Security management method and device and electronic equipment
By using bypass mirroring in the network to obtain traffic data, generate logs, and use association analysis and all-inclusive forensics engines, problems that are difficult to deal with in complex network attacks are solved, network threat detection and traceability capabilities are realized, and security operation and maintenance efficiency and decision-making and prediction capabilities are improved.
Patent Information
- Application Number
- CN202510214880.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-25
- Publication Date
- 2025-05-30
AI Technical Summary
The current cyber attack methods are complex and traditional security protection methods are difficult to deal with. How to improve security protection capabilities, enhance decision-making and prediction capabilities, improve security operation and maintenance efficiency, normalized offense and defense capabilities, and reduce the burden of security operation and maintenance has become a key research direction.
Bypass mirroring is used to obtain network traffic data from the target network's switching devices, generate network logs, generate alarm data using the association analysis engine, and generate traffic traceability results using the full-inclusive forensics engine to realize network threat detection, deep threat detection and full-inclusive traceability forensics capabilities.
It has realized the capabilities of network threat detection, in-depth threat detection and full-inclusive traceability and evidence collection, helping customers enhance their decision-making and prediction capabilities, quickly discover and solve problems, improve security operation and maintenance efficiency, and reduce the burden of enterprise security operation and maintenance.
Smart Images

Figure CN120074912A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and in particular, to a security management method, apparatus, and electronic device. Background Art
[0002] Currently, network attack means are becoming increasingly complex, and traditional security protection methods are difficult to cope with. How to improve the security protection ability, enhance the enterprise's decision-making prediction ability, improve the security operation and maintenance efficiency, normalize the attack and defense ability, and reduce the enterprise's security operation and maintenance burden is the key research direction in this field. Summary of the Invention
[0003] To overcome the problems existing in the related art, this application provides a security management method, apparatus, and electronic device.
[0004] According to the first aspect of the embodiments of this application, a security management method is provided. The method includes:
[0005] Obtaining network traffic data from a switching device of a target network in a way of bypass mirroring;
[0006] Generating network logs according to the network traffic data;
[0007] Using an association analysis engine to generate alarm data according to the network logs;
[0008] Using a full-packet forensics engine to generate a traffic traceability result according to the selected alarm data.
[0009] According to the second aspect of the embodiments of this application, a security management apparatus is provided. The apparatus includes:
[0010] A data acquisition module, configured to obtain network traffic data from a switching device of a target network in a way of bypass mirroring;
[0011] A log generation module, configured to generate network logs according to the network traffic data;
[0012] An advanced analysis module, configured to use an association analysis engine to generate alarm data according to the network logs;
[0013] A traceability module, configured to use a full-packet forensics engine to generate a traffic traceability result according to the selected alarm data.
[0014] According to the third aspect of the embodiments of this application, an electronic device is provided, including: a memory, one or more processors; the memory is coupled to the processor; wherein, computer program code is stored in the memory, and the computer program code includes computer instructions. When the computer instructions are executed by the processor, the electronic device executes the method as described above.
[0015] According to a fourth aspect of the embodiments of the present application, there is provided a computer-readable storage medium including computer instructions, which, when running on an electronic device, cause the electronic device to execute the method described above.
[0016] According to a fifth aspect of the embodiments of the present application, there is provided a computer program product, which, when running on a computer, causes the computer to execute the method described above.
[0017] The technical solutions provided by the embodiments of the present application may include the following beneficial effects:
[0018] The embodiments of the present application adopt the method of bypass mirroring to obtain network traffic data from the switching device of the target network; generate network logs according to the network traffic data; use an association analysis engine to generate alarm data according to the network logs; use a full-packet forensics engine to generate a traffic traceability result according to the selected alarm data. It realizes the capabilities of network threat detection, in-depth threat detection and full-packet traceability forensics, and can help customers enhance their decision-making and prediction capabilities, quickly discover and solve problems, and improve the efficiency of security operation and maintenance. It enhances the decision-making and prediction capabilities, improves the efficiency of security operation and maintenance, and normalizes the offensive and defensive capabilities of enterprises, and reduces the burden of enterprise security operation and maintenance.
