Network security event generation method and device, electronic equipment and storage medium
By extracting relevant attributes from network sessions for risk assessment and generating network security events, the false positives and omissions caused by relying on manual analysis and judgment in the existing technology are solved, and the accuracy and automation of analysis are improved.
Patent Information
- Application Number
- CN202311675775.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-07
- Publication Date
- 2025-06-10
AI Technical Summary
The prior art relies on manual analysis in network security incident analysis, resulting in false positives or omissions, reducing the accuracy of the analysis.
Risk assessment is performed and network security events are generated when a security risk is determined to exist when a security risk is determined.
Improves the accuracy of network security incident generation, reduces false positives and omissions, and enhances the automation and standardization of analysis.
Smart Images

Figure CN120128348A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technologies, and in particular, to a method, apparatus, electronic device, and storage medium for generating network security events. Background Art
[0002] In network security event analysis, when traffic is generated in the monitored network, the generated traffic is acquired by a monitoring device. The monitoring device matches the acquired traffic with preset alarm rules therein. When the match is successful, it indicates that there may be a security problem with the traffic, and the monitoring device generates an alarm for the traffic. The analyst conducts further analysis on the alarm to determine whether the traffic corresponds to a network security event.
[0003] Currently, in the process of analyzing network security events based on alarms, mainly analysts analyze network security events from alarms through manual analysis. Specifically, according to the content in the alarm, if an analyst can directly determine it as a network security event, the content in the alarm is directly determined as a network security event. If an analyst cannot directly determine it as a network security event, other alarms or traffic need to be combined to determine that the alarm and other alarms or traffic are a network security event.
[0004] However, the above methods for determining network security events all rely on the personal experience of analysts. If the analyst has rich experience, they can accurately analyze network security events based on alarms. If the analyst lacks experience, they cannot accurately analyze network security events based on alarms. For example: directly and arbitrarily believing that there is a network security event corresponding to an alarm. Another example: when it is impossible to determine whether there is a network security event through alarm A, originally, by combining alarm B, it can be determined that alarm A and alarm B correspond to a network security event. However, due to the lack of experience of the analyst, alarm A is combined with alarm C for analysis, and this network security event is not discovered. In this way, it will lead to false alarms or omissions of network security events, thereby reducing the accuracy of network security event analysis. Summary of the Invention
[0005] The purpose of the embodiments of this application is to provide a method, apparatus, electronic device, and storage medium for generating network security events to improve the accuracy of network security event analysis.
[0006] To solve the above technical problems, the embodiments of this application provide the following technical solutions:
[0007] The first aspect of the present application provides a method for generating a network security event. The method includes: obtaining at least one session of the monitored network, where the at least one session is used to characterize the interaction process between a visitor and a visited party; extracting at least one of the visitor attribute, access time attribute, access behavior attribute, access data attribute, and visited asset attribute from the at least one session to obtain the session attribute of the at least one session; determining whether there is a security risk in the session attribute; if so, generating a network security event based on the at least one session.
[0008] Compared with the prior art, the method for generating a network security event provided by the first aspect of the present application can convert a session into what person, at what time, by what means, and access what data of what service by extracting the visitor attribute, access time attribute, access behavior attribute, access data attribute, and visited asset attribute from at least one session of the interaction between the visitor and the visited party. Thus, risk assessment can be performed according to the session attribute, and when it is determined that there is a security risk in the session attribute, a corresponding network security event is generated. The network security event generated in this way does not require a researcher to analyze the alarm of the session based on personal experience, and the visitor attribute, access time attribute, access behavior attribute, access data attribute, and visited asset attribute cover all aspects of risk assessment. The risk assessment of the session is directly carried out using a unified standard, improving the accuracy of the generation of network security events.
[0009] In some modified embodiments of the first aspect of the present application, the extracting at least one of the visitor attribute, access time attribute, access behavior attribute, access data attribute, and visited asset attribute from the at least one session includes: obtaining the inbound intelligence log, vulnerability exploitation log, abnormal behavior log, sensitive access log, and interface risk log of the at least one session; extracting at least one of the visitor attribute, access time attribute, access behavior attribute, access data attribute, and visited asset attribute from the inbound intelligence log, vulnerability exploitation log, abnormal behavior log, sensitive access log, and interface risk log.
[0010] By extracting the visitor attribute, access time attribute, access behavior attribute, access data attribute, and visited asset attribute from the inbound intelligence log, vulnerability exploitation log, abnormal behavior log, sensitive access log, and interface risk log, since different logs contain different attribute data, the visitor attribute, access time attribute, access behavior attribute, access data attribute, and visited asset attribute can be accurately obtained.
[0011] In some modified embodiments of the first aspect of the present application, extracting at least one of the visitor attribute, access time attribute, access behavior attribute, access data attribute, and accessed asset attribute from the inbound intelligence log, exploit log, abnormal behavior log, sensitive access log, and interface risk log includes: extracting visitor-related information, access time-related information, access behavior-related information, access data-related information, and accessed asset-related information from the inbound intelligence log, exploit log, abnormal behavior log, sensitive access log, and interface risk log; and processing the visitor-related information, access time-related information, access behavior-related information, access data-related information, and accessed asset-related information based on a preset enrichment rule to obtain the visitor attribute, access time attribute, access behavior attribute, access data attribute, and accessed asset attribute.
[0012] In the process of extracting corresponding attribute data from each log, by enriching the attribute-related data extracted from the log, more accurate and comprehensive attribute data can be obtained.
[0013] In some modified embodiments of the first aspect of the present application, the visitor-related information is an Internet Protocol (IP) address; and the processing the visitor-related information, access time-related information, access behavior-related information, access data-related information, and accessed asset-related information based on a preset enrichment rule to obtain the visitor attribute, access time attribute, access behavior attribute, access data attribute, and accessed asset attribute includes: determining the region name corresponding to the IP address of the visitor-related information according to the preset correspondence between the IP address and the region name, and using the determined region name as the visitor attribute; or determining the user name corresponding to the IP address of the visitor-related information according to the preset correspondence between the IP address and the user name, and using the determined user name as the visitor attribute.
[0014] In the process of enriching the visitor attribute, by converting the visitor's IP address into a region name or a user name, the visitor attribute in the correspondence between the attribute and the score can use the region name or the user name, which is more convenient to set than the IP address and improves the convenience of configuring the scoring rule. And when the session corresponds to a security event, outputting the region name or the user name is more convenient for the network administrator or the visitor to identify than outputting the IP address.
[0015] In some alternative embodiments of the first aspect of the present application, determining whether there is a security risk for the session attribute includes: determining a risk score of the session attribute according to a preset correspondence between the session attribute and the risk score; determining whether the risk score is greater than a preset threshold; if so, determining that there is a security risk for the session attribute; if not, determining that there is no security risk for the session attribute.
[0016] When determining whether there is a security risk for the session attribute, by using the preset correspondence between the session attribute and the risk score to find out the risk score of the current session attribute, it is possible to accurately and quickly determine the security risk of the session attribute, improving the efficiency and accuracy of determining the security risk of the session attribute.
