Method, device and equipment for processing clue data of attack event and medium
By obtaining and aggregating clue data from the business system regularly, building attack event trees and forests, it solves the problem that clue data cannot be regularly aggregated in the existing technology, and improves the threat detection and response capabilities of the business system.
Patent Information
- Application Number
- CN202510383668.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-28
- Publication Date
- 2025-07-01
AI Technical Summary
The prior art cannot regularly aggregate the clue data of attack events, making it difficult to capture long-term latent attacks in business systems, resulting in low detection and response capabilities.
By obtaining clue data in the preset time period regularly, aggregating clue data based on the generation time and path information, building an attack event tree and forest, and providing it to the target user for timely analysis of latent attacks.
It realizes regular aggregation of clue data for processing attack events, improves the ability of business systems to detect and respond to potential threats, and promptly detects long-term latent attacks.
Smart Images

Figure CN120238352A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular, to a method, apparatus, device and medium for processing clue data of attack events. Background Art
[0002] There are more and more attack events against the business systems of enterprises. Attackers usually initiate multiple attack events against business systems in a long-term process, and cooperate with each other through the multiple attack events initiated to lurk in the business systems for a long time, steal data in the business systems or damage the business systems. Clue data of each attack event that has occurred is usually stored in the business system. Each attack event usually has one or more clue data. The respective clue data of the attack event can be log information or alarm information generated by different functional modules in the business system during the occurrence of the attack event for describing the attack event.
[0003] In the related art, the commonly used clue data processing solution for attack events is that after technicians discover that the data in the business system has been stolen or the business system has been damaged, they perform retrospective analysis based on the clue data of the attack events stored in the business system. The clue data processing solution for attack events in the related art relies on manual operations and cannot regularly aggregate the clue data of attack events, aggregate the clue data belonging to the same attack event, and aggregate the clue data of attack events belonging to the same attack path, making it difficult to capture long-term latent attacks in the business system, resulting in low detection and response capabilities of the business system to potential threats. Summary of the Invention
[0004] The present invention provides a method, apparatus, device and medium for processing clue data of attack events to solve the problem that the clue data processing solution for attack events in the related art cannot regularly aggregate the clue data of attack events, aggregate the clue data belonging to the same attack event, and aggregate the clue data of attack events belonging to the same attack path, making it difficult to capture long-term latent attacks in the business system, resulting in low detection and response capabilities of the business system to potential threats.
[0005] According to one aspect of the present invention, there is provided a method for processing clue data of attack events, including:
[0006] Regularly obtain each piece of clue data within a preset time period; wherein, each piece of clue data is log layer clue data or alarm layer clue data;
[0007] Aggregate each piece of clue data according to the generation time in each piece of clue data to obtain a plurality of attack event trees; wherein, each attack event tree is composed of clue data belonging to the same attack event;
[0008] Aggregate each attack event tree according to the path information, identification information, and time information of each attack event tree to obtain one or more attack event forests; wherein, each attack event forest is composed of attack event trees belonging to the same attack path;
[0009] Provide each attack event forest to a target user.
[0010] According to another aspect of the present invention, there is provided a clue data processing device for attack events, including:
[0011] A data acquisition module, configured to periodically acquire each clue data within a preset time period; wherein, each clue data is log layer clue data or alarm layer clue data;
[0012] A first aggregation module, configured to aggregate each clue data according to the generation time in each clue data to obtain multiple attack event trees; wherein, each attack event tree is composed of clue data belonging to the same attack event;
[0013] A second aggregation module, configured to aggregate each attack event tree according to the path information, identification information, and time information of each attack event tree to obtain one or more attack event forests; wherein, each attack event forest is composed of attack event trees belonging to the same attack path;
[0014] An information providing module, configured to provide each attack event forest to a target user.
[0015] According to another aspect of the present invention, there is provided an electronic device, and the electronic device includes:
[0016] At least one processor;
[0017] And a memory communicatively connected to the at least one processor;
[0018] Wherein, the memory stores a computer program executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the clue data processing method for attack events according to any embodiment of the present invention.
[0019] According to another aspect of the present invention, there is provided a computer-readable storage medium, and the computer-readable storage medium stores computer instructions, and the computer instructions are used to implement the clue data processing method for attack events according to any embodiment of the present invention when executed by a processor.
[0020] According to another aspect of the present invention, there is provided a computer program product, which includes a computer program that, when executed by a processor, implements the method for processing clue data of attack events according to any embodiment of the present invention.