[0019] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] The accompanying drawings herein are incorporated into the specification and form a part of the present application, showing embodiments consistent with the present application and used together with the specification to explain the principles of the present application.
[0021] Figure 1 It is a schematic flowchart of a security management method provided by an embodiment of the present application;
[0022] Figure 2 It is a system architecture diagram of a security management method provided by an embodiment of the present application;
[0023] Figure 3 It is a schematic diagram of the implementation principle of a security management method provided by an embodiment of the present application;
[0024] Figure 4 It is a functional block diagram of a security management device provided by an embodiment of the present application;
[0025] Figure 5 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0026] The following describes the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. Among them, in the description of the embodiments of the present application, the terms used in the following embodiments are only for the purpose of describing specific embodiments, and are not intended to limit the present application.
[0027] It should be noted that "at least one" in the present application means one or more, and "a plurality" means two or more than two. "And / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone, where A and B can be singular or plural. The terms "first", "second", "third", etc. (if any) in the specification, claims and drawings of the present application are used to distinguish similar objects, rather than to describe a specific order or sequence.
[0028] In the embodiments of the present application, words such as "exemplary" or "for example" are used to represent examples, illustrations or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of words such as "exemplary" or "for example" is intended to present relevant concepts in a specific manner.
[0029] The present application provides a security management method, device and electronic device, which can perform full-flow and high-performance real-time intelligent analysis on network data packets, detect suspicious behaviors such as abnormal traffic and security threats in the network, and aims to build a network security threat defense system that integrates pre-event prediction, in-event detection, and post-event traceability based on network traffic analysis.
[0030] Next, the embodiments of the present application will be described in detail.
[0031] The embodiments of the present application provide a security management method, as Figure 1 shown, the method may include the following steps:
[0032] Step 110: Obtain network traffic data from the switching device of the target network in a bypass mirroring manner;
[0033] Step 120: Generate network logs according to the network traffic data;
[0034] Step 130: Use the correlation analysis engine to generate alarm data according to the network logs;
[0035] Step 140: Use the full-packet forensics engine to generate a traffic traceability result according to the selected alarm data.
[0036] In this embodiment, the target network refers to the network that needs to be monitored. As Figure 2As shown, the target network includes a switching device and other network devices ( Figure 2 not shown). The security device is connected in parallel to the switching device. The security management method of this embodiment is implemented based on the security device. The security device obtains network traffic data from the switching device of the target network in a bypass mirroring manner.
[0037] After that, the security device generates network logs according to the network traffic data. Specifically, the threat detection engine is used to identify known and unknown threats according to the network traffic data, including malware, vulnerability exploitation, abnormal behavior, etc. Through functions such as virus protection and URL (Uniform Resource Locator) filtering, in-depth analysis and detection up to the seventh layer are carried out to discover attacks and malicious behaviors such as viruses, worms, Trojans, spyware, and web page tampering hidden in the network traffic in real time. The number of identifiable threat features can reach more than 9000+, which can comprehensively protect against various threat attacks. Moreover, it can also jointly protect the security of the Web server in combination with the semantic analysis engine, and can identify more than 120 real file types to prevent the purpose of sending out files by modifying the file suffix.
[0038] Network logs are generated through the above technologies, including different types of security logs such as malicious files, vulnerability scanning exploitation, scanning detection, and Web security, as well as traffic logs. Then, the network logs accessed through data analysis are subjected to normalization adaptation processing to map different fields.
[0039] The correlation analysis engine further conducts advanced analysis and matches the correlation analysis rules to generate security alarm data. The correlation analysis detection rules are such as malicious host external connection. The detection conditions are that the traffic log contains source internal and external network identifiers, destination internal and external network identifiers, whether the destination IP is in the intelligence database, whether the destination IP belongs to the intelligence IP, etc. During the reporting process of the traffic data, the correlation analysis engine synchronously analyzes the fields after the log is enriched and generates security alarms for the data that meets the conditions of the correlation analysis engine rules. The correlation analysis engine is such as the internal network vulnerability exploitation rule, and the detection conditions are the attack type whether it is vulnerability exploitation, source internal and external network identifiers, and feature hit direction.
[0040] Specifically, the traffic log may include the following fields: log identifier, log generation time, IP type of the device generating the log, IP of the device generating the log, type of the device generating the log, name of the device generating the log, source IP type, source IP, source port, source asset name, destination IP type, destination IP, and destination port.