[0017] In some alternative embodiments of the first aspect of the present application, the at least one session includes at least two attributes, and each attribute has a corresponding relationship between the attribute and the risk score; determining the risk score of the session attribute according to the preset correspondence between the session attribute and the risk score includes: respectively determining the corresponding relationship between each attribute in the at least two attributes and the risk score; according to the corresponding relationship between each attribute and the risk score, respectively determining the risk score of the corresponding attribute; weighting the risk scores of the at least two attributes to obtain the risk score of the session attribute.
[0018] Configuring a corresponding relationship for each attribute respectively, and determining the risk score for each attribute of the session according to the corresponding relationship, and then weighting the risk scores, can obtain accurate risk scores for each attribute, and weight the risk scores according to the corresponding weights, improving the accuracy of the final risk score.
[0019] In some alternative embodiments of the first aspect of the present application, when each attribute includes a visitor attribute, the corresponding relationship between the attribute and the risk score includes: overseas visitors, domestic extranet visitors, intranet visitors and their corresponding risk scores; when each attribute includes an access behavior attribute, the corresponding relationship between the attribute and the risk score includes: various access frequencies and their corresponding risk scores; when each attribute includes an access time attribute, the corresponding relationship between the attribute and the risk score includes: non-working hours, working hours and their corresponding risk scores; when each attribute includes an access data attribute, the corresponding relationship between the attribute and the risk score includes: sensitive data, non-sensitive data and their corresponding risk scores; when each attribute includes an accessed asset attribute, the corresponding relationship between the attribute and the risk score includes: various business hosts and their corresponding risk scores.
[0020] By refining visitor attributes into overseas visitors, domestic external network visitors, and internal network visitors, refining access behavior attributes into various access frequencies, refining access time attributes into non-working hours and working hours, refining access data attributes into sensitive data and non-sensitive data, and refining the accessed asset attributes into various business hosts, it is possible to effectively distinguish different risk levels within the attributes without over-refining the attributes and increasing the complexity of scoring, ensuring the accuracy of risk scoring.
[0021] In some modified implementation manners of the first aspect of the present application, before weighting the risk scores of the at least two session attributes, the method further includes: obtaining the scenario type of the current network security event monitoring; determining the key attention attributes corresponding to the scenario type from the correspondence between the preset scenario types and the key attention attributes; configuring a first weight for the session attributes that are the same as the key attention attributes among the at least two session attributes, and configuring a second weight for the session attributes that are different from the key attention attributes among the at least two session attributes, where the first weight is greater than the second weight; the weighting of the risk scores of the at least two session attributes includes: weighting the risk scores of the at least two session attributes based on the first weight and the second weight.
[0022] By determining the key attention session attributes through the scenario type of the current network security event monitoring and assigning higher weights to the corresponding session attributes in the session when performing risk score weighting, the security monitoring can be made more in line with the current scenario requirements, improving the scenario applicability of network security event generation.
[0023] In some modified implementation manners of the first aspect of the present application, generating a network security event based on the at least one session includes: adding all the attributes included in the at least one session to a network security event template to obtain the network security event, where the network security event template is used to describe the network security event using a preset language framework; after generating the network security event based on the at least one session, the method further includes: obtaining the correspondence between the attributes at the reserved positions in the network security event template and the handling suggestions; matching each attribute in the at least one session with the corresponding correspondence in the network security event template to obtain the handling suggestions for each attribute; integrating the handling suggestions for each attribute to obtain and output the handling suggestions for the network security event.
[0024] Generate network security events through a security event template, making the content of the generated network security events more standardized and facilitating users to read. Moreover, based on the corresponding relationships at the reserved positions in the template, generate handling suggestions corresponding to each session attribute in the session, and integrate and output the handling suggestions corresponding to each session attribute, which can comprehensively and accurately output the handling suggestions for the current network security event.
[0025] The second aspect of this application provides a device for generating network security events. The device includes: an acquisition module for acquiring at least one session of the monitored network, where the at least one session is used to represent the interaction process between a visitor and a visited party; an extraction module for extracting at least one of the visitor attribute, access time attribute, access behavior attribute, access data attribute, and visited asset attribute from the at least one session to obtain the session attributes of the at least one session; a judgment module for judging whether there is a security risk in the session attributes; if so, enter the generation module; a generation module for generating network security events based on the at least one session.
[0026] The third aspect of this application provides an electronic device. The electronic device includes: a processor, a memory, and a bus; wherein, the processor and the memory communicate with each other through the bus; the processor is used to call program instructions in the memory to execute the method in the first aspect.
[0027] The fourth aspect of this application provides a computer-readable storage medium. The storage medium includes: a stored program; wherein, when the program runs, it controls the device where the storage medium is located to execute the method in the first aspect.
[0028] The device for generating network security events provided in the second aspect of this application, the electronic device provided in the third aspect, and the computer-readable storage medium provided in the fourth aspect have the same or similar technical effects as the method for generating network security events provided in the first aspect. Description of the Drawings
[0029] By referring to the accompanying drawings and reading the following detailed description, the above and other purposes, features, and advantages of the exemplary embodiments of this application will become easily understandable. In the drawings, several embodiments of this application are shown in an exemplary rather than restrictive manner, and the same or corresponding reference numerals represent the same or corresponding parts, where:
[0030] Figure 1 It is a schematic diagram of the application scenario of the method for generating network security events in the embodiments of this application;
[0031] Figure 2 It is a flowchart of the method for generating network security events in the embodiments of this application Figure 1 ;
[0032] Figure 3 It is a schematic diagram of the overall architecture of the method for generating network security events in the embodiments of the present application;
[0033] Figure 4 It is a flowchart of the method for generating network security events in the embodiments of the present application Figure 2 ;
[0034] Figure 5 It is a schematic diagram of the structure of the device for generating network security events in the embodiments of the present application Figure 1 ;
[0035] Figure 6 It is a schematic diagram of the structure of the device for generating network security events in the embodiments of the present application Figure 2 ;
[0036] Figure 7 It is a schematic diagram of the structure of the electronic device in the embodiments of the present application. Detailed implementation manners
[0037] Hereinafter, the exemplary embodiments of the present disclosure will be described in more detail with reference to the accompanying drawings. Although the exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present disclosure can be more thoroughly understood and the scope of the present disclosure can be completely conveyed to those skilled in the art.
[0038] It should be noted that unless otherwise specified, the technical terms or scientific terms used in the present application should have the ordinary meanings understood by those skilled in the art to which the present application belongs.
[0039] Currently, in the process of generating network security events, it is necessary for the analysts to analyze the alarms of the sessions based on personal experience, either directly analyze the alarms or analyze the current alarms in combination with other alarms. This analysis method highly depends on the personal experience of the analysts and sometimes may lead to false alarms or missed alarms of network security events.
