Multi-source log association fusion method, system and device based on safety behavior semantic analysis and medium
Through the multi-source log association fusion method based on security behavior semantic analysis, the BERT model and custom attributes are used for log processing and association, which solves the problems of missing and understanding of multi-source log information, and improves the traceability and response capabilities of security incidents.
Patent Information
- Application Number
- CN202510236487.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-28
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2045-02-28
AI Technical Summary
When handling multi-source heterogeneous security logs, existing network security protection systems have problems such as missing log information, difficult to understand, large number of logs, and difficult to mine effective information, making it difficult to accurately judge threats and respond quickly.
The multi-source log association fusion method based on semantic analysis of security behavior is adopted, and the key attributes of the log text are obtained through the BERT basic model, and the custom log basic attributes and semantic descriptive attributes are used for preliminary association and deep semantic mapping, a deep semantic information association diagram is constructed, and a security event description is generated through cluster analysis and semantic fusion features.
It effectively solves the problems of missing log information and understanding, improves log correlation analysis capabilities, helps quickly discover potential security threats, accurately trace incidents, and improves the efficiency of detection and analysis of complex network attacks.
Smart Images

Figure FT_1 
Figure FT_2 
Figure SMS_1
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of multi-source log correlation analysis in industrial Internet, and particularly relates to a multi-source log correlation and fusion method, system, device and medium based on security behavior semantic analysis. Background Art
[0002] With the rapid development of informatization and intelligence, the Internet has deeply penetrated into all fields of social production and life. While bringing convenience to people, it also brings huge security risks. For example, the MOVEit Transfer data breach incident in 2023 led to 2,706 organizations being attacked by ransomware, and the personal data of more than 93 million people was leaked, exposing the deficiencies in current network security protection.
[0003] To improve the security protection ability of information systems, security devices such as firewalls, intrusion detection systems, and intrusion prevention systems are generally deployed in enterprise networks, and a network security situation awareness platform is used to aggregate a large amount of security logs to achieve real-time security situation awareness and protection of the system network. However, with the increasing complexity of network scenarios and the diversification of security devices, security logs exhibit the following characteristics: huge data volume, wide sources, high heterogeneity, and high false alarm rate. This makes it extremely difficult to quickly discover potential real security threats from the logs.
[0004] To address this problem, a large number of studies have attempted to perform automated analysis of logs through machine learning and deep learning techniques, mainly focusing on log parsing, anomaly detection, and log compression. However, the existing methods still face the following two major challenges: 1. Log information is missing and difficult to understand: The alarm logs generated by security devices usually depend on specific network environments and hierarchies, lack context information, and do not comprehensively describe network events, resulting in difficulty for staff to accurately judge threats and poor interpretability.
[0005] 2. The number of logs is huge and it is difficult to mine effective information: During the analysis and tracing of security events, staff need to perform correlation analysis on multi-source heterogeneous security logs. However, the types of logs are numerous and the semantic differences are significant. Even experienced engineers need to spend a lot of time to filter out effective logs and complete the correlation analysis.
[0006] Therefore, there is an urgent need to study a fusion representation method for multi-source heterogeneous security logs to improve the semantic correlation analysis ability of massive log data, achieve accurate tracing and rapid response to security events, and further enhance the security protection ability of the system. Summary of the Invention
[0007] The object of the present invention is to provide a multi-source log association and fusion method, system, device and medium based on security behavior semantic analysis, which solves the defects of existing network security protection, such as missing log information, being difficult to understand, a large number of logs, and being difficult to mine effective information.
[0008] To achieve the above object, the technical solution adopted by the present invention is: A multi-source log association and fusion method based on security behavior semantic analysis provided by the present invention includes the following steps: Step 1, taking the obtained original multi-source host logs as the input of a pre-constructed BERT base model to obtain the attributes corresponding to each log text; Step 2, using custom log basic attributes to initially associate the original multi-source host logs, and constructing an initial association relationship graph corresponding to the original multi-source host log text; Mapping the original multi-source host log text using custom log semantic descriptive attributes to obtain a deep semantic attribute space; Step 3, constructing a deep semantic information association graph using the obtained initial association relationship graph and deep semantic attribute space; Step 4, performing clustering analysis on the obtained deep semantic information association graph to obtain multiple sub-communities; Step 5, performing semantic fusion features on the obtained multiple sub-communities to obtain a security event description corresponding to the original multi-source host logs.
