Alarm processing method and device, equipment and storage medium
Through automated alarm processing methods, alarm data is obtained and alarm types are determined according to triage rules, which solves the problem of low alarm processing efficiency in the prior art, and achieves efficient and flexible alarm processing and cost reduction.
Patent Information
- Application Number
- CN202311668562.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-06
- Publication Date
- 2025-06-06
AI Technical Summary
In the prior art, alarm processing efficiency is low, operational costs are high and inefficient, and the operation personnel rely on manual analysis and handling of alarms.
By obtaining alarm data, determining the alarm type according to the configured triage rules, and automatically processing it according to the alarm type and handling method, automatic triage and processing of alarm data is realized.
It improves the efficiency and flexibility of alarm processing, reduces the workload and impact of false alarms of operation personnel, and reduces operating costs.
Smart Images

Figure CN120110879A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular to an alarm processing method, device, equipment and storage medium. Background Art
[0002] With the continuous development of the Internet and information technology, information networks are becoming more and more important. The information security of information networks is of vital importance. In order to ensure information security, users often use alarm mechanisms to warn of spam, attack behaviors, etc. in information networks.
[0003] In order to deal with attack behaviors in a timely manner, it is necessary to analyze the alarms. The existing alarm analysis solution relies on operators to manually analyze each alarm on the alarm display page and analyze and handle the alarms that can be confirmed.
[0004] The above solution has the following problems: 1. High operating cost: The workload of operators is heavy, the dependence on operators is too high, and the security analysis capabilities of operators are high; 2. Low operating efficiency: There are a large number of false alarms that affect the analysis of operators, and each alarm needs to be analyzed and handled manually. Summary of the invention
[0005] The present invention provides an alarm processing method, device, equipment and storage medium, which are used to solve the defect of low alarm processing efficiency in the prior art and realize an efficient alarm processing method.
[0006] The present invention provides an alarm processing method, comprising:
[0007] Get at least one piece of alarm data;
[0008] Determine the alarm type corresponding to each of the alarm data according to the configured triage rules, wherein the triage rules are used to classify the alarm data;
[0009] Each of the alarm data is processed according to the alarm type corresponding to the alarm data and the handling method corresponding to the alarm type.
[0010] According to an alarm processing method provided by the present invention, the obtaining of at least one piece of alarm data includes:
[0011] According to the target field and / or the data source of the target field included in the preset association rule, the log and / or network traffic data is screened to obtain the at least one piece of alarm data.
[0012] According to an alarm processing method provided by the present invention, different alarm types correspond to different handling priorities, and the processing of each alarm data according to the alarm type corresponding to each alarm data and the handling method corresponding to the alarm type includes:
[0013] Each of the alarm data is processed according to the alarm type corresponding to the alarm data, the handling method corresponding to the alarm type, and the handling priority corresponding to the alarm type.
[0014] According to an alarm processing method provided by the present invention, after determining the alarm type corresponding to each alarm data according to the configured triage rule, the method further includes:
[0015] A label corresponding to the alarm type to which the alarm data belongs is added to each of the alarm data, and each of the alarm data is stored; the label is used to indicate the importance of the alarm type corresponding to the alarm data.
[0016] According to an alarm processing method provided by the present invention, the triage rule is established based on at least one of the threat source, threat type and threat degree.
[0017] According to an alarm processing method provided by the present invention, the triage rules include: a white triage rule, a custom triage rule and a pre-configured triage rule, the white triage rule is a triage rule for filtering false alarms, the custom triage rule is a triage rule for classifying alarm data formulated based on user environment requirements, the pre-configured triage rule is a pre-configured triage rule for classifying alarm data, and the alarm type corresponding to each of the alarm data is determined according to the configured triage rule, including:
[0018] Determining whether each of the alarm data matches the whitening triage rule;
[0019] If there is alarm data matching the whitening triage rule, determining that the alarm data matching the whitening triage rule is a false alarm;
[0020] If there is alarm data that does not match the whitening triage rule, determining whether the alarm data that does not match the whitening triage rule matches the custom triage rule;
[0021] If there is alarm data matching the custom triage rule, then based on the custom triage rule, determine the alarm type corresponding to the alarm data matching the custom triage rule;
[0022] If there is alarm data that does not match the custom triage rule, the alarm type corresponding to the alarm data that does not match the custom triage rule is determined based on the preconfigured triage rule.
