Multi-class network security threat perception and active and passive cooperative response processing system and method

By designing a multi-category network security threat perception and active and passive collaborative response and handling system, the problem of insufficient synergy between traditional defense means in the face of complex network threats is solved, and accurate perception and effective response to multiple threats is achieved, improving the efficiency and effectiveness of network security protection.

CN120223394APending Publication Date: 2025-06-27CHINA ELECTRONICS TECH CYBER SECURITY CO LTD +2
View PDF 0 Cites 7 Cited by

Patent Information

Application Number
CN202510374364.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-27
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

When traditional cybersecurity defense methods face complex and changeable cyber threats, it is difficult to form an effective synergy, resulting in insufficient coordination between threat perception and response.

Method used

Design a multi-class network security threat perception and active and passive collaborative response and handling system, including multiple-class threat perception modules, threat information association modules, threat path analysis modules based on attack maps, and policy generation modules. Through the coordinated work of these modules, the perception, analysis and response and handling of multiple network security threats can be realized.

Benefits of technology

The system can more accurately identify and perceive network security threats, achieve rapid response and effective disposal, improve the efficiency and effectiveness of network security protection, and adapt to changes in the development of network technology and the upgrading of attack methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223394A_ABST
    Figure CN120223394A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-class network security threat perception and active and passive cooperative response processing system and method, and the system comprises a multi-class threat perception module which is used for perceiving a plurality of security threats existing in a network environment, and transmitting an obtained security event to a threat information association module; the threat information association module is used for analyzing and integrating various security events and extracting threat information from the security events; the attack graph-based threat path analysis module is used for mining vulnerability information in a network system, describing a network topology structure and an operation state, constructing an attack graph and obtaining active defense nodes in combination with a currently occurring security event and an analysis result of the attack graph; and the strategy generation module generates a corresponding response processing strategy according to the threat information and the property and the emergency degree of the security event, and generates an active defense strategy in combination with the active defense node, thereby realizing active defense and advanced deployment and control of potential threats. According to the invention, network security threats can be timely and effectively found and coped with.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and particularly to a multi-class network security threat perception and active-passive collaborative response and handling system and method. Background Art

[0002] In the field of computer network security, traditional security threat perception methods mainly rely on firewalls, intrusion detection systems, and anti-virus systems. However, with the development of network technology and the continuous upgrading of network attack means, these traditional security defenses gradually show their limitations. A firewall mainly defends against external attacks, but it cannot effectively prevent malicious behaviors or misoperations inside the network; an intrusion detection system may generate false positives or false negatives due to complex network environments and attack means, thus affecting its accuracy and reliability; an anti-virus system mainly relies on known virus signatures for identification and defense; in terms of response and handling, traditional methods mostly rely on simple measures such as installing reliable anti-virus software, setting up firewalls, regularly updating system and application patches, and restricting employees' access rights. Although these defense measures can reduce security risks to a certain extent, there are obvious deficiencies in the coordination of threat perception and response handling, and it is difficult to form an effective joint force to cope with complex and changeable network threats.

[0003] Facing this challenge, the most direct and effective response strategy is to closely combine with the actual needs of business systems on the basis of traditional defense means to build diversified threat perception and collaborative handling methods. These methods can more accurately identify and perceive various network security threats. At the same time, through the close linkage of security events and handling strategies, rapid response and effective handling can be achieved. Summary of the Invention

[0004] In view of this, this application provides a multi-class network security threat perception and active-passive collaborative response and handling system and method.

[0005] This application discloses a multi-class network security threat perception and active-passive collaborative response and handling system, which includes a multi-class threat perception module, a threat information association module, an attack graph-based threat path analysis module, and a policy generation module;

[0006] The multi-class threat perception module is used to perceive various security threats existing in the network environment, identify and extract potential security events, and send the security events to the threat information association module;

[0007] The threat information correlation module is used to parse and integrate various security events captured by multiple threat perception modules, extract threat information from them, and send it to the policy generation module; the threat information includes abnormal users, abnormal ports, abnormal terminals / IPs, abnormal services, abnormal files, attack types, and attacked nodes / IPs;

[0008] The policy generation module is used to generate corresponding response and handling policies based on the threat information and the nature and urgency of security events, and immediately apply them to the network system to achieve passive handling under event triggering;

[0009] The attack graph threat path analysis module is used to mine vulnerability information in the network system, depict the network topology structure and operating status, construct an attack graph, combine the currently occurring security events with the analysis results of the attack graph, obtain active defense nodes, and send them to the policy generation module;

[0010] The policy generation module is also used to generate defense policies for active defense nodes to strengthen the network system, achieve active defense against potential threats, and advance layout and control.

