System and method for correlated processing of network security events
The network security event association processing system improves the analysis of interconnected attacks by using a feature extractor and controller to determine reference sequence segments and evaluate association scores, enhancing the accuracy and reliability of association degree assessment.
Patent Information
- Application Number
- CN202510528278.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-25
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2045-04-25
AI Technical Summary
Traditional network security incident association processing methods cannot effectively perform correlation analysis, resulting in the inability to confirm the correlation between correlation features, affecting the acquisition of attack targets.
Using the extraction matrix and association processing matrix, the feature comprehensive values and correlation coefficients are generated through feature recognizers, association code generators, controllers and evaluators, the reference sequence segment is determined, and the identification rules are adjusted to evaluate the association scores of the association events, so as to realize multi-dimensional correlation analysis.
It clarifies the correlation between related events, can represent association relationships in multiple dimensions, supports real-time improvements in traceability analysis and identification rules, and improves the processing efficiency and accuracy of related events.
Smart Images

Figure CN120050156B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security events, and particularly to a system and method for associated processing of network security events. Background Art
[0002] Traditional network security events do not exist singly. Especially for network attacks, data theft, and network paralysis, etc., they are not single attack behaviors, but a series of associated attacks. Therefore, through associated analysis, it is an effective means to obtain the attack target. At present, the associated processing of most network security events basically adopts the methods of data stripping and semantic processing. Semantic processing can only extract relevant associated features, but the degree of association between the associated features cannot be confirmed and needs to be determined through degree-of-association analysis later. However, the degree of association shows different levels of association, and traditional methods cannot perform effective degree-of-association analysis. Summary of the Invention
[0003] In view of this, the purpose of the present invention is to provide a system and method for associated processing of network security events to solve the problems raised in the background art.
[0004] The main purpose of the present application is to provide a system for associated processing of network security events, including:
[0005] An extraction matrix configured to extract identification features from multiple associated events; and
[0006] An associated processing matrix, including:
[0007] A feature recognizer configured to be connected to the extraction matrix according to a set recognition rule and classify the associated events according to the identification features;
[0008] An association code generator configured to generate a correlation coefficient based on a feature comprehensive value formed by the obtained identification features, and
[0009] A controller and an evaluator;
[0010] The controller is configured to:
[0011] Input at least one identification feature obtained from a single associated event into the association code generator to form a feature comprehensive value by the association code generator;
[0012] Use the feature comprehensive value to determine a reference sequence segment; determine the similarity between reference sequence segments through the correlation coefficient;
[0013] Control the feature recognizer using the reference sequence segment to receive the associated event from any extraction unit in the extraction matrix according to the set recognition rules, and generate a processed associated event;
[0014] Use the evaluator to load the processed associated event to evaluate the association score of the associated event, and transfer the association score to the controller. The controller adjusts the recognition rules according to the association score.
[0015] Further, the extraction matrix has:
[0016] A logic control unit, a plurality of extraction units, and an association configuration unit;
[0017] The logic control unit is used to configure the extraction rules of a plurality of extraction units, set the output rules after the extraction units extract recognition features, and
[0018] Call the association configuration unit according to the output rules to set the reference sequence segment of the associated event.
[0019] Further, the associated event is associated with at least one reference sequence segment.
[0020] Further, the logic control unit configures the extraction rules of a plurality of extraction units according to the following method:
[0021] Perform manual expert annotation according to historical associated events, obtain the recognition feature set and the association feature value of any recognition feature in the recognition feature set, and establish a recognition feature library according to the obtained recognition feature set;
[0022] Load the recognition feature library, perform iterative training according to the association feature value, obtain different class libraries, classify the association feature values within the same association range into the same class library, and reset the recognition feature library according to the obtained processed class library to form a classification feature library;
[0023] Configure one extraction unit corresponding to one class library to form a configuration relation table, and set the polling rules of a plurality of extraction units according to the configuration relation table, so as to obtain the extraction rules of the extraction units.
[0024] Further, the output rule is proximity output according to the association feature values corresponding to several recognition features extracted from the associated event, where the proximity output means that the association feature values are within the same value range.
[0025] Further, the association configuration unit is used to configure the reference sequence segment according to several recognition feature sets with different value ranges obtained from any associated event, and the same associated event has at least one reference sequence segment.