[0021] The technical solution of the embodiment of the present invention obtains each clue data within a preset time period at regular intervals. Each clue data is clue data of the log layer or clue data of the alarm layer. Then, according to the generation time in each clue data, each clue data is aggregated to obtain a plurality of attack event trees. Each attack event tree is composed of clue data belonging to the same attack event. According to the path information, identification information, and time information of each attack event tree, each attack event tree is aggregated to obtain one or more attack event forests. Each attack event forest is composed of attack event trees belonging to the same attack path, and each attack event forest is provided to the target user. This solves the problem that the clue data processing solution for attack events in the related art cannot regularly aggregate the clue data of attack events, aggregate the clue data belonging to the same attack event, and aggregate the clue data of attack events belonging to the same attack path, making it difficult to capture long-term latent attacks in the business system, resulting in low detection and response capabilities of the business system to potential threats. It can regularly aggregate each clue data according to the time information of the clue data of each attack event that has occurred within a preset time period to obtain a plurality of attack event trees composed of clue data belonging to the same attack event, and aggregate each attack event tree according to the path information, identification information, and time information of each obtained attack event tree to obtain one or more attack event forests composed of attack event trees belonging to the same attack path, so as to regularly aggregate the clue data of attack events, aggregate the clue data belonging to the same attack event, and aggregate the clue data of attack events belonging to the same attack path. The obtained attack event forests containing the clue data of attack events belonging to the same attack path after aggregation can be provided to relevant technical personnel. Thus, the relevant technical personnel can timely analyze and determine whether there is a long-term latent attack against the business system based on the clue data of attack events belonging to the same attack path in each attack event forest, improving the detection and response capabilities of the business system to potential threats.
[0022] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] To more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.
[0024] Figure 1 It is a flowchart of a method for processing clue data of an attack event provided in Embodiment 1 of the present invention.
[0025] Figure 2 It is a flowchart of a method for processing clue data of an attack event provided in Embodiment 2 of the present invention.
[0026] Figure 3 It is a schematic structural diagram of a device for processing clue data of an attack event provided in Embodiment 3 of the present invention.
[0027] Figure 4 It is a schematic structural diagram of an electronic device for implementing the method for processing clue data of an attack event in the embodiments of the present invention. Specific Embodiments
[0028] To enable those skilled in the art to better understand the solutions of the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0029] It should be noted that the terms "target", "first", "second", etc. in the specification and claims of the present invention and the above accompanying drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described here can be implemented in an order other than those illustrated or described here. In addition, the terms "comprising", "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not necessarily need to be limited to those clearly listed steps or units, but may include other steps or units that are not clearly listed or are inherent to these processes, methods, products or devices.
[0030] Embodiment 1
[0031] Figure 1The figure is a flowchart of a method for processing clue data of attack events provided in the first embodiment of the present invention. This embodiment is applicable to the situation of processing clue data of attack events stored in a business system. This method can be executed by a device for processing clue data of attack events, and the device for processing clue data of attack events can be implemented in the form of hardware and / or software, and the device for processing clue data of attack events can be configured in the business system of an enterprise. The business system of an enterprise can be a server set up in the enterprise for processing the business of the enterprise. The business can refer to the process of producing products and providing the products to users. As Figure 1 shown, the method includes:
[0032] Step 101, regularly obtain each piece of clue data within a preset time period.
[0033] Among them, each piece of clue data is clue data at the log layer or clue data at the alarm layer.
[0034] Optionally, an attack event against a business system may refer to an event that occurs in the business system and uses configuration defects, protocol defects, program defects of the business system or brute-force attacks to attack the business system, causing potential harm to the business system or data in the business system. Exemplarily, attack events against a business system include, but are not limited to: an external device sending a phishing email to the business system using an email, an external device using a system vulnerability of the business system to increase its own permissions in the business system, an external device spreading horizontally in the business system to obtain more information and permissions, an external device obtaining data in the business system without authorization, an external device logging in to the business system using an unauthorized account, and an external device accessing the business system through a Virtual Private Network (VPN). The external device may refer to other electronic devices other than each electronic device set up in the enterprise.
[0035] Optionally, during the occurrence of an attack event, clue data of the attack event will be generated in the business system. Each attack event usually has one or more pieces of clue data. Each piece of clue data of the attack event can be log information or alarm information generated in the business system during the occurrence of the attack event for describing the attack event.