[0041] Further, the traffic log may also include a protocol field. This embodiment supports protocols such as TCP (Transmission Control Protocol), UDP (User Datagram Protocol), ICMP (Internet Control Message Protocol), ARP (Address Resolution Protocol), and ICMPv6 (Internet Control Message Protocol for IPv6).
[0042] Further, the traffic log may also include a traffic log classification field. This embodiment supports traffic log classifications such as session logs, NAT (Network Address Translation) logs, and aggregation logs.
[0043] Further, for session logs, the traffic log also includes a log sub-classification field. This embodiment supports log sub-classifications such as session start, session update, session end, and session start & end.
[0044] On this basis, in practical applications, the warning data is generated from the network log in the following specific way: Determine whether the current traffic log meets the first correlation analysis rule (malicious host external connection). If the determination result is yes, generate the first warning data according to the current traffic log. Among them, the first correlation analysis rule includes: the source address belongs to the internal network, the destination address belongs to the external network, the destination address is an intelligence address, the log classification is a session log, and the log sub-classification is session end or between session start and session end. The first warning data includes: warning name, warning description, correlation analysis rule name, and intelligence information.
[0045] Specifically, this embodiment pre-sets an intelligence library. The intelligence library includes multiple pieces of intelligence information. Each piece of intelligence information includes an intelligence address, and also includes a port, an intelligence type, a virus family name, etc. The status of each piece of intelligence information also supports being set to enabled or disabled.
[0046] Further, the first alarm data is generated from the current traffic log in the following specific manner: match the destination address of the current traffic log with the intelligence addresses in the intelligence database to determine whether the destination address of the current traffic log is the same as any intelligence address in the intelligence database; if the judgment result is yes and the current traffic log meets the first correlation analysis rule, determine the target intelligence information corresponding to the target intelligence address in the intelligence database; generate the first alarm data according to the current traffic log and the target intelligence information; wherein, the intelligence database includes multiple pieces of intelligence information, and each piece of intelligence information includes an intelligence address.
[0047] Specifically, the security log may include the following fields: log unique identifier, log generation time, generating log device IP type, generating log device IP, generating log device type, generating log device name, source IP type, source IP, source port, destination IP type, destination IP, destination port.
[0048] Further, the security log of this embodiment may also include an attack classification field. This embodiment supports attack classifications such as denial of service, scanning and reconnaissance, malicious files, vulnerability exploitation, privilege acquisition, trace cleaning, malicious website access, data leakage, malicious communication, vulnerability risk, risk access, abnormal login, web security, email security, abnormal operations, system damage, abnormal external connection, threat intelligence, etc.
[0049] Further, the security log of this embodiment may also include a feature hit direction field. This embodiment supports two feature hit directions: client to server and server to client.
[0050] On this basis, in practical applications, the alarm data is generated from the network log in the following specific manner: determine whether the current security log meets the second correlation analysis rule (intranet vulnerability exploitation attack); if the judgment result is yes, generate the second alarm data according to the current security log; wherein, the second correlation analysis rule includes: the attack type is vulnerability exploitation, the source address belongs to the intranet, and the feature hit direction is client to server; the second alarm data includes: alarm name, alarm description, and correlation analysis rule name.
[0051] It is worth mentioning that the second alarm data may further include an attack status.
[0052] The security log of this embodiment may also include an action type field. This embodiment supports action types such as blocking the source, resetting, allowing, blocking, redirecting, blocking the source + packet capture, dropping packets + packet capture, resetting + packet capture, allowing + packet capture, redirecting + packet capture, and failure. The security log of this embodiment may also include a response code field. This embodiment supports response codes such as 404, 403, 500, and 200.
[0053] On this basis, the above attack states are specifically generated in the following manner: Determine the attack state based on the action type, feature hit direction, and response code; among them, the attack states are successful attack, attack attempt, or attack failure, and the respective judgment rules are as follows:
[0054] Successful attack: The action type is allow or allow + packet capture, and the confidence level corresponding to the attack ID in the feature hit direction is compromised; or, the confidence level corresponding to the attack ID is not compromised, but the response code in the original log is 200.