[0026] Further, the association configuration unit is used to configure the order of the reference sequence segments according to the concentration and quantity of the recognition features in each recognition feature set of multiple recognition feature sets with different value ranges obtained from any one association event.
[0027] Further, the feature recognizer is used to classify the association event according to the reference sequence segment of any one association event.
[0028] Further, the association code generator forms a feature comprehensive value by obtaining the association feature values possessed by the recognition features, where any one recognition feature has at least one association feature value.
[0029] The present invention also provides an association processing method for network security events, including the following steps:
[0030] Input at least one recognition feature obtained from a single association event into the association code generator to form a feature comprehensive value by the association code generator;
[0031] Use the feature comprehensive value to determine the reference sequence segment;
[0032] Use the reference sequence segment to control the feature recognizer to receive the association event from any one extraction unit in the extraction matrix according to the set recognition rules, and generate a processed association event;
[0033] Use the evaluator to load the processed association event to evaluate the association score of the association event, and transfer the association score to the controller, and the controller adjusts the recognition rules according to the association score.
[0034] The present application performs feature extraction on the obtained association events again, determines the feature comprehensive value, generates the correlation coefficient, and determines the reference sequence segment for the recognition features. Use the reference sequence segment to control the feature recognizer to receive the association event from any one extraction unit in the extraction matrix according to the set recognition rules, and generate a processed association event; the processed association event can clarify the association degree with other association events. Since there is at least one reference sequence segment, the reference sequence segment of any one association event can classify the association event. And multiple reference sequence segments of the same association event indicate that the association event has associations with multiple other association events with different association degrees, and can represent the association of the association event in multiple dimensions. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] Figure 1 It is a schematic diagram of the framework principle of the present invention;
[0036] Figure 2 It is a flowchart of the method of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0037] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0038] The purpose of this application is to provide a system and method for associative processing of network security events. Specifically, under the determination of traditional associated events, the degree of association of associated events is obtained by re-analyzing and processing the associated events.
[0039] As described above, associated events can be understood as a series of network attack behaviors. For example, the attack behavior of malicious programs on the network system. The set of corresponding associated events can be obtained by analyzing the security logs of network attacks, or specific attack behaviors can be obtained in real time with the help of detection tools, such as a large number of abnormal subprocess chains, atypical function calls, malicious signatures, etc. The set of associated events is obtained in these ways.
[0040] As described above, network attack events cannot be simply understood as the malicious programs listed above in this application. It should also include data security, information content security, facility and equipment security, etc. Specific attack behaviors vary depending on the tools used and the attack targets, but attack data information can be obtained through security logs and active detection.
[0041] As shown above, this application can also discard the determination of traditional associated events and establish the analysis of associated events. For example, security events are established through data information sources such as abnormal subprocess chains, atypical function calls, malicious signatures, etc. Different ways are used as the main body of security events, and the security events under different main bodies can be specifically determined through specific matters. For example, several different security events can be determined according to the abnormal subprocess chain. The call of the subprocess chain is not chaotic and has a precise purpose. Therefore, there are definite association relationships between these subprocess chains, and these association relationships can be obtained through data stripping and semantic analysis, or can be obtained by establishing corresponding models.
[0042] Therefore, based on the above existing facts, the main object of the present application is to provide a system for associated processing of network security events, including: an extraction matrix configured to extract identification features from multiple associated events; and an associated processing matrix including: a feature recognizer configured to be connected to the extraction matrix according to a set recognition rule and classify the associated events according to the identification features; an association code generator configured to generate an association coefficient based on a feature comprehensive value formed by the obtained identification features, as well as a controller and an evaluator; the controller is configured to: input at least one identification feature obtained from a single associated event into the association code generator to form a feature comprehensive value by the association code generator; determine a reference sequence segment using the feature comprehensive value; determine the proximity between reference sequence segments through the association coefficient; use the reference sequence segment to control the feature recognizer to receive the associated event from any extraction unit in the extraction matrix according to the set recognition rule and generate a processed associated event; use the evaluator to load the processed associated event to evaluate the association score of the associated event, transfer the association score to the controller, and the controller adjusts the recognition rule according to the association score.
