Method, device and system for processing computer network intrusion data

By detecting network intrusion events and using mapping relationship tables to determine the event level and root cause, the problem of difficulty in judging the risk level of network intrusion events is solved, and reasonable resource allocation and efficient solution to the root cause of the event is achieved.

CN120223385APending Publication Date: 2025-06-27YUNNAN UNITED POWER DEV CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510354800.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-25
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

When a network intrusion occurs, it is difficult for staff to quickly and reasonably determine the risk of the incident, resulting in improper resource allocation and inability to effectively solve the root cause problems.

Method used

By detecting network intrusion events, obtaining relevant event information, and using the preset mapping relationship table to determine the event level. If there is no match, the initial level and root cause will be determined based on the event information, vulnerability repair and retesting will be performed, and the mapping relationship table will be updated after success.

Benefits of technology

It has achieved a rapid understanding of the importance of network intrusion incidents, reasonably allocated resources for repair, and improved the efficiency of solving the root causes of network intrusion incidents.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223385A_ABST
    Figure CN120223385A_ABST
Patent Text Reader

Abstract

The invention relates to a method, a device and a system for processing computer network intrusion data. The method comprises the following steps: in response to a detected network intrusion event, obtaining event information associated with the network intrusion event, and based on the event information and a preset first mapping relation table, determining whether an event level matched with an event type exists in the first mapping relation table, and under the condition that the event level matched with the event type does not exist in the first mapping relation table, determining an initial event level and an initial root cause of the network intrusion event based on the event information, and in response to monitoring that the repair operation of the vulnerability associated with the network intrusion event is ended, retesting the network intrusion event, and when the retest result is that the vulnerability is successfully repaired, labeling the network intrusion event based on the initial event level. According to the scheme, the solving efficiency of the root problem of the network intrusion event is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of network security, and in particular to a method, device and system for processing computer network intrusion data. Background Art

[0002] Among the related technologies, computer networks have penetrated widely into various fields, and the importance of network security has become increasingly prominent.

[0003] At present, in the event of a network intrusion, it is usually necessary to promptly repair system vulnerabilities in response to the network intrusion incident. However, in the traditional repair process, it is difficult for staff to effectively and reasonably judge the degree of danger of the network intrusion incident in a timely manner. As a result, when resources are limited, it is impossible to invest corresponding manpower and time costs according to the degree of danger of the network intrusion incident, making it difficult to efficiently solve the root cause of the network intrusion incident. Summary of the invention

[0004] In order to overcome the problems existing in the related art, the present disclosure provides a method, device and system for processing computer network intrusion data.

[0005] According to a first aspect of an embodiment of the present disclosure, a method for processing computer network intrusion data is provided, comprising:

[0006] In response to detecting a network intrusion event, acquiring event information associated with the network intrusion event; the event information includes an event type of the network intrusion event;

[0007] Based on the event information and a preset first mapping relationship table, determining whether there is an event level matching the event type in the first mapping relationship table; the first mapping relationship table includes a mapping relationship between event types and event levels;

[0008] In the case that there is no event level matching the event type in the first mapping relationship table, determining the initial event level and initial root cause of the network intrusion event based on the event information;

[0009] In response to monitoring that a repair operation of a vulnerability associated with the network intrusion event is completed, retesting the network intrusion event to obtain a retest result; the repair operation is a repair operation for the initial root cause;

[0010] When the retest result is that the vulnerability is repaired successfully, the network intrusion event is labeled based on the initial event level, and the mapping relationship between the initial event level and the event type of the network intrusion event is stored in the first mapping relationship table.

[0011] In some embodiments of the present disclosure, when there is no event level matching the event type in the first mapping relationship table, determining the initial event level and the initial root cause of the network intrusion event based on the event information includes:

[0012] If there is no event level matching the event type in the first mapping relationship table, sending the event information and first inquiry information about the event level of the network intrusion event to a terminal device of the first user;

[0013] A first reply message for the first inquiry message sent by a terminal device is received; the first reply message includes an initial event level and an initial root cause input by the first user to the terminal device based on the event information and the first inquiry message.

[0014] In some embodiments of the present disclosure, after determining whether there is an event level matching the event type in the first mapping relationship table based on the event information and the preset first mapping relationship table, the method further includes:

[0015] In the case where there is an event level matching the network intrusion event in the first mapping relationship table, taking the event level matching the event type as a reference level;

[0016] In the case where the event level is not the lowest event level, downgrading the reference level to obtain a downgraded reference level;

[0017] The network intrusion event is labeled with the downgraded reference level, and the first mapping relationship table is updated based on the downgraded reference level.

[0018] In some embodiments of the present disclosure, after the repair operation of the vulnerability associated with the network intrusion event is completed in response to monitoring, the network intrusion event is retested to obtain the retest result, the method further includes:

[0019] When the retest result is that the vulnerability repair fails, the initial event level is upgraded to obtain the upgraded initial event level;

[0020] The network intrusion event is labeled with the upgraded initial event level, and the first mapping relationship table is updated based on the upgraded reference level.