[0009] Preferably, the construction method of the BERT base model: Constructing an initial BERT base model; Performing word segmentation and annotation on the obtained original multi-source host logs to obtain an annotated data set; Using the obtained annotated data set to optimize the initial BERT base model to obtain an optimized BERT base model.
[0010] Preferably, the method for performing word segmentation and annotation on the obtained original multi-source host logs to obtain an annotated data set is as follows: Performing word segmentation on each log text in the obtained original multi-source host logs according to spaces; Using the BIO annotation format to annotate each word segmentation obtained, where the annotation categories include template static words and variable parameters, and the variable parameters include object ID, position identifier, object name, type identifier, switch indicator, duration of action, computing resources, number of objects, status code, others, where the position identifier includes source IP, source port, destination IP, destination port and file path; the object name is the user name; Combine the original words of the template static words and the class names of the variable parameters to obtain an annotated data set.
[0011] Preferably, use the custom log basic attributes to preliminarily correlate the original multi-source host logs, and construct a preliminary correlation relationship graph corresponding to the original multi-source host logs. The specific method is as follows: The custom log basic attributes obtained are the core fields used to identify and describe the key information in the logs in security behavior analysis, and this attribute has unique identification and can reflect the basic characteristics of the log records; Use the intersection of the basic attributes of security behaviors between logs to preliminarily correlate the original multi-source host logs, and obtain a preliminary correlation relationship graph corresponding to the original multi-source host logs.
[0012] Preferably, use the custom log semantic descriptive attributes to map the original multi-source host log texts to obtain a deep semantic attribute space. The specific method is as follows: The custom log semantic descriptive attributes obtained are the attributes with natural language characteristics in the original multi-source host logs, and the descriptions of the same event vary due to the different sources of the original multi-source host logs; Based on the custom semantic descriptive attributes, map the original multi-source security logs to obtain a deep semantic attribute space.
[0013] Preferably, the nodes of the deep semantic information correlation graph are the sets of log texts with the same log semantic descriptive attributes in the deep semantic attribute space; the edges of the deep semantic information correlation graph are the basic attribute correlation relationships between the log texts included in the two deep semantic nodes, and the weight of the edge of the deep semantic information correlation graph is the number of basic attribute correlation relationships.
[0014] Preferably, perform semantic fusion features on the obtained multiple sub-communities to obtain a security event description corresponding to the original multi-source host logs. The specific method is as follows: Based on the hint design method of the ICIO framework, perform semantic fusion features on the obtained multiple sub-communities to obtain the result of the correlation fusion of the original multi-source host logs and the corresponding security event description.
[0015] A multi-source log correlation fusion system based on security behavior semantic analysis includes: A log attribute acquisition unit, which is used to take the obtained original multi-source host logs as the input of a pre-constructed BERT basic model to obtain the attributes corresponding to each log text; A correlation relationship graph construction unit, which is used to use the custom log basic attributes to preliminarily correlate the original multi-source host logs and construct a preliminary correlation relationship graph corresponding to the original multi-source host log texts; Meanwhile, it is used to map the original multi-source host log text by using the descriptive attributes of custom log semantics to obtain a deep semantic attribute space; An association graph construction unit is used to construct a deep semantic information association graph by using the obtained preliminary association graph and deep semantic attribute space; A clustering analysis unit is used to perform clustering analysis on the obtained deep semantic information association graph to obtain multiple sub-communities; A semantic fusion unit is used to perform semantic fusion features on the obtained multiple sub-communities to obtain a security event description corresponding to the original multi-source host log.
[0016] A computer-readable storage medium storing one or more programs, characterized in that the one or more programs include instructions that, when executed by a computing device, cause the computing device to execute the method according to any one of claims 1 to 7.
