Threat detection method and device based on risk score

By establishing a risk assessment rule base based on compliance behavior and threat characteristics, combining real-time status and historical operation records, efficient identification of unknown threats is achieved, false alarm rates and missed rates are reduced, and the accuracy of threat detection is improved.

CN120238319APending Publication Date: 2025-07-01RICHFIT INFORMATION TECH +1
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202311830381.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-28
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

Existing threat detection methods have high underreport rates when facing unknown threats and are difficult to effectively identify differences between compliance behavior and threat characteristics.

Method used

By establishing a risk assessment rule base based on compliance behavior and threat characteristics, combining real-time status records and historical operation records, double searching is performed, risk values ​​are obtained, and threat detection results are determined based on the preset alarm threshold range.

Benefits of technology

It improves the recognition rate of unknown threats, reduces the false alarm rate and missed alarm rate, and enhances the perception of the overall security situation and the accuracy of threat detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238319A_ABST
    Figure CN120238319A_ABST
Patent Text Reader

Abstract

The invention discloses a threat detection method and device based on risk scoring, and the method comprises the steps: building a risk evaluation rule library based on the obtained compliance behaviors and threat features; establishing a real-time state record based on an entity in the obtained to-be-detected security log; performing information enhancement on the to-be-detected security log based on the real-time state record to obtain a rich security log; establishing a historical operation record based on operations in the enriched security log; based on the risk assessment rule base, retrieving the real-time state record and the historical operation record to obtain a risk value; and obtaining a threat detection result according to the risk value and a preset alarm threshold range.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular, to a threat detection method and device based on risk scoring. Background Art

[0002] In today's information security field, the attack and defense confrontation is constantly evolving, and attack techniques and tactics have developed rapidly. There are mainly two methods: traditional threat detection methods and machine learning-based methods.

[0003] Traditional threat detection methods adopt a traditional paradigm of feature extraction and rule writing. This method extracts features from threat behaviors and then writes detection rules based on these features to identify known threat patterns. Machine learning-based threat detection methods learn the features of threats from a large amount of data through model training. Among them, supervised learning algorithms can be trained with labeled data to enable the model to distinguish normal and abnormal behaviors, and unsupervised learning algorithms can be applied to scenarios such as mutations and interruptions of periodic or continuous data, so as to better discover potential threats. Summary of the Invention

[0004] In order to obtain a more accurate and better threat detection method, embodiments of the present invention provide a threat detection method and device based on risk scoring.

[0005] In a first aspect, embodiments of the present invention provide a threat detection method based on risk scoring, the method comprising:

[0006] Establish a risk assessment rule base based on the obtained compliance behaviors and threat features;

[0007] Establish a real-time status record based on the entities in the security log to be detected obtained;

[0008] Enhance the information of the security log to be detected based on the real-time status record to obtain an enriched security log;

[0009] Establish a historical operation record based on the operations in the enriched security log;

[0010] Retrieve the real-time status record and the historical operation record based on the risk assessment rule base to obtain a risk value;

[0011] Obtain a threat detection result according to the risk value and a preset alarm threshold range.

[0012] In one or some optional implementation manners of the embodiments of the present application, the compliance behaviors and threat features respectively include a plurality of real-time status descriptions and a plurality of historical operation descriptions; wherein, establishing a risk assessment rule base based on the obtained compliance behaviors and threat features includes:

[0013] Based on multiple real-time elements and state risk values described by each of the real-time states, corresponding real-time state rules are extracted;

[0014] Based on the sequence information and operation risk values of multiple events described by each of the historical operations, corresponding historical operation rules are extracted; each of the events includes multiple operation elements;

[0015] Based on all the obtained real-time state rules and all the historical operation rules, the risk assessment rule library is obtained.

[0016] In one or some alternative embodiments of the embodiments of the present application, after obtaining the risk assessment rule library, it further includes:

[0017] If new compliance behaviors and / or new threat features are obtained, determine the real-time state rules and / or historical operation rules corresponding to the new compliance behaviors, and / or the real-time state rules and / or historical operation rules corresponding to the new threat features, and update them to the risk assessment rule library.