[0023] The present invention also provides an alarm processing device, comprising:
[0024] An acquisition module, used to acquire at least one piece of alarm data;
[0025] A processing module, used to determine the alarm type corresponding to each of the alarm data according to a configured triage rule, wherein the triage rule is used to classify the alarm data;
[0026] The processing module is further used to process each of the alarm data according to the alarm type corresponding to the alarm data and the handling method corresponding to the alarm type.
[0027] The present invention also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, any of the above-mentioned alarm processing methods is implemented.
[0028] The present invention also provides a non-transitory computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the alarm processing method described in any one of the above is implemented.
[0029] The present invention also provides a computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the alarm processing method described above is implemented.
[0030] The alarm processing method, apparatus, device and storage medium provided by the present invention first obtain at least one alarm data; determine the alarm type corresponding to each alarm data according to the configured triage rules, and the triage rules are used to classify the alarm data; further, process each alarm data according to the alarm type corresponding to each alarm data and the handling method corresponding to the alarm type, thereby realizing the automatic triage and processing function of alarm data, and for a large amount of alarm data, the handling corresponding to each alarm type can be performed based on the classified alarm type, with high efficiency and great flexibility. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0032] Figure 1 It is one of the flowcharts of the alarm processing method provided by the present invention;
[0033] Figure 2 It is a system architecture diagram of the alarm processing method provided by the present invention;
[0034] Figure 3 It is a schematic diagram of the principle of the alarm processing method provided by the present invention;
[0035] Figure 4 This is the second flow chart of the alarm processing method provided by the present invention;
[0036] Figure 5 It is a structural schematic diagram of the alarm processing device provided by the present invention;
[0037] Figure 6 It is a structural schematic diagram of the electronic device provided by the present invention. DETAILED DESCRIPTION
[0038] In order to make the purpose, technical solution and advantages of the present invention clearer, the technical solution of the present invention will be clearly and completely described below in conjunction with the drawings of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0039] Combine the following Figure 1-Figure 6 The technical solution of the embodiment of the present invention is described in detail with specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described in detail in some embodiments.
[0040] Figure 1 FIG. 1 is a flow chart of the alarm processing method provided by the present invention. Figure 1 As shown, the method provided in this embodiment includes:
[0041] Step 101: Obtain at least one piece of alarm data;
[0042] Specifically, the alarm data may be obtained based on the detection of network flow data and / or log data. For example, log data and / or network flow data from different sources may be collected, and the alarm data may be obtained based on the detection of the collected network flow data and / or log data.
[0043] For example, if a user needs brute force cracking alarm data, he or she can configure certain rules for detection. For example, the rule generates alarm data when it comes from a certain data source, meets certain filtering conditions, and occurs a certain number of times within a certain period of time.
[0044] Step 102: Determine the alarm type corresponding to each alarm data according to the configured triage rule, where the triage rule is used to classify the alarm data;
[0045] Specifically, triage rules are a set of rules for intelligent analysis configured during the intelligent triage process; security analysts or users can classify alarm data according to actual needs, that is, alarms that meet certain conditions need to produce certain triage results, that is, determine which alarm type the alarm data belongs to. For example, if the alarm data corresponding to the asset value greater than or equal to a certain fixed value is considered to be a key concern alarm type, then the filtering condition of the triage rule needs to be configured as the asset value corresponding to the alarm data is greater than or equal to a certain fixed value, and the alarm type corresponding to the triage rule is key concern.
[0046] Optionally, the triage rule is established based on at least one of the threat source, threat type and threat degree;
[0047] Specifically, alarm types can be classified based on the source, such as server alarms, application alarms and database alarms, or they can also be classified based on threat types, such as malware threats including Trojans, viruses and worms, network targeted attacks, abuse of access rights, eavesdropping attacks and database injections; or they can also be classified based on the threat level, for example including: types with higher threat levels, types with medium threat levels, and types with lower threat levels, so triage rules can be established based on at least one of the threat source, threat type and threat level.
