Security event handling suggestion generation method and device and electronic equipment

By using historical event databases and feature extraction technology in security incident handling, the most similar treatment suggestions are recommended, which solves the problems of long handling time and low accuracy in the prior art, and improves the efficiency and accuracy of security incident handling.

CN120216566APending Publication Date: 2025-06-27DUXIAOMAN TECH (BEIJING) CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510357067.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-25
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

The prior art requires searching for a large amount of historical data in the handling of security incidents, which leads to long disposal time and inexperienced individuals that find it difficult to quickly analyze and judge, resulting in inaccurate disposal or waste of resources.

Method used

By obtaining event information of security events to be handled, extracting target keywords (such as IP, domain name, attack payload), looking for similar events in the historical event database, performing feature extraction and similarity calculation, and recommending the most similarity handling suggestions.

Benefits of technology

It improves the efficiency and accuracy of handling security incidents, reduces handling time, helps inexperienced personnel to quickly obtain accurate handling suggestions, and avoid waste of resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120216566A_ABST
    Figure CN120216566A_ABST
Patent Text Reader

Abstract

The invention provides a security event handling suggestion generation method and device and electronic equipment, and the method comprises the steps: extracting target keywords such as an IP, a domain name and a payload from a to-be-handled security event, retrieving a reference security event similar to the target keywords from a historical event database, extracting TF-IDF features of the reference security event, and generating the TF-IDF features of the reference security event; and calculating the similarity between the reference security events and the to-be-handled security events based on the features and the target keywords, and selecting the handling suggestion corresponding to the reference security event with the highest similarity as a target handling suggestion to be output. Through an automatic process, multiple times of feature extraction are performed on historical security events, and the similarity between the historical security events and the latest security events is calculated, so that the similarity between the historical security events and the latest security events can be quickly and comprehensively considered in a multi-level manner, and the most similar historical security events can be output; security event handling events are shortened, security event handling efficiency and accuracy are improved, and then security operation efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular, to a method, apparatus, and electronic device for generating security event handling suggestions. Background Art

[0002] Security event handling refers to the process in which an organization or individual takes a series of measures to identify, isolate, investigate, repair, and restore an affected system or network when a security event occurs, while notifying relevant parties, summarizing experience, and strengthening security awareness training to minimize losses, improve security protection levels, and prevent future events from occurring.

[0003] In related technologies, security event handling is usually carried out by using security event cases accumulated in a knowledge base and the experience and expertise of security analysts. However, in this method, relevant personnel need to search for a large amount of historical data when handling events, rely on historical experience to find similar security events, and then make corresponding handling, which consumes a large amount of handling time. Moreover, for inexperienced personnel, due to their lack of historical handling experience, they cannot quickly analyze and judge security events, resulting in inaccurate event handling or the re-handling of events that have been handled before, causing waste of resources. Summary of the Invention

[0004] In view of this, embodiments of the present invention provide a method, apparatus, and electronic device for generating security event handling suggestions to improve the efficiency and accuracy of security event handling.

[0005] According to one aspect of the present invention, there is provided a method for generating security event handling suggestions, the method including:

[0006] Obtain event information of a security event to be handled, where the event information includes target keywords included in the security event to be handled, and the keywords include IP, domain name, and attack payload;

[0007] Based on the event information of the security event to be handled, search for historical security events similar to the target keywords of the security event to be handled in a historical event database as candidate reference events, where the historical event database includes event information of historical security events and event handling methods corresponding to the historical security events;

[0008] Extract features of the keywords of the candidate reference events to obtain reference features of each candidate reference event;

[0009] Calculate the similarity between the security event to be handled and each candidate reference event based on the target keywords and each reference feature;

[0010] Determine the candidate reference event with the highest similarity as the target reference event, and search the historical event database for the event handling method corresponding to the target reference event as the target handling recommendation for recommendation.

[0011] In a possible embodiment, the method further includes: obtaining the event information of the historical security event and the event handling method corresponding to the historical security event;

[0012] Extract keywords from the event information of each historical security event according to a preset keyword to obtain the keywords included in each historical security event;

[0013] Correspondingly store each historical security event identifier, the keywords included in the historical security event, and the event handling method corresponding to the historical security event into a preset database to obtain a historical event database;

[0014] The searching for a historical security event similar to the target keyword of the to-be-disposed security event in the historical event database based on the event information of the to-be-disposed security event includes:

[0015] Search for each target keyword included in the to-be-disposed security event in the historical event database;

[0016] If the target keyword is found, the historical security event corresponding to the event information where the target keyword is found is used as the historical security event similar to the target keyword of the to-be-disposed security event.

