Security detection method and device and information generation method and device

By deploying security detection methods and devices in a cloud computing environment, analyzing user behavior data in real time and matching detection rules, the problem of user abnormal operation detection in cloud computing is solved, and a rapid response to security threats to the cloud computing environment is achieved.

CN120223343APending Publication Date: 2025-06-27HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410382033.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-12-26
Filing Date
2024-03-28
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

In cloud computing scenarios, how to effectively detect and prevent users from performing abnormal operations with security risks, such as attackers installing malicious code or users who do not have permissions to create and delete computing instances.

Method used

A security detection method and device are provided, by obtaining security detection events triggered by a user terminal, analyzing user behavior data, and matching them with predefined detection rules. If the user behavior data matches any detection rule, it is determined that the operation is abnormal and sends security alert information to the relevant user.

Benefits of technology

Real-time security detection of user behavior is realized, and it can quickly and accurately identify and respond to potential security threats, improving the security of the cloud computing environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223343A_ABST
    Figure CN120223343A_ABST
Patent Text Reader

Abstract

The invention provides a security detection method and device and an information generation method and device, which are used for performing security detection on user behaviors in a cloud computing scene. The security detection device obtains a security detection event triggered by the user terminal, the security detection event is used for requesting security detection on a first operation, and the first operation is an operation executed by a first user on the cloud service through the user terminal; determining user behavior data according to the security detection event; if the user behavior data is matched with at least one detection rule in a detection rule set corresponding to the cloud service, determining that the first operation is an unsafe operation with an abnormal behavior, the detection rules in the detection rule set being used for representing the abnormal behavior of the user; and sending the security alarm information to the second user. The security detection device can judge whether the operation of the user is the non-security operation or not in real time in a mode of matching the user behavior data with the detection rule, so that the security detection can be quickly and accurately performed on the user behavior.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims the priority of a Chinese patent application with the application number 202311824984.0 and the application title "An Abnormal Behavior Detection Method and Device" filed with the National Intellectual Property Administration of the People's Republic of China on December 26, 2023, the entire content of which is incorporated herein by reference. Technical Field

[0002] This application relates to the field of cloud security technology, and in particular, to a security detection, information generation method and device. Background Art

[0003] Cloud computing is a type of distributed computing, which means that through the network "cloud", huge data computing programs are decomposed into countless small programs, and then these small programs are processed and analyzed by a system composed of multiple servers, and the results are returned to users (including enterprise users and individual users).

[0004] With the continuous development of cloud computing, more and more cloud services will be deployed in cloud computing systems. Users can directly obtain the required cloud services with corresponding software functions from the cloud computing system based on the service level agreement through the network. However, in the cloud computing scenario, during the process of users invoking cloud services, they may perform some abnormal operations with security risks (such as attackers (or moles) invoking application programming interfaces (APIs) to install malicious code, and users without permission creating, deleting, etc. computing instances in cloud computing). Therefore, in the cloud computing scenario, how to perform security detection on user behavior has become a problem to be solved. Summary of the Invention

[0005] This application provides a security detection, information generation method and device for performing security detection on user behavior in the cloud computing scenario.

[0006] In a first aspect, an embodiment of the present application provides a security detection method, which can be executed by a security detection device. The security detection device can be deployed in a computing device or in a cluster composed of multiple computing devices. The security detection device obtains a security detection event triggered by a user terminal. The security detection event is used to request a security detection of a first operation. The first operation is an operation performed by a first user on a cloud service through the user terminal. The security detection device determines user behavior data according to the security detection event. The user behavior data characterizes the behavior of the first user performing the first operation. If the user behavior data matches at least one detection rule in the detection rule set corresponding to the cloud service, the security detection device determines that the first operation is a non-secure operation with abnormal behavior. The detection rule set includes multiple detection rules, and each detection rule is used to characterize the abnormal behavior of the user. The security detection device sends a security warning message to a second user.

[0007] Through the above method, when the security detection device obtains a security detection event triggered by the user terminal, it can perform real-time analysis on the security detection event, analyze the user behavior data of the first operation that triggers the security detection event, and by matching the user behavior data with the detection rules, it can determine in real time whether the user's operation is a non-secure operation, so as to quickly and accurately perform security detection on the user behavior.

[0008] In a possible implementation manner, the security detection device extracts behavioral features from the event content corresponding to the security detection event to obtain at least one behavioral information of the first user. The security detection device respectively performs format conversion on each behavioral information to obtain user behavior data.

[0009] Through the above method, the security detection device can accurately analyze user behavior data from the event content of the security detection event, so as to perform security detection on the user behavior based on the user behavior data.

[0010] In a possible implementation manner, the security detection device can generate a detection rule set. Exemplarily, the security detection device obtains at least one security policy configured by a second user for the cloud service in the cloud service control interface. The security detection device expands the target security policy in the at least one security policy according to at least one set dimension to obtain a derivative policy corresponding to the target security policy. The target security policy is used to indicate an operation prohibited for the user to perform on the cloud service. The security detection device generates a detection rule set according to the target security policy and the derivative policy corresponding to the target security policy.

[0011] Through the above method, the security detection device can, based on the security policies configured by the user, expand the security policies from multiple different dimensions to obtain derivative policies, thereby obtaining a richer set of detection rules, so that the multiple detection rules included in the generated set of detection rules can cover various operations prohibited for the user to perform. In this way, when performing security detection according to the set of detection rules, the user behavior can be detected more accurately.

[0012] Optionally, at least one set dimension includes a time dimension and / or a resource dimension.

[0013] Optionally, at least one security policy includes an Identity and Access Management (IAM) policy and / or a Service Control Policy (SCP).

[0014] In a possible implementation manner, the security detection device can obtain the security detection event triggered by the user terminal in the following manner: The security detection device receives the authentication result sent by the IAM unit, determines that the user terminal triggers a security detection event, and the authentication result is the authentication result corresponding to the authentication request sent by the user terminal, and the authentication request is used to request authentication for the first operation; or the security detection device receives the security detection request sent by the user terminal and determines that the user terminal triggers a security detection event.

[0015] Through the above method, the security detection device can accurately obtain the security detection event triggered by the user terminal in multiple different ways.

[0016] Optionally, the first operation is a management operation for resource and / or permission control of cloud services.

[0017] Through the above method, the security detection device can perform accurate security detection on the operations of the user management plane.

[0018] In a second aspect, an information generation method provided by an embodiment of the present application can be executed by a security detection device, or the method can also be executed by other devices (or modules). Taking the execution by the security detection device as an example, the security detection device can be deployed in a computing device or in a cluster composed of multiple computing devices. The security detection device obtains at least one security policy configured by a second user for a cloud service in a cloud service control interface; the security detection device expands a target security policy in the at least one security policy according to at least one set dimension to obtain a derivative policy corresponding to the target security policy; the target security policy is used to indicate an operation prohibited for the user to perform on the cloud service; the security detection device generates a set of detection rules according to the target security policy and the derivative policy corresponding to the target security policy.

[0019] Through the above method, the security detection device can, based on the security policies configured by the user, expand the security policies from multiple different dimensions to obtain derivative policies, thereby obtaining a richer set of detection rules, so that the multiple detection rules included in the generated set of detection rules can cover a variety of operations prohibited for users. In this way, when performing security detection according to the set of detection rules, the user behavior can be detected more accurately.