[0018] In one or some alternative embodiments of the embodiments of the present application, the risk assessment rule library includes multiple compliance behavior rules and multiple threat feature rules; based on the risk assessment rule library, retrieving the real-time state record and the historical operation record to obtain a risk value includes:

[0019] Retrieve the real-time state record and the historical operation record respectively based on each real-time state rule and each historical operation rule among all the compliance behavior rules in the risk assessment rule library to obtain retrieval results;

[0020] Judge whether the retrieval result is empty:

[0021] If so, the risk value is zero;

[0022] If not, retrieve the real-time state record and the historical operation record respectively based on each real-time state rule and each historical operation rule among all the threat feature rules in the risk assessment rule library to obtain the risk value.

[0023] In one or some alternative embodiments of the embodiments of the present application, the retrieving the real-time state record and the historical operation record respectively based on each real-time state rule and each historical operation rule among all the threat feature rules in the risk assessment rule library to obtain a risk value includes:

[0024] Retrieve the real-time status record and the historical operation record respectively according to each real-time status rule and each historical operation rule among all threat feature rules in the risk assessment rule library, and obtain a threat retrieval result;

[0025] Determine whether the threat retrieval result is empty:

[0026] If so, the risk value is a preset value;

[0027] If not, the risk value is the status risk value of the real-time status rule corresponding to the threat retrieval result, or the operation risk value of the historical operation rule.

[0028] In one or some alternative embodiments of the embodiments of the present application, it further includes:

[0029] Obtain a load risk value based on the security factor of the real-time elements in the real-time status record;

[0030] Calculate an optimized risk value based on the risk value and the load risk value.

[0031] In one or some alternative embodiments of the embodiments of the present application, after establishing a real-time status record based on the entity in the obtained security log to be detected, it further includes:

[0032] Obtain the historical record associated with the user identifier according to the user identifier in the security log to be detected;

[0033] Add the data related to the security log to be detected in the historical record to the real-time status record.

[0034] In one or some alternative embodiments of the embodiments of the present application, the information enhancement of the security log to be detected based on the real-time status record to obtain a rich security log includes:

[0035] Obtain the relevant logs of each real-time element according to multiple real-time elements in the real-time status record;

[0036] Add the associated elements in each relevant log to the security log to be detected according to the standard fields to obtain a rich security log.

[0037] In a second aspect, an embodiment of the present invention provides a threat detection device based on risk scoring, and the device includes:

[0038] A first establishment module, configured to establish a risk assessment rule library based on the obtained compliance behaviors and threat features;

[0039] An entity status module, configured to establish a real-time status record based on the entity in the obtained security log to be detected;

[0040] A first enhancement module for enhancing information of the security log to be detected based on the real-time status record to obtain an enriched security log;

[0041] A historical operation module for establishing a historical operation record based on operations in the enriched security log;

[0042] A first acquisition module for retrieving the real-time status record and the historical operation record based on the risk assessment rule library to obtain a risk value;

[0043] A second acquisition module for obtaining a threat detection result according to the risk value and a preset alarm threshold range.

[0044] In a third aspect, an embodiment of the present invention provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the above-mentioned threat detection method based on risk scoring is implemented.

[0045] In a fourth aspect, an embodiment of the present invention provides a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the above-mentioned threat detection method based on risk scoring is implemented.

[0046] In a fifth aspect, an embodiment of the present invention provides a computer program product containing instructions. When the computer program product runs on a computer device, the computer device is enabled to execute the above-mentioned threat detection method based on risk scoring.

[0047] In a sixth aspect, an embodiment of the present invention provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor, and the processor is used to run a computer program or instruction to implement the above-mentioned threat detection method based on risk scoring.

[0048] The beneficial effects of the above technical solutions provided by the embodiments of the present invention at least include:

[0049] The threat detection method based on risk scoring provided by the embodiments of the present invention, by establishing a risk assessment rule library based on compliance behaviors and threat characteristics, can cover more risk factors compared with the existing methods that only establish rules based on threat characteristics, realizes dual retrieval of compliance behaviors and threat characteristics, increases the probability of identifying unknown threats, and reduces the false alarm rate and missed alarm rate. By establishing a real-time status record based on the security log to be detected, enhancing the information of the real-time status record, and then establishing a historical operation record according to the enriched security log, the enriched security log contains more context information, and the historical operation record can comprehensively analyze multiple related events, improving the perception of the overall security situation, and effectively improving the accuracy and credibility of threat detection.