[0017] In a possible embodiment, the feature extraction of the keywords of the candidate reference event to obtain the reference features of each candidate reference event includes:

[0018] Perform Jieba word segmentation on the keywords of each candidate reference event to obtain the word segmentation results of each candidate reference event;

[0019] Perform TF-IDF feature extraction on each word segmentation result to obtain the reference features of each candidate reference event.

[0020] In a possible embodiment, the method further includes:

[0021] Obtain the feedback information of the target handling recommendation, where the feedback information is used to represent the acceptance situation of the target handling recommendation;

[0022] Correspondingly store the event information of the to-be-disposed security event, the target handling recommendation, and the feedback information of the target handling recommendation into the historical event database.

[0023] According to another aspect of the present invention, there is provided a security incident handling suggestion generation device, which includes:

[0024] An acquisition module, configured to acquire the event information of the security incident to be handled, where the event information includes the target keywords included in the security incident to be handled, and the keywords include IP, domain name, and attack payload;

[0025] A search module, configured to search for historical security incidents similar to the target keywords of the security incident to be handled in the historical event database based on the event information of the security incident to be handled, as candidate reference events, where the historical event database includes the event information of historical security incidents and the corresponding event handling methods of the historical security incidents;

[0026] An extraction module, configured to perform feature extraction on the keywords of the candidate reference events to obtain the reference features of each candidate reference event;

[0027] A calculation module, configured to calculate the similarity between the security incident to be handled and each candidate reference event based on the target keywords and each reference feature;

[0028] A determination module, configured to determine the candidate reference event with the highest similarity as the target reference event, and search for the event handling method corresponding to the target reference event in the historical event database as the target handling suggestion for recommendation.

[0029] In a possible embodiment, the device further includes:

[0030] A construction module, configured to acquire the event information of historical security incidents and the corresponding event handling methods of the historical security incidents; perform keyword extraction on the event information of each historical security incident according to preset keywords to obtain the keywords included in each historical security incident; store the identifiers of each historical security incident, the keywords included in the historical security incident, and the corresponding event handling methods of the historical security incident in a preset database correspondingly to obtain a historical event database;

[0031] The searching for historical security incidents similar to the target keywords of the security incident to be handled in the historical event database based on the event information of the security incident to be handled includes:

[0032] Searching for each target keyword included in the security incident to be handled in the historical event database;

[0033] If the target keyword is found, the historical security incident corresponding to the event information of the found target keyword is used as the historical security incident similar to the target keyword of the security incident to be handled.

[0034] In a possible embodiment, the feature extraction of the keywords of the candidate reference events to obtain the reference features of each candidate reference event includes:

[0035] Perform Jieba word segmentation on the keywords of each candidate reference event to obtain the word segmentation results of each candidate reference event;

[0036] Perform TF-IDF feature extraction on each word segmentation result to obtain the reference features of each candidate reference event.

[0037] In a possible embodiment, the device further includes:

[0038] A feedback module for obtaining feedback information on the target handling suggestion, where the feedback information is used to represent the acceptance situation of the target handling suggestion;

[0039] Correspondingly store the event information of the security event to be handled, the target handling suggestion, and the feedback information of the target handling suggestion into the historical event database.

[0040] According to another aspect of the present invention, there is provided an electronic device, including:

[0041] A processor; and

[0042] A memory storing a program,

[0043] wherein the program includes instructions that, when executed by the processor, cause the processor to execute the security event handling suggestion generation method described in any one of the above.

[0044] According to another aspect of the present invention, there is provided a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to cause a computer to execute the security event handling suggestion generation method described in any one of the above.