[0055] Attack attempt: (1) The action type is allow, allow + packet capture; (2) The confidence level corresponding to the attack ID in the feature hit direction is not compromised; (3) The case where the response code field in the original log is not 404, 403, 500, 200.
[0056] Attack failure: (1) The action type is: block source, reset, block, redirect, block source + packet capture, drop packet + packet capture, reset + packet capture, redirect + packet capture, failure; (2) The attack ID in the feature hit direction is not compromised; (3) The log response code is 404, 403, 500.
[0057] The full-packet forensics engine stores and analyzes all network traffic. It stores metadata logs according to different protocols and records network traffic information including source IP, destination IP, protocol, application layer protocols such as HTTP request method, URL address, request body, response body, etc. All-network traffic storage enables traffic traceback analysis, helping administrators trace security alerts that have occurred and achieving source forensics of security alerts. It can display network traffic trends, accurately identify the source / destination IP addresses of traffic data packets and the corresponding regions, determine the network path, and at the same time provide multi-dimensional filtering and retrieval of statistical data, facilitating administrators to quickly locate the required content in the vast amount of data. It also supports the analysis of real-time traffic and historical traffic, viewing the parsing results of each protocol field of data packets and the original data, and supports downloading captured packets for further analysis by administrators.
[0058] As a specific implementation, this embodiment displays the alert data generated according to network logs through an NDR (Network Detection and Response) platform. The alert data can be viewed. For the selected alert data, the full-packet forensics engine is used to obtain the original packets for traffic tracing. The traffic tracing results include the tracing time period, source IP, destination IP, and all packets transmitted within the time period. It also supports downloading the PCAP packet information to the local.
[0059] That is, in this embodiment, the message is downloaded in the following manner: in response to a download request, the PCAP data between the source address to be traced and the destination address to be traced within the target time period is downloaded to the local.
[0060] In summary, the full - flow advanced threat analysis and traceability system, as Figure 3 shown, at the data access layer, the security device obtains the mirror traffic from the switching device for full - flow storage. At the data analysis layer, the threat detection engine generates network logs through IPS signature detection, virus analysis, file threat identification, in - depth metadata analysis, etc.
[0061] At the advanced analysis layer, advanced analysis is achieved through the correlation analysis engine, and alarm data is generated in the system. Specifically, different types of alarm data are generated by matching different correlation analysis rule conditions for the network logs, including types such as vulnerability exploitation, remote control, brute - force cracking, hacking tools, malicious external connection, etc.
[0062] At the application presentation layer, the full - package forensics engine, through key technologies such as full - flow analysis, PCAP full - package storage, and accurate traceability and evidence presentation, decodes and restores files, logs, and sessions in the data stream for the data packets, realizing fine - grained threat detection and traceability capabilities. Specifically, full - package forensics can be performed on the alarm data. According to the source IP, destination IP, source port, destination port, and tracking time in the alarm data, the PCAP data packets are downloaded from the full - package stored traffic data for traffic traceability flow tracking, the message content is viewed, and evidence is obtained for the alarm event.
[0063] It can be seen that this application realizes the organic combination of threat detection and full - flow storage, can display the associated messages of the security event alarm data and the dimension of the attack process, and highlights the key feature fields, making the traceability process clear, professional, and refined. It can also count the recent abnormal traffic alarms and the distribution statistics of abnormal types, facilitating the rapid positioning of abnormal traffic in the network, eliminating risks, and perceiving risks in advance to make corresponding security policies. It supports in - depth panoramic attack chain traceability in the front and back based on the attack chain and the backtracking chain, fully demonstrating the threat infection and propagation paths of risk assets and risk users, and realizing threat visualization. The investigation and analysis support multi - dimensional traceability from time, user, intelligence information, and external network attackers. Each event is clearly evidenced, truly realizing evidence - based reasoning.
[0064] Through traffic analysis, this application provides network threat detection, in - depth threat detection, and full - package traceability and evidence - obtaining capabilities, helping customers enhance decision - making and prediction capabilities, quickly discover and solve problems, and improve the efficiency of security operation and maintenance. It helps enterprises normalize the security capabilities demonstrated in attack and defense drills, achieve active and effective protection, enhance decision - making and prediction capabilities for enterprises, improve the efficiency of security operation and maintenance, normalize attack and defense capabilities, and reduce the security operation and maintenance burden of enterprises.