[0036] Optionally, the log module can be a software module or a hardware module set in the business system for monitoring and recording various events occurring in the business system. During the operation of the business system, the business system can monitor various events occurring in the business system through the log module, generate log information for each event, and store the generated log information. Each log information can be text for describing an event occurring in the business system. The log information stored in the business system includes but is not limited to: traffic log information, firewall log information, host security log information, website server log information, and database log information.
[0037] Optionally, the traffic log information can refer to the log information of various events related to the traffic of the network used by the business system. The traffic log information can include log information for describing attack events related to the traffic of the network used by the business system. Exemplarily, the attack events related to the traffic of the network used by the business system include but are not limited to: a sudden increase in the traffic of the network used by the business system controlled by an external device, and an external device accessing the port of the network used by the business system without authorization.
[0038] Optionally, the firewall log information can refer to the log information of various events related to the firewall of the network used by the business system. The firewall log information can include log information for describing attack events related to the firewall of the network used by the business system. Exemplarily, the attack events related to the firewall of the network used by the business system include but are not limited to: an external device attempting to access the business system without authorization, and a request from an external device to access the business system being rejected without authorization.
[0039] Optionally, the host security log information can refer to the log information of various events related to the host in the business system. The host security log information can include log information for describing attack events related to the host in the business system. Exemplarily, the attack events related to the host in the business system include but are not limited to: an external device failing to log in to the host in the business system without authorization, and an external device changing the permissions of files in the host in the business system without authorization.
[0040] Optionally, the website server log information may refer to the log information of various events related to the website server (Web server) used by the business system. The website server log information may include the log information for describing attack events related to the website server used by the business system. Exemplarily, the attack events related to the website server used by the business system include, but are not limited to: injecting Structured Query Language (SQL) into the website server used by the business system by an external device, injecting malicious instruction codes into the website server used by the business system by an external device.
[0041] Optionally, the database log information may refer to the log information of various events related to the database in the business system. The database log information may include the log information for describing attack events related to the database in the business system. Exemplarily, the attack events related to the database in the business system include, but are not limited to: querying data in the database in the business system by an external device without authorization, changing the permissions of the database in the business system by an external device without authorization.
[0042] Optionally, during the operation of the business system, the business system may monitor whether the business system has an anomaly through an anomaly monitoring module. When it is detected that the business system has an anomaly, warning information for describing the occurred anomaly situation is generated, the generated warning information is provided to the target user and the generated warning information is stored. The target user may be a technician responsible for handling attack events occurring in the business system. Each warning information may be a text for describing an anomaly situation occurring in the business system. The anomaly monitoring module may include an anomaly monitoring hardware module and an anomaly monitoring software module. The anomaly monitoring hardware module may be a hardware module set in the business system for monitoring whether the business system has an anomaly and generating warning information for describing the occurred anomaly situation when it is detected that the business system has an anomaly. The anomaly monitoring software module may be a software module set in the business system for monitoring whether the business system has an anomaly and generating warning information for describing the occurred anomaly situation when it is detected that the business system has an anomaly.
[0043] Optionally, the warning information stored in the business system may include the warning information for describing attack events monitored by the anomaly monitoring hardware module or the anomaly monitoring software module. The attack events monitored by the anomaly monitoring hardware module include, but are not limited to: scanning the ports of the network used by the business system by an external device without authorization, operating using the vulnerabilities of the network used by the business system by an external device. The attack events monitored by the anomaly monitoring software module include, but are not limited to: operating on the host in the business system by an external device resulting in abnormal processes of the host in the business system, using the memory of the host in the business system by an external device without authorization.
[0044] Optionally, the log information and alert information used to describe attack events related to the network used by the business system can be collectively referred to as network layer clue data. Exemplarily, the network layer clue data includes: alert information used to describe that an external device scans the ports of the network used by the business system without authorization as monitored by the anomaly monitoring hardware module, alert information used to describe that an external device operates using the vulnerabilities of the network used by the business system as monitored by the anomaly monitoring hardware module, log information in the traffic log information used to describe a sudden increase in the traffic of an external device controlling the network used by the business system, log information in the traffic log information used to describe that an external device accesses the ports of the network used by the business system without authorization, log information in the firewall log information used to describe that an external device attempts to access the business system without authorization, and log information in the firewall log information used to describe that the request of an external device to access the business system without authorization is rejected.