[0045] In one or more technical solutions provided in the embodiments of the present invention, target keywords such as IP, domain name, and payload are extracted from the security event to be handled, reference security events similar to the target keywords are retrieved from the historical event database, TF-IDF features of the reference security events are extracted, and the similarity between the reference security events and the security event to be handled is calculated based on the features and the target keywords. The handling suggestion corresponding to the reference security event with the highest similarity is selected as the target handling suggestion for output. Through an automated process and multiple feature extractions of historical security events and calculation of the similarity with the latest security event, the similarity between the historical security event and the latest security event can be considered quickly, multi-levelly, and comprehensively, which helps to output the most similar historical security event, shorten the security event handling time, improve the security event handling efficiency and accuracy, and thus improve the security operation efficiency. Brief Description of the Drawings

[0046] In the following description of exemplary embodiments with reference to the drawings, more details, features, and advantages of the present invention are disclosed. In the drawings:

[0047] Figure 1 FIG. is a schematic flowchart of a method for generating security incident handling suggestions provided by an embodiment of the present invention;

[0048] Figure 2 FIG. is another schematic flowchart of a method for generating security incident handling suggestions provided by an embodiment of the present invention;

[0049] Figure 3 FIG. is a schematic logical structure diagram of a security incident handling suggestion generation device provided by an embodiment of the present invention;

[0050] Figure 4 FIG. shows a structural block diagram of an exemplary electronic device that can be used to implement the embodiments of the present invention. Detailed Description of the Embodiments

[0051] The embodiments of the present invention will be described in more detail below with reference to the drawings. Although some embodiments of the present invention are shown in the drawings, it should be understood that the present invention can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Instead, these embodiments are provided to more thoroughly and completely understand the present invention. It should be understood that the drawings and embodiments of the present invention are only for exemplary purposes and are not used to limit the protection scope of the present invention.

[0052] It should be understood that the steps recited in the method embodiments of the present invention can be executed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present invention is not limited in this regard.

[0053] As used herein, the term "comprising" and its variations are open-ended, i.e., "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". The relevant definitions of other terms will be given in the following description. It should be noted that the concepts of "first", "second", etc. mentioned in the present invention are only used to distinguish different devices, modules, or units, and are not used to limit the order of the functions executed by these devices, modules, or units or their interdependent relationships.

[0054] It should be noted that the modifiers "one" and "multiple" mentioned in the present invention are illustrative rather than restrictive. Those skilled in the art should understand that unless otherwise clearly specified in the context, it should be understood as "one or more".

[0055] The names of the messages or information exchanged between multiple devices in the embodiments of the present invention are only for illustrative purposes and are not used to limit the scope of these messages or information.

[0056] In order to improve the efficiency and accuracy of security incident handling, embodiments of the present invention provide a method, device, electronic device, and storage medium for generating security incident handling suggestions. The method for generating security incident handling suggestions provided by the embodiments of the present invention can be applied to any electronic device with the function of generating security incident handling suggestions. The electronic device can be a server, computer, mobile terminal, etc. The solution of the present invention will be described below with reference to the accompanying drawings:

[0057] As Figure 1 shown, Figure 1 is a schematic flowchart of a method for generating security incident handling suggestions provided by an embodiment of the present invention, which may include the following steps:

[0058] S101. Obtain the event information of the security incident to be handled, where the event information includes the target keywords included in the security incident to be handled, and the keywords include IP, domain name, and attack payload;

[0059] S102. Based on the event information of the security incident to be handled, search for historical security incidents similar to the target keywords of the security incident to be handled in the historical event database as candidate reference events. Among them, the historical event database includes the event information of historical security incidents and the corresponding event handling methods of the historical security incidents;

[0060] S103. Extract the features of the keywords of the candidate reference events to obtain the reference features of each candidate reference event;

[0061] S104. Calculate the similarity between the security incident to be handled and each candidate reference event based on the target keywords and each reference feature;

[0062] S105. Determine the candidate reference event with the highest similarity as the target reference event, and search for the corresponding event handling method of the target reference event in the historical event database as the target handling suggestion for recommendation.

[0063] Applying the embodiments of the present invention, target keywords such as IP, domain name, payload, etc. are extracted from the security events to be processed. Reference security events similar to the target keywords are retrieved from the historical event database, the TF-IDF features of the reference security events are extracted, and the similarity between the reference security events and the security events to be processed is calculated based on the features and the target keywords. The handling suggestions corresponding to the reference security event with the highest similarity are selected as the target handling suggestions for output. Through an automated process and multiple feature extractions of historical security events and calculation of the similarity with the latest security event, the similarity between the historical security event and the latest security event can be considered quickly, multi-levelly, and comprehensively, which helps to output the most similar historical security event, shorten the handling time of security events, improve the handling efficiency and accuracy of security events, and thus improve the security operation efficiency.