[0050] Other features and advantages of the present invention will be described in the following specification, and, in part, will become apparent from the specification or will be understood by practicing the present invention. The objectives and other advantages of the present invention can be achieved and obtained by the structures specifically pointed out in the written specification, claims, and drawings.

[0051] The technical solutions of the present invention will be further described in detail below with reference to the drawings and embodiments. Description of the Drawings

[0052] The drawings are used to provide a further understanding of the present invention and constitute a part of the specification. They are used together with the embodiments of the present invention to explain the present invention and do not constitute a limitation to the present invention. In the drawings:

[0053] Figure 1 is a schematic diagram of the steps of a threat detection method based on risk scoring provided by an embodiment of the present invention;

[0054] Figure 2 is a schematic flowchart of a threat detection method based on risk scoring provided by an embodiment of the present invention;

[0055] Figure 3 is a schematic diagram of a threat detection module provided by an embodiment of the present invention;

[0056] Figure 4 is a schematic structural diagram of a threat detection device based on risk scoring provided by an embodiment of the present application. Detailed Embodiments

[0057] In the following description, specific details such as specific system structures and technologies are presented for the purpose of illustration rather than limitation, so as to thoroughly understand the embodiments of the present application. However, those skilled in the art should understand that the present application can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid unnecessary details from interfering with the description of the present application.

[0058] It should be understood that when used in the specification and appended claims of the present application, the term "comprising" indicates the presence of the described features, wholes, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their combinations.

[0059] It should also be understood that the term "and / or" used in the specification and appended claims of the present application refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations.

[0060] As used in the specification of this application and the appended claims, the term "if" may be construed, depending on the context, as "when", "once", "in response to determining", or "in response to detecting". Similarly, the phrases "if determined" or "if [the described condition or event] is detected" may be construed, depending on the context, as meaning "once determined", "in response to determining", "once [the described condition or event] is detected", or "in response to detecting [the described condition or event]".

[0061] In addition, in the description of the specification of this application and the appended claims, the terms "first", "second", "third", etc. are only used for differentiating descriptions and cannot be construed as indicating or implying relative importance.

[0062] Reference to "one embodiment" or "some embodiments" or the like described in the specification of this application means that a specific feature, structure, or characteristic described in connection with that embodiment is included in one or more embodiments of this application. Thus, statements such as "in one embodiment", "in some embodiments", "in other some embodiments", "in still other embodiments", etc. that appear in different places in this specification do not necessarily all refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways. The terms "comprising", "including", "having", and their variants all mean "including but not limited to", unless otherwise specifically emphasized in other ways.

[0063] It should be understood that the magnitudes of the sequence numbers of the steps in the following embodiments do not mean the order of execution is prior or subsequent. The order of execution of each process should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of this application.

[0064] To illustrate the technical solution of this application, the following specific embodiments are used for illustration.

[0065] The inventors found that in the prior art, traditional threat detection methods, which are based on extracting features of threats and writing detection rules, have a relatively high false negative rate and cannot detect an increasing number of unknown threats. Based on this, the inventors made further research and developed the present invention, which provides a threat detection method and device based on risk scoring.

[0066] Embodiment 1

[0067] The embodiment of the present invention provides a threat detection method based on risk scoring. Referring to Figure 1 as shown, the method includes:

[0068] S101: Based on the obtained compliance behaviors and threat features, establish a risk assessment rule library.

[0069] In the embodiment of the present application, in the above step S101, the compliance behaviors and threat features respectively include a plurality of real-time status descriptions and a plurality of historical operation descriptions. Among them, the steps of establishing a risk assessment rule library include: extracting corresponding real-time status rules based on a plurality of real-time elements and status risk values of each real-time status description; extracting corresponding historical operation rules based on the sequence information of a plurality of events of each historical operation description (such as sequence operation information such as file access, process operation, network access, etc. on entities in real-time elements) and operation risk values; each event includes a plurality of operation elements; based on all the obtained real-time status rules and all the historical operation rules, the risk assessment rule library is obtained. Among them, the real-time status description represents a description of operations on entities (such as users, devices, applications, etc.), and the historical operation description contains the association relationships of multiple rules. For example, rule 1 is that the system starts the Excel process, rule 2 is that Excel starts the msiexec process, and the association relationship is that the Excel processes of the two rules are the same and the interval time does not exceed 30s.