[0011] Furthermore, it also includes a network system deployment analysis module;

[0012] The network system deployment analysis module is used to start from the network topology structure, analyze and display the overall deployment and operation overview of the network system; the overall deployment and operation overview includes software / hardware deployment and status, physical / logical connection and configuration status.

[0013] Furthermore, it also includes a log and traffic acquisition module;

[0014] The log and traffic acquisition module is used to capture log and traffic data from the multi-source heterogeneous environment provided by the network system deployment analysis module; for key nodes in the network system, deploy a traffic monitoring system to capture network traffic in real time; send the obtained network traffic and the processed log and traffic data to multiple threat perception modules.

[0015] Furthermore, the multiple threat perception modules are specifically used for:

[0016] In terms of detecting abnormal user behaviors, by mining and analyzing the collected log data, capture possible abnormal terminals and abnormal user behaviors;

[0017] In terms of detecting network abnormal behaviors, monitor and analyze the operating status of network nodes and services in the network environment; achieve network abnormal behavior detection through traffic analysis and active detection methods; among them, network nodes and services include servers, routing and switching devices, security devices, terminals, and application APPs;

[0018] In terms of malicious traffic detection, by monitoring and analyzing the traffic of network nodes in the network system, it is identified whether there is an attack behavior, and then the specific pattern of the attack is determined;

[0019] In terms of malicious file detection, through hash value checking, file type identification and signature scanning, the file operations of key nodes in the network environment are initially analyzed, and static analysis and dynamic analysis are used for detection. The maliciousness of the file is comprehensively judged through threat information association; File operations include file upload, file download and file transfer;

[0020] In terms of malicious domain name detection, based on open source threat intelligence and DGA detection models, the domain name access operations of network nodes in the network environment are monitored and analyzed, that is, by collecting and analyzing malicious domain name intelligence, constructing a database, and then comparing the database. If there is a match, an alarm is issued. If there is no match, the DGA detection model is used for in-depth analysis to identify whether there is the use of malicious domain names; Domain name access operations include DNS queries, HTTP requests and mail link clicks.

[0021] Furthermore, the attack graph threat path analysis module is specifically used for:

[0022] Through the active detection of the network system deployment situation, vulnerability information, topology structure and operating status are obtained. According to the vulnerability information, topology structure and operating status, an attack graph is constructed. Based on the attack graph, potential threat paths are analyzed, and weak nodes and key nodes in the threat paths are identified. Nodes that need active defense are obtained from the weak nodes and key nodes in the threat paths;

[0023] At the same time, during the analysis of the threat path, based on the threat information generated by the threat information association module, the nodes, edges and the threat or threatened situation of the nodes themselves or between nodes in the attack graph are assisted in being revised.

[0024] Furthermore, the policy generation module is specifically used for:

[0025] According to the threat information sent by the threat information association module and the nodes that need active defense obtained through the threat path analysis using the attack graph, corresponding disposal methods and strategies are obtained.

[0026] Furthermore, the operation modes of the policy generation module include automatic disposal and manual disposal;

[0027] The automatic disposal mode is used to realize the instant identification and response to network threats, and the preset defense strategies can be automatically executed without manual intervention;

[0028] The manual disposal mode is used to manually adjust or execute the specified defense strategies according to the actual situation and specific requirements.