[0020] Optionally, at least one set dimension includes a time dimension and / or a resource dimension.

[0021] Optionally, at least one security policy includes an Identity and Access Management (IAM) policy and / or a Service Control Policy (SCP).

[0022] In a third aspect, an embodiment of the present application further provides a security detection device, which has the behavioral functions of the security detection device in the method example of the first aspect above. The beneficial effects can be seen in the description of the first aspect and will not be elaborated here. The functions can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. In a possible design, the structure of the security detection device includes an event acquisition module, an event analysis module, a detection module, and a notification module. These modules can execute the corresponding functions in the method example of the first aspect above. For specific details, refer to the detailed description in the method example and will not be elaborated here.

[0023] In a fourth aspect, an embodiment of the present application further provides an information generation device, which has the behavioral functions of the security detection device in the method example of the second aspect above. The beneficial effects can be seen in the description of the second aspect and will not be elaborated here. The functions can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. In a possible design, the structure of the information generation device includes an acquisition module, an analysis module, and a rule generation module. These modules can execute the corresponding functions in the method example of the second aspect above. For specific details, refer to the detailed description in the method example and will not be elaborated here.

[0024] Fifth aspect, embodiments of the present application further provide a computing device, which has the function of implementing the behavior of the security detection device in the method example of the first aspect above. The beneficial effects can be referred to the description of the first aspect and will not be elaborated here. Alternatively, the computing device has the function of implementing the behavior of the security detection device in the method example of the second aspect above. The beneficial effects can be referred to the description of the second aspect and will not be elaborated here. The structure of the computing device includes a processor and a memory. The processor is configured to support the security detection device to execute the corresponding functions in the method of the first aspect or the second aspect above. The memory is coupled to the processor and stores the necessary computer program instructions and data of the security detection device. The structure of the computing device also includes a communication interface for communicating with other devices.

[0025] Sixth aspect, embodiments of the present application further provide a computing device cluster, which has the function of implementing the behavior of the security detection device in the method example of the first aspect above. The beneficial effects can be referred to the description of the first aspect and will not be elaborated here. Alternatively, the computing device cluster has the function of implementing the behavior of the security detection device in the method example of the second aspect above. The beneficial effects can be referred to the description of the second aspect and will not be elaborated here. The computing device cluster includes at least one computing device. The structure of any computing device includes a processor and a memory. The processor in any computing device is configured to support the security detection device to execute some or all of the functions in the first aspect and each possible implementation manner of the first aspect above, or the processor in any computing device is configured to support the security detection device to execute some or all of the functions in the second aspect and each possible implementation manner of the second aspect above. The memory is coupled to the processor and stores the necessary computer program instructions and data of the security detection device or the information generation device. The structure of the computing device also includes a communication interface for communicating with other devices.

[0026] Seventh aspect, the present application further provides a computer-readable storage medium, in which instructions are stored. When it runs on a computer, it causes the computer to execute the methods in the first aspect and each possible implementation manner of the first aspect above, or causes the computer to execute the methods in the second aspect and each possible implementation manner of the second aspect above.

[0027] Eighth aspect, the present application further provides a computer program product containing instructions. When it runs on a computer, it causes the computer to execute the methods in the first aspect and each possible implementation manner of the first aspect above, or causes the computer to execute the methods in the second aspect and each possible implementation manner of the second aspect above.

[0028] In a ninth aspect, the present application further provides a computer chip. The chip is connected to a memory and is configured to read and execute a software program stored in the memory, and execute the methods in the first aspect and all possible implementation manners of the first aspect, or execute the methods in the second aspect and all possible implementation manners of the second aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] Figure 1 FIG.

[0030] Figure 2 Schematic diagram of an architecture of a cloud service system provided by an embodiment of the present application;

[0031] Figure 3 FIG.

[0032] Figure 4 Flowchart of a security detection method provided by an embodiment of the present application;

[0033] Figure 5 Flowchart of a method for generating a detection rule set provided by an embodiment of the present application;

[0034] Figure 6 Schematic diagram of a configuration page for unified identity authentication provided by an embodiment of the present application;

[0035] Figure 7 Schematic diagram of a configuration page for unified identity authentication provided by an embodiment of the present application;

[0036] Figure 8 Schematic diagram of a permission management page provided by an embodiment of the present application;

[0037] Figure 9 Schematic diagram of a custom policy creation page provided by an embodiment of the present application;

[0038] Figure 10 Flowchart of a security detection method and a method for generating a detection rule set provided by an embodiment of the present application;

[0039] Figure 11 Schematic diagram of the structure of a security detection device provided by an embodiment of the present application;

[0040] Figure 12 Schematic diagram of the structure of an information generation device provided by an embodiment of the present application;

[0041] Figure 13 Schematic diagram of the structure of a computing device provided by an embodiment of the present application;

[0042] Figure 14A schematic structural diagram of a computing device cluster provided by an embodiment of the present application. Detailed implementation manners

[0043] The following explains some terms in the embodiments of the present application to facilitate understanding by those skilled in the art.

[0044] 1. Cloud service: Services such as elastic computing, virtual network, data storage, and database required to meet enterprise Internet technology (IT) needs, provided in the form of representational state transfer application programming interface (REST API) based on the Internet. In the embodiments of the present application, the provider of cloud services can be simply referred to as a cloud vendor.

[0045] 2. Tenant: The owner of cloud resources, who is the subject with management authority over cloud resources. Among them, a tenant can order or rent cloud resources from a cloud vendor by paying according to business needs. The management authority of a tenant over the purchased cloud resources can include but is not limited to security management authority, access control authority, etc.

[0046] 3. User: An operator of a user terminal, a server, or cloud resources; among them, an operator of a server needs to be authorized by a server management platform to operate server resources, and an operator of cloud resources needs to be authorized by the owner of the cloud resources to operate cloud resources. In the embodiments of the present application, the operation of cloud resources or a server by a user can be realized through the user's user terminal (including physical devices and / or virtual devices).

[0047] 4. Identity and access management (IAM) policy: A security measure used to provide permission management, access control, and identity authentication. A tenant can create and manage users through IAM, allow or deny users' access to resources through authorization, improve the security of accounts and resources by setting permission policies, and at the same time provide multiple secure access credentials. The purpose of the IAM policy is to ensure that only authorized users can access specific cloud resources.

[0048] 5. Service control policy (SCP): An organizational policy that can be used to manage permissions in an organization. SCP can be used to provide centralized control of the maximum available permissions for all accounts in an organization, and select a legal set of permissions for organizational units (OUs) and accounts. SCP can help the behavior of cloud member accounts comply with the access control guidelines of the organization.

[0049] 6. Management plane operations: Operations for users to control cloud resources and permissions. Correspondingly, management plane traffic refers to the data stream for users to control cloud resources and permissions.

[0050] In the embodiments of the present application, "at least one" means one or more, and "a plurality" means two or more. "And / or" describes the association relationship of associated objects and indicates that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone, where A and B may be singular or plural. The character " / " generally represents an "or" relationship between the preceding and following associated objects. "At least one (item) of the following" or its similar expressions refer to any combination of these items, including any combination of single item (s) or plural item (s). For example, at least one (item) of a, b, or c may represent: a, b, c, a and b, a and c, b and c, or a, b, and c, where each of a, b, and c itself may be an element or a set containing one or more elements.

