Network security alarm intelligent analysis and decision recommendation method and system
Through custom alarm rules, related Internet intelligence and historical data analysis, intelligent monitoring suggestions are generated, which solves the problems of insufficient alarm context analysis capabilities and high manual dependence in existing network security alarm monitoring systems, and achieves efficient and accurate network security alarm processing.
Patent Information
- Application Number
- CN202510165589.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-14
- Publication Date
- 2025-06-17
AI Technical Summary
The existing network security alarm monitoring system has problems such as insufficient ability to analyze alarm context, high artificial dependence, delayed response and lack of adaptability, making it difficult to effectively deal with rapidly evolving attack methods.
Provide an intelligent analysis and decision-making recommendation method for network security alarms. Through custom alarm rules, related Internet intelligence and historical data analysis, intelligent monitoring suggestions are generated to improve the efficiency and accuracy of alarm processing.
It realizes intelligent processing of network security alarms, improves the pertinence and effectiveness of monitoring, reduces the need for manual intervention, and improves the ability to understand the alarm context and the efficiency of security incident handling.
Smart Images

Figure CN120165902A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security alarm monitoring and analysis, and particularly to an intelligent analysis and decision-making recommendation method for network security alarms. Background Art
[0002] With the rapid development of information technology, network security has become one of the core issues of global concern. In the past few decades, the means and complexity of network attacks have increased significantly. From early single virus infections to today's advanced persistent threats (APTs), attackers' strategies show a trend of diversification and intelligence. To cope with the increasingly complex network threats, traditional network security monitoring systems have gradually developed from rule-based static monitoring to dynamic analysis and intelligent processing. Currently, mainstream network security monitoring technologies mostly rely on means such as log analysis, anomaly detection, and protocol parsing to identify potential threats through preset rules and feature library matching. These technologies show high reliability in dealing with conventional attacks, but in the face of rapidly evolving attack means, especially zero-day vulnerability attacks and advanced penetration tests, their response capabilities and accuracy are still severely challenged.
[0003] The existing network security alarm monitoring systems mainly have the following deficiencies: the limitations of static rule detection. The current alarm systems highly rely on preset rules and feature libraries, and these rules often lag behind the update of attack means and cannot cope with new attacks. Attackers bypass detection through means such as obfuscation, encryption, and camouflage, resulting in frequent false alarms and missed alarms in the system. Lack of correlation analysis ability. Traditional systems only process single alarm information and fail to effectively integrate multi-dimensional data such as asset information, geographical information, and threat intelligence, restricting the in-depth analysis of alarm context. Dependence on manual intervention. Due to the low level of system intelligence, a large number of false alarms need to be screened manually, increasing the workload of professionals. Especially in high-traffic environments, it is easy to cause response delays and affect the timely handling of security incidents. Lack of adaptability. Existing systems generally lack the ability to dynamically adjust rules and optimize detection strategies and cannot adjust their own algorithms according to the real-time threat environment, resulting in a decline in long-term protection ability. Summary of the Invention
[0004] In view of the above problems, the present invention is proposed.
[0005] Therefore, the technical problem solved by the present invention is: the existing network security alarm monitoring method has insufficient ability to analyze alarm context, high dependence on manual labor, response delay, and how to optimize the intelligent and efficient network alarm processing.
[0006] To solve the above technical problems, the present invention provides the following technical solutions: A method for intelligent analysis and decision-making recommendation of network security alerts, including customizing alert rules and performing a first detection on alert features; associating Internet intelligence and performing a first analysis on alert data; generating alert monitoring recommendation suggestions based on historical alert monitoring analysis data.
[0007] As a preferred solution of the method for intelligent analysis and decision-making recommendation of network security alerts according to the present invention, wherein: the customizing alert rules include selecting and matching alert fields.
[0008] As a preferred solution of the method for intelligent analysis and decision-making recommendation of network security alerts according to the present invention, wherein: the performing a first detection on alert features includes detecting alert features through rules.
[0009] As a preferred solution of the method for intelligent analysis and decision-making recommendation of network security alerts according to the present invention, wherein: the associating Internet intelligence includes matching attack geographical location information.
[0010] As a preferred solution of the method for intelligent analysis and decision-making recommendation of network security alerts according to the present invention, wherein: the associating Internet intelligence further includes matching known tags.