[0070] Among them, the compliance behaviors and threat features are manually summarized, including: abstracting compliance and reasonable operation rules based on various normal compliance operations, introducing general threat features and rules, and continuously introducing externally announced threat rules.

[0071] In the embodiment of the present application, after obtaining the risk assessment rule library, it further includes: if new compliance behaviors and / or new threat features are obtained, determining the real-time status rules and / or historical operation rules corresponding to the new compliance behaviors, and / or the real-time status rules and / or historical operation rules corresponding to the new threat features, and updating them to the risk assessment rule library.

[0072] S102: Establish a real-time status record based on the entities in the obtained security log to be detected.

[0073] In the embodiment of the present application, establishing a real-time status record for the entities in the security log to be detected means extracting information such as users, devices, applications, etc. from the security log to be detected, establishing a real-time status record, and recording various real-time status information in the security log to be detected in the real-time status record.

[0074] In the embodiment of the present application, after establishing a real-time status record based on the security log to be detected, it further includes: obtaining the historical record associated with the user identifier according to the user identifier in the security log to be detected, and adding the data related to the security log to be detected in the historical record to the real-time status record.

[0075] In a specific embodiment, if the security log to be detected is "User admin successfully logged in in password mode", a real-time status record is established, including: the user is "admin", the device is the host that collected this log (such as host12), the application is ssh. The real-time status record also includes: asset and operation, the asset is "source code library", the operation is "login", the login status is "logged in", the last successful login time is "2022-10-10T15:42:45+0800", etc. Among them, the information of the last successful login time does not exist in the current security log to be detected and is obtained by searching the historical records associated with the user identifier "admin" in the security log.

[0076] S103: Enhance the information of the security log to be detected based on the real-time status record to obtain an enriched security log.

[0077] In the embodiment of the present application, in the above step S103, the steps of enhancing the information of the security log to be detected to obtain an enriched security log include: according to multiple entity elements in the real-time status record, inserting the entity elements not displayed in the security log to be detected into the security log to be detected according to standard fields or standard extended fields. At the same time, obtain the relevant logs of each entity element, and add the associated elements in each relevant log to the security log to be detected according to standard fields or standard extended fields to obtain an enriched security log. The relevant log herein refers to the log having the same identifier (such as user identifier, device identifier) as each entity element.

[0078] For example, if the security log to be detected is "User admin logged in to the system", the enriched security log is: "User admin logged in to the system. user.id:admin. Source.ip:192.168.1.100. Time: 2023-10-10T15:42:46+0800"

[0079] S104: Establish a historical operation record based on the operation in the enriched security log.

[0080] In the embodiment of the present application, in the above step S104, based on the entities (such as users, devices, applications, etc.) in the real-time status record, operations such as file access, process operation, and network access are performed on these entities to establish a historical operation record. Therefore, the historical operation record contains the association relationships of multiple real-time status records. The specific operation of establishing the historical operation record is to extract each element in the enriched security log, query other log sources according to these elements (such as user identification, device identification, IP address, timestamp, etc.), and obtain the logs that have an association relationship with the enriched security log, that is, the selected elements exist in the associated log and can identify that the associated log and the enriched security log are the same event. After determining the associated log, update the content of the associated log into the enriched security log to obtain the historical operation record.

[0081] Among them, other log sources may include: other security logs, system event logs, application logs, etc. At the same time, when performing log association, it is necessary to consider using a time window to ensure that the time interval between the associated log and the enriched security log is within a reasonable time range.

[0082] Illustrate the update operation of the enriched security log and the associated log. The enriched security log is "User admin logs in to the system. user.id:admin. Source.ip:192.168.1.100", and the associated log is "User admin accesses a file. user.id:admin. Source.ip:192.168.1.100. File path: / documents / report.xlsx. Operation: Read.", and the obtained historical operation record is "User admin logs in to the system. user.id:admin. Source.ip:192.168.1.100. Successfully accesses the file. File path: " / documents / report.xlsx". Operation type: Read".

[0083] S105: Based on the risk assessment rule library, retrieve the real-time status record and the historical operation record to obtain a risk value.