[0051] In the present application, "exemplary", "in some embodiments", "in other embodiments", etc. are used to give examples, illustrations, or explanations. Any embodiment or design solution described as "exemplary" in the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of the word "exemplary" is intended to present concepts in a specific manner.

[0052] In the present application, "(of)", "corresponding", and "corresponding" can sometimes be used interchangeably. It should be noted that when their differences are not emphasized, their intended meanings are the same. In the embodiments of the present application, communication and transmission can sometimes be used interchangeably. It should be noted that when the differences are not emphasized, their intended meanings are the same. For example, transmission may include sending and / or receiving, and can be a noun or a verb.

[0053] It should be noted that the terms "first", "second", etc. involved in the embodiments of the present application are only used for the purpose of distinguishing descriptions, and should not be construed as indicating or implying relative importance, nor as indicating or implying an order.

[0054] The present application will be described in detail below with reference to the accompanying drawings and embodiments.

[0055] Figure 1 The architecture diagram of the security detection system applicable to the embodiments of the present application is shown. As Figure 1 shown, the security detection system 100 may include a user terminal 101 and a security detection device 102.

[0056] In the security detection solution provided by the embodiments of the present application, the first user can operate the user terminal 101 to call the cloud service through the user terminal 101, and implement corresponding functions by calling the cloud service. For example, a client corresponding to the cloud service can be installed on the user terminal 101, and the first user operates the cloud service client installed on the user terminal 101 to implement the call of the cloud service; alternatively, the first user can access the web page corresponding to the cloud service through the browser on the user terminal 101, and the first user implements the call of the cloud service by operating the web page corresponding to the cloud service on the user terminal 101.

[0057] When the first user calls the cloud service through the user terminal 101, the first user can perform a first operation on the cloud service through the user terminal 101. The user terminal 101 sends a security detection request to the security detection device 102. The security detection device 102 receives the security detection request, determines that the user terminal 101 triggers a security detection event, and the security detection event is used to request a security detection of the first operation. The security detection device 102 performs a security detection on the first operation according to the security detection event.

[0058] The security detection device 102 in the embodiments of the present application can be implemented by software or by hardware.

[0059] As an example of a software functional unit, the security detection device 102 can be deployed in the cloud service system.

[0060] Such as Figure 2 The schematic diagram of the architecture of the cloud service system shown. The cloud service system 200 may include a cloud management platform 210 provided by a cloud provider for tenants and a backend system 220.

[0061] The cloud management platform 210 can be externally connected to the user terminal operated by the tenant through the Internet. The tenant can order cloud services on the cloud provider side through the cloud management platform 210 and perform resource configuration on the purchased cloud services. For example, the tenant can register an account on the cloud management platform 210 through the user terminal, and this account has the qualification to purchase (including different payment forms such as ordering or renting) cloud resources. After successfully purchasing cloud resources, the cloud management platform 210 can notify the corresponding backend system 220 to create cloud resources for the tenant, and provide appropriate access methods to the tenant and the users authorized by the tenant, so that the tenant can remotely manage the cloud resources, and control the tenant / user's remote access or use of the cloud resources, to provide at least one cloud service for the tenant and the users.

[0062] For example, the cloud resource is, for instance, a virtual machine. A tenant can select the specifications of the virtual machine (such as memory, processor, disk, etc.) on the cloud management platform 210. After the tenant's payment is successful, the cloud management platform 210 notifies the corresponding backend system 220 to create a virtual machine with such specifications. The tenant can configure the access rights of the users authorized by the tenant to the virtual machine (such as logging in to the virtual machine, performing shutdown operations, deletion operations, etc. on the virtual machine). After the configuration is successful, the users can perform the corresponding authorized operations on the virtual machine. The tenant can also grant the right to purchase or create a virtual machine to users. It should be understood that in the embodiments of this application, the cloud resource can also be various cloud services such as containers, bare metal servers, Elastic IP Address (EIP), etc. The embodiments of this application do not limit the type of cloud services.

[0063] The cloud management platform 210 can be connected to the corresponding backend system 220 through an internal network within the cloud service system 200. The backend system 220 can provide various data processing functions such as access, processing, aggregation, storage, etc. for requests or data from user terminals or third-party devices, and functions such as querying and using the saved data for tenants / users, so as to provide corresponding cloud services for tenants / users.

[0064] For example, the security detection device 102 can be at least one cloud service in the cloud service system; for instance, the security detection device 102 can be the cloud security service provided by the backend system 220.

[0065] When the security detection device 102 is a cloud security service, when a first user calls a cloud service to perform a first operation through the user terminal 101, the security detection device 102 can receive the security detection request sent by the user terminal 101 and determine that the user terminal triggers a security detection event.

[0066] Or, when the security detection device 102 is a cloud security service, security detection can be performed based on the architecture diagram of the security detection system 300 as shown in Figure 3 For example, when a first user calls a cloud service to perform a first operation through the user terminal 101, the user terminal 101 sends an authentication request to the IAM module (or IAM unit or IAM device) 103 in the cloud service system to request authentication for the first operation; the security detection device 102 can receive the authentication result corresponding to the authentication request sent by the IAM module 103, determine that the user terminal triggers a security detection event, and the security detection device 102 performs security detection on the first operation according to this security detection event.

[0067] For another example, the security detection device 102 can be integrated into one or more modules (or units) of the backend system 220. For example, the security detection device 102 can be integrated into the IAM module (it can be understood that the function of the security detection device 102 is a newly added function of the IAM module).

[0068] As an example of a hardware functional unit, the security detection device 102 can include at least one computing device, such as a server, etc. Alternatively, the security detection device 102 can also be a device implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). Among them, the above PLD can be implemented by a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. The multiple computing devices included in the security detection device 102 can be distributed in the same region or in different regions. The multiple computing devices included in the security detection device 102 can be distributed in the same availability zone (AZ) or in different AZs. Similarly, the multiple computing devices included in the security detection device 102 can be distributed in the same virtual private cloud (VPC) or in multiple VPCs. Among them, the multiple computing devices can be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.

[0069] The user terminal in the embodiments of the present application can be a mobile phone, a tablet computer, a laptop computer, a personal computer, etc.

[0070] Next, in combination with the accompanying drawings, the security detection method in the embodiments of the present application will be introduced.

[0071] As Figure 4 shown, it is a flowchart of a security detection method provided by the embodiments of the present application. Here, the security detection method is introduced by taking the security detection device as an example to execute the security detection method.

[0072] Step 400: The security detection device obtains a security detection event triggered by the user terminal.

[0073] Among them, the security detection event is used to request a security detection for the first operation, and the first operation is an operation performed by the first user on the cloud service through the user terminal.

[0074] The first user can operate the client installed on the user terminal or the web page on the user terminal. During the process of operating the client or web page of the user terminal, the user terminal can call the corresponding cloud service and execute the corresponding functions by calling the cloud service.

[0075] During the process of the first user scheduling the cloud service by operating the user terminal, when the first user performs a first operation on the cloud service, the user terminal can trigger a security detection event to request a security detection of the first operation. For example, the first operation performed by the first user can be a management operation for resource and / or permission control of the cloud service; for instance, the first operation is an operation to create a virtual machine for the cloud service, or the first operation can also be an operation to modify the permissions of the first user. Another example is that the first operation performed by the first user can also be an operation related to business data.

[0076] The user terminal can trigger the security detection event in a variety of different ways. These will be introduced separately below.

[0077] Method 1: The user terminal sends a security detection request to the security detection device.