[0064] The following is an exemplary description of the above S101-S105:

[0065] A security event refers to an alarm event generated during the network security monitoring process. In a possible embodiment, the running status of a cluster can be monitored through cluster monitoring tools such as Prometheus and Nagios Core, and the alarm events generated in the cluster can be recorded. Correspondingly, the security events to be processed can be obtained through the preset interface of the monitoring tool or the database where the monitoring tool stores the alarm data. As another possible implementation, the alarm data can be obtained through system logs as the security events to be processed.

[0066] After obtaining the security events to be processed, the target keywords included in the security events to be processed can be extracted. As a possible implementation, since the corresponding information is usually stored in fixed fields in the alarm data, keyword fields can be preset, and the target keywords of the alarm data can be extracted from the preset keyword fields of the alarm data. The above preset keywords can be set according to the actual application scenario. Exemplarily, the keywords can include IP, domain name, url (Uniform Resource Locator), user, time, payload (payload), etc. Among them, the IP can include the source IP and the destination IP. The source IP refers to the Internet protocol address of the source device that triggers the alarm event. Through the source IP, the source location of the request and the possible network range can be initially judged, which helps to trace and locate the source of the problem. The destination IP is the IP address of the target device targeted by the alarm event. The domain name is a hierarchical network identifier corresponding to the IP address, usually used to identify the location of a website, server, or other network services. The URL is used to completely describe the address of a web page or other resources on the Internet. The user can refer to the user information corresponding to the request that triggers the alarm. The payload is the data content transmitted to the recipient. In the alarm data, the payload contains key contents such as specific attack information, abnormal data, or error details.

[0067] In a possible embodiment, the above keywords may further include the rule name for triggering the alarm basis. In practical applications, it is necessary to determine whether to trigger an alarm event based on a preset rule, and the rule may include data thresholds, access objects, access time periods, and so on. Exemplarily, the above data threshold may trigger an alarm when the indicator or measured point data value of the asset reaches or exceeds a preset threshold.

[0068] After extracting the target keywords of the security event to be disposed of, similar historical security events to the target keywords can be searched in a preset historical event database. The above historical event database is generated in advance according to historical security events that have occurred and corresponding disposal methods. Specifically, it is obtained by formatting historical security events and importing them into the database.

[0069] As a possible implementation manner, the event information of the historical security event and the event disposal method corresponding to the historical security event can be obtained; keyword extraction is performed on the event information of each historical security event according to a preset keyword to obtain the keywords included in each historical security event, and the historical security event identifier, the keywords included in the historical security event, and the event disposal method corresponding to the historical security event are stored in a preset database in a corresponding manner to obtain a historical event database.

[0070] The keyword extraction method of the historical security event is the same as that of the security event to be disposed of, which will not be elaborated here. The above historical security event identifier may be the number, name, etc. of the historical security event, and the disposal method corresponding to the historical security event may include multiple operations, such as expansion, adding to the blacklist, etc. When storing, the full amount of disposal operations corresponding to the historical security event can be stored corresponding to the historical security event.

[0071] In a possible embodiment, each target keyword can be searched in the historical event database. If there is a keyword of a historical security event that includes the full amount of target keywords, it can be determined that the historical security event whose keyword includes the full amount of target keywords is a reference security event. Exemplarily, each keyword of each historical security event can be traversed in the historical event database, and each target keyword can be searched in turn in the keywords of each historical security event. If all target keywords are found, this historical security event can be retained as a reference security event.

[0072] In a possible embodiment, if there is no historical security event that contains all the target keywords, historical security events that contain a number of target keywords exceeding a preset threshold may be retained as reference security events. The threshold may be 80%, 90%, etc. Exemplarily, if the number of target keyword groups is 5, historical security events that contain four or more groups of target keywords may be retained as reference security events. Herein, one group of target keywords corresponds to the same keyword type, which includes the aforementioned IP, domain name, url, user, time, payload, etc.