[0040] In view of this, the embodiments of the present application provide a method, an apparatus, an electronic device, and a storage medium for generating network security events. Instead of analyzing the alarms of sessions based on the personal experience of analysts, the accessor attributes, access time attributes, access behavior attributes, access data attributes, and accessed asset attributes are directly extracted from the sessions to obtain session attributes. By performing a security risk assessment on the session attributes and generating corresponding network security events directly based on the sessions when it is determined that the session attributes have security risks. The accessor attributes, access time attributes, access behavior attributes, access data attributes, and accessed asset attributes can cover the entire access process, and the session attributes can accurately reflect the security risks of the sessions, without missing or misjudging network security events, and combining the alarm rules and manual analysis into one, improving the accuracy and efficiency of generating network security events.
[0041] First, the application scenario of the method for generating network security events provided by the embodiments of the present application is described.
[0042] Figure 1 For the schematic diagram of the application scenario of the method for generating network security events in the embodiments of the present application, see Figure 1 As shown, this scenario may include: a network 11 and a security device 12 in the network 11. The network 11 is the network that needs to be monitored for security. In practical applications, the network 11 may be the internal network of a certain enterprise or a part of the public network. The security device 12 is a device used to monitor whether there are security events in the network 11.
[0043] When a new session is generated in the network 11, the security device 12 obtains the session. The security device 12 extracts the accessor attributes, access time attributes, access behavior attributes, access data attributes, and accessed asset attributes from the session to obtain session data, and determines whether the session attributes have security risks, and then generates the network security event of the session when it is determined that the session attributes have security risks.
[0044] Next, the method for generating network security events provided by the embodiments of the present application is described in detail.
[0045] Figure 2 For the flowchart of the method for generating network security events in the embodiments of the present application Figure 1 see Figure 2 As shown, the method may include:
[0046] S21: Obtain at least one session of the monitored network.
[0047] Wherein, the at least one session is used to represent the interaction process between the accessor and the accessed.
[0048] The monitored network is the network that needs to be security-monitored. In practical applications, it can be the internal network of a certain object or a certain public network.
[0049] In the monitored network, it can include clients and an Application Programming Interface (API). Data is transmitted between the client and the API interface. Each time data is transmitted between the client and the API, the transmitted data can be regarded as a session. If the data transmitted multiple times can represent a complete interaction process between the visitor and the visited party, then the data transmitted multiple times is at least one session that needs to be obtained in this step.
[0050] Generally, there are multiple sessions between the client and the API. These sessions may belong to one interaction process or different interaction processes. To obtain the sessions of a complete interaction process from multiple sessions, a five-tuple (source IP address, source port, destination IP address, destination port, API unique identifier) can be extracted from each session, and the sessions with the same five-tuple are used as at least one session to be obtained this time. Of course, other criteria can also be used to obtain at least one session required this time, for example: selecting sessions with the same Cookies.
[0051] S22: Extract at least one of the visitor attribute, access time attribute, access behavior attribute, access data attribute, and visited asset attribute from at least one session to obtain the session attributes of at least one session.
[0052] Generally speaking, the entire access process can be described by the visitor, access behavior, access time, access data, and visited asset, that is, who (visitor), when (access time), by what means (access behavior), and what data (access data) of what device (visited asset) is accessed. Therefore, the extraction of these five attribute data of visitor attribute, access time attribute, access behavior attribute, access data attribute, and visited asset attribute can be performed from the session.
[0053] When extracting the above five attribute data from the session, due to the limited content of the session itself, sometimes only one or several of the attribute data can be extracted from the session. At this time, the number of attribute data that can be extracted from the session is the number of attribute data used later. All the attribute data that can be extracted from the session constitutes the session attributes of at least one session.
[0054] S23: Determine whether there is a security risk in the session attributes. If so, execute S24; if not, execute S25.
[0055] Since session attributes can characterize who accesses what data in what device by what means at what time, the purpose of this session can be determined through session attributes, and then whether there is a security risk in this session can be determined. In other words, judging whether there is a security risk in the session attributes in the above steps is equivalent to judging whether there is a security risk in the session based on the session attributes.
[0056] In the specific judgment process, a corresponding relationship can be set in advance. In this corresponding relationship, it includes various session attributes and their corresponding security risk scores. The extracted session data is searched in the corresponding relationship to find the corresponding score, so as to determine whether there is a security risk in the session attributes according to the level of the score. Some keywords can also be set in advance. If the session attributes contain these keywords, it is determined that the session attributes have a security risk. There are various specific ways to judge whether there is a security risk in the session attributes, which are not limited here.
[0057] S24: Generate a network security event based on at least one session.
[0058] When there is a security risk in the session attributes, it means that at least one session corresponding to the session attributes has a security risk. At this time, it is necessary to generate a network security event for this session.
[0059] In the process of generating a network security event, the session can be directly output as a network security event, or the visitor attributes, access time attributes, access behavior attributes, access data attributes, and accessed asset attributes in the session can be output as a network security event.
[0060] S25: Determine that at least one session has no security risk.
[0061] When there is no security risk in the session attributes, it means that at least one session is relatively secure. At this time, no processing may be performed on at least one session, so that the session can flow normally.
[0062] As can be seen from the above, the method for generating a network security event provided by the embodiments of the present application extracts visitor attributes, access time attributes, access behavior attributes, access data attributes, and accessed asset attributes from at least one session of interaction between a visitor and an accessed party, and can transform the session into what person, at what time, by what means, and access what data of what service. Thus, risk assessment is performed based on the session attributes, and when it is determined that there is a security risk in the session attributes, a corresponding network security event is generated. The network security event generated in this way does not require a researcher to analyze the alarms of the session based on personal experience, and the visitor attributes, access time attributes, access behavior attributes, access data attributes, and accessed asset attributes cover all aspects of risk assessment. The risk assessment of the session is directly performed using a unified standard, which improves the accuracy of network security event generation.
[0063] Further, as a refinement and extension of the Figure 2 method shown, the embodiments of the present application also provide a method for generating a network security event.
[0064] Figure 3 For the overall architecture diagram of the method for generating a network security event in the embodiments of the present application, see Figure 3 shown. In this architecture, after a session is generated, it will be sent to the corresponding rules for matching. If the match is successful, corresponding logs will be generated, namely, inbound intelligence logs, vulnerability exploitation logs, abnormal behavior logs, sensitive access logs, and interface risk logs. Through these logs, corresponding attributes can be extracted, namely, visitor attributes, access time attributes, access behavior attributes, access data attributes, and accessed asset attributes. In the process of extracting visitor attributes from the inbound intelligence logs, the data in the logs needs to be enriched before the required visitor attributes can be obtained. And the access time attributes can also be enriched from the inbound intelligence logs. For the access behavior attributes, they can be obtained from the vulnerability exploitation logs and abnormal behavior logs. Then, the visitor attributes, access time attributes, access behavior attributes, access data attributes, and accessed asset attributes form a session attribute, and then enter the event scoring calculation engine for risk scoring. If the output risk score exceeds the preset threshold, it means that the session corresponds to a network security event. After the session is enriched, a network security event is generated.
[0065] Figure 4 For the flow diagram of the method for generating a network security event in the embodiments of the present application Figure 2 , see Figure 4 shown. The method may include:
[0066] S41: Obtain at least one session of the monitored network.
[0067] Step S41 is implemented in the same way as the aforementioned step S21 and will not be elaborated here.