[0078] In Method 1, when the first user performs a first operation on the cloud service through the user terminal, the user terminal triggers the security detection event by sending a security detection request to the security detection device.

[0079] Correspondingly, the security detection device receives the security detection request sent by the user terminal and determines that the user terminal has triggered the security detection event.

[0080] Method 2: The user terminal sends an authentication request to the IAM unit, and the IAM unit sends an authentication result to the security detection device.

[0081] In Method 1, when the first user performs a first operation on the cloud service through the user terminal, the user terminal triggers the security detection event by sending an authentication request to the IAM unit.

[0082] In implementation, after receiving the authentication request, the IAM unit authenticates the authentication request to obtain an authentication result.

[0083] For example, the IAM unit authenticating the authentication request can be to determine whether the first user has the permission to perform the first operation on the cloud service, thereby generating an authentication result. For example, the authentication result can be authentication passed, indicating that the first user has the permission to perform the first operation on the cloud service; or the authentication result is authentication failed, indicating that the first user does not have the permission to perform the first operation on the cloud service.

[0084] After obtaining the authentication result of the authentication request sent by the user terminal, the IAM unit sends the authentication result to the security detection device.

[0085] Correspondingly, the security detection device receives the authentication result sent by the IAM unit and determines that the user terminal triggers a security detection event.

[0086] Step 401: The security detection device determines user behavior data according to the security detection event.

[0087] Among them, the user behavior data characterizes the behavior of the first user performing the first operation.

[0088] Since the security detection device is triggered after the first user performs the first operation on the cloud service, and the security detection event is used to request a security detection of the first operation, the security detection device needs to extract the user behavior data according to the security detection event after obtaining the security detection event. The user behavior data can be used to describe the behavior of the first user performing the first operation.

[0089] Optionally, the security detection device determines the user behavior data according to the following steps:

[0090] Step 1: The security detection device extracts behavior features from the event content corresponding to the security detection event to obtain at least one behavior information of the first user.

[0091] Since the security detection event in the embodiment of the present application is used to request a security detection of the first operation, the security detection event may describe information related to the first operation. For example, the event content of the security detection event may be: The first user accesses cloud service A at 18:00 on February 20, 2024 and creates a virtual machine through resource instance 1.

[0092] The security detection device can extract behavior features from the event content corresponding to the security detection event and extract the behavior information included in the security detection event. For example, the event content of the security detection event may be: The first user accesses cloud service A at 18:00 on February 20, 2024 and creates a virtual machine through resource instance 1; then the extracted behavior information includes: time information (18:00 on February 20, 2024), operation information (operating resource instance 1, creating a virtual machine).

[0093] Step 2: The security detection device respectively performs format conversion on each behavior information to obtain user behavior data.

[0094] In implementation, the security detection device respectively performs format conversion on each behavior information extracted in Step 1; for example, the security detection device can convert each behavior information into a preset format according to the preset format, so as to obtain user behavior data.

[0095] In the security detection device according to the embodiment of the present application, each behavior information is format-converted to convert the behavior information into a preset format, so that when performing security detection subsequently, the user behavior data in the preset format can be matched with the detection rules in the detection rule set.

[0096] It should be noted that the process of the security detection device determining user behavior data according to the security detection event in step 401 can also be referred to as serializing the security detection event; by serializing the security detection event, the security detection device can obtain at least one behavior stream, and the at least one behavior stream can be referred to as user behavior data.

[0097] Step 402: If the user behavior data matches at least one detection rule in the detection rule set corresponding to the cloud service, the security detection device determines that the first operation is a non-secure operation with abnormal behavior.

[0098] Among them, the detection rule set includes multiple detection rules, and each detection rule is used to characterize the abnormal behavior of the user.

[0099] In step 402, the security detection device compares the user behavior data determined in step 401 with multiple detection rules in the detection rule set corresponding to the cloud service. If the user behavior data matches at least one detection rule in the detection rule set (or it can be understood that the user behavior data hits at least one detection rule in the detection rule set), it is determined that the first operation performed by the first user is a non-secure operation with abnormal behavior.

[0100] The detection rule set according to the embodiment of the present application can be a pre-generated rule set corresponding to the cloud service, and the multiple detection rules included in the detection rule set can be used to describe the abnormal behavior of the user. In this way, the security detection device compares the user behavior data extracted from the security detection event with the detection rule set. If the user behavior data matches at least one detection rule in the detection rule set, it indicates that the first operation performed by the first user includes abnormal behavior. At this time, the security detection device can determine that the first operation performed by the first user is a non-secure operation with abnormal behavior.

[0101] Step 403: The security detection device sends a security warning message to the second user.

[0102] Optionally, the second user can be the tenant corresponding to the cloud service. Or it can be understood that the second user is the administrator of the cloud service.

[0103] Optionally, the security detection device can send a security warning message to the user terminal operated by the second user, and present the security warning message sent by the security detection device on the interface of the user terminal operated by the second user.

[0104] The security detection device can send security warning messages to the second user in a variety of different ways. For example, the security detection device can send security warning messages to the user terminal of the second user in the form of text messages; for instance, the security detection device can obtain the number registered by the second user when purchasing cloud services and send security warning messages to the user terminal of the second user in the form of text messages. Another example is that the security detection device can send security warning messages to the user terminal of the second user in the form of emails; for example, the security detection device can obtain the email address registered by the second user when purchasing cloud services and send security warning messages to the user terminal of the second user in the form of emails.

[0105] In an embodiment of the present application, a possible implementation is that after the second user receives the security warning message, the second user can operate the user terminal to confirm whether the first operation performed by the first user is a non-secure operation with abnormal behavior. After the second user confirms that the first operation performed by the first user is a non-secure operation with abnormal behavior, the second user sends a confirmation of abnormality message to the security detection device through the user terminal, and then the security detection device blocks the first operation performed by the first user on the cloud service; after the second user confirms that the first operation performed by the first user is not a non-secure operation with abnormal behavior, the second user sends a confirmation of normality message to the security detection device through the user terminal, and then the security detection device notifies other subsequent devices to execute the processing flow corresponding to the first operation.

[0106] Regarding the detection rule set adopted in step 402 in the above text, the embodiments of the present application provide various ways to generate the detection rule set. The following details the generation methods of the detection rule set.

[0107] Generation method 1: Generate a detection rule set according to the security policy configured by the second user.

[0108] In this generation method, in an embodiment of the present application, the security detection device can generate a detection rule set according to the security policy configured by the second user; or in an embodiment of the present application, other devices (or modules or equipment) can also generate a detection rule set according to the security policy configured by the second user.

[0109] As Figure 5 shown, it is a flowchart of an information generation method provided by an embodiment of the present application, where the generation of a detection rule set by the security detection device is taken as an example for introduction.

[0110] Step 500: The security detection device obtains at least one security policy configured by the second user for the cloud service in the cloud service control interface.

[0111] Optionally, the second user can be the tenant corresponding to the cloud service. Or it can be understood that the second user is the administrator of the cloud service.

[0112] A second user can log in to the cloud management platform through an account, and can configure at least one security policy for the cloud service in the cloud service control interface of the cloud management platform.

[0113] For example, at least one security policy configured by the second user for the cloud service may include an IAM policy and / or a service control policy (SCP).

[0114] Taking the IAM policy as an example below, the process of the second user configuring the security policy will be introduced in combination with the accompanying drawings.