[0065] Based on the same inventive concept, the present application also provides a security management device, the structural schematic diagram of which is as Figure 4 shown, and specifically includes:
[0066] A data acquisition module 401, configured to acquire network traffic data from a switching device of a target network in a bypass mirroring manner;
[0067] A log generation module 402, configured to generate network logs according to the network traffic data;
[0068] An advanced analysis module 403, configured to use an association analysis engine to generate alarm data according to the network logs;
[0069] A traceability module 404, configured to use a full-packet forensics engine to generate a traffic traceability result according to the selected alarm data.
[0070] As a specific implementation manner, the log generation module 402 specifically generates network logs according to network traffic data in the following manner:
[0071] Using a threat detection engine, threat detection is performed on the network traffic data to generate network logs.
[0072] As a specific implementation manner, the network logs include traffic logs, and the advanced analysis module 403 specifically generates alarm data according to the network logs in the following manner:
[0073] Judge whether the current traffic log meets the first association analysis rule. If the judgment result is yes, generate first alarm data according to the current traffic log; wherein, the first association analysis rule includes: the source address belongs to the internal network, the destination address belongs to the external network, the destination address is an intelligence address, the log classification is a session log, and the log sub-classification is session end or between session start and session end; the first alarm data includes: alarm name, alarm description, association analysis rule name, and intelligence information.
[0074] As a specific implementation manner, the advanced analysis module 403 specifically generates first alarm data according to the current traffic log in the following manner:
[0075] Match the destination address of the current traffic log with the intelligence addresses in the intelligence database, and judge whether the destination address of the current traffic log is the same as any intelligence address in the intelligence database; if the judgment result is yes, and the current traffic log meets the first association analysis rule, determine the target intelligence information corresponding to the target intelligence address in the intelligence database; generate first alarm data according to the current traffic log and the target intelligence information; wherein, the intelligence database includes multiple pieces of intelligence information, and each piece of intelligence information includes an intelligence address.
[0076] As a specific implementation manner, the network log includes a security log, and the advanced analysis module 403 specifically generates alarm data according to the network log in the following manner:
[0077] Determine whether the current security log meets the second correlation analysis rule. If the judgment result is yes, generate second alarm data according to the current security log; wherein, the second correlation analysis rule includes: the attack type is vulnerability exploitation, the source address belongs to the internal network, and the feature hit direction is from the client to the server; the second alarm data includes: alarm name, alarm description, correlation analysis rule name, and attack status.
[0078] As a specific implementation manner, the advanced analysis module 403 specifically generates second alarm data in the following manner:
[0079] Determine the attack status according to the action type, feature hit direction, and response code; generate second alarm data according to the attack status; wherein, the attack status is attack success, attack attempt, or attack failure.
[0080] As a specific implementation manner, the device further includes:
[0081] A download module, configured to download PCAP data between the source address to be traced and the destination address to be traced within a target time period to the local in response to a download request.
[0082] An embodiment of the present application provides an electronic device, which may include: a memory and one or more processors. The memory is used to store computer program code, and the computer program code includes computer instructions. When the processor executes the computer instructions, the electronic device can execute each function or step of the above method embodiment.
[0083] The structure of the electronic device may refer to Figure 5 the structure of the electronic device 100 shown.
[0084] The above-mentioned processor may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
[0085] An embodiment of the present application also provides a computer-readable storage medium, which includes computer instructions. When the computer instructions run on an electronic device, the electronic device is caused to execute each function or step of the above method embodiment.
[0086] The above computer-readable storage medium includes, but is not limited to, any of the following: USB flash drive, mobile hard disk, read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disc, etc., which are various media that can store program codes.
[0087] An embodiment of the present application also provides a computer program product. When the computer program product runs on a computer, the computer is caused to execute each function or step of the above method embodiment.
[0088] Among them, the electronic device, computer-readable storage medium, and computer program product provided by the embodiments of the present application are all used to execute the corresponding methods provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding methods provided above, and will not be elaborated here.