[0048] For example, the alarm type includes at least one of the following: a high-value alarm requiring attention, an uncertain low-value alarm, an alarm not requiring attention, a false alarm, and an unrecognizable alarm.
[0049] Step 103: Process each alarm data according to the alarm type corresponding to each alarm data and the handling method corresponding to the alarm type.
[0050] Specifically, according to the needs of operators, the corresponding handling methods of alarm types can be configured in advance, and then the program can be used to automatically handle the alarm data using the pre-configured handling methods. Alarms that users originally needed to analyze and handle manually can now be configured to automatically handle certain alarm types using certain handling methods and obtain certain handling results, saving users some analysis and handling time.
[0051] Optionally, the handling methods include, for example, alarm analysis, alarm response and storage. Alarm analysis includes extracting the cause of the alarm and identifying the authenticity of the alarm. Specifically, the alarm event can be restored, the cause of the event can be analyzed, the cause of the alarm can be determined, and false alarms and alarms that do not require attention can be eliminated.
[0052] Alarm response, for example, analyzes the cause of the alarm and determines the response measures for high-value alarms that require attention.
[0053] Storage into the warehouse, for example, stores uncertain low-concern alarms, unrecognizable alarms, and high-value alarms that require attention, for easy subsequent analysis.
[0054] Exemplarily, the alarm data comes from the daily web scanning tool that scans the business system. The scanning tool detects a web security vulnerability, triggers the generation of an alarm event, and generates alarm data corresponding to the alarm event, and then performs alarm analysis and disposal on the alarm data, determines the alarm type and the disposal method corresponding to the alarm type, and executes the corresponding disposal method. Optionally, after executing the alarm processing, the security personnel can evaluate the execution results, and after the evaluation, the alarm processing results can be confirmed and recorded. When the closed-loop processing of the alarm data of the web vulnerability is completed and the expected effect is achieved, an alarm disposal record of the web vulnerability is generated and archived; or, if the alarm data processing does not meet expectations, it can be transferred to manual processing.
[0055] The method of this embodiment first obtains at least one piece of alarm data; determines the alarm type corresponding to each of the alarm data according to the configured triage rules, and the triage rules are used to classify the alarm data; further, processes each of the alarm data according to the alarm type corresponding to each of the alarm data and the handling method corresponding to the alarm type, thereby realizing the automatic triage and processing function of the alarm data. For a large amount of alarm data, the handling corresponding to each alarm type can be performed based on the classified alarm type, which is more efficient and flexible.
[0056] Optionally, step 101 may be implemented in the following manner:
[0057] According to the target field and / or the data source of the target field included in the preset association rule, the log and / or network traffic data is screened to obtain the at least one piece of alarm data.
[0058] Specifically, the log and / or network flow data are detected according to the preset association rules, and the association rules are rules for analyzing whether the log data and / or network flow data generate alarms. Optionally, the association rules can be run on the association analysis engine to generate detection results, which are used to discover various threats that may exist in the network information system environment, generate alarm data based on the detection results, and assist security analysts in analyzing and handling threats.
[0059] According to the target field and / or the data source of the target field included in the preset association rule, the log and / or network traffic data is filtered, that is, the data including the target field in the log and / or network traffic data, and / or the data of the target field with the same data source are filtered to obtain alarm data.
[0060] Optionally, the correlation analysis engine can be designed based on a streaming processing framework, which can perform real-time correlation analysis on security data of various dimensions at large data volumes, discover more complex and valuable threat events, control the scale of threat events to a level that can be handled manually, and support retrospective analysis of the output results.
[0061] For example, through the correlation analysis engine, big data and machine learning technology are used to accurately locate attack events, discover threat information, and generate alarm data.
[0062] For example, if a user needs brute force cracking alarm data, the following rules can be configured: alarm data is generated when it comes from a certain data source, meets certain filtering conditions, and occurs a certain number of times within a certain period of time. The above rules are run on the association analysis engine, and real-time streaming computing generates corresponding alarm data. What fields are required in this type of alarm data and what the data source of the field is need to be configured in the association rules.