[0021] In some embodiments of the present disclosure, before the repair operation of the vulnerability associated with the network intrusion event is completed in response to monitoring, the network intrusion event is retested to obtain the retest result, the method further includes:

[0022] In the case that there is no event level in the first mapping relationship table that matches the event type, based on the initial event level and a preset second mapping relationship table, determine a target terminal device that matches the initial event level; the target terminal device is the terminal device of a second user who can perform a vulnerability repair operation on the network intrusion event of the initial event level; the second mapping relationship table includes the mapping relationship between the event level and the terminal device;

[0023] In the case that there is an event level in the first mapping relationship table that matches the event type, based on the reference level and the second mapping relationship table, determine a target terminal device that matches the reference level

[0024] Send event information associated with the network intrusion event to the target terminal device, so that the terminal device displays vulnerability repair reminder information to the user on the display screen based on the event information.

[0025] According to a second aspect of the embodiments of the present disclosure, there is provided a processing device for computer network intrusion data, including:

[0026] An acquisition unit, configured to, in response to detecting a network intrusion event, acquire event information associated with the network intrusion event; the event information includes the event type of the network intrusion event;

[0027] A first determination unit, configured to, based on the event information and a preset first mapping relationship table, determine whether there is an event level in the first mapping relationship table that matches the event type; the first mapping relationship table includes the mapping relationship between the event type and the event level;

[0028] A second determination unit, configured to, in the case that there is no event level in the first mapping relationship table that matches the event type, determine the initial event level and the initial root cause of the network intrusion event based on the event information;

[0029] A retest unit, configured to, in response to monitoring that the repair operation of the vulnerability associated with the network intrusion event ends, retest the network intrusion event to obtain a retest result; the repair operation is a repair operation for the initial root cause;

[0030] A tagging unit, configured to, in the case that the retest result is that the vulnerability repair is successful, tag the network intrusion event based on the initial event level, and store the mapping relationship between the initial event level and the event type of the network intrusion event into the first mapping relationship table.

[0031] In the embodiments of the present application, the second determination unit is specifically configured to:

[0032] If there is no event level matching the event type in the first mapping relationship table, sending the event information and first inquiry information about the event level of the network intrusion event to a terminal device of the first user;

[0033] A first reply message for the first inquiry message sent by a terminal device is received; the first reply message includes an initial event level and an initial root cause input by the first user to the terminal device based on the event information and the first inquiry message.

[0034] According to a third aspect of an embodiment of the present disclosure, an electronic device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the method described in any one of the first aspects is implemented.

[0035] According to a fourth aspect of an embodiment of the present disclosure, there is provided a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the method according to any one of the first aspects is implemented.

[0036] According to a fifth aspect of an embodiment of the present disclosure, a computer program product is provided, comprising a computer program, wherein the computer program implements the method as described in any one of the first aspects when executed by a processor.

[0037] The technical solution provided by the embodiments of the present disclosure may include the following beneficial effects: in response to detecting a network intrusion event, obtaining event information associated with the network intrusion event, determining whether there is an event level matching the event type in the first mapping relationship table based on the event information and a preset first mapping relationship table, and in the case where there is no event level matching the event type in the first mapping relationship table, determining the initial event level and initial root cause of the network intrusion event based on the event information, and in response to monitoring that the repair operation of the vulnerability associated with the network intrusion event is completed, retesting the network intrusion event to obtain a retest result, wherein the repair operation is a repair operation for the initial root cause, and in the case where the retest result is that the vulnerability is successfully repaired, labeling the network intrusion event based on the initial event level, and storing the mapping relationship between the initial event level and the event type of the network intrusion event in the first mapping relationship table, so that in the event of a network intrusion event, users can quickly and intuitively understand the importance of the network intrusion event, and reasonably invest corresponding manpower costs and time costs to repair related vulnerabilities according to the importance, thereby improving the efficiency of solving the root cause problems of the network intrusion event.

[0038] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] The accompanying drawings herein are incorporated into and constitute a part of this specification, showing embodiments consistent with the present invention, and are used together with the specification to explain the principles of the present invention.

[0040] Figure 1 It is a flowchart of a method for processing computer network intrusion data shown according to an exemplary embodiment.

[0041] Figure 2 It is a block diagram of an apparatus for processing computer network intrusion data shown according to an exemplary embodiment.

[0042] Figure 3 It is a block diagram of an apparatus for a method for processing computer network intrusion data shown according to an exemplary embodiment. Detailed implementation manners

[0043] Here, the exemplary embodiments will be described in detail, and the examples are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with the present invention. On the contrary, they are merely examples of apparatuses and methods consistent with some aspects of the present invention as detailed in the appended claims.

[0044] The terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments and are not intended to limit the embodiments of the present disclosure. The singular forms "a" and "the" used in the embodiments of the present disclosure and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise.

[0045] It should be understood that although the terms first, second, third, etc. may be used in the embodiments of the present disclosure to describe various information, such information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of the embodiments of the present disclosure, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the words "if" and "when" as used herein may be interpreted as "when" or "while" or "in response to determining".