[0045] Optionally, the log information and alert information used to describe attack events related to the hosts in the business system can be collectively referred to as host layer clue data. Exemplarily, the host layer clue data includes: log information in the host security log information used to describe that an external device fails to log in to the host in the business system without authorization, log information in the host security log information used to describe that an external device changes the permissions of files in the host in the business system without authorization, alert information used to describe that an external device operates on the host in the business system and causes the process of the host in the business system to be abnormal as monitored by the anomaly monitoring software module, and alert information used to describe that an external device uses the memory of the host in the business system without authorization as monitored by the anomaly monitoring software module.
[0046] Optionally, the log information used to describe attack events related to the website server used by the business system or the database in the business system can be collectively referred to as application layer clue data. Exemplarily, the application layer clue data includes: log information in the website server log information used to describe that an external device injects structured query language into the website server used by the business system, log information in the website server log information used to describe that an external device injects malicious instruction codes into the website server used by the business system, log information in the database log information used to describe that an external device queries data in the database in the business system without authorization, and log information in the database log information used to describe that an external device changes the permissions of the database in the business system without authorization.
[0047] Optionally, the preset time period may refer to a time period of a preset duration up to the current moment. The preset duration may be a preset duration. Exemplarily, the preset duration is 7 days, 15 days, 1 month, 3 months, 6 months or 1 year. Each lead data within the preset time period may refer to each lead data generated within the preset time period stored in the business system. Each lead data may be a log message or an alarm message for describing an attack event. The lead data may include a generation time and attack identification information. The generation time may refer to the time when the lead data is generated. The attack identification information may be a string used to identify that the data is related to an attack event. All log messages and alarm messages whose generation time is within the preset time period and contain attack identification information are the respective lead data generated within the preset time period. The respective lead data are log layer lead data or alarm layer lead data. The log layer lead data refers to the log messages for describing an attack event. The alarm layer lead data refers to the alarm messages for describing an attack event.
[0048] Optionally, the lead collection component may be a component set in the business system for collecting each lead data within the preset time period. The lead collection component may screen out all log messages and alarm messages whose generation time is within the preset time period and contain attack identification information from the log messages and alarm messages stored in the business system, so as to obtain each lead data within the preset time period. Timely obtaining each lead data within the preset time period includes: through the lead collection component, obtaining each lead data within the preset time period at regular intervals according to the preset duration. The operation of obtaining each lead data within the preset time period may be performed once every preset duration through the lead collection component.
[0049] Optionally, timely obtaining each lead data within the preset time period includes: obtaining each lead data within the preset time period regularly uploaded by the target user. The target user may upload each lead data within the preset time period collected from the business system to the target storage location in the business system through the terminal device every preset duration. The target storage location may be a database preset for storing each lead data within the preset time period.
[0050] Optionally, after timely obtaining each lead data within the preset time period, it further includes: performing the following operations on each target log layer lead data lacking entity information among the respective lead data: determining the complete log message matching the target log layer lead data; constructing a virtual entity of the target log layer lead data according to the entity information in the complete log message, and adding the relevant information of the virtual entity of the target log layer lead data to the target log layer lead data.
[0051] Optionally, the entity of the log information may include an initiating entity and a responding entity. The initiating entity of the log information may refer to an external device that initiates the event to which the log information belongs. The responding entity of the log information may refer to a software module or a hardware module in a business system affected by the event to which the log information belongs. Exemplarily, the initiating entity of the log information may be a host located outside the enterprise that initiates the event to which the log information belongs. The responding entity of the log information may be a host in a business system affected by the event to which the log information belongs.
[0052] Optionally, the log information usually includes entity information. The entity information includes initiating entity information and responding entity information. The initiating entity information may refer to the relevant information of the initiating entity of the log information. The initiating entity information may include the attribute information and behavior information of the initiating entity. The attribute information of the initiating entity may include information such as the name, label, Internet Protocol (IP) address, and timestamp of the initiating entity. The name of the initiating entity may be a string used to identify and describe the initiating entity. The label of the initiating entity may be a string used to identify and describe the type of the initiating entity. The timestamp of the initiating entity may be the start time and end time of the event to which the log information belongs. The start time of the event may be the time when the recorded event starts. The end time of the event may be the time when the recorded event ends. The behavior information of the initiating entity may include the command sequence executed by the initiating entity in the event to which the log information belongs. The responding entity information may refer to the relevant information of the responding entity of the log information. The responding entity information may include the attribute information and behavior information of the responding entity. The attribute information of the responding entity may include information such as the name, label, IP address, and timestamp of the responding entity. The name of the responding entity may be a string used to identify and describe the responding entity. The label of the responding entity may be a string used to identify and describe the type of the responding entity. The timestamp of the responding entity may be the start time and end time of the event to which the log information belongs. The behavior information of the responding entity may include the command sequence executed by the responding entity in the event to which the log information belongs.
