correlation analysis of network security events is realized, the correlation relationship between related events is clarified, and the correlation of related events can be expressed in multiple dimensions.
Smart Images

Figure CN120050156A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security events, and particularly to a system and method for correlative processing of network security events. Background Art
[0002] Traditional network security events do not exist singly. Especially for network attacks, data theft, and network paralysis, etc., they are not single attack behaviors but a series of correlative attacks. Therefore, correlative analysis is an effective means to obtain the attack target. At present, most correlative processing of network security events basically adopts the methods of data stripping and semantic processing. Semantic processing can only extract relevant correlative features, but the correlation degree between the correlative features cannot be confirmed. It needs to be determined through correlation degree analysis later. However, the correlation degree shows different levels of correlation, and traditional methods cannot perform effective correlation degree analysis. Summary of the Invention
[0003] In view of this, the purpose of the present invention is to provide a system and method for correlative processing of network security events to solve the problems raised in the background art.
[0004] The main purpose of the present application is to provide a system for correlative processing of network security events, including: An extraction matrix configured to extract recognition features from multiple correlative events; and A correlative processing matrix, which includes: A feature recognizer configured to be connected to the extraction matrix according to a set recognition rule and classify the correlative events according to the recognition features; An association code generator configured to generate a correlation coefficient based on a feature comprehensive value formed by the obtained recognition features, and A controller and an evaluator; The controller is configured to: Input at least one recognition feature obtained from a single correlative event into the association code generator to form a feature comprehensive value by the association code generator; Use the feature comprehensive value to determine a reference sequence segment; determine the proximity between reference sequence segments through the correlation coefficient; Use the reference sequence segment to control the feature recognizer to receive the correlative event from any extraction unit in the extraction matrix according to the set recognition rule and generate a processed correlative event; Use the evaluator to load the processed correlative event to evaluate the correlation score of the correlative event, transfer the correlation score to the controller, and the controller adjusts the recognition rule according to the correlation score.
[0005] Furthermore, the extraction matrix has: A logic control unit, a plurality of extraction units, and an association configuration unit; The logic control unit is used to configure the extraction rules of the plurality of extraction units, set the output rules after the extraction units extract recognition features, and Call the association configuration unit according to the output rules to set the reference sequence segment of the association event.
[0006] Furthermore, the association event is associated with at least one reference sequence segment.
[0007] Furthermore, the logic control unit configures the extraction rules of the plurality of extraction units according to the following method: Perform manual expert annotation according to historical association events, obtain the recognition feature set and the association feature value of any one recognition feature in the recognition feature set, and establish a recognition feature library according to the obtained recognition feature set; Load the recognition feature library, perform iterative training according to the association feature value, obtain different class libraries, classify the association feature values within the same association range into the same class library, and reset the recognition feature library according to the obtained processed class library to form a classification feature library; Configure one extraction unit corresponding to one class library to form a configuration relationship table, and set the polling rules of the plurality of extraction units according to the configuration relationship table, so as to obtain the extraction rules of the extraction units.
[0008] Furthermore, the output rule is to perform proximity output according to the association feature values corresponding to a plurality of recognition features extracted from the association event, where the proximity output means that the association feature values are within the same value range.
[0009] Furthermore, the association configuration unit is used to configure the reference sequence segment according to a plurality of recognition feature sets with different value ranges obtained from any one association event, and the same association event has at least one reference sequence segment.
[0010] Furthermore, the association configuration unit is used to configure the order of the reference sequence segments according to the concentration degree and quantity of the recognition features in each recognition feature set among a plurality of recognition feature sets with different value ranges obtained from any one association event.
[0011] Furthermore, the feature recognizer is used to classify the association event according to the reference sequence segment of any one association event.
[0012] Furthermore, the association code generator forms a feature comprehensive value by obtaining the association feature value of the recognition feature, where any one recognition feature has at least one association feature value.
[0013] The present invention also provides a method for correlating and processing network security events, comprising the following steps: Input at least one recognition feature obtained from a single said correlation event into a correlation code generator to form a feature comprehensive value by the correlation code generator; Use the feature comprehensive value to determine a reference sequence segment; Use the reference sequence segment to control the feature recognizer to receive the correlation event from any one extraction unit in the extraction matrix according to a set recognition rule, and generate a processed correlation event; Use the evaluator to load the processed correlation event to evaluate the correlation score of the correlation event, and transfer the correlation score to the controller, and the controller adjusts the recognition rule according to the correlation score.