[0017] A computing device, comprising: One or more processors, a memory, and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, and the one or more programs include steps for executing the method.
[0018] Compared with the prior art, the beneficial effects of the present invention are: A multi-source log association and fusion method based on security behavior semantic analysis provided by the present invention obtains the key attributes corresponding to each log text in the original multi-source host log through the BERT base model, and then uses the custom log base attributes and log semantic descriptive attributes to process the original multi-source host log in combination with the attributes corresponding to each log text, constructs the association relationship of the original multi-source host log files, and mines deep semantic associations, solving the problem of missing log information in existing network security protection; performing semantic fusion features on the obtained multiple sub-communities, and finally generating a log fusion representation describing the same security behavior, solving the defects of existing network security protection that are difficult to understand, have a large number of logs, and are difficult to mine effective information; the present invention not only effectively solves the problems of information loss and semantic understanding difficulties in multi-source heterogeneous logs, but also significantly improves the log association analysis ability, helps staff quickly discover potential security threats, accurately trace events, and greatly improves the detection and judgment efficiency of complex network attacks. Description of the Drawings
[0019] Figure 1 It is the overall flowchart of the multi-source log association and fusion method based on security behavior semantic analysis of the present invention; Figure 2 It is the annotation result of the original multi-source host log with the auth log as an example. Detailed implementation manners
[0020] In the following description, for the purpose of illustration rather than limitation, specific details such as specific system architectures, technologies, etc. are presented to provide a thorough understanding of the embodiments of the present application. However, those skilled in the art should understand that the present application can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid unnecessary details from interfering with the description of the present application.
[0021] Embodiment 1 Figure 1 The overall flowchart of the multi-source log association and fusion method based on security behavior semantic analysis proposed for this embodiment shows the basic framework of the multi-source log association analysis in the industrial Internet of Things scenario.
[0022] A multi-source log association and fusion method based on security behavior semantic analysis provided in this embodiment includes the following steps: Step 1: Segment and label the obtained original multi-source host logs to obtain a labeled data set; In order to train a model that can identify the word segmentation categories of the original multi-source host logs (the word segmentation categories include various types of template static words and variable parameters), it is first necessary to perform word segmentation and labeling on the original multi-source host log data. The purpose of word segmentation is to divide the log text into multiple independent words according to spaces to prepare for subsequent labeling.
[0023] After completing the word segmentation, it is necessary to label the word segmentation results. The goal of labeling is to classify the segmented log words according to their semantic categories, and the categories include various types of template static words and variable parameters. The template static words represent the fixed structure part in the log, while the variable parameters represent the dynamically changing information. By labeling the log content, a high-quality labeled data set can be generated for subsequent model training.
[0024] To achieve accurate annotation, this embodiment refers to the definition of variable parameter types in "Did We Miss Something Important? Studying and Exploring Variable-Aware Log Abstraction" (in this embodiment, variable parameters are divided into 10 categories, including object ID, location identifier, object name, type identifier, switch indicator, duration of action, computing resources, number of objects, status code, others, and based on the analysis requirements of the network attack and defense scenario, combined with the security behavior semantic information in the original multi-source host logs, the original type definition is adjusted. Different from the original category division, in this embodiment, two of the categories, "location indicator" and "object name", are re-divided into 6 sub-categories, as specifically shown in the following table: Table 1 Classification of Variable Parameter Types in Original Multi-Source Host Logs
[0025] Based on the type definition of the above log word segmentation, the BIO format is used to annotate the category of each word segmentation. As Figure 2 shown, taking the auth log "Disconnected from username Jerrold.reddick 10.0.254.202 port 37198" as an example, the type of each word segmentation is annotated: The username Jerrold.reddick is annotated with the category B- <username>; The IP address 10.0.254.202 is labeled as category B- <sip>(Source IP); The port number 37198 is marked with category B- <sport>(source port).
[0026] The remaining word segmentation annotation categories are <o>(Template static words).
[0027] Based on the above annotation rules, by combining the original words of the template static words and the class names of the variable parameters, the log content is further converted into a log template: Disconnected from username B- <username> B- <sip>port B- <sport>。Thus, an accurate labeled dataset is obtained.