[0011] As a preferred solution of the method for intelligent analysis and decision-making recommendation of network security alerts according to the present invention, wherein: the performing a first analysis on alert data includes training an alert data model.
[0012] As a preferred solution of the method for intelligent analysis and decision-making recommendation of network security alerts according to the present invention, wherein: the generating alert monitoring recommendation suggestions based on historical alert monitoring analysis data includes alert data of intelligent monitoring suggestions.
[0013] Another object of the present invention is to provide a system for intelligent analysis and decision-making recommendation of network security alerts, which can perform multi-dimensional correlation analysis on the received alert data through a data analysis module, and solves the problems of lack of context correlation and low response efficiency of current alert information.
[0014] As a preferred solution of the system for intelligent analysis and decision-making recommendation of network security alerts according to the present invention, wherein: it includes a feature detection module, a data analysis module, and an intelligent suggestion recommendation module; the feature detection module is used to customize alert rules and perform a first detection on alert features; the data analysis module is used to associate Internet intelligence and perform a first analysis on alert data; the intelligent suggestion recommendation module is used to generate alert monitoring recommendation suggestions based on historical alert monitoring analysis data.
[0015] A computer device includes a memory and a processor. The memory stores a computer program. It is characterized in that when the processor executes the computer program, the steps of the intelligent analysis and decision recommendation method for network security alerts are implemented.
[0016] A computer-readable storage medium stores a computer program thereon. It is characterized in that when the computer program is executed by a processor, the steps of the intelligent analysis and decision recommendation method for network security alerts are implemented.
[0017] Advantages of the present invention: The intelligent analysis and decision recommendation method for network security alerts provided by the present invention allows the security team to customize monitoring rules according to specific requirements and environments, can quickly adapt to newly emerging threats and attack methods, improve the pertinence and effectiveness of monitoring. The customized rules can quickly generate alert monitoring suggestions, help the security team identify and respond to potential threats in a timely manner, reduce response time and potential losses. By associating multi-dimensional information such as assets, geographical locations, and threat intelligence, the context understanding ability of alerts is improved. Through automated alert analysis and recommendation, the overall efficiency of security incident handling is improved, automatically conduct research and analysis, provide specific disposal suggestions, improve the processing efficiency and accuracy of alert information. The present invention achieves better results in terms of effectiveness, understanding ability, and processing efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for the description of the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts. Among them:
[0019] Figure 1 It is the overall flowchart of an intelligent analysis and decision recommendation method for network security alerts provided by the first and second embodiments of the present invention.
[0020] Figure 2 It is the customized rule alert monitoring diagram of an intelligent analysis and decision recommendation method for network security alerts provided by the first and second embodiments of the present invention.
[0021] Figure 3 It is the intelligent monitoring and analysis diagram of alert information of an intelligent analysis and decision recommendation method for network security alerts provided by the first and second embodiments of the present invention.
[0022] Figure 4 It is the alert correlation analysis and intelligent recommendation diagram of an intelligent analysis and decision recommendation method for network security alerts provided by the first and second embodiments of the present invention.
[0023] Figure 5 This is the overall module diagram of an intelligent analysis and decision-making recommendation system for network security alerts provided by the fourth embodiment of the present invention. Detailed implementation manners
[0024] To make the above objects, features, and advantages of the present invention more obvious and understandable, the following will describe the detailed implementation manners of the present invention with reference to the accompanying drawings of the specification. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0025] Embodiment 1
[0026] Refer to Figures 1 - 4 , which is an embodiment of the present invention, and provides an intelligent analysis and decision-making recommendation method for network security alerts, including:
[0027] S1: Customize alert rules and perform a first detection on alert features.
[0028] Furthermore, customizing alert rules includes selecting matching alert fields.
[0029] It should be noted that users can configure rules through a visual interface. For example, they can select and match fields such as the source IP address of the attack, the target IP address, the port, the attack method, and the original message. The matching methods of the rules support various forms, including JSON format, regular expression (RegEx), specific value ranges or intervals, etc. The diverse matching means enable the rules to cover more potential attack patterns, improving the adaptability of the system. It also supports users to upload and online edit Python scripts. When users need to deeply analyze the attack messages of a specific IP segment, they can write scripts to complete operations such as Base64 decoding or URL decoding, extract key information from the messages. For alerts with the source IP of the 3.4.0.0 / 16 network segment, the Python script uploaded by the user is automatically called to decode and analyze the original attack message to ensure the accuracy of the alert information.