[0014] In this application, feature extraction is performed again on the obtained correlation events. By determining the feature comprehensive value, generating the correlation coefficient, and determining the reference sequence segment for the recognition features. Use the reference sequence segment to control the feature recognizer to receive the correlation event from any one extraction unit in the extraction matrix according to a set recognition rule, and generate a processed correlation event; the processed correlation event can clarify the correlation degree with other correlation events. Since there is at least one reference sequence segment, the reference sequence segment of any correlation event can classify the correlation event. And multiple reference sequence segments of the same correlation event indicate that the correlation event has different degrees of correlation with multiple other correlation events, and can represent the correlation of the correlation event in multiple dimensions. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Figure 1 is a schematic diagram of the framework principle of the present invention; Figure 2 is a flowchart of the method of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0016] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0017] The purpose of this application is to provide a system and method for correlating and processing network security events, specifically to obtain the correlation degree of correlation events by analyzing and processing the correlation events again under the determination of traditional correlation events.
[0018] As described above, associated events can be understood as a set of corresponding associated events obtained by analyzing security logs of network attacks, such as attacks on a network system by malicious programs, or by obtaining specific attack behaviors in real time with the help of detection tools, such as a large number of abnormal subprocess chains, atypical function calls, malicious signatures, etc. The set of associated events can be obtained in these ways.
[0019] As described above, network attack events should not be simply understood as the malicious programs listed above in this application, but should also include data security, information content security, facility and equipment security, etc. Specific attack behaviors vary depending on the tools used and the attack targets, but attack data information can be obtained through security logs and active detection.
[0020] As shown above, this application can also bypass the determination of traditional associated events and establish the analysis of associated events. For example, security events can be established from data information sources such as abnormal subprocess chains, atypical function calls, and malicious signatures. Different ways serve as the main body of security events, and the security events under different main bodies can be specifically determined through specific matters. For example, several different security events can be determined according to the abnormal subprocess chain. The call of the subprocess chain is not chaotic but has a precise purpose. Therefore, there are definite association relationships between these subprocess chains, and these association relationships can be obtained through data stripping and semantic analysis, or by establishing corresponding models.
[0021] Therefore, based on the above facts, the main purpose of this application is to provide an associated processing system for network security events, including: an extraction matrix configured to extract identification features from multiple associated events; and an associated processing matrix including: a feature recognizer configured to be connected to the extraction matrix according to a set identification rule and classify the associated events according to the identification features; an association code generator configured to generate an association coefficient based on a feature comprehensive value formed by the obtained identification features, as well as a controller and an evaluator; the controller is configured to: input at least one identification feature obtained from a single associated event into the association code generator to form a feature comprehensive value by the association code generator; determine a reference sequence segment using the feature comprehensive value; determine the similarity between reference sequence segments through the association coefficient; use the reference sequence segment to control the feature recognizer to receive the associated event from any extraction unit in the extraction matrix according to the set identification rule and generate a processed associated event; use the evaluator to load the processed associated event to evaluate the association score of the associated event, transfer the association score to the controller, and the controller adjusts the identification rule according to the association score.
[0022] In some embodiments, by extracting features from associated events, determining a feature comprehensive value, generating a correlation coefficient, and determining a reference sequence segment for the recognition features. Using the reference sequence segment to control the feature recognizer to receive the associated event from any one of the extraction units in the extraction matrix according to the set recognition rules, and generating a processed associated event; the processed associated event can clarify the degree of association with other associated events. Since there is at least one reference sequence segment, the reference sequence segment of any associated event can classify the associated event. And multiple reference sequence segments of the same associated event indicate that the associated event has associations with multiple other associated events with different degrees of association, and can represent the associations of the associated event in multiple dimensions. The associations in multiple dimensions indicate that the concentration of the association relationships between the same associated event and other associated events is different, or in other words, the similarity is arranged according to certain rules.