[0028] Step 2: Use the obtained original multi-source host logs as the input of the pre-built BERT base model to obtain the attributes corresponding to each log text.
[0029] Construct an initial BERT base model; use the labeled dataset obtained in Step 1 to optimize the initial BERT base model to obtain an optimized BERT base model. Specifically: Model architecture: The core structure of this initial BERT base model consists of multiple layers of Transformer encoders, which can capture the context semantic features of the input text. On this basis, a linear classifier layer is added to classify the labels of characters or words at each position to adapt to the named entity recognition task. This architecture can efficiently identify static words and variable parameter types from log texts and provide support for subsequent behavior semantic analysis.
[0030] Loss function and optimizer: To evaluate the difference between the model prediction results and the true labels, the cross-entropy loss function is selected as the objective function during the training process. Cross-entropy loss can effectively handle multi-classification problems and ensure the prediction accuracy of the model for different class labels. In terms of the optimizer, this embodiment uses the AdamW optimizer, which combines the weight decay mechanism and is more suitable for the training of deep learning models compared to the traditional Adam optimizer. In addition, to improve the training effect of the model, a learning rate scheduler is introduced to dynamically adjust the learning rate during the training process to accelerate the convergence of the model and avoid falling into local optima.
[0031] Model training: In the model training stage, the mini-batch gradient descent method is used to efficiently train the large-scale multi-source log data. To avoid the problem of gradient explosion, a gradient clipping strategy is introduced during the training process to limit the maximum norm of the gradient, thereby ensuring the stability of the model. The specific training process is as follows: Forward propagation: Input the batch of multi-source log data into the model. After passing through the BERT encoder and the linear classifier, the predicted labels at each position are generated.
[0032] Loss calculation: Calculate the value of the cross-entropy loss function according to the predicted labels and the true labels.
[0033] Backward propagation: Calculate the gradient using the loss function value and update the model parameters through backward propagation.
[0034] Parameter optimization: Use the AdamW optimizer to update the model weights, and at the same time dynamically adjust the learning rate through the learning rate scheduler.
[0035] Log Parsing and Structuring: The trained and fine-tuned model has the ability to efficiently parse log texts. In the application stage, this model is used to parse the obtained original multi-source host logs. The parsing results are shown in the following table, and the category to which each token belongs (i.e., source IP, source port, username in the table) can be obtained. Then, the categories of template static words and variable parameters are combined to generate a log template. Each field in the table is an attribute corresponding to each original log text in the original multi-source host logs.
[0036] Table 2 Example of the Result of Parsing Unstructured Logs into Structured Data
[0037] Through this log parsing method based on behavioral semantic understanding, not only the automated processing of complex log information is realized, but also unified structured data support is provided for subsequent security behavior analysis.
[0038] Step 3: Use the custom log basic attributes to preliminarily associate the original multi-source host logs, and construct a preliminary association relationship graph corresponding to the original multi-source host log texts.
[0039] First, in order to construct the association between multi-source logs, custom log basic attributes are defined first, that is: log basic attributes refer to the core fields used to identify and describe key information in logs during security behavior analysis. These attributes include but are not limited to timestamp, hostname, host IP, process PID, service name, source IP, destination IP, source port, and destination port, etc. The above attributes have unique identification and can reflect the basic characteristics of log records, providing basic support for the analysis and determination of security behaviors.
[0040] For logs triggered by the same security event, their basic attributes must be the same. For example, an SSH connection failure behavior may be recorded in multiple security logs, but the basic attributes of these logs (such as hostname, timestamp, source IP, source port, etc.) must be the same.
[0041] Secondly, in this embodiment, the intersection of the basic attributes of security behaviors between logs is first used to preliminarily associate the original multi-source host logs, and a preliminary association relationship graph corresponding to the original multi-source host logs is obtained.