[0030] Furthermore, performing a first detection on alert features includes detecting alert features through rules.
[0031] In the embodiment of the present application, the first detection is an intelligent detection of alarm features driven by rules. When an alarm is generated, the alarm data is standardized. The alarm data is sequentially matched with the static rules in the rule library. For example, when the attack source IP is 192.168.4.3 and the attack method is SQL injection, the rule identifies and generates corresponding monitoring suggestions. For the alarm data that cannot be fully covered by the rules, the matching Python script is called to complete in-depth detection. For example, the original attack packet with the alarm source IP of 3.4.5.6 is decoded, and malicious code instructions are identified. The system integrates the detection results with the corresponding monitoring suggestions to form the final alarm output.
[0032] In an alternative embodiment, the first detection can also be implemented in other ways. For example, dynamic alarm feature detection based on behavior modeling continuously collects traffic data and alarm logs in the network, and uses unsupervised learning algorithms in machine learning to classify traffic patterns to form different types of behavior baseline models. Key attributes such as the access frequency of various devices, source IP addresses, access targets, and communication protocols are recorded in the models.
[0033] When new alarm data arrives, the alarm features are compared with the existing behavior models, the anomaly score is calculated, and hidden threats in the traffic are detected, such as stealth attacks based on small traffic or gradually increasing scanning behaviors.
[0034] If the deviation of the alarm data from the historical behavior pattern exceeds the threshold, an alarm is automatically triggered, corresponding suggestions are given, and the new abnormal traffic features are automatically incorporated into the model to further optimize the detection accuracy.
[0035] S2: Associate Internet intelligence and perform a first analysis on the alarm data.
[0036] Furthermore, associating Internet intelligence includes matching attack geographical location information.
[0037] It should be noted that after the alarm occurs, first, multi-dimensional asset association analysis is performed on the alarm information. For example, when it is found that the attack source IP is 3.4.5.6, the asset information of the internal network host under attack is automatically matched, including asset name, affiliated department, person in charge, operation and maintenance person in charge, and contact information. Through these associations, the security team can quickly locate the specific object under attack and its business importance, shorten the alarm handling time, and perform geographical information matching on the attack source IP, such as identifying its source as a certain country or region. Combining geographical information with Internet threat intelligence, such as IP operators, attack tools, attacker analysis, etc., can more comprehensively reveal the attack background.
[0038] Furthermore, associating Internet intelligence also includes matching known tags.
[0039] It should be noted that for alarm information, custom label matching is supported. For example, specific IPs can be marked as Internet penetration testing or filing scanning, making the classification of alarms more explicit. Multidimensional correlation analysis enhances the context understanding ability of alarms, enabling the security team to more comprehensively judge the severity and potential impact of threats.
[0040] Furthermore, the first analysis of alarm data includes training the alarm data model.
[0041] In the embodiment of the present application, the first analysis uses historical alarm data and feature information to train using decision tree models such as random forest and XGBoost to generate an alarm monitoring recommendation dataset. When a new alarm arrives, feature analysis is performed based on the model and recommendations are generated, including the credibility score of the attack behavior and the disposal priority. For example, for an alarm with a credibility score of 60 points, it is marked as a priority object for manual review. Compared with traditional alarm systems, the present invention reduces the need for manual intervention through intelligent recommendations and automated analysis, improving the accuracy and efficiency of alarm disposal.
[0042] In an alternative embodiment, the first analysis can also be implemented in other ways. For example, multi-dimensional correlation alarm analysis based on a knowledge graph collects and analyzes network device information, asset information, and Internet threat intelligence, constructs nodes and relationships, and updates the knowledge graph in real time to ensure that the latest threat intelligence and asset changes can be quickly reflected in the graph;
[0043] Whenever a new alarm is triggered, nodes associated with the alarm features will be searched in the knowledge graph, and the possible attack paths or known vulnerabilities involved will be traced, automatically associating alarm information from different sources, such as an IP accessing different ports multiple times or abnormal scanning behaviors of multiple subnets, and comprehensive analysis will be performed;
[0044] According to the correlation depth of the knowledge graph and the alarm features, the threat level is dynamically generated, and corresponding disposal suggestions are given. For example, if the IP involved in the alarm appears multiple times in overseas APT attack records, it is recommended to immediately block or restrict access. For alarms that cannot be matched in the existing knowledge graph, they are automatically marked as unknown risks, and relevant nodes and relationships are supplemented through manual review afterwards to gradually improve the graph data.