[0046] In addition, various forms of processes shown in the embodiments of the present disclosure can be used, with steps reordered, added, or deleted. For example, the steps described in the present application can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in the present disclosure can be achieved, and no limitations are imposed herein.

[0047] In the related technologies, computer networks have been widely infiltrated into various fields, and the importance of network security has become increasingly prominent. At present, in the case of network intrusion, it is usually necessary to promptly repair system vulnerabilities in response to network intrusion events. However, in the traditional repair process, it is difficult for staff to effectively and reasonably judge the degree of danger of network intrusion events in a timely manner, resulting in the inability to invest corresponding manpower and time costs according to the degree of danger of network intrusion events under limited resources, making it difficult to efficiently solve the root cause of network intrusion events.

[0048] In order to solve the above problems, the present disclosure provides a method, device and system for processing computer network intrusion data, which obtains event information associated with the network intrusion event in response to detecting a network intrusion event, determines whether there is an event level matching the event type in the first mapping relationship table based on the event information and a preset first mapping relationship table, and determines the initial event level and initial root cause of the network intrusion event based on the event information when there is no event level matching the event type in the first mapping relationship table. In response to monitoring that the repair operation of the vulnerability associated with the network intrusion event is completed, the network intrusion event is retested to obtain a retest result; the repair operation is a repair operation for the initial root cause, and when the retest result is that the vulnerability is repaired successfully, the network intrusion event is labeled based on the initial event level, and the mapping relationship between the initial event level and the event type of the network intrusion event is stored in the first mapping relationship table, so that when a network intrusion event occurs, the user can quickly and intuitively understand the importance of the network intrusion event, and reasonably invest corresponding manpower costs and time costs to repair related vulnerabilities according to the importance, thereby improving the efficiency of solving the root cause of the network intrusion event.

[0049] Figure 1 is a flowchart of a method for processing computer network intrusion data according to an exemplary embodiment. Figure 1 As shown, it should be noted that the method for processing computer network intrusion data in the embodiment of the present disclosure is applied to a computer network intrusion data processing device. Figure 1 As shown, the method may include the following steps:

[0050] Step 101: in response to detecting a network intrusion event, obtaining event information associated with the network intrusion event.

[0051] The event information includes the event type of the network intrusion event.

[0052] In one embodiment, the above event information may further include any one or more of an event title, a relevant department, the event occurrence time, affected assets, and an IP address. For example, the event title is "The company's network is suspected of being hacked", the relevant department is the "Network Security Department", and the occurrence time is accurate to the specific hour, minute, and second. In the part of affected assets, fill in the asset name as "Company's core business server", the asset type as "Physical server", and the IP address as "192.168.1.101". In the part of suspicious objects, add the suspicious file IP "10.10.1.5" and the suspicious domain name "maliciousdomain.com", and describe the suspicious objects, such as "This IP and domain name frequently interacted with the server during the attack period and are suspected to be the hacker control end".

[0053] Step 102: Based on the event information and a preset first mapping relation table, determine whether there is an event level in the first mapping relation table that matches the event type.

[0054] Among them, the first mapping relation table includes the mapping relation between the event type and the event level.

[0055] It can be understood that the mapping relation between the event type and the event level including different network intrusion events can be preset according to historical network intrusion events or according to the actual situation. The first mapping relation table may not cover all possible mapping relations between the event type and the event level.

[0056] Therefore, in some embodiments, it is possible to check in the first mapping relation table whether there is an event level that matches the event type of the detected network intrusion event, that is, to determine whether the first mapping relation table covers the above event type.

[0057] As an example, the event level may include different levels such as low, medium, high, and urgent.

[0058] Step 103: In the case where there is no event level in the first mapping relation table that matches the event type, determine the initial event level and the initial root cause of the network intrusion event based on the event information.

[0059] In some embodiments, in the case where there is no event level in the first mapping relation table that matches the event type, it is necessary to determine the initial event level and the initial root cause of the network intrusion event according to the event information (that is, the specific situation of the network intrusion event).

[0060] In some embodiments, the event information can be input into a trained AI model to obtain the initial event level and the initial root cause output after the AI model analyzes the event information.

[0061] It is understandable that the initial root cause is the fundamental cause that triggers the above network intrusion event based on the analysis and judgment of event information.

[0062] In some embodiments of the present application, step 103 may specifically include:

[0063] In the case where there is no event level in the first mapping table that matches the event type, send the event information and the first inquiry information regarding the event level of the network intrusion event to the terminal device of the first user;

[0064] Receive the first reply information to the first inquiry information sent by the terminal device.

[0065] Wherein, the first reply information includes the initial event level and the initial root cause input by the first user to the terminal device based on the event information and the first inquiry information.

[0066] In one embodiment, in the case where there is no event level in the first mapping table that matches the event type, the first inquiry information may be sent to the terminal device of the first user to inquire the event level of the network intrusion event from the first user based on the event information.