[0073] In practical applications, there may be multiple such reference security events, and the similarities between each reference security event and the security event to be handled may be further compared. In a possible embodiment, feature extraction may be performed on the reference security events and the security event to be handled, and the similarity between the security event to be handled and the reference security events may be calculated based on the extracted text features. The above-mentioned text features may be extracted through a natural language understanding (NLP) network.

[0074] In a possible embodiment, Jieba word segmentation may be performed on the keywords of each of the candidate reference events to obtain the word segmentation results of each of the candidate reference events; for each of the word segmentation results, TF-IDF (Term Frequency-Inverse Document Frequency) feature extraction is performed to obtain the reference features of each of the candidate reference events.

[0075] Among them, Jieba word segmentation is a word segmentation tool that can perform word segmentation on target keywords based on a preset word list. Specifically, it can implement efficient word graph scanning based on a prefix dictionary to generate a directed acyclic graph (DAG) composed of all possible word formation situations of Chinese characters in a sentence, and then find the maximum probability path through dynamic programming to find the maximum segmentation combination based on word frequency. For words not present in the word list, an HMM model based on the word formation ability of Chinese characters is adopted, and the Viterbi algorithm is used for decoding to obtain the word segmentation result.

[0076] TF-IDF consists of two parts: term frequency and inverse document frequency. Among them, term frequency refers to the frequency of a certain word appearing in a specific document, which represents the ratio of the number of times a certain word appears in the document to the total number of words in the document. A higher term frequency means that the word is more important in the document, but only considering term frequency may ignore the importance of common words. Inverse document frequency is a factor used to weaken the importance of common words (such as "de", "shi", etc.). That is, if a word appears in many documents, then this word may not be discriminatory; on the contrary, if a word only appears in a few documents, then this word may be more unique and discriminatory. IDF usually takes a logarithmic form to avoid too small values.

[0077] In a possible embodiment, for each word segmentation result t, the frequency of occurrence of the word segmentation result t in the keywords d of each historical security event in the historical event database can be calculated to obtain the term frequency TF(t, d) of the word segmentation result t. For each word segmentation result t, the number of historical security events nt that contain t in the historical security events can be determined, and the IDF value of t can be calculated through IDF(t) = log(N / (1 + nt)). For each word segmentation result t, multiplying its TF and IDF can obtain the TF-IDF value of the word segmentation result. The TF-IDF values of the word segmentation results included in the reference security event and the TF-IDF features constituting the reference security event are referred to.

[0078] After that, the similarity between the TF-IDF features of the security event to be handled and the TF-IDF features of the reference security event can be calculated. This similarity can be the cosine distance, Euclidean distance, etc. The reference security event with the highest similarity to the security event to be handled among each reference security event is the target reference event that needs to be referred to when handling the security event to be handled.

[0079] Based on the identifier of the target reference event, the corresponding target handling suggestion can be obtained from the historical event database and output, so that relevant personnel can refer to the target handling suggestion to handle the security event to be handled.

[0080] In a possible embodiment, after outputting the target handling suggestion, the feedback information of the target handling suggestion can be obtained. The feedback information is used to represent the acceptance situation of the target handling suggestion; the event information of the security event to be handled, the target handling suggestion, and the feedback information of the target handling suggestion are stored in the historical event database in correspondence.

[0081] As a possible implementation manner, the final handling method of the security event to be handled can be obtained, and it can be determined whether the actual handling method is consistent with the target handling suggestion. If they are consistent, the security event to be handled and the target handling suggestion can be stored in the historical event database in correspondence. If they are not consistent, it can be determined that the target handling suggestion is inaccurate. Therefore, the security event to be handled and the actual handling method can be stored in the historical event database in correspondence.

[0082] In a possible embodiment, if the security event to be handled and the target handling suggestion already exist in the historical event database, the count can be increased in the corresponding storage record to increase the association strength between the security event and the target handling suggestion.

[0083] As a possible implementation, the above-mentioned security event handling recommendation generation method can be implemented as a big data model, which can include an input layer, a calculation layer, and an output layer. The input layer is used to accept the input of the security event to be handled. The calculation layer is used to extract keywords from the security event to be handled, find target keywords in the historical event database to determine reference security events, extract the features of the reference security events, and determine target reference events. The output layer is used to output the target handling recommendations corresponding to the target reference events.