[0029] The present application also discloses a multi-class network security threat perception and active-passive collaborative response and handling method, which is applicable to the multi-class network security threat perception and active-passive collaborative response and handling system described above, and includes:

[0030] The multi-class threat perception module perceives various security threats existing in the network environment, identifies and extracts potential security events, and sends the security events to the threat information association module; various potential threats include abnormal user behaviors, network abnormal behaviors, malicious traffic, malicious files, and malicious domain names;

[0031] The threat information association module parses and integrates various security events captured by the multi-class threat perception module, extracts threat information from them, and sends it to the policy generation module; the threat information includes abnormal users, abnormal ports, abnormal terminals / IPs, abnormal services, abnormal files, attack types, and attacked nodes / IPs;

[0032] The policy generation module generates corresponding response and handling policies according to the threat information and the nature and urgency of the security events, and applies them to the network system to achieve passive handling under event triggering;

[0033] Based on the attack graph threat path analysis module, it mines vulnerability information in the network system, depicts the network topology structure and operating status, constructs an attack graph, combines the current security events with the analysis results of the attack graph, obtains active defense nodes, and sends them to the policy generation module;

[0034] The policy generation module also generates defense policies for the active defense nodes to strengthen the network system, so as to achieve active defense against potential threats and advance layout and control.

[0035] Due to the adoption of the above technical solutions, the present application has the following advantages:

[0036] 1. By designing multi-class threat perception methods such as user anomaly detection, network anomaly detection, malicious traffic, malicious domain names, and malicious files, the present application can perceive various security threats in the network more comprehensively and accurately, and discover potential security risks in a timely manner.

[0037] 2. The threat perception method and collaborative handling method designed in the present application have good adaptability and scalability. With the continuous development of network technology and the continuous upgrading of network attack means, the present application can continuously maintain the defense ability against new security threats by updating and expanding the threat perception model and handling policies.

[0038] 3. This application designs a collaborative disposal system that combines passive defense driven by security events and active defense based on attack graph threat paths. The system can quickly and accurately take corresponding disposal measures according to different types of security events, effectively cut off the attack chain, and prevent the spread and spread of security threats.

[0039] 4. This application can reduce operation and maintenance costs and alleviate the workload of operation and maintenance personnel through automated and intelligent threat perception and disposal methods.

[0040] 5. Based on traditional defense methods, this application designs multiple threat perception requirements and execution processes such as user anomaly detection, network anomaly detection, malicious traffic, malicious domain names, and malicious files, and designs a collaborative disposal method that combines passive defense driven by security events with active defense based on attack graph threat paths. This method can not only expand the perception capability of network security threats, but also enhance the coordination and effectiveness of response disposal, providing a feasible and effective system configuration solution for the discovery and response of network security threats. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the embodiments of the present application. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.

[0042] Figure 1 This is a block diagram of a multi-type network security threat perception and active and passive coordinated response and disposal system according to an embodiment of the present application. DETAILED DESCRIPTION

[0043] The present application is further described in conjunction with the accompanying drawings and embodiments, and the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by ordinary technicians in this field should fall within the scope of protection of the embodiments of the present application.

[0044] For cybersecurity threat perception and response issues, see Figure 1 , the present application proposes an embodiment of a multi-class network security threat perception and active and passive coordinated response disposal system, which includes a multi-class threat perception module, a threat information association module, an attack graph-based threat path analysis module, and a strategy generation module;

[0045] The multi-type threat perception module is used to perceive various security threats in the network environment, identify and extract potential security events, and send the security events to the threat information association module;

[0046] The threat information correlation module is used to parse and integrate various security events captured by multiple types of threat perception modules, extract threat information from them, and send it to the policy generation module; the threat information includes abnormal users, abnormal ports, abnormal terminals / IPs, abnormal services, abnormal files, attack types, and attacked nodes / IPs;

[0047] The policy generation module is used to generate corresponding response and handling policies according to the threat information and the nature and urgency of security events, and immediately apply them to the network system to achieve passive handling under event triggering;

[0048] The attack graph threat path analysis module based on is used to mine vulnerability information in the network system, depict the network topology structure and operating status, construct an attack graph, combine the analysis results of the current security events and the attack graph, obtain active defense nodes, and send them to the policy generation module;

[0049] The policy generation module is also used to generate defense policies for active defense nodes to strengthen the network system, so as to achieve active defense against potential threats and advance layout and control.

[0050] This application designs multiple types of threat perception requirements and execution processes such as user anomaly detection, network anomaly detection, malicious traffic detection, malicious domain name detection, and malicious file detection, and designs a collaborative handling method that combines passive defense driven by security events and active defense based on the attack graph threat path for response handling problems.