[0115] First, the second user logs in to the cloud management platform through an account, and the cloud service control interface is displayed.

[0116] In the cloud service control interface, the second user can select the unified identity authentication service and enter the configuration page of the unified identity authentication. For example, Figure 6 the configuration page of the unified identity authentication shown. In Figure 6 the configuration page of the unified identity authentication shown, the second user can manage IAM users as an administrator; for example, the second user can create users and configure permissions for the users in the configuration page of the unified identity authentication. In addition, in the configuration page of the unified identity authentication, the second user can manage user groups as an administrator; for example, Figure 7 in the configuration page of the unified identity authentication shown, the second user can create a user group, configure permissions for the user group; the second user can also add the created users to the user group so that the users obtain the permissions corresponding to the user group.

[0117] When the second user manages the permissions of users or user groups, the second user can assign different permissions to different users or user groups. Among them, the IAM pre-sets the common permissions of each cloud service, such as administrator permissions and read-only permissions; when the second user assigns permissions to a user or a user group, the second user can authorize the user or the user group from the pre-configured system permissions; after authorization, the users in the user or the user group can operate on the cloud service based on their own permissions.

[0118] In the embodiments of this application, the permissions of a user or user group include roles and policies. Among them, a role is a coarse-grained authorization mechanism initially provided by IAM for defining permissions based on the job functions of users. This mechanism uses services as the granularity and provides a limited number of service-related roles for authorization. Since there are business dependencies among cloud services, when granting a role to a user, it may be necessary to grant other dependent roles together to correctly complete the business. A policy is a fine-grained authorization capability newly provided by IAM, which can be precise to operations, resources, and request conditions of specific services, etc. Authorization based on policies is a more flexible authorization method that can meet the enterprise's security control requirements for minimizing permissions. For example, for the ECS service, an administrator can control that a user can only perform specified management operations on a certain type of cloud server resources.

[0119] The IAM policies configured by the second user for an IAM user or user group can include system policies and custom policies. Among them, a system policy is a commonly used authorization item pre-configured for cloud services, called a system policy. When the second user authorizes a user or user group, they can directly select and use the corresponding system policy, but cannot modify the system policy. A custom policy is a policy customized by the administrator according to the authorization items supported by the cloud service, and fine-grained access control is performed by granting the custom policy to a user or user group. The custom policy is an extension and supplement to the system policy.

[0120] The IAM policies in the embodiments of this application can include allow execution policies and deny execution policies according to the policy content. Among them, the allow execution policy describes the operation behaviors that a user can perform, and the deny execution policy describes the operation behaviors that are prohibited for a user to perform.

[0121] When configuring IAM policies for a user, the second user can click on the "Permission Management" option in the configuration page of unified identity authentication as shown in Figure 6 to enter the permission management page. In the permission management page, the second user can select the system policy corresponding to the cloud service for a user or user group. Or, in the permission management page, the second user can create a custom policy for the cloud service. In the permission management page as shown in Figure 8 , the second user can click on "Create Custom Policy", and then enter the custom policy creation page as shown in Figure 9 . In the custom policy creation page, the second user can enter the policy name of the custom policy, select the policy configuration method (visual view or JSON view), select the type of the custom policy (allow execution policy or deny execution policy), and the second user can also enter the policy description of the custom policy (such as the policy content of the custom policy), so as to complete the creation of the custom policy.

[0122] Step 501: The security detection device expands the target security policy in at least one security policy according to at least one set dimension to obtain a derivative policy corresponding to the target security policy.

[0123] Among them, the target security policy is used to indicate the operations that users are prohibited from performing on cloud services.

[0124] After the security detection device obtains at least one security policy configured by the second user for the cloud service, it can select the target security policy from at least one security policy. For example, the target security policy can be a prohibition execution policy configured by the second user for the cloud service, and the prohibition execution policy indicates the operations that users are prohibited from performing on the cloud service.

[0125] After the security detection device obtains the target security policy, it expands the target security policy according to at least one set dimension to obtain a derivative policy corresponding to the target security policy.

[0126] It should be noted that the target security policy that the security detection device can select from at least one security policy can be one or more. When there are multiple target security policies, the security detection device determines the derivative policy corresponding to each target security policy; in addition, for one target security policy, one or more derivative policies can be expanded from each set dimension.

[0127] Optionally, at least one set dimension includes a time dimension and / or a resource dimension. Or at least one set dimension can also include a custom condition dimension in the security policy.

[0128] For the time dimension, if the target security policy indicates that the user is not allowed to perform operation A within the first time period, then expanding this target security policy can obtain a derivative policy: the user is not allowed to perform operation A within the second time period.

[0129] For the resource dimension, if the target security policy indicates that the user is not allowed to perform operation A through resource instance B, then expanding this target security policy can obtain a derivative policy: the user is not allowed to perform operation A through other resource instances; where other resource instances can be resource instances that share commonalities with resource instance B, such as resource instances in the same region.

[0130] For the custom condition dimension, where the custom condition can be a condition customized in the target security policy; if the target security policy indicates that the user is not allowed to perform operation A through image C, then expanding this target security policy can obtain a derivative policy: the user is not allowed to perform operation A through other images; where other images can be images that share commonalities with image C.

[0131] For example, the content included in the target security policy is as follows:

[0132] The actions that are not allowed for users in the policy include: users are not allowed to create virtual machines between 6.00 - 18.00, and users are not allowed to modify virtual machines between 6.00 - 18.00;

[0133] The resources corresponding to the policy include: resource instance B.

[0134] Then: By expanding the target security policy from the time dimension, the derived policies that can be obtained include: users are not allowed to create virtual machines through resource instance B between 18.00 - 24.00 and 0:00 - 6:00, and users are not allowed to modify virtual machines through resource instance B between 18.00 - 24.00 and 0:00 - 6:00;

[0135] By expanding the target security policy from the resource dimension, the derived policies that can be obtained include: users are not allowed to create virtual machines through resource instance D between 6.00 - 18.00, and users are not allowed to modify virtual machines through resource instance D between 6.00 - 18.00.

[0136] Moreover, by expanding the target security policy from both the time dimension and the resource dimension, the derived policies that can be obtained include: users are not allowed to create virtual machines through resource instance D between 18.00 - 24.00 and 0:00 - 6:00, and users are not allowed to modify virtual machines through resource instance D between 18.00 - 24.00 and 0:00 - 6:00.

[0137] Step 502: The security detection device generates a set of detection rules according to the target security policy and the derived policies corresponding to the target security policy.

[0138] After determining the derived policies corresponding to the target security policy, the security detection device can generate a set of detection rules according to the actions that are prohibited for users as indicated by the target security policy and the derived policies corresponding to the target security policy.