[0023] In some embodiments, the present application can also use the evaluator to load the processed associated event to evaluate the association score of the associated event. Through the association score, it can be determined whether the set recognition rules are reliable. At the same time, the recognition rules can also be improved in real time.
[0024] In some embodiments, the extraction matrix has: a logic control unit, a plurality of extraction units, and an association configuration unit; the logic control unit is used to configure the extraction rules of the plurality of extraction units, set the output rules after the extraction units extract the recognition features, and call the association configuration unit according to the output rules to set the reference sequence segment of the associated event.
[0025] In some embodiments, the associated event is associated with at least one reference sequence segment. Specifically, a plurality of recognition feature sets with different value ranges obtained for any one associated event are used to configure the reference sequence segment, and the same associated event has at least one reference sequence segment. The order of the reference sequence segment is configured according to the concentration and quantity of the recognition features in each recognition feature set among the plurality of recognition feature sets with different value ranges obtained for any one associated event.
[0026] In some embodiments, the logic control unit configures the extraction rules of a number of extraction units according to the following method: perform manual expert annotation based on historical associated events, obtain an identification feature set and the associated feature values of any one identification feature in the identification feature set, and establish an identification feature library according to the obtained identification feature set; load the identification feature library, perform iterative training according to the associated feature values, obtain different class libraries, classify the associated feature values within the same associated range into the same class library, and reset the identification feature library according to the obtained processed class libraries to form a classification feature library; configure one extraction unit corresponding to one class library to form a configuration relation table, and set the polling rules of a number of extraction units according to the configuration relation table, so as to obtain the extraction rules of the extraction units.
[0027] In some embodiments, the extraction rules can also be implemented by constructing a corresponding model. For example, the identification feature set obtained by expert annotation and the associated feature values of any one identification feature in the identification feature set are trained using a CNN training model.
[0028] In some embodiments, the output rule performs proximity output according to the associated feature values corresponding to a number of identification features extracted from the associated events, where the proximity output means that the associated feature values are within the same value range.
[0029] In some embodiments, the association configuration unit is used to configure reference sequence segments according to a number of identification feature sets with different value ranges obtained from any one associated event, and the same associated event has at least one reference sequence segment.
[0030] In some embodiments, the association configuration unit is used to configure the order of the reference sequence segments according to the concentration degree and quantity of the identification features of each identification feature set in a number of identification feature sets with different value ranges obtained from any one associated event.
[0031] In some embodiments, the feature recognizer is used to classify the associated event according to the reference sequence segment of any one associated event. The classification of the associated event helps to trace the source of different attack sources. As shown above, security events are established through data information sources such as abnormal subprocess chains, atypical function calls, and malicious signatures. Different methods are used as the main body of the security event, and the security events under different main bodies can be specifically determined through specific matters. Therefore, the classification of security events can accurately obtain the association set between events, so as to better perform source tracing.
[0032] In some embodiments, the association code generator forms a feature comprehensive value by obtaining the associated feature values possessed by the identification features, where any one identification feature has at least one associated feature value.
[0033] The present invention also provides a method for correlatively processing network security events, including the following steps: inputting at least one identification feature obtained from a single said correlation event into a correlation code generator to form a feature comprehensive value by the correlation code generator; using the feature comprehensive value to determine a reference sequence segment; using the reference sequence segment to control the feature recognizer to receive the correlation event from any one extraction unit in the extraction matrix according to a set recognition rule and generate a processed correlation event; using the evaluator to load the processed correlation event to evaluate the correlation score of the correlation event, and transmitting the correlation score to a controller, and the controller adjusts the recognition rule according to the correlation score. This application extracts features again from the already obtained correlation events, determines the feature comprehensive value, generates the correlation coefficient, and determines the reference sequence segment for the identification features. Using the reference sequence segment to control the feature recognizer to receive the correlation event from any one extraction unit in the extraction matrix according to a set recognition rule and generate a processed correlation event; the processed correlation event can clarify the correlation degree with other correlation events. Since there is at least one reference sequence segment, the reference sequence segment of any correlation event can classify the correlation event. And multiple reference sequence segments of the same correlation event indicate that the correlation event has correlations with multiple other correlation events with different correlation degrees, and can represent the correlation of the correlation event in multiple dimensions.