[0051] The overall functions that this application can achieve include: First, it realizes the perception of multiple types of network threats such as abnormal user behaviors, network abnormal behaviors, malicious domain names, malicious files, and malicious traffic; Second, it realizes fine-grained dynamic response handling driven by multiple types of security events; Third, it realizes active defense based on attack graph threat path analysis, and collaborates with event-driven passive defense to improve the accuracy and effectiveness of active defense.

[0052] This application also designs an active defense method, that is: through active detection technology, it deeply mines the vulnerability information in the network system, accurately depicts the network topology structure and operating status, and on this basis, constructs a detailed attack graph, and then combines the analysis results of the current security events and the attack graph to analyze key active defense nodes. Subsequently, the policy generation module comes into play again, generates specific and targeted defense policies for these defense nodes, and strengthens the network system, so as to achieve active defense against potential threats and advance layout and control.

[0053] The embodiment of this application also includes a network system deployment analysis module:

[0054] Starting from the network topology structure, the network system deployment analysis module deeply analyzes and comprehensively presents the overall deployment and operation overview of the concerned network system, including: software / hardware deployment and status, and physical / logical connection and configuration status. Among them, the software / hardware deployment and status include: device model, software version, operating system version, port opening status, service running status, etc.; the physical / logical connection and configuration status include: firewall configuration policy, routing and switching device configuration policy, IP address allocation, subnet division, routing protocol, system authentication method, etc.; this information provides basic support for the implementation of subsequent modules.

[0055] The embodiment of this application also includes a log and traffic acquisition module:

[0056] The log and traffic acquisition module focuses on efficiently capturing key log and traffic data from a multi-source heterogeneous environment, widely covering key information sources such as business system logs, application logs, security device logs, and network device logs, ensuring that every detail of network activities is captured without omission. At the same time, for key nodes in the network system, this module needs to carefully deploy a traffic monitoring system to capture network traffic in real time. The collected log and traffic data, after being carefully sorted and preprocessed, are input into subsequent multiple threat perception modules for in-depth mining and comprehensive analysis to accurately identify security events.

[0057] Multiple threat perception modules in the embodiment of this application:

[0058] As the cornerstone and core component of the entire network security architecture, the multiple threat perception modules can rely on diversified and highly accurate detection technologies and strategies to achieve comprehensive, in-depth perception and accurate identification of various potential threats in the network environment, and output specific security events. Its functions cover security monitoring in multiple dimensions such as user abnormal behavior, network abnormal behavior, malicious traffic, malicious files, and malicious domains. The design of each threat detection is as follows:

[0059] 1) In terms of user anomaly detection, by deeply mining and analyzing the collected log data, it keenly captures possible abnormal terminal and abnormal user behaviors. For example, when there are abnormal situations such as multiple users logging in to a single terminal frequently, the same user logging in at different locations simultaneously, and users accessing the terminal illegally during non-working hours. User anomaly detection can be achieved by defining and executing complex association rules;

[0060] 2) In terms of network anomaly detection, it focuses on real-time monitoring and analysis of the operating status of important nodes and services (such as servers, routing and switching devices, security devices, terminals, and application APPs, etc.) in the network environment. It mainly detects whether there are abnormal conditions such as interruptions and delays in network nodes and services, and whether there are situations such as unauthorized enabling, a large number of accesses, and access at unauthorized times for services. Network anomaly detection can be achieved through traffic analysis (such as the size, frequency, traffic pattern, connection pattern, and protocol usage of data packets) and active probing (such as performing active probing operations like Ping tests and Telnet tests to monitor the network connectivity and service status in real time);

[0061] 3) In terms of malicious traffic detection, by continuously monitoring and analyzing the traffic of important nodes in the network system, it accurately identifies whether there is an attack behavior and further determines the specific pattern of the attack. Specifically, in implementation, an advanced autoencoder technology can be used to build a malicious traffic anomaly detection model for learning the characteristics of normal traffic and accurately identifying abnormal traffic based on this. At the same time, in order to identify known attack patterns, a deep learning model can be used to build a deep traffic feature mining algorithm for extracting deep features in traffic data and matching them with known attack patterns;