[0063] like Figure 2 As shown, Figure 2 The system architecture of the solution is shown in , which generates alarm data by configuring association rules, running association rules, detecting network traffic data and / or log data, and the association rules can be run on the association analysis engine; intelligent triage includes: triage rule configuration and triage rule operation. The triage rule configuration determines what kind of alarm type different alarm data belongs to. Different alarm types have different importance. Analysts only need to analyze the alarm data under the alarm type they are concerned about. The triage rules also run on the association analysis engine. The engine analyzes the alarm data in real time and calculates the final alarm type for the alarm data.
[0064] Automated processing configures the processing methods and processing results required for different alarm types, and automatically processes the alarm data through the automated processing backend, saving analysts a lot of time for manual analysis and processing.
[0065] In the above implementation, log and / or network traffic data are screened according to the target field and / or data source of the target field included in the preset association rule to obtain the at least one alarm data. The implementation scheme is simple and efficient.
[0066] Optionally, different alarm types correspond to different handling priorities, and step 103 may be implemented in the following manner:
[0067] Each of the alarm data is processed according to the alarm type corresponding to the alarm data, the handling method corresponding to the alarm type, and the handling priority corresponding to the alarm type.
[0068] Specifically, the handling priority can be obtained by performing a security scoring on the alarm type. For example, the alarm type is obtained based on the threat level. The alarm data with a greater threat level has a higher handling priority for the alarm type, and the alarm data with a smaller threat level has a lower handling priority for the alarm type. For example, the alarm data with a greater threat level has a higher score for the alarm type, and the alarm data with a smaller threat level has a lower score for the alarm type. The corresponding handling priority can be determined based on the score.
[0069] For example, the alarm type is obtained based on the threat type. The greater the threat level of the threat type, the higher the corresponding handling priority, and the smaller the threat level of the threat type, the lower the corresponding handling priority.
[0070] For example, the alarm type is obtained based on the threat source, such as server alarm type, application alarm type and database alarm type. The higher the importance of the alarm type corresponding to the user's needs, the higher the handling priority; the lower the importance, the lower the handling priority.
[0071] When processing the alarm data, the alarm data with a high processing priority is placed in front and processed preferentially.
[0072] In the above implementation, each alarm data is processed according to the alarm type corresponding to each alarm data, the handling method corresponding to the alarm type and the handling priority corresponding to the alarm type. Alarms with higher priorities can be handled immediately based on the handling priority, which has higher security and improves the efficiency of alarm processing.
[0073] Optionally, the following operations may be performed after step 102:
[0074] A label corresponding to the alarm type to which the alarm data belongs is added to each of the alarm data, and each of the alarm data is stored; the label is used to indicate the importance of the alarm type corresponding to the alarm data.
[0075] Specifically, the alarm data is matched through triage rules, the alarm data is automatically classified, and a label corresponding to the alarm type is added to the alarm data, and the labeled alarm data is stored for subsequent analysis and use. For example, the user only pays attention to the alarm data of the alarm type with a high threat level.
[0076] like Figure 3As shown, after the operator configures the association rules, they are run on the association analysis engine, and the network traffic data and / or log data are filtered, analyzed, and calculated according to the configuration information of the association rules, and the original events are finally generated. The alarm generation service of the application software obtains the configuration information of the association rules, and generates a manually analyzable original alarm data according to the configuration information. Intelligent triage analyzes and calculates the original alarm data according to the triage rules configured by the operator, obtains the alarm type of the alarm data, and can generate a label to mark the alarm importance corresponding to the alarm type, and puts the marked data into the database.
[0077] Operators can analyze alarm data of different importance based on tags on the alarm list page. Automatic processing functions can be configured for alarm data of different importance. After the alarm data is stored in the database, the alarm service will automatically process the alarm according to the operator's configuration, saving the operator's processing time.
[0078] In the above implementation manner, by adding a label corresponding to the alarm type to each of the alarm data, the efficiency of subsequent processing and analysis of the alarm data can be improved.