[0042] Step 4: Use the obtained preliminary association relationship graph and the deep semantic attribute space to construct a deep semantic information association graph First, customize the semantic descriptive attributes of the logs. The semantic descriptive attributes of the logs refer to the attributes with natural language characteristics such as log templates and attack types in the original multi-source host logs. Different from the basic attributes of the logs, such attributes will have significant differences in the description of the same event due to different original log sources. Although these attributes are of great value to the staff in analyzing the logs, due to their complex and diverse semantics, they are difficult to be directly understood by machines. Therefore, the attributes that are crucial for log analysis but difficult for machine processing are defined as deep semantic information.
[0043] In order to accurately identify security events and achieve efficient traceability, in this embodiment, the original multi-source security logs are mapped based on the customized semantic description attributes to obtain a deep semantic attribute space.
[0044] A deep semantic information association graph is constructed by using the deep semantic attribute space and the preliminary association relationship graph. Among them, the nodes of the graph represent the set of log texts with the same log semantic descriptive attributes in the deep semantic attribute space, the edges represent the basic attribute association relationships between the log texts included in the two deep semantic nodes, and the weights of the edges represent the number of basic attribute association relationships, which are used to measure the strength of the association between different deep semantic information.
[0045] On the basis of constructing the deep semantic information association graph, the Louvain graph clustering algorithm is used to cluster and partition the association graph to obtain multiple sub-communities. This algorithm divides the deep semantics with strong relevance into the same community, identifying the set of logs describing the same type of security behavior. For example, in an SSH scanning behavior, the network alarm log may be recorded as "suspected port scanning behavior", while the original multi-source host log may be recorded as "multiple SSH login failures". By constructing the deep semantic association graph and performing clustering analysis, when these events are divided into the same sub-community, it can be inferred that the attacker's behavior at this time is SSH port scanning combined with brute-force cracking attack.
[0046] In this way, this embodiment realizes the association and unified modeling of heterogeneous security logs from different sources in the deep semantic dimension. This cross-semantic association reveals the potential behavior logic behind security events, helping to more comprehensively understand complex security events. For example, the combination of network layer logs and host layer logs can completely restore the attacker's behavior chain, and the joint analysis of multi-source logs improves the accuracy and efficiency of abnormal behavior recognition, thus providing strong support for the detection and traceability of complex network security events.
[0047] Step 5: Perform semantic fusion features on the obtained multiple sub-communities to obtain the result of the association and fusion of the original multi-source host logs and the corresponding security event descriptions.
[0048] Based on log correlation, to achieve deep semantic fusion of correlated logs and generate a unified security event description, this embodiment adopts a prompt design method based on the ICIO framework. This method can effectively generate high-quality and task-oriented results through clear task guidance and structured input and output requirements. The specific prompt content is as follows: Instruction: Design a comprehensive label for a set of cross-source log data to ensure that the label concisely and accurately summarizes the essence of the security event they jointly indicate.
[0049] Background information: In the field of security operations, integrating and analyzing diverse log data from network alerts and host activity records is crucial for timely identifying potential threats and unifying event descriptions. By comprehensively evaluating and refining concise and accurate event labels, the speed and accuracy of security responses can be significantly improved, ensuring rapid understanding and effective response to complex security situations.
[0050] Supplementary data: A series of correlated log data sets, covering network alerts, raw multi-source host logs, and user operation records. Specific examples include, but are not limited to, specific alert signatures such as "ET POLICY Reserved Internal IPTraffic" and raw multi-source host log templates such as "pam_unix(cron:session): session opened for user <obn>by (uid=0)”。
[0051] Output format: Simplicity: The generated tags need to be concise, with the number of characters limited to 10 to 15; Accuracy: Ensure that the tags accurately reflect the core security events and behavioral characteristics revealed by the log set; Event orientation: The tags should directly point to the event characteristics, such as "Abnormal traffic monitoring", "Probing activities", or "Potential data leakage", so as to clearly convey the essence of the security event.
[0052] Through this hint design method based on the ICIO framework, this embodiment realizes the deep semantic fusion of multi-source logs and successfully generates accurate and unified security event descriptions. This method not only improves the efficiency of security event analysis but also enhances the accuracy of security event tracing and response.