[0053] Optionally, the log layer clue data refers to the log information used to describe an attack event. The target log layer clue data missing entity information may refer to the log layer clue data missing the initiating entity information or the responding entity information. After obtaining each clue data within a preset time period, it is possible to detect whether the log layer clue data in each clue data includes the initiating entity information and the responding entity information, and determine the target log layer clue data missing entity information.
[0054] Optionally, for each piece of target log layer clue data with missing entity information in the respective clue data, the complete log information matching the target log layer clue data may refer to the log information similar to the log layer clue data that includes initiating entity information and responding entity information.
[0055] Optionally, determining the complete log information matching the target log layer clue data includes: detecting whether there is log information in each log information including initiating entity information and responding entity information that contains the same Media Access Control (MAC) address or host name as the target log layer clue data; determining any detected log information that contains the same MAC address or host name as the target log layer clue data as the complete log information matching the target log layer clue data.
[0056] Optionally, determining the complete log information matching the target log layer clue data further includes: calculating the matching value between each log information including initiating entity information and responding entity information and the target log layer clue data; determining any log information with a matching value greater than the target value between the target log layer clue data as the complete log information matching the target log layer clue data.
[0057] Optionally, the matching value between two log information may be a value used to measure the similarity degree between the two log information. The larger the matching value between the two log information, the higher the similarity degree between the two log information. The smaller the matching value between the two log information, the lower the similarity degree between the two log information.
[0058] Optionally, calculating the matching value between each log information including initiating entity information and responding entity information and the target log layer clue data includes: performing the following operations for each log information including initiating entity information and responding entity information: calculating the similarity between the name information in the log information and the name information in the target log layer clue data through the first similarity algorithm; calculating the similarity between the command sequence in the log information and the command sequence in the target log layer clue data through the second similarity algorithm; calculating the event correlation degree between the log information and the target log layer clue data through a preset event correlation algorithm; calculating the spatio-temporal correlation degree between the log information and the target log layer clue data through a preset spatio-temporal correlation algorithm; performing a weighted sum on the similarity between the name information in the log information and the name information in the log layer clue data, the similarity between the command sequence in the log information and the command sequence in the target log layer clue data, the event correlation degree between the log information and the target log layer clue data, and the spatio-temporal correlation degree between the log information and the target log layer clue data to obtain the matching value between the log information and the target log layer clue data.
[0059] Optionally, the name information in the log information may refer to the name of a hardware module or a software module included in the log information. The first similarity algorithm may be a pre-set algorithm for calculating the similarity between the name information in two log information. The command sequence in the log information may refer to the command sequence included in the log information. The second similarity algorithm may be a pre-set algorithm for calculating the similarity between the command sequences in two log information. The event correlation degree between two log information may be a value used to measure whether the events to which the two log information belong are on the same attack path. The greater the event correlation degree between two log information, the higher the possibility that the events to which the two log information belong are on the same attack path. The smaller the event correlation degree between two log information, the higher the possibility that the events to which the two log information belong are not on the same attack path. The attack path may refer to an event sequence composed of multiple attack events initiated by an attacker. The pre-set event correlation degree algorithm may be a pre-set algorithm for calculating the event correlation degree between two log information. The spatio-temporal correlation degree between two log information may be a value used to measure whether the events to which the two log information belong are in the same time period and the same network environment. The greater the spatio-temporal correlation degree between two log information, the higher the possibility that the events to which the two log information belong are in the same time period and the same network environment. The smaller the spatio-temporal correlation degree between two log information, the higher the possibility that the events to which the two log information belong are not in the same time period and the same network environment. The pre-set spatio-temporal correlation degree algorithm may be a pre-set algorithm for calculating the spatio-temporal correlation degree between two log information.