[0084] In the embodiment of the present application, in the above step S105, the risk assessment rule library contains multiple compliance behavior rules and multiple threat feature rules, and the compliance behavior rules and the threat feature rules respectively include multiple real-time status rules and multiple historical operation rules.

[0085] The steps of retrieving the risk value by retrieving the real-time status record and the historical status record based on the risk assessment rule library include: retrieving the real-time status record and the historical operation record respectively based on each real-time status rule and each historical operation rule in all compliance behavior rules in the risk assessment rule library to obtain the retrieval result. This step will identify whether the records in the security log to be detected are compliance behaviors, and as long as they are not compliance behaviors, they will be filtered out. Next, it is judged whether the retrieval result is empty: if so, the risk value is zero, that is, the records in the security log to be detected are all compliance behaviors; if not, the real-time status record and the historical operation record are retrieved respectively based on each real-time status rule and each historical operation rule in all threat feature rules in the risk assessment rule library to obtain the threat retrieval result, and it is judged whether the threat retrieval result is empty: if so, the risk value is a preset value, and this preset value will take a middle value within the range of the risk value range, indicating that the behavior in the security log to be detected is not a compliance behavior; if not, the risk value is the status risk value or the operation risk value corresponding to the threat feature rule in the threat retrieval result.

[0086] Next, an example is given for the above operation of retrieving the real-time status record and the historical operation record respectively based on the real-time status rule and the historical operation rule. The real-time status rule 1 is: the basic support system administrator logs in to the source code library, the login source is the bastion host, the login account is "admin", and the real-time risk value is 0. The risk value of this rule is 0, which is a compliance behavior rule. The historical operation rule 1 is: the system starts the Excel process. Within 30 seconds, Excel starts the msiexec process. Within 10 seconds, the msiexec process accesses the blacklisted IP 193.10.5.3. The operation risk value is 10, and this operation indicates the use of malware based on Excel macros, which is a threat feature rule.

[0087] Then, based on the storage method of the security logs to be detected, convert the real-time status rules and historical operation rules into statements in the corresponding query language. For example, if Elasticsearch database is selected for storing the security logs to be detected, the query language can be KQL (Kibana Query Language) or EQL (Elasticsearch Query Language). The query statement corresponding to the above real-time status rule 1 is: user.role: "infrastructure-admin" and event.action: "ssh_login" and destination.ip: "11.1.1.2" and source.ip: "11.2.1.2" and user.name: "admin". The query statement corresponding to the historical operation rule 1 is: sequence by destination.ip with maxspan = 40s [process where event.action == "process_create" and process.name == "excel"] by process.id [process where event.action == "process_create" and process.name == "msiexec"] by process.parent_id [network where event.action == "outbound" and destination.ip == "193.10.5.3"]. Retrieve the real-time status records and historical operation records one by one based on the above query statements to obtain the risk value.

[0088] In the embodiment of the present application, after obtaining the risk value, it further includes: obtaining the load risk value based on the security coefficient of the entity elements in the real-time status record, and calculating based on the risk value and the load risk value to obtain the optimized risk value. For example, in the above historical operation rule 1, it describes a malware based on Excel macros. If the storage location of Excel is in a highly secure isolation area, the load risk value will take a safe value. If the storage location of Excel is not securely fortified or stored in a public network environment, the load risk value will take a higher value according to the specific danger level. When calculating based on the risk value and the load risk value, a formula such as the Euclidean distance formula can be selected for calculation to obtain the optimized risk value as the risk value of the security logs to be detected.

[0089] In the embodiments of the present application, by first retrieving compliance behavior rules, filtering out non-compliant security logs, and then retrieving threat feature rules, double verification of threat features is achieved, which can effectively increase the recognition probability of unknown threats and reduce the false alarm rate and missed alarm rate.

[0090] S106: Obtain a threat detection result according to the risk value and a preset alarm threshold range.

[0091] In the embodiments of the present application, a threat detection result is obtained according to the risk value and a preset alarm threshold range. For example, if the value range of the risk value is from 0 to 10, the high-risk range can be set to 7 to 10 points, the medium-risk range to 4 to 7 points, and the low-risk range to 0 to 4 points. If the risk value is within the high-risk range, a threat detection result is obtained, indicating that there is a threat and an alarm is issued.