[0043] In some embodiments, by performing feature extraction on the associated events, determining a feature comprehensive value, generating an association coefficient, and determining a reference sequence segment for the identification features. Use the reference sequence segment to control the feature recognizer to receive the associated event from any extraction unit in the extraction matrix according to the set recognition rule and generate a processed associated event; the processed associated event can clarify the association degree with other associated events. Since there is at least one reference sequence segment, the reference sequence segment of any associated event can classify the associated event. And multiple reference sequence segments of the same associated event indicate that the associated event has associations with multiple other associated events with different association degrees, and can represent the associations of the associated event in multiple dimensions. The associations in multiple dimensions indicate that the concentration degrees of the association relationships between the same associated event and other associated events are different, or in other words, the proximities are arranged according to a certain rule.
[0044] In some embodiments, the present application can also use the evaluator to load the processed associated event to evaluate the association score of the associated event. Through the association score, it can be determined whether the set recognition rule is reliable. At the same time, the recognition rule can also be improved in real time.
[0045] In some embodiments, the extraction matrix has: a logic control unit, a plurality of extraction units, and an association configuration unit; the logic control unit is configured to configure the extraction rules of the plurality of extraction units, set the output rules after the extraction units extract recognition features, and call the association configuration unit according to the output rules to set the reference sequence segments of the association events.
[0046] In some embodiments, the association event is associated with at least one reference sequence segment. Specifically, a plurality of recognition feature sets with different value ranges obtained from any one association event are used to configure the reference sequence segment, and the same association event has at least one reference sequence segment. The order of the reference sequence segments is configured according to the concentration degree and quantity of the recognition features of each recognition feature set among the plurality of recognition feature sets with different value ranges obtained from any one association event.
[0047] In some embodiments, the logic control unit configures the extraction rules of the plurality of extraction units according to the following method: perform manual expert annotation according to historical association events, obtain the recognition feature set and the association feature value of any one recognition feature in the recognition feature set, establish a recognition feature library according to the obtained recognition feature set; load the recognition feature library, perform iterative training according to the association feature value, obtain different class libraries, classify the association feature values in the same association range into the same class library, and reset the recognition feature library according to the obtained processed class library to form a classification feature library; configure one extraction unit corresponding to one class library to form a configuration relation table, and set the polling rules of the plurality of extraction units according to the configuration relation table, so as to obtain the extraction rules of the extraction units.
[0048] In some embodiments, the extraction rules can also be implemented by constructing a corresponding model, such as training the recognition feature set marked by experts and the association feature value of any one recognition feature in the recognition feature set using a CNN training model.
[0049] In some embodiments, the output rule performs proximity output according to the association feature values corresponding to a plurality of recognition features extracted from the association event, where the proximity output means that the association feature values are within the same value range.
[0050] In some embodiments, the association configuration unit is configured to configure the reference sequence segment according to a plurality of recognition feature sets with different value ranges obtained from any one association event, and the same association event has at least one reference sequence segment.
[0051] In some embodiments, the association configuration unit is configured to configure the order of the reference sequence segments according to the concentration degree and quantity of the recognition features of each recognition feature set among the plurality of recognition feature sets with different value ranges obtained from any one association event.
[0052] In some embodiments, the feature recognizer is used to classify an associated event according to a reference sequence segment of any associated event. The classification of associated events helps to trace the source of different attack sources. As shown above, security events are established through data information sources such as abnormal subprocess chains, atypical function calls, and malicious signatures. Different ways serve as the main body of security events, and the security events under different main bodies can be specifically determined through specific matters. Therefore, the classification of security events can accurately obtain the association set between events, thereby enabling better traceability.
[0053] In some embodiments, the association code generator forms a feature comprehensive value by obtaining the association feature value of the recognition feature, where any recognition feature has at least one association feature value.
[0054] The present invention also provides an association processing method for network security events, including the following steps: inputting at least one recognition feature obtained from a single associated event into an association code generator to form a feature comprehensive value by the association code generator; using the feature comprehensive value to determine a reference sequence segment; using the reference sequence segment to control the feature recognizer to receive the associated event from any extraction unit in the extraction matrix according to a set recognition rule and generate a processed associated event; using the evaluator to load the processed associated event to evaluate the association score of the associated event, and transmitting the association score to the controller, and the controller adjusts the recognition rule according to the association score. This application performs feature extraction on the already obtained associated events again, determines the feature comprehensive value, generates the correlation coefficient, and determines the reference sequence segment for the recognition features. Use the reference sequence segment to control the feature recognizer to receive the associated event from any extraction unit in the extraction matrix according to a set recognition rule and generate a processed associated event; the processed associated event can clarify the association degree with other associated events. Since there is at least one reference sequence segment, the reference sequence segment of any associated event can classify the associated event. And multiple reference sequence segments of the same associated event indicate that the associated event has associations with multiple other associated events with different association degrees, and can represent the association of the associated event in multiple dimensions.