[0062] 4) In terms of malicious file detection, it focuses on continuously monitoring and deeply analyzing file operations (such as uploading, downloading, transferring, etc.) of key nodes in the network environment, aiming to accurately determine whether there is an intrusion of malicious files. Specifically, in implementation, preliminary analysis can be carried out through hash value checking, file type identification, and signature scanning, and then in-depth detection can be carried out using static analysis (such as gray-level co-occurrence matrix, GIST algorithm, abstract model) and dynamic analysis (sandbox, virtualization environment, heuristic scanning), and finally, the maliciousness of the file is comprehensively judged through threat information association;

[0063] 5) In terms of malicious domain name detection, it focuses on continuously monitoring and deeply analyzing domain name access operations (such as DNS queries, HTTP requests, email link clicks, etc.) of key nodes in the network environment, aiming to accurately identify whether there is the use of malicious domain names. Specifically, it can be implemented based on open-source threat intelligence and DGA detection models, that is: by collecting and analyzing malicious domain name intelligence to build a database, and then when detecting malicious domain names, first quickly compare with the database, raise an alarm if there is a match, and use the DGA detection model for in-depth analysis if there is no match.

[0064] The threat information association module of the embodiment of the present application:

[0065] The threat information correlation module deeply analyzes and integrates various security events captured by multiple threat perception modules, and extracts threat information crucial for the security situation from them. This information covers multiple dimensions, including but not limited to abnormal users, abnormal ports, abnormal terminals / IPs, abnormal services, abnormal files, attack types, attacked nodes / IPs, and so on. By comprehensively collecting and sorting out this information, the threat information correlation module can not only provide a clear and comprehensive threat view for the security team, but also support the subsequent policy generation module to formulate more accurate and effective security protection policies.

[0066] The attack graph-based threat path analysis module of the embodiment of the present application:

[0067] The attack graph-based threat path analysis module actively probes the deployment of the network system to obtain vulnerability information (vulnerability ID, vulnerability type, vulnerability description, vulnerability CVSS score, etc.), topological structure and operating status, and then uses advanced algorithms and technologies to construct an attack graph (such as a Bayesian attack graph, which not only shows the attack path, but also introduces probability factors through a Bayesian network, making the analysis more accurate and in-depth), so as to analyze possible threat paths and accurately identify weak nodes and key nodes in these paths (weak nodes refer to nodes with great vulnerability hazards and are easily attacked, while key nodes play an important role in the network, and once attacked, may cause major losses to the entire system), and obtain the nodes that need active defense. At the same time, when analyzing the threat path, it is also necessary to consider the threat information generated by the threat information correlation module to assist in revising the threats or threatened situations of nodes, edges, and nodes themselves or between nodes in the attack graph.

[0068] The policy generation module of the embodiment of the present application:

[0069] The strategy generation module plays a crucial role in the network defense system. Based on the detailed threat intelligence provided by the threat information correlation module and the defense node information determined through the attack graph threat path analysis, it carefully selects and formulates the most appropriate disposal methods and strategies. These strategies are designed to directly act on the software and hardware facilities in the network system, or the connection configuration parameters at the physical and logical levels, so as to ensure that the network can flexibly respond to various security challenges. This module skillfully integrates the event-driven passive defense method and the active defense method based on the attack graph threat path analysis, achieving collaborative response and efficient disposal between the two. In terms of passive defense, the module can immediately respond to security events in the network. According to the specific nature and impact scope of the events, it quickly takes necessary defense measures to contain the further spread of threats. At the active defense level, the module can rely on the potential threat paths revealed by the attack graph, anticipate and lock in possible attack targets in advance, and then adopt forward-looking defense strategies to effectively reduce the risk of the network being attacked.

[0070] In terms of specific implementation, the strategy generation module provides two flexible operation modes: automatic disposal and manual disposal. The automatic disposal mode can rely on advanced automation technologies to achieve instant identification and rapid response to network threats, and automatically execute the preset defense strategies without manual intervention. The manual disposal mode gives security managers greater operation freedom, and they can manually adjust or execute specific defense strategies according to the actual situation and specific requirements to ensure the absolute security of the network. In terms of the selection of disposal strategies, defense means such as restricting terminal / user login, interrupting services / ports / networks, restricting file propagation / upload / download, vulnerability repair, and generating alarms are designed. The selection and execution of these strategies are all based on in-depth analysis and accurate judgment of network threats, aiming to protect the safe and stable operation of the network system in the most effective way.