[0079] Optionally, the triage rules include: a white triage rule, a custom triage rule and a preconfigured triage rule. The white triage rule is a triage rule for filtering false alarms. The custom triage rule is a triage rule for classifying alarm data formulated based on user environment requirements. The preconfigured triage rule is a preconfigured triage rule for classifying alarm data. Step 102 can be specifically implemented in the following manner:
[0080] Determining whether each of the alarm data matches the whitening triage rule;
[0081] If there is alarm data matching the whitening triage rule, determining that the alarm data matching the whitening triage rule is a false alarm;
[0082] If there is alarm data that does not match the whitening triage rule, determining whether the alarm data that does not match the whitening triage rule matches the custom triage rule;
[0083] If there is alarm data matching the custom triage rule, then based on the custom triage rule, determine the alarm type corresponding to the alarm data matching the custom triage rule;
[0084] If there is alarm data that does not match the custom triage rule, the alarm type corresponding to the alarm data that does not match the custom triage rule is determined based on the preconfigured triage rule.
[0085] Specifically, the white triage rule is also a type of triage rule. The white triage rule can be understood as a secondary filtering of the generated alarm data, filtering out the alarm data that the user believes does not need to be alarmed, generating a special triage result, and classifying it as a false alarm type. For example, part of the alarm data in the user information system environment is a false alarm generated by internal personnel. By configuring the white triage rule, such alarm data is classified as white alarms and marked with the "white" type label. Users can ignore this type of alarm data.
[0086] For example, Figure 4 As shown, the method comprises the following steps:
[0087] Step 1: Obtain original alarm data;
[0088] Step 2: Determine whether the original alarm data matches the whitening triage rule;
[0089] If the original alarm data matches the whitening triage rule, execute step 3 to obtain the triage result. If the triage result is that the type of the alarm data is the whitening alarm type, no processing is required;
[0090] If the original alarm data does not match the whitening triage rule, execute step 4 to determine whether the original alarm data matches the custom triage rule;
[0091] If the original alarm data matches the custom triage rule, execute step 5 to determine whether there are multiple triage results; for example, whether there are multiple alarm types;
[0092] If there are multiple triage results, execute step 6 to determine whether all the original alarm data are not triaged; (the original alarm data includes multiple alarm data)
[0093] If not all of them are not triaged, then execute step 7 to calculate the triage result, such as determining the alarm type of each alarm data obtained by triage;
[0094] If all are not triaged, execute step 8 to determine whether the original alarm data matches the preset triage rules;
[0095] If the preset triage rule is matched, then step 9 is executed to determine whether there are multiple triage results;
[0096] If there are multiple triage results, execute step 10 to calculate the triage results, such as dividing the alarm data into data of multiple alarm types;
[0097] If there are no multiple triage results, execute step 11 to obtain the triage result and determine the corresponding alarm type;
[0098] If the preset triage rule is not matched, step 12 is executed to obtain the triage result of not triaged;
[0099] If it is determined in step 5 that there are no multiple triage results, then step 13 is performed to determine whether the original alarm data is not triaged;
[0100] If the patient has not been triaged, proceed to step 8; if the patient has been triaged, proceed to step 14 to obtain the triage result.
[0101] Specifically, this solution can be implemented through an application software. The operator will configure the custom triage rules that conform to the system environment according to the specific situation of the user information system environment. The application software will also come with some preset triage rules when it leaves the factory. The original alarm data will first hit the whitening triage rule. If the alarm data hits the whitening triage rule, the final triage result will be "whitening", that is, no processing is required. If the whitening triage rule is not hit, the custom triage rule of the user information system environment will continue to be hit. If the triage result calculated according to the custom triage rule is not triaged, it is necessary to continue to hit the preset triage rule, and calculate the final triage result according to the configuration of the preset triage rule. If it is not not triaged, the final triage result is calculated, that is, the alarm type is determined, and the alarm data is processed based on the disposal method corresponding to the alarm type.
[0102] In summary, the method of the embodiment of the present invention uses intelligent triage to automatically classify alarm data into high-value alarms that need to be paid attention to at all times in daily operations, uncertain low-concern alarms, alarms that do not need to be paid attention to, false alarms, and alarms that cannot be identified by the current configuration, etc. In daily operations, operators do not need to respond but need to review and analyze uncertain low-concern alarms and focus on processing high-value alarms, thereby achieving intelligent, standardized, and visualized alarm operations.
[0103] The alarm processing device provided by the present invention is described below. The alarm processing device described below and the alarm processing method described above can be referred to each other.