[0068] S42: Obtain inbound intelligence logs, exploit logs, abnormal behavior logs, sensitive access logs, and interface risk logs for at least one session.
[0069] After a session is generated in the monitored network, the session will be matched with different rules. Among them, there are five rules closely related to the data access process. After the session is matched with these five rules, if the match is successful, corresponding logs will be generated, namely inbound intelligence logs, exploit logs, abnormal behavior logs, sensitive access logs, and interface risk logs.
[0070] Inbound intelligence logs, which record relevant information about the session request entering the monitored network, such as access requests, login requests, download requests, etc. The request information in the session can be directly recorded in the inbound intelligence logs. If no request information is obtained from the session, no inbound intelligence logs will be generated.
[0071] Exploit logs, which record the actions taken by the session to exploit vulnerabilities. It is possible to check whether there are vulnerabilities in the network through the session. If there are, it means that the actions corresponding to the session exploit network vulnerabilities, and the action data of the vulnerabilities exploited by the session can be recorded in the exploit logs. If not, no exploit logs for the session will be generated.
[0072] Abnormal behavior logs, which record the abnormal behavior of the session. The session can be matched with abnormal behavior characteristics. If the match is successful, the data in the session that matches the abnormal behavior characteristics is abnormal behavior data, and the matched abnormal behavior data in the session can be recorded in the abnormal behavior logs. If the match is not successful, no abnormal behavior logs for the session will be generated.
[0073] Sensitive access logs, which record the sensitive data accessed by the session. By analyzing the session, determine the data it needs to access, and match the data to be accessed with sensitive rules. If the match is successful, it means that the data the session needs to access is sensitive data, and the sensitive data will be recorded in the sensitive access logs. If the match fails, it means that the data the session needs to access is non-sensitive data, and no sensitive access logs will be generated.
[0074] Interface risk logs, which record the business hosts accessed by the session through the API. Determine the business hosts it needs to access from the session, and determine the importance of the business hosts. Then record the determined business hosts and their importance in the interface risk logs. If no business hosts can be determined, no interface risk logs will be generated.
[0075] Since the inbound intelligence log, exploit log, abnormal behavior log, sensitive access log, and interface risk log cover all key points in the access process, namely, who, by what means, at what time, and what data in what device was accessed, it is possible to obtain the inbound intelligence log, exploit log, abnormal behavior log, sensitive access log, and interface risk log of the session, and then conveniently and accurately obtain the visitor attribute, access time attribute, access behavior attribute, access data attribute, and accessed asset attribute of the session from these logs respectively.
[0076] S43: Extract visitor-related information, access time-related information, access behavior-related information, access data-related information, and accessed asset-related information from the inbound intelligence log, exploit log, abnormal behavior log, sensitive access log, and interface risk log.
[0077] Since the inbound intelligence log records access requests and involves access time, the exploit log and abnormal behavior log record abnormal access behaviors, the sensitive access log records sensitive data accessed, and the interface risk log records the business hosts accessed, it is possible to directly and quickly obtain visitor-related information, access time-related information, access behavior-related information, access data-related information, and accessed asset-related information respectively through the access requests, abnormal access behaviors, abnormal access times, sensitive data accessed, and business hosts accessed.
[0078] For obtaining visitor-related information, in the access request, there are generally source IP address, source port, destination IP address, destination port, etc. And the source IP address is the IP address of the visitor. Therefore, the source IP address can be directly obtained from the access request and directly used as visitor-related information.
[0079] For obtaining access time-related information, the time information of the access request can be obtained from the inbound intelligence log, and this time information is the access time-related information.
[0080] For obtaining access behavior-related information, the abnormal behaviors recorded in the exploit log and abnormal behavior log are obtained from the exploit log and abnormal behavior log, and these abnormal behaviors are used as access behavior-related information.
[0081] For obtaining access data-related information, the sensitive data recorded in the sensitive access log are obtained from the sensitive access log, and these sensitive data are used as access data-related information.
[0082] For obtaining information related to the accessed asset, for the business hosts recorded in the interface risk log, obtain the information and importance of these business hosts from the interface risk log, and use the obtained information and importance of the business hosts as the information related to the accessed asset.
[0083] Of course, it is also possible to directly extract at least one of the visitor attributes, access time attributes, access behavior attributes, access data attributes, and accessed asset attributes from the inbound intelligence log, vulnerability exploitation log, abnormal behavior log, sensitive access log, and interface risk log.
[0084] S44: Process the information related to the visitor, access time, access behavior, access data, and accessed asset based on the preset enrichment rules to obtain the visitor attributes, access time attributes, access behavior attributes, access data attributes, and accessed asset attributes.
[0085] Sometimes, the relevant information obtained from the relevant logs cannot be directly used to calculate the risk score, and it is necessary to convert the relevant information into content that can be used for risk score calculation. This requires using the preset enrichment rules to process the relevant information obtained from the logs into attribute data that can be used for risk score calculation.
[0086] When different relevant information is converted into corresponding attribute data, different preset enrichment rules are used. The preset enrichment rules here can be regarded as a data conversion rule or a data addition rule.
[0087] For enriching and processing the information related to the visitor, when the information related to the visitor is an IP address, the region name corresponding to the IP address of the information related to the visitor can be determined according to the preset correspondence between the IP address and the region name, and the determined region name can be used as the visitor attribute. Or, the user name corresponding to the IP address of the information related to the visitor can be determined according to the preset correspondence between the IP address and the user name, and the determined user name can be used as the visitor attribute.
[0088] For example, assume the correspondence is that IP address a - b corresponds to region 1 and IP address c - d corresponds to region 2. When the IP address a is extracted from the inbound intelligence log of the session, through the above correspondence, it can be obtained that the sender of the session belongs to region 1.
[0089] In practical applications, the above region name can be the name of a region, such as: XX country, XX province, XX city, etc. It can also be the name of a subject, such as: XX enterprise, XX school, etc.
[0090] For another example, assume that the correspondence is such that IP address a corresponds to user 1 and IP address b corresponds to user 2. When IP address a is extracted from the inbound intelligence log of the session, through the above correspondence, the sender of the session can be obtained as user 1.
[0091] In practical applications, the above username can be the name of the account registered by the visitor in the network, or the real name of the visitor, etc.
[0092] Regarding the enrichment of information related to the access time, it can be converting the specific moment into the elapsed time. For example: The sending time of the access request obtained from the inbound intelligence log is 12:00:00 on November 1, 2023. Assuming the current time is 12:00:00 on November 2, 2023, and the information related to the access time is 12:00:00 on November 1, 2023. After enrichment processing, the obtained access time attribute is one day ago.
[0093] Regarding the enrichment of information related to the access behavior, access data, and accessed asset, when there is a lack of information related to the access behavior, access data, or accessed asset, the relevant information extracted from the corresponding log is empty. At this time, the relevant information missing from the current session can be obtained from a session that is homologous (the same sender) as the current session. After verifying that the other relevant information of the two sessions is the same, this relevant information of the homologous session is supplemented in the relevant information missing from the current session.