[0139] For example, the target security policy is that users are not allowed to create virtual machines through resource instance B between 6:00 and 18:00, and users are not allowed to modify virtual machines through resource instance B between 6:00 and 18:00. The derived policies determined by the security detection device include: users are not allowed to create virtual machines through resource instance B between 18:00 and 24:00 and between 0:00 and 6:00, users are not allowed to modify virtual machines through resource instance B between 18:00 and 24:00 and between 0:00 and 6:00, users are not allowed to create virtual machines through resource instance D between 6:00 and 18:00, users are not allowed to modify virtual machines through resource instance D between 6:00 and 18:00, users are not allowed to create virtual machines through resource instance D between 18:00 and 24:00 and between 0:00 and 6:00, and users are not allowed to modify virtual machines through resource instance D between 18:00 and 24:00 and between 0:00 and 6:00. Then, the set of detection rules generated by the security detection device based on the target security policy and the derived policies includes detection rule 1 (users are not allowed to create virtual machines through resource instance B between 6:00 and 18:00), detection rule 2 (users are not allowed to modify virtual machines through resource instance B between 6:00 and 18:00), detection rule 3 (users are not allowed to create virtual machines through resource instance B between 18:00 and 24:00 and between 0:00 and 6:00), detection rule 4 (users are not allowed to modify virtual machines through resource instance B between 18:00 and 24:00 and between 0:00 and 6:00), detection rule 5 (users are not allowed to create virtual machines through resource instance D between 6:00 and 18:00), detection rule 6 (users are not allowed to modify virtual machines through resource instance D between 6:00 and 18:00), detection rule 7 (users are not allowed to create virtual machines through resource instance D between 18:00 and 24:00 and between 0:00 and 6:00), and detection rule 8 (users are not allowed to modify virtual machines through resource instance D between 18:00 and 24:00 and between 0:00 and 6:00).

[0140] The following combines the attached Figure 10 to introduce the complete process of the embodiments of the present application. Taking the security detection device executing the security detection method of the present application and generating a set of detection rules as an example for illustration.

[0141] Step 1001: The second user configures at least one security policy for the cloud service in the unified identity authentication service through the cloud service control interface.

[0142] Step 1002: The security detection device obtains at least one security policy configured by the second user.

[0143] Step 1003: The security detection device extends the target security policy in at least one security policy to obtain a derived policy, and generates a set of detection rules based on the target security policy and the derived policy.

[0144] Among them, the target security policy is used to indicate the operations that are prohibited for users to perform on cloud services.

[0145] Step 1004: The first user operates the user terminal to perform a first operation on the cloud service.

[0146] Among them, the first user performing the first operation on the cloud service can be understood as the first user using a legitimate account to call the cloud service API, or performing the first operation on the cloud service on the cloud management platform.

[0147] For example, the first user performing the first operation on the cloud service may include Figure 10 the multiple operations shown in: configuring a virtual private cloud (VPC), accessing critical resources; modifying the firewall policy; accessing user data; creating an elastic IP (EIP), creating a backdoor web service or a file transfer protocol (FTP) service, etc.; accessing the backdoor (such as an elastic IP).

[0148] Step 1005: The security detection device obtains the security detection event triggered by the user terminal. The security detection event is used to request a security detection of the first operation.

[0149] Step 1006: The security detection device performs behavior analysis on the security detection event to determine user behavior data.

[0150] Step 1007: The security detection device compares the user behavior data with the detection rules in the set of detection rules.

[0151] Step 1008: If the user behavior data matches at least one detection rule in the set of detection rules corresponding to the cloud service, the security detection device determines that the first operation is a non-secure operation with abnormal behavior and sends a security warning message.

[0152] This application also provides a security detection device, as Figure 11 shown, including:

[0153] An event acquisition module 1101, configured to obtain a security detection event triggered by a user terminal, where the security detection event is used to request a security detection of a first operation, and the first operation is an operation performed by a first user on a cloud service through the user terminal;

[0154] An event analysis module 1102, configured to determine user behavior data according to the security detection event, where the user behavior data characterizes the behavior of the first user performing the first operation;

[0155] A detection module 1103, configured to determine that the first operation is a non-secure operation with abnormal behavior if the user behavior data matches at least one detection rule in the detection rule set corresponding to the cloud service, where the detection rule set includes multiple detection rules, and each detection rule is used to characterize the abnormal behavior of the user;

[0156] A notification module 1104, configured to send a security warning message to a second user.

[0157] In a possible implementation manner, the event analysis module 1102 is configured to:

[0158] Extract behavior features from the event content corresponding to the security detection event to obtain at least one behavior information of the first user; perform format conversion on each behavior information respectively to obtain the user behavior data.

[0159] In a possible implementation manner, the apparatus further includes a rule generation module 1105;

[0160] The rule generation module 1105 is configured to generate the detection rule set according to the following method:

[0161] Obtain at least one security policy configured by the second user for the cloud service in the cloud service control interface;

[0162] Expand the target security policy in the at least one security policy according to at least one set dimension to obtain a derivative policy corresponding to the target security policy; the target security policy is used to indicate an operation prohibited for the user to perform on the cloud service;

[0163] Generate the detection rule set according to the target security policy and the derivative policy corresponding to the target security policy.

[0164] Optionally, the at least one set dimension includes a time dimension and / or a resource dimension.

[0165] Optionally, the at least one security policy includes an Identity and Access Management (IAM) policy and / or a Service Control Policy (SCP).

[0166] In a possible implementation manner, the event acquisition module 1101 is configured to:

[0167] Receive the authentication result sent by the IAM unit, and determine that the user terminal triggers the security detection event. The authentication result is the authentication result corresponding to the authentication request sent by the user terminal, and the authentication request is used to request authentication for the first operation; or

[0168] Receive the security detection request sent by the user terminal, and determine that the user terminal triggers the security detection event.

[0169] Optionally, the first operation is a management operation for resource and / or permission control of the cloud service.

[0170] Among them, the event acquisition module 1101, the event analysis module 1102, the detection module 1103, the notification module 1104, and the rule generation module 1105 can all be implemented by software or by hardware. Exemplarily, next, taking the event analysis module 1102 as an example, the implementation manner of the event analysis module 1102 will be introduced. Similarly, the implementation manners of the event acquisition module 1101, the detection module 1103, the notification module 1104, and the rule generation module 1105 can refer to the implementation manner of the event analysis module 1102.

[0171] As an example of a software functional unit, the event analysis module 1102 can include code running on a computing instance. Among them, the computing instance can include at least one of a physical host (computing device), a virtual machine, and a container. Further, the above computing instance can be one or more. For example, the event analysis module 1102 can include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers for running this code can be distributed in the same region, or can be distributed in different regions. Further, the multiple hosts / virtual machines / containers for running this code can be distributed in the same availability zone (AZ), or can be distributed in different AZs. Each AZ includes one data center or multiple geographically close data centers. Among them, usually one region can include multiple AZs.

[0172] Similarly, the multiple hosts / virtual machines / containers for running this code can be distributed in the same virtual private cloud (VPC), or can be distributed in multiple VPCs. Among them, usually one VPC is set within one region. For cross-region communication between two VPCs within the same region and between VPCs in different regions, a communication gateway needs to be set in each VPC, and the interconnection between VPCs is realized through the communication gateway.

[0173] As an example of a hardware functional unit, the event analysis module 1102 may include at least one computing device, such as a server, etc. Alternatively, the event analysis module 1102 may also be a device implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). Among them, the above PLD may be implemented by a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.

[0174] The multiple computing devices included in the event analysis module 1102 may be distributed in the same region or in different regions. The multiple computing devices included in the event analysis module 1102 may be distributed in the same availability zone (AZ) or in different AZs. Similarly, the multiple computing devices included in the event analysis module 1102 may be distributed in the same virtual private cloud (VPC) or in multiple VPCs. Among them, the multiple computing devices may be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.