[0104] Figure 5 Schematic diagram of the structure of the alarm processing device provided by the present invention. Figure 5 As shown, the alarm processing device provided in this embodiment includes:
[0105] An acquisition module 510, configured to acquire at least one piece of alarm data;
[0106] A processing module 520, configured to determine the alarm type corresponding to each of the alarm data according to a configured triage rule, wherein the triage rule is used to classify the alarm data;
[0107] The processing module 520 is further configured to process each of the alarm data according to the alarm type corresponding to the alarm data and the handling method corresponding to the alarm type.
[0108] In this embodiment, at least one piece of alarm data is first obtained; the alarm type corresponding to each of the alarm data is determined according to the configured triage rules, and the triage rules are used to classify the alarm data; further, each of the alarm data is processed according to the alarm type corresponding to each of the alarm data and the handling method corresponding to the alarm type, thereby realizing the automatic triage and processing function of the alarm data. For a large amount of alarm data, the handling corresponding to each alarm type can be performed based on the classified alarm type, which is more efficient and flexible.
[0109] Optionally, the acquisition module 510 is specifically configured to:
[0110] According to the target field and / or the data source of the target field included in the preset association rule, the log and / or network traffic data is screened to obtain the at least one piece of alarm data.
[0111] Optionally, different alarm types correspond to different handling priorities, and the processing module 520 is specifically used to:
[0112] Each of the alarm data is processed according to the alarm type corresponding to the alarm data, the handling method corresponding to the alarm type, and the handling priority corresponding to the alarm type.
[0113] Optionally, the processing module 520 is further configured to:
[0114] A label corresponding to the alarm type to which the alarm data belongs is added to each of the alarm data, and each of the alarm data is stored; the label is used to indicate the importance of the alarm type corresponding to the alarm data.
[0115] Optionally, the triage rule is established based on at least one of a threat source, a threat type, and a threat degree.
[0116] Optionally, the triage rule includes: a white triage rule, a user-defined triage rule and a pre-configured triage rule. The white triage rule is a triage rule for filtering false alarms. The user-defined triage rule is a triage rule for classifying alarm data formulated based on user environment requirements. The pre-configured triage rule is a pre-configured triage rule for classifying alarm data. The processing module 520 is specifically used to:
[0117] Determining whether each of the alarm data matches the whitening triage rule;
[0118] If there is alarm data matching the whitening triage rule, determining that the alarm data matching the whitening triage rule is a false alarm;
[0119] If there is alarm data that does not match the whitening triage rule, determining whether the alarm data that does not match the whitening triage rule matches the custom triage rule;
[0120] If there is alarm data matching the custom triage rule, then based on the custom triage rule, determining the alarm type corresponding to the alarm data matching the custom triage rule;
[0121] If there is alarm data that does not match the custom triage rule, the alarm type corresponding to the alarm data that does not match the custom triage rule is determined based on the preconfigured triage rule.
[0122] The device of the embodiment of the present invention is used to execute the method in any of the aforementioned method embodiments. Its implementation principle and technical effects are similar and will not be repeated here.
[0123] Figure 6 An example of a physical structure diagram of an electronic device is shown in FIG. Figure 6 As shown, the electronic device may include: a processor 610, a communication interface 620, a memory 630 and a communication bus 640, wherein the processor 610, the communication interface 620 and the memory 630 communicate with each other through the communication bus 640. The processor 610 may call the logic instructions in the memory 630 to execute the alarm processing method, which includes: obtaining at least one alarm data;
[0124] Determine the alarm type corresponding to each of the alarm data according to the configured triage rules, wherein the triage rules are used to classify the alarm data;
[0125] Each of the alarm data is processed according to the alarm type corresponding to the alarm data and the handling method corresponding to the alarm type.
[0126] In addition, the logic instructions in the above-mentioned memory 630 can be implemented in the form of a software functional unit and can be stored in a computer-readable storage medium when it is sold or used as an independent product. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk and other media that can store program codes.
[0127] On the other hand, the present invention further provides a computer program product, the computer program product includes a computer program, the computer program can be stored in a non-transitory computer-readable storage medium, when the computer program is executed by a processor, the computer can execute the alarm processing method provided by the above methods, the method includes: obtaining at least one alarm data;
[0128] Determine the alarm type corresponding to each of the alarm data according to the configured triage rules, wherein the triage rules are used to classify the alarm data;
[0129] Each of the alarm data is processed according to the alarm type corresponding to the alarm data and the handling method corresponding to the alarm type.