[0055] The above are only some embodiments of the present application, and do not limit the patent scope of the present application. All equivalent structural transformations made under the technical concept of the present application by using the content of the specification and drawings of the present application, or directly / indirectly applied in other related technical fields are included in the patent protection scope of the present application.
Claims
1. An associated processing system for network security events, characterized in that, Comprising: An extraction matrix configured to extract recognition features from multiple associated events, and An association processing matrix, which includes: A feature recognizer configured to be connected to the extraction matrix according to set recognition rules and classify the associated events based on the recognition features; An association code generator configured to generate an association coefficient based on a feature comprehensive value formed by the obtained recognition features, and A controller and an evaluator; The controller is configured to: Input at least one recognition feature obtained from a single associated event into the association code generator to form a feature comprehensive value by the association code generator; Use the feature comprehensive value to determine a reference sequence segment; Use the reference sequence segment to control the feature recognizer to receive the associated event from any one extraction unit in the extraction matrix according to the set recognition rules and generate a processed associated event; Utilize the evaluator to load the processed associated event to evaluate the association score of the associated event, transfer the association score to the controller, and the controller adjusts the recognition rules according to the association score.
2. The correlation processing system for network security incidents according to claim 1, wherein The extraction matrix has: A logic control unit, several extraction units, and an association configuration unit; The logic control unit is used to configure the extraction rules of several extraction units, set the output rules after the extraction units extract recognition features, and Call the association configuration unit according to the output rules to set the reference sequence segment of the associated event.
3. The correlation processing system for network security events according to claim 1 or 2, characterized in that, The associated event is associated with at least one reference sequence segment.
4. The correlation processing system for network security events according to claim 2, characterized in that, The logic control unit configures the extraction rules of several extraction units according to the following method: Perform manual expert annotation on historical associated events, obtain a recognition feature set and the association feature value of any one recognition feature in the recognition feature set, and establish a recognition feature library based on the obtained recognition feature set; Load the recognition feature library, perform iterative training according to the association feature value, obtain different class libraries, classify the association feature values within the same association range into the same class library, and reset the recognition feature library according to the obtained processed class library to form a classification feature library; Configure one extraction unit corresponding to one class library to form a configuration relationship table, and set the polling rules of several extraction units according to the configuration relationship table, thereby obtaining the extraction rules of the extraction units.
5. The correlation processing system for network security incidents according to claim 2, wherein The output rule is proximity output according to the association feature values corresponding to several recognition features extracted from the associated event, where proximity output means that the association feature values are within the same value range.
6. The correlation processing system for network security incidents according to claim 2, wherein The association configuration unit is used to configure a reference sequence segment according to several recognition feature sets with different value ranges obtained from any one associated event, and the same associated event has at least one reference sequence segment.
7. The correlation processing system for network security events according to claim 2 or 6, characterized in that, The association configuration unit is used to configure the order of the reference sequence segments according to the concentration and quantity of the recognition features of each recognition feature set in several recognition feature sets with different value ranges obtained from any one associated event.
8. The correlation processing system for network security events according to claim 1, wherein, The feature recognizer is used to classify the associated event according to the reference sequence segment of any one associated event.
9. The correlation processing system for network security events according to claim 1, wherein The associated code generator forms a feature comprehensive value by obtaining the associated feature values of the recognition features, wherein any one recognition feature has at least one associated feature value.
10. Method for correlating and processing network security events, characterized in that, It includes the following steps: Input at least one recognition feature obtained from a single said associated event into the associated code generator, and use the associated code generator to form a feature comprehensive value; Use the feature comprehensive value to determine a reference sequence segment; Use the reference sequence segment to control the feature recognizer to receive the associated event from any one extraction unit in the extraction matrix according to the set recognition rules, and generate a processed associated event; Use an evaluator to load the processed associated event to evaluate the associated score of the associated event, transfer the associated score to the controller, and the controller adjusts the recognition rules according to the associated score.
Citation Information
Patent Citations
Internet of Things security event identification method and device thereof and computer equipment
CN111641621A
Rule-based network security event association analysis method and system
CN114143020A