[0084] As Figure 2 shown, Figure 2 FIG. is another flowchart of the security event handling recommendation generation method provided by the embodiment of the present invention, which may specifically include the following processes:

[0085] Pre-store historical security events in a database to obtain a historical security event database. Specifically, historical alarms and the corresponding handling recommendations for the historical alarms can be correspondingly stored in a preset database to obtain a historical security event database. After obtaining the latest security event, extract keywords such as the IP, domain name, Payload, submitting user, generation time, and the name of the preset rule based on which the latest security event is generated from the latest security event, and extract the features of each historical security event stored in the historical security event database, and match the keywords of the latest security event with the features in the historical security event database to obtain multiple historical security events.

[0086] Perform Jieba word segmentation and TF-IDF feature extraction on the multiple historical security events to obtain the reference features of the historical security events, calculate the similarity between the historical security events and the latest security event based on the reference features and the keywords of the latest security event, and determine the historical security event with the highest similarity to the latest security event as the reference security event, and output the handling recommendation corresponding to the reference security event as the most suitable security handling recommendation.

[0087] Applying the embodiment of the present invention, summarize all historical security events and import them into the database, extract keywords such as IP, domain name, url, user, time, payload, etc. from the new security event, and retrieve the security events containing all the keywords from the database. Finally, perform a similarity comparison analysis on these historical security events and the new security event to obtain the most similar historical security event, and extract and output the historical handling recommendation and features. By means of an automated process, the problems of long time, low efficiency, and low accuracy in handling security events by security engineers are solved, thereby improving the security operation efficiency. And by performing multiple feature extractions on historical security events and calculating the similarity with the latest security event, the similarity between the historical security event and the latest security event is considered more comprehensively and multi-levelly, which helps to output the most similar historical security event and further improve the accuracy of security event handling.

[0088] Based on the same inventive concept, an embodiment of the present invention further provides a device for generating security event handling suggestions, as Figure 3 shown. The device 300 may include:

[0089] An acquisition module 301, configured to acquire event information of a security event to be handled, where the event information includes target keywords included in the security event to be handled, and the keywords include IP, domain name, and attack payload;

[0090] A search module 302, configured to search for historical security events similar to the target keywords of the security event to be handled in a historical event database as candidate reference events, where the historical event database includes event information of historical security events and event handling methods corresponding to the historical security events;

[0091] An extraction module 303, configured to perform feature extraction on the keywords of the candidate reference events to obtain reference features of each candidate reference event;

[0092] A calculation module 304, configured to calculate the similarity between the security event to be handled and each candidate reference event based on the target keywords and each reference feature;

[0093] A determination module 305, configured to determine the candidate reference event with the highest similarity as the target reference event, and search for the event handling method corresponding to the target reference event in the historical event database as the target handling suggestion for recommendation.

[0094] In a possible embodiment, the device further includes:

[0095] A construction module, configured to acquire event information of historical security events and event handling methods corresponding to the historical security events; perform keyword extraction on the event information of each historical security event according to a preset keyword to obtain keywords included in each historical security event; and store the historical security event identifiers, keywords included in the historical security events, and event handling methods corresponding to the historical security events in a preset database in a corresponding manner to obtain a historical event database;

[0096] The searching for historical security events similar to the target keywords of the security event to be handled in the historical event database includes:

[0097] Searching for each target keyword included in the security event to be handled in the historical event database;

[0098] If the target keyword is found, the historical security event corresponding to the event information of finding the target keyword is used as the historical security event similar to the target keyword of the to-be-disposed security event.

[0099] In a possible embodiment, the feature extraction of the keywords of the candidate reference events to obtain the reference features of each candidate reference event includes:

[0100] Perform Jieba word segmentation on the keywords of each candidate reference event to obtain the word segmentation results of each candidate reference event;

[0101] Perform TF-IDF feature extraction on each word segmentation result to obtain the reference features of each candidate reference event.

[0102] In a possible embodiment, the device further includes:

[0103] A feedback module, configured to obtain feedback information of the target handling suggestion, where the feedback information is used to represent the acceptance situation of the target handling suggestion;

[0104] Correspondingly store the event information of the to-be-disposed security event, the target handling suggestion, and the feedback information of the target handling suggestion into the historical event database.

[0105] Wherein, in the present invention, the collection, storage, use, processing, transmission, provision, and disclosure of user personal information comply with the provisions of relevant laws and regulations and do not violate public order and good customs.