[0130] In another aspect, the present invention further provides a non-transitory computer-readable storage medium having a computer program stored thereon, the computer program being implemented when executed by a processor to execute the alarm processing method provided by the above methods, the method comprising: obtaining at least one alarm data;
[0131] Determine the alarm type corresponding to each of the alarm data according to the configured triage rules, wherein the triage rules are used to classify the alarm data;
[0132] Each of the alarm data is processed according to the alarm type corresponding to the alarm data and the handling method corresponding to the alarm type.
[0133] The device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Ordinary technicians in this field can understand and implement it without paying creative labor.
[0134] Through the description of the above implementation methods, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solution is essentially or the part that contributes to the prior art can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0135] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. An alarm processing method, It is characterized in that include: Get at least one piece of alarm data; Determine the alarm type corresponding to each of the alarm data according to the configured triage rules, wherein the triage rules are used to classify the alarm data; Each of the alarm data is processed according to the alarm type corresponding to the alarm data and the handling method corresponding to the alarm type.
2. The alarm processing method according to claim 1, It is characterized in that The obtaining of at least one piece of alarm data includes: According to the target field and / or the data source of the target field included in the preset association rule, the log and / or network traffic data is screened to obtain the at least one piece of alarm data.
3. The alarm processing method according to claim 1 or 2, It is characterized in that Different alarm types correspond to different handling priorities. The processing of each alarm data according to the alarm type corresponding to each alarm data and the handling method corresponding to the alarm type includes: Each of the alarm data is processed according to the alarm type corresponding to the alarm data, the handling method corresponding to the alarm type, and the handling priority corresponding to the alarm type.
4. The alarm processing method according to claim 1 or 2, It is characterized in that After determining the alarm type corresponding to each of the alarm data according to the configured triage rule, the method further includes: A label corresponding to the alarm type to which the alarm data belongs is added to each of the alarm data, and each of the alarm data is stored; the label is used to indicate the importance of the alarm type corresponding to the alarm data.
5. The alarm processing method according to claim 1 or 2, It is characterized in that The triage rule is established based on at least one of the threat source, threat type and threat degree.
6. The alarm processing method according to claim 1 or 2, It is characterized in that The triage rules include: a white triage rule, a custom triage rule and a pre-configured triage rule. The white triage rule is a triage rule for filtering false alarms. The custom triage rule is a triage rule for classifying alarm data formulated based on user environment requirements. The pre-configured triage rule is a pre-configured triage rule for classifying alarm data. The alarm type corresponding to each of the alarm data is determined according to the configured triage rule, including: Determining whether each of the alarm data matches the whitening triage rule; If there is alarm data matching the whitening triage rule, determining that the alarm data matching the whitening triage rule is a false alarm; If there is alarm data that does not match the whitening triage rule, determining whether the alarm data that does not match the whitening triage rule matches the custom triage rule; If there is alarm data matching the custom triage rule, then based on the custom triage rule, determining the alarm type corresponding to the alarm data matching the custom triage rule; If there is alarm data that does not match the custom triage rule, the alarm type corresponding to the alarm data that does not match the custom triage rule is determined based on the preconfigured triage rule.
7. An alarm processing device, It is characterized in that include: An acquisition module, used to acquire at least one piece of alarm data; A processing module, used to determine the alarm type corresponding to each of the alarm data according to a configured triage rule, wherein the triage rule is used to classify the alarm data; The processing module is further used to process each of the alarm data according to the alarm type corresponding to the alarm data and the handling method corresponding to the alarm type.
8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, It is characterized in that When the processor executes the program, the alarm processing method according to any one of claims 1 to 6 is implemented.
9. A non-transitory computer-readable storage medium having a computer program stored thereon, It is characterized in that When the computer program is executed by a processor, the alarm processing method according to any one of claims 1 to 6 is implemented.
10. A computer program product comprising a computer program, It is characterized in that When the computer program is executed by a processor, the alarm processing method according to any one of claims 1 to 6 is implemented.