[0094] For example, assume that session 1 lacks information related to the accessed asset. At this time, determine the sender a of session 1, find session 2 sent by sender a other than session 1, obtain the information related to the accessed asset of session 2, and when the information related to the access behavior and access data of session 2 is the same as that of session 1, supplement the information related to the accessed asset of session 2 in the information related to the accessed asset of session 1.
[0095] It should be noted here that in addition to obtaining relevant information from the log and then enriching the relevant information to obtain attribute data, if the format of the relevant information recorded in the log is sufficient for calculating the risk score, then the attribute data can be directly obtained from the log without enrichment processing. For example: If the access behavior attribute can be directly extracted from the vulnerability exploitation log, then there is no need to extract the information related to the access behavior from the vulnerability exploitation log, and further there is no need to enrich the information related to the access behavior to obtain the access behavior attribute.
[0096] S45: Determine the risk score of the session attribute according to the correspondence between the preset session attribute and the risk score.
[0097] For some sessions, there may not be only one type of detection log corresponding to them. There may be multiple detection logs, that is, there are at least two types of logs among the inbound intelligence log, the exploitation log, the abnormal behavior log, the sensitive access log, and the interface risk log. Correspondingly, there are at least two attributes corresponding to this session, that is, at least two attributes among the visitor attribute, the access time attribute, the access behavior attribute, the access data attribute, and the accessed asset attribute. That is to say, at least two attributes are included in at least one session.
[0098] Moreover, the roles and evaluation criteria of each attribute in the security risk score are different. Therefore, it is necessary to configure a specific correspondence between each attribute and the risk score. In this way, the risk score of each attribute in the session can be made precise, thereby improving the accuracy of the overall risk score of the session, and further improving the accuracy of generating network security events.
[0099] Specifically, the above step S45 may include:
[0100] Step A1: Determine the correspondence between each attribute among at least two attributes and the risk score respectively.
[0101] Step A2: Determine the risk score of the corresponding attribute respectively according to the correspondence between each attribute and the risk score.
[0102] Step A3: Weight the risk scores of at least two attributes to obtain the risk score of the session attributes.
[0103] For example, assume that the visitor attribute, the access time attribute, and the access behavior attribute are extracted from the session. The correspondence includes: the correspondence between the visitor attribute and its risk score, the correspondence between the access time attribute and its risk score, the correspondence between the access behavior attribute and its risk score, the correspondence between the access data attribute and its risk score, and the correspondence between the accessed asset attribute and its risk score. From these five correspondences, determine the correspondence between the visitor attribute and its risk score, the correspondence between the access time attribute and its risk score, and the correspondence between the access behavior attribute and its risk score. Determine the risk score of the visitor attribute in the session according to the correspondence between the visitor attribute and its risk score, determine the risk score of the access time attribute in the session according to the correspondence between the access time attribute and its risk score, and determine the risk score of the access behavior attribute in the session according to the correspondence between the access behavior attribute and its risk score. Then weight these three risk scores to obtain the risk score of the session.
[0104] The following gives the correspondence between five attributes and their risk scores.
[0105] 1. When each attribute includes an access behavior attribute, the corresponding relationship between the attribute and the risk score includes various access frequencies and their corresponding risk scores.
[0106] Specifically: overseas visitors, domestic extranet visitors, intranet visitors and their corresponding risk scores. The scores of the risk scores here decrease in sequence.
[0107] That is to say, visitors are divided into overseas, domestic extranet and intranet. Generally, intranet visitors are the users of the monitored network, with a relatively high security level, and a relatively low risk score can be assigned. Overseas visitors, generally speaking, use overseas networks for network access in order to avoid being tracked, and the degree of security threat to the monitored network is relatively high, and a relatively high risk score can be assigned. And domestic extranet visitors are between overseas visitors and intranet visitors, and an intermediate risk score can be assigned.
[0108] 2. When each attribute includes an access behavior attribute, the corresponding relationship between the attribute and the risk score includes various access frequencies and their corresponding risk scores.
[0109] Specifically: various access frequencies and their corresponding risk scores.
[0110] Specific access behaviors are diverse and not easy to identify features. However, abnormal access behaviors generally have a common feature, that is, multiple accesses. Because only through multiple accesses can as much data information of the target object be obtained as possible. Therefore, the access frequency can be used as the specific content of the access behavior attribute to conduct different security level divisions.
[0111] Generally speaking, the higher the access frequency, the more likely it is to continuously obtain the data information of the target object. Therefore, the access frequency can be divided into different intervals. The higher the access frequency interval, the higher the corresponding risk score, and the lower the access frequency interval, the lower the corresponding risk score.
[0112] 3. When each attribute includes an access time attribute, the corresponding relationship between the attribute and the risk score includes non-working hours, working hours and their corresponding risk scores.
[0113] Specifically: non-working hours, working hours and their corresponding risk scores. The scores of the risk scores here decrease in sequence.
[0114] During working hours, most of the accesses are accesses required in normal work. And during non-working hours, if there are still accesses, the probability of being an access required for normal work is greatly reduced. Therefore, a relatively high risk score can be configured for non-working hours, and a relatively low risk score can be configured for working hours.
[0115] The division between working hours and non - working hours can be defined according to the working hours of the users of the monitored network. For example, the working hours are from 9:00 am to 6:00 pm from Monday to Friday, and the non - working hours are from 0:00 am to 9:00 am, from 6:00 pm to 0:00 am from Monday to Friday, and on Saturday and Sunday.
[0116] 4. When each attribute includes access data attributes, the corresponding relationship between the attribute and the risk score includes: sensitive data, non - sensitive data, and their corresponding risk scores.
[0117] Specifically: sensitive data, non - sensitive data, and their corresponding risk scores. The scores of the risk scores here decrease in sequence.
[0118] As the core of enterprise information, once sensitive data is leaked, it will cause relatively large losses to the enterprise. Therefore, dividing the access data attributes into sensitive and non - sensitive, and configuring a higher risk score for sensitive data and a lower risk score for non - sensitive data can achieve a simple and accurate distinction of access data attributes.
[0119] The sensitive data here can refer to the financial data, account data, R & D data, etc. of the enterprise.
[0120] For sensitive data, more detailed classification can be carried out. For example, it can be divided into: business - type sensitive data and general sensitive data. Business - type sensitive data can refer to the data generated by the enterprise in the corresponding business, and these data are not convenient for people outside the enterprise to know. General sensitive data can refer to the data such as user identities involved in the process of code R & D of the enterprise. Once business - type sensitive data is leaked, it may cause relatively large economic losses to the enterprise. When general sensitive data is leaked, the losses caused to the enterprise are sometimes not significant, and the leaked information may be test data. Therefore, the risk score of business - type sensitive data should be higher than that of general - type sensitive data.
[0121] 5. When each attribute includes accessed asset attributes, the corresponding relationship between the attribute and the risk score includes: various business hosts and their corresponding risk scores.
[0122] Specifically: various business hosts and their corresponding risk scores.
[0123] Different hosts handle different businesses. For an enterprise, the importance of different businesses will vary. When accessing the hosts of important businesses, more attention needs to be paid. Because once a security problem occurs during the process of accessing the hosts of important businesses, the important business data of the enterprise in the important business hosts may be leaked, which will cause relatively serious losses to the enterprise. Therefore, a higher risk rating can be configured for important business hosts, and a lower risk score can be configured for some non - important business hosts.