[0071] This application also discloses an embodiment of a multi-class network security threat perception and active-passive collaborative response disposal method, which is applicable to the multi-class network security threat perception and active-passive collaborative response disposal system described in the above embodiment, and includes:

[0072] The multi-class threat perception module perceives various security threats existing in the network environment, identifies and extracts potential security events, and sends the security events to the threat information correlation module; various potential threats include abnormal user behaviors, network abnormal behaviors, malicious traffic, malicious files, and malicious domain names;

[0073] The threat information correlation module analyzes and integrates various security events captured by the multi-class threat perception module, extracts threat information from them and sends it to the strategy generation module; the threat information includes abnormal users, abnormal ports, abnormal terminals / IPs, abnormal services, abnormal files, attack types, and attacked nodes / IPs;

[0074] Based on the threat information and the nature and urgency of security incidents, the policy generation module generates corresponding response and handling policies and applies them to the network system to achieve passive handling triggered by events.

[0075] Based on the attack graph threat path analysis module, it mines vulnerability information in the network system, depicts the network topology structure and operating status, constructs an attack graph, combines the currently occurring security incidents with the analysis results of the attack graph, obtains active defense nodes and sends them to the policy generation module.

[0076] The policy generation module also generates defense policies for the active defense nodes to strengthen the network system, so as to achieve active defense against potential threats and advance layout and control.

[0077] This application designs a collaborative response and handling system that combines various threat perceptions such as user anomaly detection, network anomaly detection, malicious traffic detection, malicious domain name detection, and malicious file detection, as well as passive defense driven by security incidents and active defense based on attack graph threat path analysis, effectively solving the problems of perception, recognition, response and handling of diverse security threats in the network environment, and improving the efficiency and effect of network security protection.

[0078] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application and not to limit them. Although this application has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that: the specific implementation manners of this application can still be modified or equivalently replaced, and any modification or equivalent replacement that does not depart from the spirit and scope of this application shall be covered by the protection scope of the claims of this application.

Claims

1. A multi-type network security threat perception and active and passive coordinated response and disposal system, characterized in that: It includes multiple threat perception modules, threat information association modules, attack graph-based threat path analysis modules, and strategy generation modules; The multi-type threat perception module is used to perceive various security threats in the network environment, identify and extract potential security events, and send the security events to the threat information association module; various potential threats include abnormal user behavior, abnormal network behavior, malicious traffic, malicious files and malicious domain names; The threat information association module is used to parse and integrate various security events captured by multiple threat perception modules, extract threat information from them and send it to the policy generation module; threat information includes abnormal users, abnormal ports, abnormal terminals / IPs, abnormal services, abnormal files, attack types and attacked nodes / IPs; The strategy generation module is used to generate corresponding response and disposal strategies based on threat information and the nature and urgency of security events, and apply them to the network system to achieve passive disposal under event triggering; The threat path analysis module based on the attack graph is used to mine vulnerability information in the network system, depict the network topology and operation status, build an attack graph, and combine the current security events with the analysis results of the attack graph to obtain the active defense node and send it to the strategy generation module; The strategy generation module is also used to generate defense strategies for active defense nodes to reinforce the network system, achieve active defense against potential threats, and implement early layout and control.

2. The multi-type network security threat perception and active and passive coordinated response and disposal system according to claim 1 is characterized in that: It also includes a network system deployment analysis module; The network system deployment analysis module is used to analyze and display the overall deployment and operation profile of the network system based on the network topology structure; the overall deployment and operation profile includes software / hardware deployment and status, physical / logical connection and configuration status.

3. The multi-type network security threat perception and active and passive coordinated response and disposal system according to claim 1 is characterized in that: It also includes log and traffic acquisition modules; The log and traffic acquisition module is used to capture log and traffic data from the multi-source heterogeneous environment provided by the network system deployment analysis module; deploy a traffic monitoring system to capture network traffic at key nodes in the network system; and send the acquired network traffic and processed log and traffic data to multiple types of threat perception modules.