[0053] Embodiment 2 A multi-source log association and fusion system based on security behavior semantic analysis provided in this embodiment includes: A log attribute acquisition unit for using the obtained original multi-source host logs as the input of a pre-constructed BERT base model to obtain the attributes corresponding to each log text; An association relationship graph construction unit for using custom log basic attributes to initially associate the original multi-source host logs and constructing an initial association relationship graph corresponding to the original multi-source host log text; At the same time, for using custom log semantic descriptive attributes to map the original multi-source host log text to obtain a deep semantic attribute space; An association graph construction unit for using the obtained initial association relationship graph and deep semantic attribute space to construct a deep semantic information association graph; A clustering analysis unit for performing clustering analysis on the obtained deep semantic information association graph to obtain multiple sub-communities; A semantic fusion unit for performing semantic fusion features on the obtained multiple sub-communities to obtain a security event description corresponding to the original multi-source host logs.
[0054] Embodiment 3 This embodiment also provides a storage medium, specifically a computer-readable storage medium (Memory). The computer-readable storage medium is a memory device in a terminal device and is used to store programs and data. It can be understood that the computer-readable storage medium here can include both the built-in storage medium in the terminal device and, of course, the extended storage medium supported by the terminal device. The computer-readable storage medium provides a storage space, and this storage space stores the operating system of the terminal. Moreover, one or more instructions suitable for being loaded and executed by a processor are stored in this storage space, and these instructions can be one or more computer programs (including program codes). It should be noted that the computer-readable storage medium here can be a high-speed RAM memory or a non-volatile memory (Non-Volatile Memory), such as at least one disk memory.
[0055] One or more instructions stored in the computer-readable storage medium can be loaded and executed by a processor to implement the corresponding steps of the method in the above embodiment; one or more instructions in the computer-readable storage medium are loaded and executed by the processor to perform the method.
[0056] Embodiment 4 A computing device provided in this embodiment, the terminal device includes a processor and a memory. The memory is used to store a computer program, and the computer program includes program instructions. The processor is used to execute the program instructions stored in the computer storage medium. The processor may be a central processing unit (Central Processing Unit, CPU), or may also be other general-purpose processors, digital signal processors (Digital Signal Processor, DSP), application specific integrated circuits (Application Specific Integrated Circuit, ASIC), field-programmable gate arrays (Field-Programmable Gate Array, FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. It is the computing core and control core of the terminal, and is suitable for implementing one or more instructions. Specifically, it is suitable for loading and executing one or more instructions to implement the corresponding method flow or corresponding function; the processor described in this embodiment can be used for the operations of the method.
[0057] The above-described embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included within the protection scope of the present application.< / obn> < / sport> < / sip> < / username> < / o> < / sport> < / sip> < / username>
Claims
1. A multi-source log association fusion method based on security behavior semantic analysis, characterized in that: The following steps are involved: Step 1: Use the original multi-source host logs obtained as input to the pre-built BERT basic model to obtain the attributes corresponding to each log text; Step 2: Use the custom log basic attributes to perform preliminary correlation on the original multi-source host logs, and construct a preliminary correlation relationship graph corresponding to the original multi-source host log texts; The original multi-source host log text is mapped using custom log semantic descriptive attributes to obtain a deep semantic attribute space; Step 3, constructing a deep semantic information association graph using the obtained preliminary association relationship graph and the deep semantic attribute space; Step 4: cluster analysis is performed on the obtained deep semantic information association graph to obtain multiple sub-communities; Step 5: semantically fuse the obtained multiple sub-communities to obtain the security event description corresponding to the original multi-source host log.
2. According to the multi-source log association fusion method based on security behavior semantic analysis according to claim 1, it is characterized in that: The construction method of BERT basic model: Build the initial BERT base model; Segment and annotate the original multi-source host logs to obtain an annotated data set; The initial BERT basic model is optimized using the obtained labeled data set to obtain an optimized BERT basic model.