[0175] It should be noted that in other embodiments, the event acquisition module 1101 may be used to execute any step in the security detection method, the event analysis module 1102 may be used to execute any step in the security detection method, the detection module 1103 may be used to execute any step in the security detection method, the notification module 1104 may be used to execute any step in the security detection method, and the rule generation module 1105 may be used to execute any step in the security detection method. The steps to be implemented by the event acquisition module 1101, the event analysis module 1102, the detection module 1103, the notification module 1104, and the rule generation module 1105 can be specified as needed. The entire function of the security detection device is realized by respectively implementing different steps in the security detection method through the event acquisition module 1101, the event analysis module 1102, the detection module 1103, the notification module 1104, and the rule generation module 1105.

[0176] This application also provides an information generation device, such as Figure 12 shown, including:

[0177] An acquisition module 1201, configured to acquire at least one security policy configured by a second user for a cloud service in a cloud service control interface;

[0178] An analysis module 1202, configured to expand a target security policy among the at least one security policy according to at least one set dimension to obtain a derivative policy corresponding to the target security policy; the target security policy is used to indicate an operation that a user is prohibited from performing on the cloud service.

[0179] A rule generation module 1203, configured to generate a set of detection rules corresponding to the cloud service according to the target security policy and the derivative policy corresponding to the target security policy, where the set of detection rules includes a plurality of detection rules, and each detection rule is used to characterize an abnormal behavior of a user.

[0180] Optionally, the at least one set dimension includes a time dimension and / or a resource dimension.

[0181] Optionally, the at least one security policy includes an IAM policy and / or an SCP policy.

[0182] Among them, the acquisition module 1201, the analysis module 1202, and the rule generation module 1203 can all be implemented by software or by hardware. Exemplarily, next, taking the rule generation module 1203 as an example, the implementation manner of the rule generation module 1203 will be introduced. Similarly, the implementation manners of the acquisition module 1201 and the analysis module 1202 can refer to the implementation manner of the rule generation module 1203.

[0183] As an example of a software functional unit, the rule generation module 1203 may include code running on a computing instance. Among them, the computing instance may include at least one of a physical host (computing device), a virtual machine, and a container. Further, the above computing instance may be one or more. For example, the rule generation module 1203 may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers for running the code may be distributed in the same region or in different regions. Further, the multiple hosts / virtual machines / containers for running the code may be distributed in the same availability zone (AZ) or in different AZs, and each AZ includes one data center or multiple geographically close data centers. Among them, generally, one region may include multiple AZs.

[0184] Similarly, multiple hosts / virtual machines / containers used to run the code can be distributed within the same VPC or across multiple VPCs. Usually, one VPC is set up within one region. For cross-region communication between two VPCs within the same region and between VPCs in different regions, communication gateways need to be set up within each VPC, and the interconnection between VPCs is achieved through the communication gateways.

[0185] As an example of a hardware functional unit, the rule generation module 1203 may include at least one computing device, such as a server. Alternatively, the rule generation module 1203 may also be a device implemented using ASIC or PLD. Among them, the above PLD may be implemented by CPLD, FPGA, GAL, or any combination thereof.

[0186] The multiple computing devices included in the rule generation module 1203 can be distributed within the same region or across different regions. The multiple computing devices included in the rule generation module 1203 can be distributed within the same AZ or across different AZs. Similarly, the multiple computing devices included in the rule generation module 1203 can be distributed within the same VPC or across multiple VPCs. Among them, the multiple computing devices can be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.

[0187] It should be noted that in other embodiments, the acquisition module 1201 can be used to execute any step in the information generation method, the analysis module 1202 can be used to execute any step in the information generation method, and the rule generation module 1203 can be used to execute any step in the information generation method. The steps to be implemented by the acquisition module 1201, the analysis module 1202, and the rule generation module 1203 can be specified as needed. The full functions of the information generation device are realized by respectively implementing different steps in the security detection method through the acquisition module 1201, the analysis module 1202, and the rule generation module 1203.

[0188] This application also provides a computing device 1300. As Figure 13 shown, the computing device 1300 can be used to implement the functions of the security detection device or the information generation device in the above embodiments, including: a bus 1301, a processor 1302, a memory 1303, and a communication interface 1304. The processor 1302, the memory 1303, and the communication interface 1304 communicate with each other through the bus 1301. The computing device 1300 can be a server or a terminal device. It should be understood that this application does not limit the number of processors and memories in the computing device 1300.

[0189] The bus 1301 can be a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, or the like. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 13 only one line is used in Figure 13 , but it does not mean that there is only one bus or one type of bus. The bus 1301 can include a path for transmitting information between various components of the computing device 1300 (for example, the memory 1303, the processor 1302, the communication interface 1304).

[0190] The processor 1302 can include any one or more of a Central Processing Unit (CPU), a Graphics Processing Unit (GPU), a Micro Processor (MP), or a Digital Signal Processor (DSP), etc.

[0191] The memory 1303 can include volatile memory, such as Random Access Memory (RAM). The processor 1302 can also include non-volatile memory, such as Read-Only Memory (ROM), flash memory, a Hard Disk Drive (HDD), or a Solid State Drive (SSD).

[0192] The memory 1303 stores executable program code, and the processor 1302 executes the executable program code to respectively implement the functions of the foregoing event acquisition module 1101, event analysis module 1102, detection module 1103, notification module 1104, and rule generation module 1105, thereby implementing the security detection method. That is, the memory 1303 stores instructions for executing the security detection method.

[0193] Alternatively, the memory 1303 stores executable program code, and the processor 1302 executes the executable program code to respectively implement the functions of the foregoing acquisition module 1201, analysis module 1202, and rule generation module 1203, thereby implementing the information generation method. That is, the memory 1303 stores instructions for executing the information generation method.

[0194] The communication interface 1304 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the computing device 1300 and other devices or a communication network.

[0195] Embodiments of this application also provide a computing device cluster. The computing device cluster includes at least one computing device. At least one computing device in the computing device cluster cooperates to implement the functions of the security detection device in the above embodiments, or at least one computing device in the computing device cluster cooperates to implement the functions of the information generation device in the above embodiments. The computing device may be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device may also be a terminal device such as a desktop computer, a laptop computer, or a smart phone.

[0196] As Figure 14 shown, the computing device cluster includes at least one computing device 1300. The same instructions for executing the security detection method may be stored in the memory 1303 of one or more computing devices 1300 in the computing device cluster, or the same instructions for executing the information generation method may be stored in the memory 1303 of one or more computing devices 1300 in the computing device cluster.

[0197] In some possible implementation manners, partial instructions for executing the security detection method may also be separately stored in the memory 1303 of one or more computing devices 1300 in the computing device cluster. In other words, a combination of one or more computing devices 1300 may jointly execute the instructions for executing the security detection method. Or, partial instructions for executing the information generation method may also be separately stored in the memory 1303 of one or more computing devices 1300 in the computing device cluster. In other words, a combination of one or more computing devices 1300 may jointly execute the instructions for executing the information generation method.

[0198] It should be noted that the memories 1303 in different computing devices 1300 in the computing device cluster may store different instructions, respectively for implementing partial functions of the security detection device. That is, the instructions stored in the memories 1303 of different computing devices 1300 may implement the functions of one or more of the event acquisition module 1101, the event analysis module 1102, the detection module 1103, the notification module 1104, and the rule generation module 1105; or, the instructions stored in the memories 1303 of different computing devices 1300 may implement the functions of one or more of the acquisition module 1201, the analysis module 1202, and the rule generation module 1203.