[0067] As an example, after receiving the first inquiry information, the terminal device displays the event information and the first inquiry information on the display screen to the first user. The first user can evaluate the event level of the network intrusion event and the fundamental cause that triggers the network intrusion event based on the event information, and input the initial event level and the initial root cause through the terminal device, that is, the first reply information.

[0068] In one embodiment, after the first user inputs the first reply information to the terminal device, the terminal device sends the first reply information to the server.

[0069] In some embodiments, after receiving the first reply information to the first inquiry information sent by the terminal device, the first reply information and the time information may also be sent to the terminal device of the reviewer for review. The reviewer carefully views the event information, confirms the authenticity of the event through investigation and analysis, fills in the reason for passing "After network traffic analysis and security tool detection, it is confirmed that the server has been hacked, and the event description is consistent with the actual situation", and may also re-evaluate the event level, and then send the review result to the server.

[0070] In addition, other security personnel can quickly query the event on the event query page by selecting the "Emergency" label or setting compound conditions (such as the event level being "Extremely High" and the relevant department being the "Cybersecurity Department"). Click the view button after the event to learn about the details of the event in detail; if you have editing permissions, you can also supplement or modify the event information; click the event chain button to view other events related to this attack event, such as whether there are other events where other servers have been attacked similarly, which is convenient for overall security situation analysis.

[0071] In some embodiments of the present application, after step 102, the method may further include:

[0072] In the case where there is an event level in the first mapping relationship table that matches the network intrusion event, use the event level that matches the event type as the reference level;

[0073] In the case where the event level is not the lowest event level, perform a downgrading process on the reference level to obtain the reference level after the downgrading process;

[0074] Tag the network intrusion event with the reference level after the downgrading process, and update the first mapping relationship table based on the reference level after the downgrading process.

[0075] In one embodiment, in the case where there is an event level in the first mapping relationship table that matches the network intrusion event, it indicates that after the last network intrusion event occurred, the relevant vulnerabilities were repaired according to the repair method corresponding to the initial root cause, and the repair was successful. That is, the true root cause of such network intrusion events has been found, and the relevant vulnerabilities can be effectively repaired according to the root cause. Therefore, the reference level can be downgraded, the network intrusion event can be tagged with the reference level after the downgrading process, and the first mapping relationship table can be updated based on the reference level after the downgrading process. In this way, the rationality of the network tags can be improved, and the rationality of the mapping relationship between the event type and the event level in the first mapping relationship table can be improved.

[0076] In one example, a technician discovered a SQL injection vulnerability while performing vulnerability detection. The technician logged into the system and filled in the vulnerability information on the vulnerability submission page. Fill in "Business System SQL Injection Vulnerability" for the vulnerability name, select "Code Security Vulnerability" for the vulnerability type, the company name for the customer, the name of the business department for the related affiliated unit, "Company Core Business System" for the related information system, "Web Application System" for the system type, and the specific page URL where the vulnerability exists, such as " / login.php", and fill in the known CVE number. Because some repair suggestions are still under study, the technician uses the temporary save function to save the filled in information. After the technician improves the repair suggestions, he opens the temporary vulnerability again for editing, supplements the repair suggestion content, such as "strictly filter and validate user input in the code, and use parameterized queries instead of directly splicing SQL statements", and then submits the vulnerability.

[0077] In addition, the auditor reviews the submitted vulnerabilities. The auditor checks the vulnerability details and related materials to confirm the authenticity of the vulnerability and the feasibility of the repair suggestions. The auditor fills in the reason for passing, "The vulnerability description is clear, the repair suggestions are reasonable and can effectively repair the vulnerability", re-evaluates the threat level to "high", and passes the vulnerability. Vulnerability information is pushed to the corresponding developer responsible for repair according to the event level, and the developer repairs the vulnerability according to the repair suggestions. Auditors have the authority to pass or reject events. When the auditor decides to pass an event, he needs to fill in a detailed reason for passing, such as "After investigation and verification, the event description is true, and the threat situation meets the submitted level", and re-evaluate the threat level of the submitted event. The level can be higher or lower than the original level. The system will perform subsequent processing and sorting of the event according to the new threat level. If the auditor rejects the event, he also needs to fill in the reason for rejection, such as "the event information is incomplete and key evidence is missing". After the rejection, ordinary users will receive a system notification and can re-fill in the relevant content and submit again. The system records the review process in detail, including the auditor, review time, review results and reasons, etc., for subsequent inquiries and audits.

[0078] Step 104, in response to monitoring that the repair operation of the vulnerability associated with the network intrusion event is completed, retesting the network intrusion event to obtain a retest result.

[0079] The repair operation is a repair operation for the initial root cause.

[0080] It is understandable that after the vulnerability associated with the network intrusion event is repaired based on the initial root cause, the network intrusion event needs to be retested to determine whether the vulnerability is successfully repaired and whether the initial root cause is the real root cause.