[0092] To facilitate the understanding of this solution by those skilled in the art, the following provides a specific schematic diagram of the threat detection method based on risk scoring provided by the embodiments of the present invention. The flowchart of the threat detection method based on risk scoring is as Figure 2 shown, corresponding to steps S101 - S106 in the above text, that is, establishing risk evaluation rules to form a rule library, processing each collected security log one by one, establishing or updating the "real-time status" records of users, devices, applications, etc. based on the logs, enhancing the context information of the logs based on the real-time status information, that is, filling the real-time status information into the relevant fields of the logs, storing the enriched logs as the data source of the "historical operation" records, evaluating the risk of the current log based on each rule in the rule library, then comprehensively evaluating each risk value, and finally obtaining a threat detection result and also obtaining a new security log to be detected, and then performing threat detection on the new security log to be detected based on the risk scoring rule library. Among them, the threat detection module that obtains a threat detection result based on the security log to be detected is as Figure 3 shown, including a log processing module and a risk evaluation engine. The log processing module includes a real-time status update module, a historical record update module, and a log enrichment module for performing steps S102 - S104 in the above text. The risk evaluation engine corresponds to step S105 in the above text. Among them, the main rule evaluation engine in the risk evaluation engine is divided into a status rule evaluation engine and a sequence rule evaluation engine, corresponding to the steps of retrieving the security log to be detected based on the real-time status rule and the historical operation rule in the above text respectively.

[0093] In the embodiments of the present application, by establishing a risk assessment rule base based on compliance behaviors and threat characteristics, compared with the existing method of establishing rules only based on threat characteristics, more risk factors can be covered, dual retrieval of compliance behaviors and threat characteristics can be achieved, the recognition probability of unknown threats can be increased, and the false alarm rate and missed alarm rate can be reduced. By establishing real-time status records based on the security logs to be detected and enhancing the information of the real-time status records, and then establishing historical operation records based on the enriched security logs, the enriched security logs contain more context information. By integrating this information, the security team can better understand file access events and identify any anomalies or potential security threats. The same principle also applies to other types of security events such as process operations and network access. Establishing context helps to comprehensively analyze multiple related events, thereby improving the perception of the overall security situation, effectively improving the accuracy and credibility of threat detection, and there is no problem that the detection method based on machine learning is not easily used in the threat detection scenario based on human behavior.

[0094] Embodiment 2

[0095] Based on the same inventive concept, an embodiment of the present invention further provides a threat detection device based on risk scoring. Referring to Figure 4 as shown, the device includes:

[0096] A first establishment module 101, configured to establish a risk assessment rule base based on the obtained compliance behaviors and threat characteristics;

[0097] An entity status module 102, configured to establish real-time status records based on the entities in the security logs to be detected obtained;

[0098] A first enhancement module 103, configured to enhance the information of the security logs to be detected based on the real-time status records to obtain enriched security logs;

[0099] A historical operation module 104, configured to establish historical operation records based on the operations in the enriched security logs;

[0100] A first acquisition module 105, configured to retrieve the real-time status records and the historical operation records based on the risk assessment rule base to obtain risk values;

[0101] A second acquisition module 106, configured to obtain threat detection results according to the risk values and a preset alarm threshold range.

[0102] Embodiment 3

[0103] Based on the same inventive concept, an embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the threat detection method based on risk scoring described in Embodiment 1 above.

[0104] Example 4

[0105] Based on the same inventive concept, an embodiment of the present invention further provides a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, it implements the threat detection method based on risk scoring described in the first embodiment above.

[0106] Example 5

[0107] Based on the same inventive concept, an embodiment of the present invention further provides a computer program product containing instructions. When the computer program product runs on a computer device, it causes the computer device to execute the threat detection method based on risk scoring described in the first embodiment above.

[0108] Example 6

[0109] Based on the same inventive concept, an embodiment of the present invention further provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor, and the processor is used to run a computer program or instructions to implement the threat detection method based on risk scoring described in the first embodiment above.

[0110] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage and optical storage, etc.) containing computer-usable program code.

[0111] The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, as well as the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the specified functions in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0112] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instruction means embodying the functionality specified in the flowchart(s) Figure 1 or block(s) of the flowchart(s) and / or Figure 1 block(s) of the block diagram(s).

[0113] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, whereby the instructions executed on the computer or other programmable apparatus provide steps for implementing the functionality specified in the flowchart(s) Figure 1 or block(s) of the flowchart(s) and / or Figure 1 block(s) of the block diagram(s).