[0199] In some possible implementations, one or more computing devices in a computing device cluster can be connected via a network. Among them, the network can be a wide area network or a local area network, etc.

[0200] The embodiments of the present application also provide a computer program product containing instructions. The computer program product can be software or a program product containing instructions that can run on a computing device or be stored in any available medium. When the computer program product runs on at least one computing device, it causes at least one computing device to execute a security detection method or an information generation method.

[0201] The embodiments of the present application also provide a computer-readable storage medium. The computer-readable storage medium can be any available medium that a computing device can store or a data storage device such as a data center containing one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive), etc. The computer-readable storage medium includes instructions that instruct the computing device to execute a security detection method or instruct the computing device to execute an information generation method.

[0202] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the protection scope of the technical solutions of the embodiments of the present invention.

Claims

1. A safety detection method, characterized in that: The method comprises: Acquire a security detection event triggered by a user terminal, where the security detection event is used to request a security detection of a first operation, where the first operation is an operation performed by a first user on a cloud service through the user terminal; determining user behavior data according to the security detection event, where the user behavior data represents behavior of the first user performing the first operation; If the user behavior data matches at least one detection rule in the detection rule set corresponding to the cloud service, determining that the first operation is a non-safe operation with abnormal behavior, the detection rule set includes multiple detection rules, each of which is used to characterize the abnormal behavior of the user; A security warning message is sent to the second user.

2. The method according to claim 1, characterized in that The determining of user behavior data according to the security detection event includes: Extracting behavior features from event content corresponding to the security detection event to obtain at least one behavior information of the first user; The format of each behavior information is converted respectively to obtain the user behavior data.

3. The method according to claim 1 or 2, characterized in that The method further comprises: The detection rule set is generated according to the following method: Obtaining at least one security policy configured by the second user for the cloud service in the cloud service control interface; According to at least one set dimension, a target security policy in the at least one security policy is expanded to obtain a derivative policy corresponding to the target security policy; the target security policy is used to indicate that the user is prohibited from performing operations on the cloud service; The detection rule set is generated according to the target security policy and a derived policy corresponding to the target security policy.

4. The method according to claim 3, characterized in that The at least one setting dimension includes a time dimension and / or a resource dimension.

5. The method according to claim 3 or 4, characterized in that The at least one security policy includes a unified identity authentication IAM policy and / or a service control policy SCP.

6. The method according to any one of claims 1 to 5, characterized in that: The obtaining of a security detection event triggered by a user terminal includes: receiving an authentication result sent by the IAM unit, and determining that the user terminal triggers the security detection event, wherein the authentication result is an authentication result corresponding to an authentication request sent by the user terminal, and the authentication request is used to request authentication of the first operation; or A security detection request sent by the user terminal is received, and it is determined that the user terminal triggers the security detection event.

7. The method according to any one of claims 1 to 6, characterized in that: The first operation is a management operation for performing resource and / or permission control on the cloud service.

8. A method for generating information, characterized in that: The method comprises: Obtaining at least one security policy configured by the second user for the cloud service in the cloud service control interface; According to at least one set dimension, a target security policy in the at least one security policy is expanded to obtain a derivative policy corresponding to the target security policy; the target security policy is used to indicate that the user is prohibited from performing operations on the cloud service; A detection rule set corresponding to the cloud service is generated according to the target security policy and a derived policy corresponding to the target security policy. The detection rule set includes multiple detection rules, and each detection rule is used to characterize abnormal behavior of a user.

9. The method according to claim 8, characterized in that The at least one setting dimension includes a time dimension and / or a resource dimension.

10. The method according to claim 8 or 9, characterized in that The at least one security policy includes an IAM policy and / or an SCP policy.

11. A safety detection device, characterized in that: The device comprises: An event acquisition module, used to acquire a security detection event triggered by a user terminal, wherein the security detection event is used to request a security detection of a first operation, where the first operation is an operation performed by a first user on a cloud service through the user terminal; an event analysis module, configured to determine user behavior data according to the security detection event, wherein the user behavior data represents the behavior of the first user performing the first operation; a detection module, configured to determine that the first operation is a non-safe operation with abnormal behavior if the user behavior data matches at least one detection rule in a detection rule set corresponding to the cloud service, wherein the detection rule set includes a plurality of detection rules, each of which is used to characterize an abnormal behavior of a user; The notification module is used to send security warning information to the second user.

12. The device according to claim 11, characterized in that The event analysis module is used to: Performing behavioral feature extraction on the event content corresponding to the security detection event to obtain at least one behavioral information of the first user; and performing format conversion on each of the behavioral information to obtain the user behavior data.

13. The device according to claim 11 or 12, characterized in that The device also includes a rule generation module; The rule generation module is used to generate the detection rule set according to the following method: Obtaining at least one security policy configured by the second user for the cloud service in the cloud service control interface; According to at least one set dimension, a target security policy in the at least one security policy is expanded to obtain a derived policy corresponding to the target security policy; The target security policy is used to indicate that the user is prohibited from performing operations on the cloud service; The detection rule set is generated according to the target security policy and a derived policy corresponding to the target security policy.

14. The device according to claim 13, characterized in that The at least one setting dimension includes a time dimension and / or a resource dimension.

15. The device according to claim 13 or 14, characterized in that The at least one security policy includes a unified identity authentication IAM policy and / or a service control policy SCP.

16. The device according to any one of claims 11 to 15, characterized in that: The event acquisition module is used for: receiving an authentication result sent by the IAM unit, and determining that the user terminal triggers the security detection event, wherein the authentication result is an authentication result corresponding to an authentication request sent by the user terminal, and the authentication request is used to request authentication for the first operation; or A security detection request sent by the user terminal is received, and it is determined that the user terminal triggers the security detection event.

17. The device according to any one of claims 11 to 16, characterized in that: The first operation is a management operation for performing resource and / or permission control on the cloud service.

18. An information generating device, characterized in that: The device comprises: An acquisition module, configured to acquire at least one security policy configured by the second user for the cloud service in the cloud service control interface; an analysis module, configured to expand a target security policy in the at least one security policy according to at least one set dimension to obtain a derivative policy corresponding to the target security policy; the target security policy is used to indicate that operations that a user is prohibited from performing on the cloud service; A rule generation module is used to generate a detection rule set corresponding to the cloud service according to the target security policy and the derived policy corresponding to the target security policy, wherein the detection rule set includes multiple detection rules, each of which is used to characterize the abnormal behavior of the user.

19. The device according to claim 18, characterized in that The at least one setting dimension includes a time dimension and / or a resource dimension.

20. The device according to claim 18 or 19, characterized in that The at least one security policy includes an IAM policy and / or an SCP policy.

21. A computing device cluster, characterized in that: comprising at least one computing device, each computing device comprising a processor and a memory; The processor of the at least one computing device is used to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster executes the method according to any one of claims 1 to 7, or executes the method according to any one of claims 8 to 10.

22. A computer program product comprising instructions, characterized in that When the instruction is executed by a computing device cluster, the computing device cluster executes the method according to any one of claims 1 to 7, or executes the method according to any one of claims 8 to 10.

23. A computer-readable storage medium, characterized in that: The method comprises computer program instructions. When the computer program instructions are executed by a computing device cluster, the computing device cluster executes the method according to any one of claims 1 to 7, or executes the method according to any one of claims 8 to 10.