[0106] An exemplary embodiment of the present invention further provides an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor. The memory stores a computer program that can be executed by the at least one processor, and when the computer program is executed by the at least one processor, it is used to cause the electronic device to execute the method according to the embodiment of the present invention.

[0107] An exemplary embodiment of the present invention further provides a non-transitory computer-readable storage medium storing a computer program, wherein when the computer program is executed by a processor of a computer, it is used to cause the computer to execute the method according to the embodiment of the present invention.

[0108] An exemplary embodiment of the present invention further provides a computer program product, including a computer program, wherein when the computer program is executed by a processor of a computer, it is used to cause the computer to execute the method according to the embodiment of the present invention.

[0109] Reference Figure 4, a structural block diagram of an electronic device 400 that can be a server or a client of the present invention will now be described. It is an example of a hardware device that can be applied to various aspects of the present invention. The electronic device is intended to represent various forms of digital electronic computer devices, such as, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, personal digital processors, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.

[0110] As Figure 4 shown, the electronic device 400 includes a computing unit 401, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 402 or a computer program loaded from a storage unit 408 into a random access memory (RAM) 403. In the RAM 403, various programs and data required for the operation of the electronic device 400 can also be stored. The computing unit 401, the ROM 402, and the RAM 403 are connected to each other through a bus 404. An input / output (I / O) interface 405 is also connected to the bus 404.

[0111] A plurality of components in the electronic device 400 are connected to the I / O interface 405, including: an input unit 406, an output unit 407, a storage unit 408, and a communication unit 409. The input unit 406 can be any type of device that can input information into the electronic device 400. The input unit 406 can receive input digital or character information, and generate key signal inputs related to the user settings and / or function controls of the electronic device. The output unit 407 can be any type of device that can present information, and can include but is not limited to a display, a speaker, a video / audio output terminal, a vibrator, and / or a printer. The storage unit 408 can include but is not limited to a magnetic disk, an optical disk. The communication unit 409 allows the electronic device 400 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks, and can include but is not limited to a modem, a network card, an infrared communication device, a wireless communication transceiver, and / or a chipset, such as a BluetoothTM device, a WiFi device, a WiMax device, a cellular communication device, and / or the like.

[0112] The computing unit 401 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 401 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 401 executes the various methods and processes described above. For example, in some embodiments, any of the above-described security event handling recommendation generation methods can be implemented as a computer software program, which is tangibly contained in a machine-readable medium, such as the storage unit 408. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 400 via the ROM 402 and / or the communication unit 409. In some embodiments, the computing unit 401 can be configured to execute any of the above-described security event handling recommendation generation methods in any other suitable manner (e.g., by means of firmware).

[0113] The program code for implementing the method of the present invention can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the program code is executed by the processor or controller, the functions / operations specified in the flowchart and / or block diagram are implemented. The program code can be executed entirely on the machine, partially on the machine, as a stand-alone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0114] In the context of the present invention, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0115] As used in this invention, the terms "machine-readable medium" and "computer-readable medium" refer to any computer program product, apparatus, and / or device (e.g., magnetic disks, optical disks, memory, programmable logic devices (PLDs)) for providing machine instructions and / or data to a programmable processor, including a machine-readable medium that receives machine instructions as a machine-readable signal. The term "machine-readable signal" refers to any signal for providing machine instructions and / or data to a programmable processor.

[0116] For providing interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, speech input, or tactile input).

[0117] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), and the Internet.

[0118] A computer system can include clients and servers. The clients and servers are generally remote from each other and typically interact through a communication network. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship to each other.

Claims

1. A method for generating security incident handling suggestions, characterized in that: The method comprises: Acquire event information of the security event to be handled, wherein the event information includes target keywords contained in the security event to be handled, and the keywords include IP, domain name, and attack payload; Based on the event information of the security event to be handled, searching in a historical event database for historical security events that are similar to the target keyword of the security event to be handled as candidate reference events, wherein the historical event database includes event information of historical security events and event handling methods corresponding to the historical security events; Extracting features from keywords of the candidate reference events to obtain reference features of each candidate reference event; Calculate the similarity between the security event to be handled and each candidate reference event based on the target keyword and each reference feature; The candidate reference event with the highest similarity is determined as the target reference event, and the event handling method corresponding to the target reference event is searched from the historical event database for recommendation as a target handling suggestion.