[0045] Embodiment 2
[0046] Refer to Figures 1 - 4 , which is an embodiment of the present invention, provides a method for intelligent analysis and decision recommendation of network security alarms, including:
[0047] S3: Generate alarm monitoring recommendation suggestions based on historical alarm monitoring analysis data.
[0048] Further, the alarm monitoring recommendation suggestions generated based on the historical alarm monitoring analysis data include alarm data with intelligent monitoring suggestions.
[0049] It should be noted that by using historical alarm data and feature information, decision tree models such as random forest and XGBoost are used for training to generate an alarm monitoring recommendation data set. When a new alarm arrives, feature analysis is performed based on the model and suggestions are generated, including the credibility score of the attack behavior and the disposal priority. For example, for an alarm with a credibility score of 60 points, it is marked as a priority object for manual review. Compared with the traditional alarm system, the present invention reduces the need for manual intervention through intelligent recommendation and automated analysis, and improves the accuracy and efficiency of alarm disposal.
[0050] Embodiment 3
[0051] An embodiment of the present invention provides a method for intelligent analysis and decision recommendation of network security alarms. In order to verify the beneficial effects of the present invention, scientific demonstration is carried out through economic benefit calculation and simulation experiments.
[0052] Custom rules are configured in the system. The rule is that for an alarm with the source IP of the attack being 192.168.4.3, the target IP of the attack being 192.168.5.29, and the attack method being SQL injection attack, the automatically supplemented monitoring suggestion is that the normal business of the system has been verified and it belongs to a false alarm. When the security device alarms that 192.168.4.3 launches an SQL injection attack on 192.168.5.29, the system alarm monitoring shows that the normal business of the system has been verified and it belongs to a false alarm.
[0053] Python script detection is added to the system. For an alarm with the source IP of the attack being in the 3.4.0.0 / 16 network segment, the Python script content is to decode the original attack message of the alarm, and support decoding operations after Base64 decoding and URL encoding. When the security device alarms that an IP in the 3.4.0.0 / 16 network segment generates an alarm, the system will automatically call the Python script to implement the decoding of the Base64 content and the content after URL encoding of the original attack message.
[0054] The security device detected an alarm that the source IP of an attack, 3.4.5.6, initiated a port scan on the host with the internal network IP 192.168.43.3. The system matched the host with the internal network asset 192.168.43.3, supplemented the asset information, and performed a geographical information match on the alarm source IP 3.4.5.6, identifying the geographical origin as the United States. The external network attack source IP address was associated with Internet intelligence information, including geo (latitude and longitude information), whois, IP domain name, operator, attack behavior, attack type, attack source, attack tool, attacker analysis, threat level, and attack threat labels, such as phishing, malware, and botnet. The alarm of the alarm source IP 3.4.5.6 for the internal network 192.168.43.3 was matched with tags and classified as an overseas attack alarm. The alarm monitoring and recommendation analysis was performed on the alarm of the alarm source IP 3.4.5.6 for the internal network 192.168.43.3, and the intelligent monitoring recommendation analysis feedback was that a port scan was detected on an overseas IP, and it was recommended to block it as soon as possible.
[0055] The newly received alarm "Source IP: 220.25.6.7 initiated a host port scan on the internal network IP: 192.168.114.13" was sent, and the alarm data information of "Source IP: 220.25.6.7 initiated a host port scan on the internal network IP: 192.168.114.13" was pushed to the intelligent monitoring recommendation analysis. The random forest decision tree dataset decision and the XGboost decision tree dataset decision were used to perform model detection on the alarm features, generating alarm monitoring recommendations, such as: "Block the attack source IP: 220.25.6.7, with a credibility of 60 points". The system automatically screened out the alarm monitoring recommendation values lower than 70 points. After manual marking, the "Source IP: 220.25.6.7 initiated a host port scan on the internal network IP: 192.168.114.13" was pushed to the intelligent monitoring recommendation analysis for training again to generate a model dataset. When the next alarm of "Source IP: 220.25.6.7 initiated a host port scan on the internal network IP: 192.168.114.113" occurred, the intelligent monitoring recommendation analysis would recommend: "Block the attack source IP: 220.25.6.7, with a credibility of 89 points".