[0034] The above are only partial embodiments of the present application, and thus do not limit the patent scope of the present application. Any equivalent structural transformation made under the technical concept of the present application by using the content of the specification and drawings of the present application, or direct / indirect application in other related technical fields, is included in the patent protection scope of the present application.
Claims
1. A network security incident correlation processing system, characterized in that: include: an extraction matrix configured to extract identification features from a plurality of correlated events, and An association processing matrix, the association processing matrix comprising: A feature identifier, the feature identifier being configured to connect with the extraction matrix according to a set recognition rule and classify the associated events according to the recognition features; an association code generator configured to generate an association coefficient based on a feature comprehensive value formed by the obtained identification feature, and Controller and evaluator; The controller is configured to: Inputting at least one identification feature obtained from a single association event into an association code generator to form a feature comprehensive value using the association code generator; Determining a reference sequence segment using the feature integrated value; Using the reference sequence segment to control the feature identifier to receive the associated event from any extraction unit in the extraction matrix according to a set identification rule, and generate a processed associated event; The evaluator loads the processed association events to evaluate the association scores of the association events, and transmits the association scores to the controller, and the controller adjusts the identification rules according to the association scores.
2. The network security incident correlation processing system according to claim 1, characterized in that: The extraction matrix has: A logic control unit, a plurality of extraction units and an associated configuration unit; The logic control unit is used to configure the extraction rules of several extraction units, set the output rules after the extraction units extract the identification features, and The association configuration unit is called according to the output rule to set the reference sequence segment of the association event.
3. The network security event correlation processing system according to claim 1 or 2, characterized in that: The associated event is associated with at least one reference sequence segment.
4. The network security event correlation processing system according to claim 2, characterized in that: The logic control unit configures the extraction rules of several extraction units according to the following method: Performing manual expert annotation based on historical related events, obtaining a set of identification features and the associated feature value of any identification feature in the set of identification features, and establishing a recognition feature library based on the obtained set of identification features; Loading the recognition feature library, performing iterative training according to the associated feature values to obtain different class libraries, classifying the associated feature values in the same associated range into the same class library, and resetting the recognition feature library according to the processed class library to form a classification feature library; One extraction unit is configured to correspond to one class library to form a configuration relationship table, and polling rules of several extraction units are set according to the configuration relationship table, thereby obtaining extraction rules of the extraction unit.
5. The network security incident correlation processing system according to claim 2, characterized in that: The output rule is to perform similarity output according to the associated feature values corresponding to a plurality of identification features extracted from the associated events, wherein the similarity output means that the associated feature values are within the same value range.
6. The network security event correlation processing system according to claim 2, characterized in that: The association configuration unit is used to configure a reference sequence segment according to a plurality of identification feature sets with different value ranges obtained from any association event, and the same association event has at least one reference sequence segment.
7. The network security event correlation processing system according to claim 2 or 6, characterized in that: The association configuration unit is used to configure the order of the reference sequence segments according to the concentration and quantity of identification features of each identification feature set in a plurality of identification feature sets with different value ranges obtained from any association event.
8. The network security event correlation processing system according to claim 1, characterized in that: The feature identifier is used to classify any associated event according to a reference sequence segment of the associated event.
9. The network security event correlation processing system according to claim 1, characterized in that: The association code generator forms a feature comprehensive value by acquiring an associated feature value of the identification feature, wherein any identification feature has at least one associated feature value.
10. A method for processing network security incidents, characterized in that: The steps include: Inputting at least one identification feature obtained from a single association event into an association code generator to form a feature comprehensive value using the association code generator; Determining a reference sequence segment using the feature integrated value; Using the reference sequence segment to control the feature identifier to receive the associated event from any extraction unit in the extraction matrix according to a set identification rule, and generate a processed associated event; The processed association events are loaded by the evaluator to evaluate the association scores of the association events, and the association scores are transmitted to the controller, and the controller adjusts the identification rules according to the association scores.
Citation Information
Patent Citations
Internet of Things security event identification method and device thereof and computer equipment
CN111641621A
Rule-based network security event association analysis method and system
CN114143020A
Industrial control network security event association analysis method
CN114172699A
Network security event assessment method and system based on artificial intelligence
CN117973695A
Network safety warning system based on cluster and relavance
CN1588880A