2. The method according to claim 1, characterized in that The method further comprises: Obtaining event information of historical security events and event handling methods corresponding to the historical security events; Perform keyword extraction on the event information of each of the historical security events according to preset keywords to obtain the keywords contained in each of the historical security events; The historical security event identifiers, the keywords included in the historical security events, and the event handling methods corresponding to the historical security events are stored in a preset database to obtain a historical event database; The searching, based on the event information of the security event to be handled, in a historical event database for a historical security event that is similar to a target keyword of the security event to be handled comprises: Searching the historical event database for each target keyword included in the security event to be handled; If the target keyword is found, the historical security event corresponding to the event information of the target keyword is taken as a historical security event similar to the target keyword of the security event to be handled.

3. The method according to claim 1, characterized in that: The step of extracting features from the keywords of the candidate reference events to obtain reference features of each of the candidate reference events includes: Perform Jieba word segmentation on the keywords of each candidate reference event to obtain the word segmentation results of each candidate reference event; TF-IDF feature extraction is performed on each of the word segmentation results to obtain reference features of each of the candidate reference events.

4. The method according to claim 1, characterized in that: The method further comprises: Acquiring feedback information of the target disposal suggestion, wherein the feedback information is used to indicate acceptance of the target disposal suggestion; The event information of the security event to be handled, the target handling suggestion and the feedback information of the target handling suggestion are correspondingly stored in the historical event database.

5. A device for generating security incident handling suggestions, characterized in that: The device comprises: An acquisition module is used to acquire event information of the security event to be handled, wherein the event information includes target keywords contained in the security event to be handled, wherein the keywords include IP, domain name, and attack payload; A search module, used to search a historical event database for historical security events similar to a target keyword of the security event to be handled based on the event information of the security event to be handled, as candidate reference events, wherein the historical event database includes event information of historical security events and event handling methods corresponding to the historical security events; An extraction module, used for extracting features from keywords of the candidate reference events to obtain reference features of each candidate reference event; A calculation module, used for calculating the similarity between the security event to be handled and each candidate reference event based on the target keyword and each reference feature; The determination module is used to determine the candidate reference event with the highest similarity as the target reference event, and to search the historical event database for the event handling method corresponding to the target reference event as a target handling suggestion for recommendation.

6. The device according to claim 5, characterized in that The device also includes: A construction module is used to obtain event information of historical security events and event handling methods corresponding to the historical security events; perform keyword extraction on the event information of each of the historical security events according to preset keywords to obtain the keywords contained in each of the historical security events; store the identifiers of each of the historical security events, the keywords contained in the historical security events, and the event handling methods corresponding to the historical security events in a preset database to obtain a historical event database; The searching, based on the event information of the security event to be handled, in a historical event database for a historical security event that is similar to a target keyword of the security event to be handled comprises: Searching the historical event database for each target keyword included in the security event to be handled; If the target keyword is found, the historical security event corresponding to the event information of the target keyword is taken as a historical security event similar to the target keyword of the security event to be handled.

7. The device according to claim 5, characterized in that The step of extracting features from the keywords of the candidate reference events to obtain reference features of each of the candidate reference events includes: Perform Jieba word segmentation on the keywords of each candidate reference event to obtain the word segmentation results of each candidate reference event; TF-IDF feature extraction is performed on each of the word segmentation results to obtain reference features of each of the candidate reference events.

8. The device according to claim 5, characterized in that The device also includes: A feedback module, used for obtaining feedback information of the target disposal suggestion, wherein the feedback information is used for indicating the acceptance of the target disposal suggestion; The event information of the security event to be handled, the target handling suggestion and the feedback information of the target handling suggestion are correspondingly stored in the historical event database.

9. An electronic device, comprising: processor; as well as Memory for storing programs, The program includes instructions, which, when executed by the processor, cause the processor to perform the method according to any one of claims 1 to 4.

10. A non-transitory computer-readable storage medium storing computer instructions, wherein: The computer instructions are used to make a computer execute the method according to any one of claims 1-4.

Citation Information

Cited By

  • Engineering experience reuse method and equipment for database migration and medium

    CN122220324A

  • A database migration engineering experience reuse method, device and medium

    CN122220324B