[0056] Embodiment 4
[0057] Refer to Figure 5 , which is an embodiment of the present invention, provides a network security alarm intelligent analysis and decision recommendation system, including: a feature detection module, a data analysis module, and an intelligent recommendation module.
[0058] The feature detection module is used to customize the alarm rules and perform the first detection on the alarm features; the data analysis module is used to correlate with Internet intelligence and perform the first analysis on the alarm data; the intelligent recommendation module is used to generate alarm monitoring recommendation suggestions according to the historical alarm monitoring analysis data.
[0059] If a function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods of the various embodiments of the present invention. The foregoing storage medium includes: USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs and other various media that can store program codes.
[0060] The logic and / or steps represented in the flowchart or described in other ways herein, for example, can be considered as a definite sequence list of executable instructions for implementing logical functions, and can be specifically implemented in any computer-readable medium for use by an instruction execution system, apparatus, or device (such as a computer-based system, a system including a processor, or other systems that can fetch instructions from the instruction execution system, apparatus, or device and execute the instructions), or in combination with these instruction execution systems, apparatus, or devices. For the purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device.
[0061] More specific examples (non-exhaustive list) of computer-readable media include the following: an electrical connection part with one or more wirings (electronic device), a portable computer disk case (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disc read-only memory (CDROM). In addition, the computer-readable medium can even be paper or other suitable media on which a program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other media, then editing, interpreting, or processing it in other suitable ways if necessary, and then storing it in the computer memory.
[0062] It should be understood that the various parts of the present invention can be implemented by hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, any one or a combination of the following techniques well known in the art can be used: discrete logic circuits having logic gate circuits for implementing logical functions on data signals, application specific integrated circuits having appropriate combinational logic gate circuits, programmable gate arrays (PGAs), field programmable gate arrays (FPGAs), and the like. It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered by the scope of the claims of the present invention.
[0063] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered by the scope of the claims of the present invention.
Claims
1. A network security alarm intelligent analysis and decision recommendation method, characterized in that: include: Customize alarm rules to perform the first detection of alarm features; Correlate Internet intelligence and conduct the first analysis of the alarm data; Generate alarm monitoring recommendations based on historical alarm monitoring analysis data.
2. The network security warning intelligent analysis and decision recommendation method according to claim 1, characterized in that: The custom alarm rule includes selecting a matching alarm field.
3. The network security warning intelligent analysis and decision recommendation method according to claim 2, characterized in that: The first detecting of the alarm feature includes detecting the alarm feature through a rule.
4. The network security warning intelligent analysis and decision recommendation method according to claim 3, characterized in that: The associated Internet intelligence includes matching attack geographic location information.
5. The network security warning intelligent analysis and decision recommendation method according to claim 4, characterized in that: The associated Internet intelligence also includes matching known tags.
6. The network security warning intelligent analysis and decision recommendation method according to claim 5, characterized in that: The first analyzing of the alarm data includes training an alarm data model.
7. The network security warning intelligent analysis and decision recommendation method according to claim 6, characterized in that: The generation of alarm monitoring recommendations based on historical alarm monitoring analysis data includes alarm data of intelligent monitoring recommendations.
8. A system using the network security alarm intelligent analysis and decision recommendation method according to any one of claims 1 to 7, characterized in that: Including feature detection module, data analysis module, and intelligent suggestion recommendation module; The feature detection module is used to customize alarm rules and perform a first detection on the alarm feature; The data analysis module is used to associate Internet intelligence and perform a first analysis on the alarm data; The intelligent suggestion recommendation module is used to generate alarm monitoring recommendation suggestions based on historical alarm monitoring analysis data.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the network security alarm intelligent analysis and decision recommendation method described in any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the network security alarm intelligent analysis and decision recommendation method described in any one of claims 1 to 7 are implemented.