[0124] For different monitoring scenarios, the emphasis on attributes is different. Therefore, it is necessary to configure weights for each attribute in the session according to different monitoring scenarios.
[0125] Specifically, before the above step A3, the method may include:
[0126] Step A301: Obtain the scenario type of the current network security event monitoring.
[0127] There are various scenarios for network security event monitoring, such as API security event monitoring, system security event monitoring, etc. Different users have different requirements for network security event monitoring. Even for the same user, the requirements for network security monitoring may vary at different times. At this time, it is necessary to determine the current monitoring scenario type according to the user's requirements for the current network security event monitoring. For example: If the user needs to monitor API security events, then the current monitoring scenario type is API security event monitoring.
[0128] Step A302: Determine the key attributes to be focused on corresponding to the scenario type from the preset correspondence between scenario types and key attributes to be focused on.
[0129] For different scenario types, the key attributes to be focused on are different. For example: In the API security event monitoring scenario, the focus is on who accessed what data, that is, the visitor attribute and the accessed data attribute are the key objects to be focused on. Therefore, in the correspondence, the correspondence between API security event monitoring and the visitor attribute and the accessed data attribute is pre-configured. So that in subsequent API security event monitoring, the key attributes to be focused on can be directly determined as the visitor attribute and the accessed data attribute through this correspondence. Of course, in the correspondence, the correspondences between various security event monitoring scenarios and their key attributes to be focused on are also pre-configured.
[0130] Step A303: Configure a first weight for the session attributes that are the same as the key attributes to be focused on among at least two session attributes, and configure a second weight for the session attributes that are different from the key attributes to be focused on among at least two session attributes.
[0131] Among them, the first weight is greater than the second weight.
[0132] The key attributes to be focused on play an important role in the judgment of network security events. Therefore, a higher weight, that is, the first weight, needs to be configured. For other attributes, their security scores do not need to be particularly concerned about in the judgment of network security events. Therefore, a lower weight, that is, the second weight, can be configured.
[0133] Still taking the API security event monitoring scenario as an example, visitor attributes, access time attributes, access behavior attributes, access data attributes, and accessed asset attributes can be extracted from the session. In the API security event monitoring scenario, visitor attributes and access data attributes are the key concerns. Therefore, weights of 0.3 are configured for visitor attributes and access data attributes, and weights of 0.1 are configured for access time attributes, access behavior attributes, and accessed asset attributes.
[0134] The specific magnitudes of the configured weight values can be configured according to actual requirements and are not limited here.
[0135] Correspondingly, step A3 above may include: weighting the risk scores of at least two session attributes based on the first weight and the second weight.
[0136] After obtaining the risk scores corresponding to each attribute in the session and the weights corresponding to each attribute, the risk score of the same attribute can be multiplied by the weight, and then the multiplication results of each attribute are added together to obtain the final risk score of at least one session.
[0137] S46: Determine whether the risk score is greater than the preset threshold. If so, execute S47 - S49; if not, execute S410.
[0138] The preset threshold can be determined according to actual security requirements. When the security requirements are high, the preset threshold can be set smaller. When the security requirements are average, the preset threshold can be set larger.
[0139] S47: Determine that there is a security risk in the session attributes.
[0140] S48: Add all the attributes included in at least one session to the network security event template to obtain a network security event.
[0141] Among them, the network security event template is used to describe network security events using a preset language framework. Here, the preset language framework can refer to a description method that uses the subject + predicate + object, which is easy to understand and does not cause ambiguity, and pre-reserves filling positions for various attribute contents. It can also refer to a certain fixed display format, such as a portrait, a logic diagram, etc.
[0142] For example, the network security event template is "XX person, at XX time, using XX means, accessing XX data in XX host". When the following attributes are extracted from the session: overseas user, 100 times / day, from 8 pm to 10 pm every day, enterprise R & D data, and R & D test host, when its risk score is greater than the preset threshold, the generated network security event is: overseas user, at the time from 8 pm to 10 pm every day, with a frequency of 100 times / day, accessing enterprise R & D data in the R & D test host.
[0143] S49: Output the disposal suggestions for network security incidents.
[0144] After a network security incident occurs, it indicates that there are security threats and security incidents in the monitored network. To ensure the security of the monitored network, a disposal suggestion can be output for this security incident so that network administrators can handle the security incident in a timely and effective manner.
[0145] Specifically, the above step S49 may include:
[0146] Step B1: Obtain the corresponding relationship between the attributes at the reserved positions of each attribute in the network security incident template and the disposal suggestions.
[0147] The empty positions in the network security incident template are the positions where specific attributes need to be filled. Different empty positions are filled with different categories of attributes. Since different categories of attributes have different security problems and specific handling methods will vary, there is a corresponding relationship between the specific content of each attribute and the corresponding disposal suggestion at each empty position in the network security incident template.
[0148] For example, for the empty position in the network security incident template that needs to fill in the visitor attribute, the corresponding relationship can be: overseas visitor - deny access; intranet visitor - allow access, etc. For the empty position in the network security incident template that needs to fill in the access behavior attribute, the corresponding relationship can be: access frequency 51 - 100 times / day - deny access; access frequency 10 - 50 times / day - limit the access interval time, etc.
[0149] Step B2: Match the attributes of each session with the corresponding relationships in the network security incident template to obtain the disposal suggestions for each attribute.
[0150] At each empty position in the network security incident template, there is a corresponding relationship between the specific content of the attribute and the disposal suggestion. Matching the attributes in the session with the corresponding relationships at the corresponding empty positions, what is obtained is the disposal suggestion corresponding to the attribute.
[0151] For example, in a network security event template, the first blank space is for various visitors and their corresponding handling suggestions, the second blank space is for various access frequencies and their corresponding handling suggestions, the third blank space is for various access times and their corresponding handling suggestions, the fourth blank space is for various access data and their corresponding handling suggestions, and the fifth blank space is for various accessed hosts and their corresponding handling suggestions. In a session, the visitor attribute is matched with the corresponding relationship in the first blank space to find the handling suggestion corresponding to the visitor in the session. The access behavior attribute is matched with the corresponding relationship in the second blank space to find the handling suggestion corresponding to the access frequency in the session. The access time attribute is matched with the corresponding relationship in the third blank space to find the handling suggestion corresponding to the access time in the session. The access data attribute is matched with the corresponding relationship in the fourth blank space to find the handling suggestion corresponding to the access data in the session. The accessed asset attribute is matched with the corresponding relationship in the fifth blank space to find the handling suggestion corresponding to the accessed asset in the session.
[0152] Step B3: Integrate the handling suggestions for each attribute to obtain and output the handling suggestions for the network security event.
[0153] After obtaining the handling suggestions for each attribute in the session, integrating these suggestions together gives a complete handling suggestion for the network security event.