[0081] In some embodiments, the retest rule can be triggered by default after one week (which can be customized according to actual needs), or the retest time can be manually specified by any person with the corresponding permission. When the retest time arrives, the vulnerability information will be handed over to the tester for retesting. Users can quickly switch between vulnerabilities in different retest statuses in the system, which is convenient for centralized processing of vulnerabilities to be retested or already retested. At the same time, users can configure query conditions through the "query function" and query vulnerabilities according to composite conditions, such as querying vulnerabilities that have not been retested and have a "high" vulnerability level in a specific business system. For vulnerabilities that have not been retested, the user clicks the retest button on the right to perform the retest operation on the vulnerability and fill in the retest feedback, including information such as whether the vulnerability has been repaired, the test results after repair, and whether there are new problems. The system updates the vulnerability status according to the retest feedback. If the vulnerability has been repaired, its status is updated to "repaired".

[0082] In some embodiments of the present application, before step 104, the method may further include:

[0083] Step a1, in the case where there is no event level in the first mapping table that matches the event type, based on the initial event level and a preset second mapping table, determine the target terminal device that matches the initial event level.

[0084] Wherein, the target terminal device is the terminal device of the second user who can perform vulnerability repair operations on network intrusion events of the initial event level; the second mapping table includes the mapping relationship between the event level and the terminal device.

[0085] In one embodiment, in the case where there is no event level in the first mapping table that matches the event type, based on the initial event level, select the target terminal device that matches the initial event level from the second mapping table, that is, the terminal device of the relevant person who can handle the network vulnerabilities of this event level, so that the relevant person can repair the vulnerabilities in a timely and effective manner.

[0086] Step a2, in the case where there is an event level in the first mapping table that matches the event type, based on the reference level and the second mapping table, determine the target terminal device that matches the reference level.

[0087] In one embodiment, based on the reference level, select the target terminal device that matches the reference level from the second mapping table, that is, the terminal device of the relevant person who can handle the network vulnerabilities of this reference level, so that the relevant person can repair the vulnerabilities in a timely and effective manner.

[0088] Step a3, send the event information associated with the network intrusion event to the target terminal device, so that the terminal device displays vulnerability repair reminder information to the user on the display screen based on the event information.

[0089] It should be noted that since the importance and handling difficulty of network intrusion events at different event levels are different, network intrusion events with higher event levels can be assigned to more capable personnel for vulnerability repair. In this way, not only can it be ensured that the vulnerabilities can be repaired, but also the efficiency of vulnerability repair can be improved.

[0090] In some embodiments of the present application, after step 104, the method may further include:

[0091] In the case where the retest result is that the vulnerability repair fails, perform an upgrade process on the initial event level to obtain the upgraded initial event level;

[0092] Tag the network intrusion event with the upgraded initial event level, and update the first mapping relationship table based on the upgraded reference level.

[0093] In one embodiment, since the vulnerability is repaired based on the initial root cause of the network intrusion event, in the case where the retest result is that the vulnerability repair fails, it indicates that the initial root cause is not the actual root cause, that is, the actual root cause of the above network intrusion event has not been found, and the determination of the root cause is difficult. Therefore, an upgrade process can be performed on the initial event level to obtain the upgraded initial event level, tag the network intrusion event with the upgraded initial event level, and update the first mapping relationship table based on the upgraded reference level, that is, replace the event level corresponding to the event type of the above network intrusion event from the initial event level with the upgraded initial event level.

[0094] Step 105, in the case where the retest result is that the vulnerability repair is successful, tag the network intrusion event based on the initial event level, and store the mapping relationship between the initial event level and the event type of the network intrusion event in the first mapping relationship table.

[0095] In one embodiment, in the case where the retest result is that the vulnerability repair is successful, it indicates that the above initial root cause is the real root cause. Tag the network intrusion event based on the initial event level, and store the mapping relationship between the initial event level and the event type of the network intrusion event in the first mapping relationship table.

[0096] In some embodiments, after determining the real event level of the network intrusion event, the real event level can be sent to the user's terminal device so that the user can reasonably allocate time cost and labor cost according to the real event level of the network intrusion event to carry out relevant repair and maintenance work.

[0097] In some embodiments, the user can also set the start time and end time to quickly obtain the detailed information of network intrusion events within this time period. Meanwhile, multiple tags can be provided, such as processed, unprocessed, pending review, etc. By selecting different tags, the user can quickly switch the event lists in different states, facilitating the centralized processing of events in specific states.

[0098] In other embodiments, the user can also utilize the query function to perform combined queries based on multiple conditions. For example, the user can simultaneously set the event level as "high", the relevant department as "Finance Department", and the occurrence time within a specific month, so as to accurately filter out the events that meet these conditions. Four operation options, namely view, edit, view event chain, and delete, are set after each event. The view function is used to display the detailed information of the event, including the basic information of the event, affected assets, suspicious objects, and processing records, etc.; the edit function allows the user to modify the relevant information of the event under certain permissions; the view event chain function can display other events associated with this event to help the user sort out the association relationships between events; the delete function is used to delete the event records that are no longer needed, but the system will perform permission control and recording on the delete operation to ensure the security and traceability of the data.