[0089] Through the description of the above embodiments, those skilled in the art can clearly understand that for the convenience and simplicity of description, only the above division of each functional module is used as an example. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above.
[0090] In several embodiments provided by the present application, it should be understood that the disclosed method can be implemented in other ways. The device embodiments described above are only illustrative. For example, the division of the module or unit is only a logical function division, and there can be other division methods in actual implementation; for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces, and the indirect coupling or communication connection of the module or unit can be in an electrical, mechanical or other form.
[0091] In addition, each functional unit in the various embodiments of the present application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0092] As described above, it is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions within the technical scope disclosed in the present application should be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claimed rights.
Claims
1. A safety management method, characterized in that: The method comprises: Use bypass mirroring to obtain network traffic data from the switching device of the target network; Generate a network log based on the network traffic data; Using a correlation analysis engine, generating alarm data based on the network log; Utilize the full-packet forensics engine to generate traffic tracing results based on the selected alarm data.
2. The method according to claim 1, characterized in that The method specifically generates a network log based on network traffic data in the following manner: A threat detection engine is used to perform threat detection on the network traffic data to generate a network log.
3. The method according to claim 1, characterized in that The network log includes a traffic log, and the method specifically generates alarm data according to the network log in the following manner: Determine whether the current traffic log satisfies the first correlation analysis rule, and if the determination result is yes, generate first alarm data according to the current traffic log; The first association analysis rule includes: the source address belongs to the intranet, the destination address belongs to the extranet, the destination address is an intelligence address, the log category is a session log, and the log subcategory is the end of the session or between the start of the session and the end of the session; The first alarm data includes: alarm name, alarm description, association analysis rule name, and intelligence information.
4. The method according to claim 3, characterized in that The method specifically generates the first alarm data according to the current traffic log in the following manner: Match the destination address of the current traffic log with the intelligence address in the intelligence library to determine whether the destination address of the current traffic log is the same as any intelligence address in the intelligence library; If the judgment result is yes, and the current traffic log satisfies the first association analysis rule, then determining the target intelligence information corresponding to the target intelligence address in the match in the intelligence database; Generate first alarm data according to the current traffic log and the target intelligence information; The intelligence database includes multiple pieces of intelligence information, and each piece of intelligence information includes an intelligence address.
5. The method according to claim 1, characterized in that The network log includes a security log, and the method specifically generates alarm data according to the network log in the following manner: Determine whether the current security log satisfies the second correlation analysis rule, and if the determination result is yes, generate second alarm data according to the current security log; The second association analysis rule includes: the attack type is vulnerability exploitation, the source address belongs to the intranet, and the feature hit direction is from the client to the server; The second alarm data includes: alarm name, alarm description, association analysis rule name, and attack status.
6. The method according to claim 5, characterized in that The method specifically generates the second warning data in the following manner: Determine the attack status based on the action type, feature hit direction, and response code; generating second warning data according to the attack status; The attack status is attack success, attack attempt or attack failure.
7. The method according to claim 1, characterized in that The method further comprises: In response to the download request, the PCAP data between the source address to be traced and the destination address to be traced within the target time period is downloaded locally.
8. A security management device, characterized in that: The device comprises: A data acquisition module is used to acquire network traffic data from a switching device of a target network by adopting a bypass mirroring method; A log generation module, used to generate a network log according to the network traffic data; An advanced analysis module, for generating alarm data according to the network log using a correlation analysis engine; The tracing module is used to generate traffic tracing results based on the selected alarm data using the full-packet forensics engine.
9. The device according to claim 8, characterized in that The device further comprises: a download module, which is used to download the PCAP data between the source address to be traced and the destination address to be traced within the target time period to the local in response to a download request.
10. An electronic device, characterized in that: include: A memory and one or more processors; the memory is coupled to the processor; wherein the memory stores computer program code, the computer program code includes computer instructions, and when the computer instructions are executed by the processor, the electronic device executes the method as described in any one of claims 1-7.
11. A computer-readable storage medium comprising computer instructions, characterized in that: When the computer instructions are executed on an electronic device, the electronic device is caused to execute the method according to any one of claims 1 to 7.
12. A computer program product, characterized in that When the computer program product is executed on a computer, the computer is caused to execute the method according to any one of claims 1 to 7.