[0154] For example, the handling suggestion corresponding to the visitor attribute in the session is to prohibit access, the handling suggestion corresponding to the access behavior attribute in the session is to limit the access time interval, the handling suggestion corresponding to the access time attribute in the session is to allow access, the handling suggestion corresponding to the access data attribute in the session is to perform authentication during access, and the handling suggestion corresponding to the accessed asset attribute in the session is to allow access. Among these five handling suggestions, there is one for prohibiting access, two for allowing access, and two for restricting access. To ensure the security of the monitored network, a handling method with the highest protection level can be selected as the handling suggestion for the network security event of this session. Of course, these five handling suggestions can also be all output and the corresponding attributes can be marked for the network administrator to select the final handling method by himself.
[0155] S410: Determine that the session attribute has no security risk, and then determine that at least one session is secure.
[0156] When the session attribute has no security risk, it means that at least one session is relatively secure. At this time, no processing needs to be performed on at least one session, and the session can flow normally.
[0157] So far, the method for generating a network security event provided by the embodiments of the present application has been fully described.
[0158] Based on the same inventive concept and as an implementation of the above method, an embodiment of the present application further provides a device for generating network security events.
[0159] Figure 5 It is a schematic structure of the device for generating network security events in the embodiment of the present application Figure 1 , see Figure 5 As shown, the device may include: an acquisition module 51, an extraction module 52, a judgment module 53, and a generation module 54. Among them, the acquisition module 51, the extraction module 52, the judgment module 53, and the generation module 54 are connected in sequence.
[0160] The acquisition module 51 is configured to acquire at least one session of the monitored network, and the at least one session is used to represent the interaction process between the visitor and the visited party.
[0161] The extraction module 52 is configured to extract at least one of the visitor attribute, access time attribute, access behavior attribute, access data attribute, and visited asset attribute from the at least one session to obtain the session attribute of the at least one session.
[0162] The judgment module 53 is configured to judge whether there is a security risk in the session attribute; if so, it enters the generation module.
[0163] The generation module 54 is configured to generate network security events based on the at least one session.
[0164] Furthermore, as a refinement and extension of the Figure 5 system shown, an embodiment of the present application further provides a device for generating network security events.
[0165] Figure 6 It is a schematic structure of the device for generating network security events in the embodiment of the present application Figure 2 , see Figure 6 As shown, the device may include: an acquisition module 61, an extraction module 62, a judgment module 63, a generation module 64, and a handling suggestion module 65. Among them, the acquisition module 61, the extraction module 62, the judgment module 63, the generation module 64, and the handling suggestion module 65 are connected in sequence.
[0166] The acquisition module 61 is configured to acquire at least one session of the monitored network, and the at least one session is used to represent the interaction process between the visitor and the visited party.
[0167] The extraction module 62 includes: a log unit 621 and an attribute unit 622. Among them, the log unit 621 and the attribute unit 622 are connected.
[0168] A log unit 621 for obtaining inbound intelligence logs, exploit logs, abnormal behavior logs, sensitive access logs, and interface risk logs of the at least one session.
[0169] An attribute unit 622 for extracting at least one of the visitor attributes, access time attributes, access behavior attributes, access data attributes, and accessed asset attributes from the inbound intelligence logs, exploit logs, abnormal behavior logs, sensitive access logs, and interface risk logs.
[0170] The attribute unit 622 is specifically configured to extract visitor-related information, access time-related information, access behavior-related information, access data-related information, and accessed asset-related information from the inbound intelligence logs, exploit logs, abnormal behavior logs, sensitive access logs, and interface risk logs; process the visitor-related information, access time-related information, access behavior-related information, access data-related information, and accessed asset-related information based on preset enrichment rules to obtain the visitor attributes, access time attributes, access behavior attributes, access data attributes, and accessed asset attributes.
[0171] When the visitor-related information is an IP address, the attribute unit 622 is specifically configured to determine the region name corresponding to the IP address of the visitor-related information according to the preset correspondence between the IP address and the region name, and use the determined region name as the visitor attribute; or determine the user name corresponding to the IP address of the visitor-related information according to the preset correspondence between the IP address and the user name, and use the determined user name as the visitor attribute.
[0172] A judgment module 63 includes: a scoring unit 631, a judgment unit 632, a first determination unit 633, and a second determination unit 634. Among them, the scoring unit 631, the judgment unit 632, and the first determination unit 633 are connected in sequence. The second determination unit 634 is connected to the judgment unit 632. If the output of the judgment module 63 is yes, then enter the generation module 64.
[0173] The scoring unit 631 is configured to determine the risk score of the session attribute according to the preset correspondence between the session attribute and the risk score.
[0174] When there are at least two attributes in the at least one session, and each attribute has a correspondence between the attribute and the risk score, the scoring unit 631 is specifically configured to respectively determine the correspondence between each attribute in the at least two attributes and the risk score; according to the correspondence between each attribute and the risk score, respectively determine the risk score of the corresponding attribute; weight the risk scores of the at least two attributes to obtain the risk score of the session attribute.
[0175] When each attribute includes visitor attributes, the correspondence between the attribute and the risk score includes: overseas visitors, domestic Internet external network visitors, intranet visitors, and their corresponding risk scores; when each attribute includes access behavior attributes, the correspondence between the attribute and the risk score includes: various access frequencies and their corresponding risk scores; when each attribute includes access time attributes, the correspondence between the attribute and the risk score includes: non-working hours, working hours, and their corresponding risk scores; when each attribute includes access data attributes, the correspondence between the attribute and the risk score includes: sensitive data, non-sensitive data, and their corresponding risk scores; when each attribute includes the accessed asset attributes, the correspondence between the attribute and the risk score includes: various business hosts and their corresponding risk scores.
[0176] The scoring unit 631 is specifically configured to obtain the scenario type of the current network security event monitoring; determine the key attention attributes corresponding to the scenario type from the correspondence between the preset scenario type and the key attention attributes; configure a first weight for the session attributes that are the same as the key attention attributes among the at least two session attributes, and configure a second weight for the session attributes that are different from the key attention attributes among the at least two session attributes, where the first weight is greater than the second weight; and perform weighting on the risk scores of the at least two session attributes based on the first weight and the second weight.
[0177] The judgment unit 632 is configured to judge whether the risk score is greater than a preset threshold.
[0178] The first determination unit 633 is configured to determine that there is a security risk for the session attribute.
[0179] The second determination unit 634 is configured to determine that there is no security risk for the session attribute.
[0180] The generation module 64 is configured to add all the attributes included in the at least one session to the network security event template to obtain the network security event, and the network security event template is used to describe the network security event using a preset language framework.
[0181] The handling suggestion module 65 is configured to obtain the correspondence between the attribute and the handling suggestion at the reserved position of each attribute in the network security event template; match each attribute in the at least one session with the corresponding relationship in the network security event template to obtain the handling suggestion for each attribute; and integrate the handling suggestions for each attribute to obtain and output the handling suggestion for the network security event.
[0182] It should be noted here that the description of the above device embodiments is similar to that of the above method embodiments and has similar beneficial effects to those of the method embodiments. For the technical details not disclosed in the device embodiments of the present application, please refer to the description of the method embodiments of the present application for understanding.