[0099] According to the method for processing computer network intrusion data proposed by the embodiments of the present disclosure, in response to detecting a network intrusion event, event information associated with the network intrusion event is obtained. Based on the event information and a preset first mapping relationship table, it is determined whether there is an event level matching the event type in the first mapping relationship table. In the case where there is no event level matching the event type in the first mapping relationship table, the initial event level and initial root cause of the network intrusion event are determined based on the event information. In response to monitoring the end of the repair operation for the vulnerability associated with the network intrusion event, a retest of the network intrusion event is performed to obtain a retest result; the repair operation is a repair operation for the initial root cause. In the case where the retest result indicates successful vulnerability repair, the network intrusion event is tagged based on the initial event level, and the mapping relationship between the initial event level and the event type of the network intrusion event is stored in the first mapping relationship table. Thus, in the case of a network intrusion event, it enables the user to quickly and intuitively understand the importance of the network intrusion event, and reasonably invest the corresponding human and time costs according to the importance to repair the relevant vulnerabilities, improving the solution efficiency of the root cause problems of network intrusion events.

[0100] Figure 2 is a block diagram of a device for processing computer network intrusion data shown according to an exemplary embodiment. Referring to Figure 2 , the device includes an acquisition unit 201, a first determination unit 202, a second determination unit 203, a retest unit 204, and a tagging unit 205.

[0101] Among them, an acquisition unit 201 is configured to acquire event information associated with a network intrusion event in response to detecting the network intrusion event; the event information includes the event type of the network intrusion event.

[0102] A first determination unit 202 is configured to determine whether there is an event level matching the event type in a preset first mapping relation table based on the event information and the first mapping relation table; the first mapping relation table includes the mapping relation between the event type and the event level.

[0103] A second determination unit 203 is configured to determine the initial event level and the initial root cause of the network intrusion event based on the event information when there is no event level matching the event type in the first mapping relation table.

[0104] A retest unit 204 is configured to retest the network intrusion event in response to detecting that the repair operation for a vulnerability associated with the network intrusion event ends, and obtain a retest result; the repair operation is a repair operation for the initial root cause.

[0105] A tagging unit 205 is configured to tag the network intrusion event based on the initial event level when the retest result indicates that the vulnerability repair is successful, and store the mapping relation between the initial event level and the event type of the network intrusion event into the first mapping relation table.

[0106] In some embodiments of the present application, the second determination unit 203 may specifically be configured to:

[0107] When there is no event level matching the event type in the first mapping relation table, send the event information and a first inquiry message for the event level of the network intrusion event to the terminal device of the first user.

[0108] Receive a first reply message for the first inquiry message sent by the terminal device; the first reply message includes the initial event level and the initial root cause input by the first user to the terminal device based on the event information and the first inquiry message.

[0109] In some embodiments of the present application, the apparatus may further include:

[0110] A setting unit is configured to use the event level matching the event type as a reference level when there is an event level matching the network intrusion event in the first mapping relation table.

[0111] A downgrading unit is configured to perform a downgrading process on the reference level to obtain a reference level after the downgrading process when the event level is not the lowest event level.

[0112] The tagging unit is further configured to tag the reference level after degradation processing as a network intrusion event, and update the first mapping relationship table based on the reference level after degradation processing.

[0113] In some embodiments of the present application, the apparatus may further include:

[0114] The upgrading unit is configured to perform an upgrading process on the initial event level to obtain an upgraded initial event level when the retest result is a failure in vulnerability repair.

[0115] The tagging unit is further configured to tag the upgraded initial event level as a network intrusion event, and update the first mapping relationship table based on the upgraded reference level.

[0116] In some embodiments of the present application, the apparatus may further include:

[0117] The third determination unit is configured to determine a target terminal device that matches the initial event level based on the initial event level and a preset second mapping relationship table when there is no event level in the first mapping relationship table that matches the event type; the target terminal device is the terminal device of a second user who can perform vulnerability repair operations on the network intrusion event of the initial event level; the second mapping relationship table includes the mapping relationship between the event level and the terminal device.

[0118] The fourth determination unit is configured to determine a target terminal device that matches the reference level based on the reference level and the second mapping relationship table when there is an event level in the first mapping relationship table that matches the event type.

[0119] The sending unit is configured to send event information associated with the network intrusion event to the target terminal device, so that the terminal device displays a vulnerability repair reminder message to the user on the display screen based on the event information.

[0120] Regarding the apparatus in the above embodiments, the specific manner in which each module performs operations has been described in detail in the embodiments related to the method, and will not be elaborated here.

[0121] A processing device for computer network intrusion data according to an embodiment of the present disclosure, by responding to the detection of a network intrusion event, obtains event information associated with the network intrusion event, and based on the event information and a preset first mapping table, determines whether there is an event level matching the event type in the first mapping table. In the case where there is no event level matching the event type in the first mapping table, based on the event information, the initial event level and the initial root cause of the network intrusion event are determined. In response to monitoring the end of the repair operation of the vulnerability associated with the network intrusion event, a retest of the network intrusion event is performed to obtain a retest result; the repair operation is a repair operation for the initial root cause. In the case where the retest result is that the vulnerability repair is successful, the network intrusion event is tagged based on the initial event level, and the mapping relationship between the initial event level and the event type of the network intrusion event is stored in the first mapping table, so that in the case of a network intrusion event, users can quickly and intuitively understand the importance of the network intrusion event, and reasonably invest corresponding human and time costs according to the importance to repair related vulnerabilities, thereby improving the efficiency of solving the root cause problem of network intrusion events.