[0114] It will be apparent to those skilled in the art that various modifications and variations can be made to the present invention without departing from the spirit and scope of the invention. Thus, if these modifications and variations of the present invention come within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these modifications and variations.

Claims

1. A threat detection method based on risk scoring, characterized in that, Including: Based on the obtained compliance behaviors and threat characteristics, establish a risk assessment rule library; Based on the entities in the obtained security logs to be detected, establish real-time status records; Based on the real-time status records, enhance the information of the security logs to be detected to obtain enriched security logs; Based on the operations in the enriched security logs, establish historical operation records; Based on the risk assessment rule library, retrieve the real-time status records and the historical operation records to obtain a risk value; According to the risk value and the preset alarm threshold range, obtain the threat detection result.

2. The method according to claim 1, characterized in that, The compliance behaviors and threat characteristics respectively include multiple real-time status descriptions and multiple historical operation descriptions; among them, establishing a risk assessment rule library based on the obtained compliance behaviors and threat characteristics includes: Based on multiple real-time elements and status risk values of each real-time status description, extract the corresponding real-time status rules; Based on the sequence information of multiple events and operation risk values of each historical operation description, extract the corresponding historical operation rules; each event includes multiple operation elements; Based on all the obtained real-time status rules and all the historical operation rules, obtain the risk assessment rule library.

3. The method according to claim 2, wherein The risk assessment rule library includes multiple compliance behavior rules and multiple threat characteristic rules; based on the risk assessment rule library, retrieving the real-time status records and the historical operation records to obtain a risk value includes: Based on each real-time status rule and each historical operation rule in all the compliance behavior rules in the risk assessment rule library, respectively retrieve the real-time status records and the historical operation records to obtain retrieval results; Judge whether the retrieval result is empty: If so, the risk value is zero; If not, based on each real-time status rule and each historical operation rule in all the threat characteristic rules in the risk assessment rule library, respectively retrieve the real-time status records and the historical operation records to obtain the risk value.

4. The method according to claim 3, characterized in that, Also including: Based on the security coefficients of the real-time elements in the real-time status records, obtain the load risk value; Based on the calculation of the risk value and the load risk value, obtain the optimized risk value.

5. The method according to claim 1, wherein After establishing the real-time status records based on the entities in the obtained security logs to be detected, it also includes: According to the user identification in the security logs to be detected, obtain the historical records associated with the user identification; Add the data related to the security logs to be detected in the historical records to the real-time status records.

6. The method according to claim 1, wherein Based on the real-time status records to enhance the information of the security logs to be detected to obtain enriched security logs, including: According to multiple real-time elements in the real-time status records, obtain the relevant logs of each real-time element; Add the associated elements in each relevant log to the security logs to be detected according to the standard fields to obtain enriched security logs.

7. A threat detection device based on risk scoring, characterized in that, Including: The first establishment module is used to establish a risk assessment rule library based on the obtained compliance behaviors and threat characteristics; The entity status module is used to establish real-time status records based on the entities in the obtained security logs to be detected; A first enhancement module, configured to enhance information of the to-be-detected security log based on the real-time status record to obtain an enriched security log; A historical operation module, configured to establish a historical operation record based on operations in the enriched security log; A first acquisition module, configured to retrieve the real-time status record and the historical operation record based on the risk assessment rule library to obtain a risk value; A second acquisition module, configured to obtain a threat detection result according to the risk value and a preset alarm threshold range.

8. A computer-readable storage medium storing instructions that, when run on a terminal, cause the terminal to execute the threat detection method based on risk scoring according to any one of claims 1-6.

9. A computer device, characterized in that, Comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the processor executes the computer program to implement the threat detection method based on risk scoring according to any one of claims 1-6.

10. A computer program product comprising instructions that, when run on a computer device, cause the computer device to execute the threat detection method based on risk scoring according to any one of claims 1-6.

11. A chip comprising a processor and a communication interface, the communication interface being coupled to the processor, and the processor being configured to run a computer program or instructions to implement the threat detection method based on risk scoring according to any one of claims 1-6.

Citation Information

Cited By

  • Safety control method and system for cloud inventory management platform

    CN120805200A

  • Industrial data security access control method and system

    CN121396576A