[0183] Based on the same inventive concept, an embodiment of the present application further provides an electronic device. Figure 7 For the structural schematic diagram of the electronic device in the embodiment of the present application, see Figure 7 As shown, the electronic device may include: a processor 71, a memory 72, and a bus 73; wherein, the processor 71 and the memory 72 complete communication with each other through the bus 73; the processor 71 is used to call program instructions in the memory 72 to execute the methods in the above one or more embodiments.
[0184] It should be noted here that the description of the above electronic device embodiments is similar to that of the above method embodiments and has similar beneficial effects to those of the method embodiments. For the technical details not disclosed in the electronic device embodiments of the present application, please refer to the description of the method embodiments of the present application for understanding.
[0185] Based on the same inventive concept, an embodiment of the present application further provides a computer-readable storage medium, which may include: a stored program; wherein, when the program runs, it controls the device where the storage medium is located to execute the methods in the above one or more embodiments.
[0186] It should be noted here that the description of the above storage medium embodiments is similar to that of the above method embodiments and has similar beneficial effects to those of the method embodiments. For the technical details not disclosed in the storage medium embodiments of the present application, please refer to the description of the method embodiments of the present application for understanding.
[0187] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed by the present application, and all of them should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A method for generating a network security event, characterized in that, the method includes: Obtain at least one session of the monitored network, where the at least one session is used to characterize the interaction process between a visitor and a visited party; Extract at least one of the visitor attribute, access time attribute, access behavior attribute, access data attribute, and visited asset attribute from the at least one session to obtain the session attributes of the at least one session; Determine whether there is a security risk in the session attributes; If so, generate a network security event based on the at least one session.
2. The method according to claim 1, characterized in that, the extracting at least one of the visitor attribute, access time attribute, access behavior attribute, access data attribute, and visited asset attribute from the at least one session includes: Obtain the inbound intelligence log, vulnerability exploitation log, abnormal behavior log, sensitive access log, and interface risk log of the at least one session; Extract at least one of the visitor attribute, access time attribute, access behavior attribute, access data attribute, and visited asset attribute from the inbound intelligence log, vulnerability exploitation log, abnormal behavior log, sensitive access log, and interface risk log.
3. The method according to claim 2, characterized in that, the extracting at least one of the visitor attribute, access time attribute, access behavior attribute, access data attribute, and visited asset attribute from the inbound intelligence log, vulnerability exploitation log, abnormal behavior log, sensitive access log, and interface risk log includes: Extract visitor-related information, access time-related information, access behavior-related information, access data-related information, and visited asset-related information from the inbound intelligence log, vulnerability exploitation log, abnormal behavior log, sensitive access log, and interface risk log; Process the visitor-related information, access time-related information, access behavior-related information, access data-related information, and visited asset-related information based on a preset enrichment rule to obtain the visitor attribute, access time attribute, access behavior attribute, access data attribute, and visited asset attribute.
4. The method according to claim 3, characterized in that, the visitor-related information is an IP address; the processing the visitor-related information, access time-related information, access behavior-related information, access data-related information, and visited asset-related information based on a preset enrichment rule to obtain the visitor attribute, access time attribute, access behavior attribute, access data attribute, and visited asset attribute includes: Determine the region name corresponding to the IP address of the visitor-related information according to the corresponding relationship between the preset IP address and the region name, and use the determined region name as the visitor attribute; or, Determine the user name corresponding to the IP address of the visitor-related information according to the corresponding relationship between the preset IP address and the user name, and use the determined user name as the visitor attribute.
5. The method according to any one of claims 1 to 4, characterized in that, the determining whether there is a security risk in the session attributes includes: Determine the risk score of the session attribute according to the correspondence between the preset session attribute and the risk score; Judge whether the risk score is greater than a preset threshold; If so, determine that there is a security risk for the session attribute; If not, determine that there is no security risk for the session attribute.
6. The method according to claim 5, wherein, at least two attributes are included in the at least one session, and each attribute has a correspondence between the attribute and the risk score; the determining the risk score of the session attribute according to the correspondence between the preset session attribute and the risk score includes: Determine the correspondence between each attribute in the at least two attributes and the risk score respectively; According to the correspondence between each attribute and the risk score, determine the risk score of the corresponding attribute respectively; Weight the risk scores of the at least two attributes to obtain the risk score of the session attribute.
7. The method according to claim 6, wherein, When each attribute includes visitor attributes, the correspondence between the attribute and the risk score includes: overseas visitors, domestic external network visitors, intranet visitors and their corresponding risk scores; When each attribute includes access behavior attributes, the correspondence between the attribute and the risk score includes: various access frequencies and their corresponding risk scores; When each attribute includes access time attributes, the correspondence between the attribute and the risk score includes: non-working hours, working hours and their corresponding risk scores; When each attribute includes access data attributes, the correspondence between the attribute and the risk score includes: sensitive data, non-sensitive data and their corresponding risk scores; When each attribute includes the accessed asset attributes, the correspondence between the attribute and the risk score includes: various business hosts and their corresponding risk scores.
8. The method according to claim 6, wherein, Before weighting the risk scores of the at least two session attributes, the method further includes: Obtain the scenario type of the current network security event monitoring; Determine the key attention attributes corresponding to the scenario type from the correspondence between the preset scenario type and the key attention attributes; Configure a first weight for the session attributes in the at least two session attributes that are the same as the key attention attributes, and configure a second weight for the session attributes in the at least two session attributes that are different from the key attention attributes, and the first weight is greater than the second weight; The weighting of the risk scores of the at least two session attributes includes: Weight the risk scores of the at least two session attributes based on the first weight and the second weight.
9. The method according to any one of claims 1 to 4, wherein, The generating a network security event based on the at least one session includes: Add all the attributes included in the at least one session to a network security event template to obtain the network security event, and the network security event template is used to describe the network security event by using a preset language framework; After generating a network security event based on the at least one session, the method further includes: Obtain the correspondence between the attribute and the handling suggestion at the reserved position of each attribute in the network security event template; Match each attribute in the at least one session with the corresponding relationship in the network security event template to obtain the handling suggestions for each attribute; Integrate the handling suggestions for each attribute to obtain and output the handling suggestions for the network security event.
10. A generating device for network security events, characterized in that the device includes: an acquisition module, configured to acquire at least one session of the monitored network, where the at least one session is used to represent the interaction process between a visitor and a visited party; an extraction module, configured to extract at least one of a visitor attribute, an access time attribute, an access behavior attribute, an access data attribute, and a visited asset attribute from the at least one session to obtain the session attributes of the at least one session; a judgment module, configured to judge whether there is a security risk in the session attributes; if so, enter the generation module; a generation module, configured to generate a network security event based on the at least one session.
11. An electronic device, characterized in that the electronic device includes: a processor, a memory, and a bus; wherein, the processor and the memory complete communication with each other through the bus; the processor is configured to call program instructions in the memory to execute the method according to any one of claims 1 to 9.
12. A computer-readable storage medium, characterized in that the storage medium includes: a stored program; wherein, when the program runs, it controls the device where the storage medium is located to execute the method according to any one of claims 1 to 9.