[0122] Figure 3 It is a block diagram of a device for a method of processing computer network intrusion data shown according to an exemplary embodiment. For example, device 300 may be an electronic device, such as a mobile phone, a computer, a digital broadcast terminal, a messaging device, a game console, a tablet device, a medical device, a fitness device, a personal digital assistant, etc.

[0123] Referring to Figure 3 , device 300 may include one or more of the following components: a processing component 302, a memory 304, a power component 306, a multimedia component 308, an audio component 310, an input / output (I / O) interface 312, a sensor component 314, and a communication component 316.

[0124] The processing component 302 generally controls the overall operation of the device 300, such as operations associated with display, telephone call, data communication, camera operation, and recording operation. The processing component 302 may include one or more processors 320 to execute instructions to complete all or part of the steps of the above method. In addition, the processing component 302 may include one or more modules to facilitate the interaction between the processing component 302 and other components. For example, the processing component 302 may include a multimedia module to facilitate the interaction between the multimedia component 308 and the processing component 302.

[0125] The memory 304 is configured to store various types of data to support the operation of the device 300. Examples of such data include instructions for any application or method operating on the device 300, contact data, phone book data, messages, pictures, videos, and the like. The memory 304 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, a magnetic disk, or an optical disk.

[0126] The power component 306 provides power to the various components of the device 300. The power component 306 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power for the device 300.

[0127] The multimedia component 308 includes a screen that provides an output interface between the device 300 and the user. In some embodiments, the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen can be implemented as a touch screen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. The touch sensors can sense not only the boundaries of a touch or swipe action but also detect the duration and pressure associated with the touch or swipe operation. In some embodiments, the multimedia component 308 includes a front camera and / or a rear camera. When the device 300 is in an operating mode, such as a shooting mode or a video mode, the front camera and / or the rear camera can receive external multimedia data. Each of the front camera and the rear camera can be a fixed optical lens system or have a focal length and optical zoom capabilities.

[0128] The audio component 310 is configured to output and / or input audio signals. For example, the audio component 310 includes a microphone (MIC) that is configured to receive external audio signals when the device 300 is in an operating mode, such as a call mode, a recording mode, and a voice recognition mode. The received audio signals can be further stored in the memory 304 or transmitted via the communication component 316. In some embodiments, the audio component 310 further includes a speaker for outputting audio signals.

[0129] The I / O interface 312 provides an interface between the processing component 302 and a peripheral interface module, which can be a keyboard, a click wheel, buttons, and the like. These buttons can include, but are not limited to: a home button, a volume button, a power button, and a lock button.

[0130] The sensor assembly 314 includes one or more sensors for providing an assessment of various aspects of the status of the device 300. For example, the sensor assembly 314 can detect the on / off state of the device 300, the relative positioning of components, such as components for the display and keypad of the device 300. The sensor assembly 314 can also detect a change in the position of the device 300 or a component of the device 300, the presence or absence of user contact with the device 300, the orientation or acceleration / deceleration of the device 300, and a change in the temperature of the device 300. The sensor assembly 314 can include a proximity sensor configured to detect the presence of nearby objects without any physical contact. The sensor assembly 314 can also include a light sensor, such as a CMOS or CCD image sensor, for use in imaging applications. In some embodiments, the sensor assembly 314 can also include an acceleration sensor, a gyroscope sensor, a magnetic sensor, a pressure sensor, or a temperature sensor.

[0131] The communication component 316 is configured to facilitate communication between the device 300 and other devices in a wired or wireless manner. The device 300 can access a wireless network based on communication standards, such as WiFi, 2G, or 3G, or a combination thereof. In one exemplary embodiment, the communication component 316 receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel. In one exemplary embodiment, the communication component 316 also includes a near field communication (NFC) module to facilitate short-range communication. For example, the NFC module can be implemented based on radio frequency identification (RFID) technology, infrared data association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology, and other technologies.

[0132] In an exemplary embodiment, the device 300 can be implemented by one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components for performing the above-described methods.

[0133] In an exemplary embodiment, a non-transitory computer-readable storage medium including instructions is also provided, such as a memory 304 including instructions that can be executed by a processor 320 of the device 300 to complete the above-described methods. For example, the non-transitory computer-readable storage medium can be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, and an optical data storage device, etc.

[0134] In an exemplary embodiment, a computer program product is also provided, including a computer program that implements the above-described methods when executed by a processor 320 of the device 300.

[0135] Other embodiments of the present invention will be readily apparent to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of the invention following the general principles thereof and including such departures from the present disclosure as come within known or customary practice in the art to which this invention pertains and which are not disclosed herein. The specification and examples are to be considered as illustrative only, and the true scope and spirit of the invention are pointed out by the following claims.