3. According to the multi-source log association fusion method based on security behavior semantic analysis according to claim 1, it is characterized in that: The original multi-source host logs are segmented and annotated to obtain an annotated data set. The specific method is: Each log text in the obtained original multi-source host log is segmented according to the space; Each obtained word segment is annotated using the BIO annotation format, where the annotated categories include template static words and variable parameters, where the variable parameters include object ID, location identifier, object name, type identifier, switch indicator, duration of action, computing resources, number of objects, status code, and others, where the location identifier includes source IP, source port, destination IP, destination port, and file path; the object name is the user name; The original words of the template static words and the category names of the variable parameters are combined to obtain the labeled data set.
4. According to the multi-source log association fusion method based on security behavior semantic analysis according to claim 1, it is characterized in that: The original multi-source host logs are initially correlated using the custom log basic attributes to construct a preliminary correlation diagram corresponding to the original multi-source host logs. The specific method is: The customized basic log attribute is the core field used to identify and describe key information in the log in security behavior analysis. The attribute is unique and can reflect the basic characteristics of the log record. The original multi-source host logs are initially correlated using the intersection of the basic attributes of security behaviors between logs, and a preliminary correlation diagram corresponding to the original multi-source host logs is obtained.
5. According to the multi-source log association fusion method based on security behavior semantic analysis according to claim 1, it is characterized in that: The original multi-source host log text is mapped using custom log semantic descriptive attributes to obtain a deep semantic attribute space. The specific method is: The log semantic descriptive attributes obtained by customization are attributes with natural language characteristics in the original multi-source host logs, and the descriptions of the same events by the attributes differ due to the different sources of the original multi-source host logs. Based on the customized semantic description attributes, the original multi-source security logs are mapped and processed to obtain a deep semantic attribute space.
6. According to the multi-source log association fusion method based on security behavior semantic analysis according to claim 1, it is characterized in that: The nodes of the deep semantic information association graph are sets of log texts with the same log semantic descriptive attributes in the deep semantic attribute space; the edges of the deep semantic information association graph are the basic attribute association relationships between the log texts contained in two deep semantic nodes, and the weight of the edges of the deep semantic information association graph is the number of basic attribute association relationships.
7. According to claim 1, a multi-source log association fusion method based on security behavior semantic analysis is characterized in that: The obtained multiple sub-communities are semantically fused to obtain the security event description corresponding to the original multi-source host logs. The specific method is: Based on the prompt design method of ICIO framework, the semantic features of multiple sub-communities are obtained to obtain the results of the original multi-source host log association fusion and the corresponding security event description.
8. A multi-source log association fusion system based on security behavior semantic analysis, characterized in that: include: A log attribute acquisition unit, used to use the acquired original multi-source host logs as input to the pre-built BERT basic model to obtain the attributes corresponding to each log text; A correlation diagram construction unit is used to perform preliminary correlation on the original multi-source host logs by using the custom log basic attributes, and construct a preliminary correlation diagram corresponding to the original multi-source host log texts; At the same time, it is used to map the original multi-source host log text using the custom log semantic descriptive attributes to obtain a deep semantic attribute space; An association graph construction unit, used to construct a deep semantic information association graph using the obtained preliminary association relationship graph and the deep semantic attribute space; A cluster analysis unit is used to perform cluster analysis on the obtained deep semantic information association graph to obtain multiple sub-communities; The semantic fusion unit is used to perform semantic fusion features on the obtained multiple sub-communities to obtain the security event description corresponding to the original multi-source host logs.
9. A computer-readable storage medium storing one or more programs, characterized in that: The one or more programs include instructions, which, when executed by a computing device, cause the computing device to perform the method of any one of claims 1 to 7.
10. A computing device, characterized in that include: One or more processors, a memory and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, and the one or more programs include steps for executing the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Automatic test method and system based on Internet of Things terminal evaluation platform
CN112039907A
Full-scene network security threat association analysis method and system
CN117478403A
Fusion risk analysis method, system and device for multi-source security logs and medium
CN119106437A
APT detection method based on semantic enhancement and attention mechanism
CN119272277A
APT anomaly detection method fusing dual-channel GNN thought
CN119341795A
Cited By
AI behavior sequence analysis-driven weblog attack chain automatic tracing method
CN121508955A
Network log attack chain automatic tracing method driven by ai behavior sequence analysis
CN121508955B