4. The multi-type network security threat perception and active and passive coordinated response and disposal system according to claim 1 is characterized in that: Multiple threat perception modules are specifically used for: In terms of abnormal user behavior detection, we can capture possible abnormal terminals and abnormal user behaviors by mining and analyzing the collected log data; In terms of network abnormal behavior detection, the operating status of related equipment in the network environment is monitored and analyzed; network abnormal behavior detection is achieved through traffic analysis and active detection; the related equipment includes servers, routing switching equipment, security equipment, terminals and application APPs; In terms of malicious traffic detection, by monitoring and analyzing the traffic of network nodes in the network system, we can identify whether there is an attack behavior and then determine the specific form of the attack; In terms of malicious file detection, the file operations of network nodes in the network environment are preliminarily analyzed through hash value checking, file type identification and signature scanning, and static and dynamic analysis are used for detection. The maliciousness of the file is comprehensively judged through threat information association. File operations include file uploading, file downloading and file transfer. In terms of malicious domain name detection, domain name access operations of network nodes in the network environment are monitored and analyzed based on open source threat intelligence and DGA detection models. That is, by collecting and analyzing malicious domain name intelligence, building a database, and then comparing the database, an alarm is issued if there is a match, otherwise the DGA detection model is used for analysis to identify whether a malicious domain name is used; domain name access operations include DNS queries, HTTP requests, and email link clicks.

5. The multi-type network security threat perception and active and passive coordinated response and disposal system according to claim 1 is characterized in that: The attack graph-based threat path analysis module is specifically used for: Through active detection of network system deployment, vulnerability information, topology structure and operation status are obtained; based on the vulnerability information, topology structure and operation status, an attack graph is constructed, and potential threat paths are analyzed based on the attack graph, and weak nodes and key nodes in the threat path are identified, and nodes that need active defense are obtained from the weak nodes and key nodes in the threat path; When analyzing the threat path, based on the threat information provided by the threat information association module, the nodes, edges, and threats or threats to the nodes themselves or between the nodes in the attack graph are assisted and adjusted.

6. The multi-type network security threat perception and active and passive coordinated response and disposal system according to claim 1 is characterized in that: The strategy generation module is specifically used for: According to the threat information sent by the received threat information association module and the nodes that need active defense obtained by threat path analysis through the attack graph, the corresponding disposal methods and strategies are obtained.

7. The multi-type network security threat perception and active and passive coordinated response and disposal system according to claim 1 is characterized in that: The operation modes of the strategy generation module include automatic disposal and manual disposal; The automatic disposal mode is used to achieve instant identification and response to network threats, and automatically execute the preset defense strategy without human intervention; The manual handling mode is used to manually adjust or execute the specified defense strategy according to the actual situation and specific needs.

8. A method for multi-type network security threat perception and active and passive coordinated response, applicable to the multi-type network security threat perception and active and passive coordinated response system according to any one of claims 1 to 7, characterized in that: include: The multi-type threat perception module perceives various security threats in the network environment, identifies and extracts potential security events, and sends the security events to the threat information association module; various potential threats include abnormal user behavior, abnormal network behavior, malicious traffic, malicious files and malicious domain names; The threat information association module analyzes and integrates various security events captured by multiple threat perception modules, extracts threat information from them and sends it to the policy generation module; threat information includes abnormal users, abnormal ports, abnormal terminals / IPs, abnormal services, abnormal files, attack types and attacked nodes / IPs; The strategy generation module generates corresponding response and disposal strategies based on threat information and the nature and urgency of security incidents, and applies them to the network system to achieve passive disposal under event triggering; Based on the attack graph threat path analysis module, the vulnerability information in the network system is mined, the network topology and operation status are depicted, and the attack graph is constructed. The active defense node is obtained and sent to the strategy generation module by combining the current security events with the analysis results of the attack graph; The strategy generation module also generates defense strategies for active defense nodes to reinforce the network system, achieve active defense against potential threats, and implement advance layout and control.

Citation Information

Cited By

  • Security protection system based on power system information communication network

    CN120768673A

  • Multi-modal fusion network situation awareness method and system

    CN120811699A

  • Intelligent decision-making method and device for coping with network attack and medium

    CN121125171A

  • Self-adaptive security event response method and system based on AI intelligent agent

    CN121239471A

  • Industrial network protection method, electronic equipment, machine readable storage medium and product

    CN121727840A