[0136] It should be understood that the present invention is not limited to the exact construction described above and shown in the accompanying drawings, and various modifications and changes may be made without departing from its scope. The scope of the invention is limited only by the appended claims.

Claims

1. A method for processing computer network intrusion data, characterized in that: include: In response to detecting a network intrusion event, acquiring event information associated with the network intrusion event; The event information includes the event type of the network intrusion event; Based on the event information and a preset first mapping relationship table, determining whether there is an event level matching the event type in the first mapping relationship table; the first mapping relationship table includes a mapping relationship between event types and event levels; In the case that there is no event level matching the event type in the first mapping relationship table, determining the initial event level and initial root cause of the network intrusion event based on the event information; In response to monitoring that a repair operation of a vulnerability associated with the network intrusion event is completed, retesting the network intrusion event to obtain a retest result; the repair operation is a repair operation for the initial root cause; When the retest result is that the vulnerability is repaired successfully, the network intrusion event is labeled based on the initial event level, and the mapping relationship between the initial event level and the event type of the network intrusion event is stored in the first mapping relationship table.

2. The method for processing computer network intrusion data according to claim 1, characterized in that: In the case that there is no event level matching the event type in the first mapping relationship table, determining the initial event level and the initial root cause of the network intrusion event based on the event information includes: If there is no event level matching the event type in the first mapping relationship table, sending the event information and first inquiry information about the event level of the network intrusion event to a terminal device of the first user; A first reply message for the first inquiry message sent by a terminal device is received; the first reply message includes an initial event level and an initial root cause input by the first user to the terminal device based on the event information and the first inquiry message.

3. The method for processing computer network intrusion data according to claim 1, characterized in that: After determining whether there is an event level matching the event type in the first mapping relationship table based on the event information and the preset first mapping relationship table, the method further includes: In the case where there is an event level matching the network intrusion event in the first mapping relationship table, taking the event level matching the event type as a reference level; In the case where the event level is not the lowest event level, downgrading the reference level to obtain a downgraded reference level; The network intrusion event is labeled with the downgraded reference level, and the first mapping relationship table is updated based on the downgraded reference level.

4. The method for processing computer network intrusion data according to claim 1, characterized in that: After the repair operation of the vulnerability associated with the network intrusion event is completed in response to monitoring, the network intrusion event is retested to obtain the retest result, the method further includes: When the retest result is that the vulnerability repair fails, the initial event level is upgraded to obtain the upgraded initial event level; The network intrusion event is labeled with the upgraded initial event level, and the first mapping relationship table is updated based on the upgraded reference level.

5. The method for processing computer network intrusion data according to claim 3, characterized in that: Before the repair operation of the vulnerability associated with the network intrusion event is completed in response to monitoring, and the network intrusion event is retested to obtain the retest result, the method further includes: In the case where there is no event level matching the event type in the first mapping relationship table, determining a target terminal device matching the initial event level based on the initial event level and a preset second mapping relationship table; the target terminal device is a terminal device of a second user who can perform vulnerability repair operations on the network intrusion event of the initial event level; the second mapping relationship table includes a mapping relationship between event levels and terminal devices; In the case where there is an event level matching the event type in the first mapping relationship table, determining a target terminal device matching the reference level based on the reference level and the second mapping relationship table. Event information associated with the network intrusion event is sent to the target terminal device, so that the terminal device displays vulnerability repair reminder information to the user on a display screen based on the event information.

6. A computer network intrusion data processing device, characterized in that: include: an acquisition unit, configured to acquire event information associated with the network intrusion event in response to detecting the network intrusion event; The event information includes the event type of the network intrusion event; A first determining unit, configured to determine whether there is an event level matching the event type in the first mapping relationship table based on the event information and a preset first mapping relationship table; the first mapping relationship table includes a mapping relationship between event types and event levels; A second determining unit, configured to determine an initial event level and an initial root cause of the network intrusion event based on the event information if there is no event level matching the event type in the first mapping relationship table; A retest unit, configured to, in response to monitoring that a repair operation of a vulnerability associated with the network intrusion event is completed, retest the network intrusion event to obtain a retest result; The repair operation is a repair operation for the initial root cause; A labeling unit is used to label the network intrusion event based on the initial event level when the retest result is that the vulnerability is repaired successfully, and store the mapping relationship between the initial event level and the event type of the network intrusion event in the first mapping relationship table.

7. The computer network intrusion data processing device according to claim 1, characterized in that: The second determining unit is specifically configured to: If there is no event level matching the event type in the first mapping relationship table, sending the event information and first inquiry information about the event level of the network intrusion event to a terminal device of the first user; A first reply message for the first inquiry message sent by a terminal device is received; the first reply message includes an initial event level and an initial root cause input by the first user to the terminal device based on the event information and the first inquiry message.

8. An electronic device, characterized in that: include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the method according to any one of claims 1 to 5 is implemented.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 5 is implemented.

10. A computer program product, comprising a computer program, characterized in that The computer program implements the method according to any one of claims 1 to 5 when executed by a processor.