[0060] Optionally, a weighted sum of the similarity between the name information in the log information and the name information in the log layer clue data, the similarity between the command sequence in the log information and the command sequence in the target log layer clue data, the event correlation degree between the log information and the target log layer clue data, and the spatio-temporal correlation degree between the log information and the target log layer clue data is calculated to obtain a matching value between the log information and the target log layer clue data, including: using the following matching value calculation formula to perform a weighted sum of the similarity between the name information in the log information and the name information in the log layer clue data, the similarity between the command sequence in the log information and the command sequence in the target log layer clue data, the event correlation degree between the log information and the target log layer clue data, and the spatio-temporal correlation degree between the log information and the target log layer clue data to obtain a matching value between the log information and the target log layer clue data:
[0061] E score = ω1A + ω2B + ω3C + ω4D,
[0062] where, E scoreIt is the matching value between the log information and the target log layer clue data. The log information is any log information containing the initiating entity information and the responding entity information. A is the similarity between the name information in the log information and the name information in the log layer clue data. B is the similarity between the command sequence in the log information and the command sequence in the target log layer clue data. C is the event correlation degree between the log information and the target log layer clue data. D is the spatio-temporal correlation degree between the log information and the target log layer clue data. ω1, ω2, ω3, ω4 are preset weight coefficients, and ω1 + ω2 + ω3 + ω4 = 1. ω1, ω2, ω3, ω4 can be adaptively adjusted. For example, ω1, ω2, ω3, ω4 are dynamically optimized through machine learning algorithms. The matching value calculation formula can be a preset formula for calculating the matching value between the log information containing the initiating entity information and the responding entity information and the target log layer clue data.
[0063] Optionally, in a specific instance, ω1 is 0.3, ω2 is 0.3, ω3 is 0.2, and ω4 is 0.2. A certain log information is the log information containing the initiating entity information and the responding entity information. The similarity between the name information in this log information and the name information in the log layer clue data is 0.85. The similarity between the command sequence in this log information and the command sequence in the target log layer clue data is 0.90. The event correlation degree between this log information and the target log layer clue data is 0.70. The spatio-temporal correlation degree between this log information and the target log layer clue data is 0.60. Using the above matching value calculation formula, the matching value between the log information and the target log layer clue data is calculated to be 0.785. The matching value 0.785 can be rounded to 0.79.
[0064] Optionally, the target value can be a preset value. Exemplarily, the target value is 0.75. Any log information with a matching value greater than the target value with respect to the target log layer clue data can be determined as the complete log information matching the target log layer clue data.
[0065] Optionally, determining the complete log information matching the target log layer clue data further includes: calculating the time difference between the start time of the event in each log information containing the initiating entity information and the responding entity information and the start time of the event in the target log layer clue data; and determining the log information with the smallest time difference as the complete log information matching the target log layer clue data.
[0066] Optionally, the virtual entity of the target log layer clue data is a virtual initiating entity or a virtual responding entity. The virtual initiating entity of the target log layer clue data is the initiating entity of the target log layer clue data inferred based on the target log layer clue data. The virtual responding entity of the target log layer clue data is the responding entity of the target log layer clue data inferred based on the target log layer clue data.
[0067] Optionally, according to the entity information in the complete log information, construct the virtual entity of the target log layer clue data, and add the relevant information of the virtual entity of the target log layer clue data to the target log layer clue data, including: if the initiating entity information of the target log layer clue data is missing, determine the initiating entity of the complete log information as the virtual initiating entity of the target log layer clue data, and add the relevant information of the virtual initiating entity of the target log layer clue data to the target log layer clue data, so as to complete the target log layer clue data; among them, the relevant information of the virtual initiating entity of the target log layer clue data includes the attribute information and behavior information of the initiating entity of the complete log information; if the responding entity information of the target log layer clue data is missing, determine the responding entity of the complete log information as the virtual responding entity of the target log layer clue data, and add the relevant information of the virtual responding entity of the target log layer clue data to the target log layer clue data, so as to complete the target log layer clue data; among them, the relevant information of the virtual responding entity of the target log layer clue data includes the attribute information and behavior information of the responding entity of the complete log information.
[0068] Optionally, if the complete log information matching the target log layer clue data cannot be determined by the above method of determining the complete log information, construct the virtual entity of the target log layer clue data according to the internal and external IP address correspondence or entity relationship knowledge graph stored in the business system, and add the relevant information of the virtual entity of the target log layer clue data to the target log layer clue data.
[0069] Optionally, the internal and external IP address correspondence includes the IP addresses of each module in the business system and the IP addresses of external devices corresponding to each module. Each module is a software module or a hardware module set in the business system. The external device corresponding to each module can be an external device accessing the module.
[0070] Optionally, according to the correspondence between internal and external IP addresses stored in the business system, construct a virtual entity of the target log layer clue data, and add relevant information of the virtual entity of the target log layer clue data to the target log layer clue data, including: if the initiating entity information is missing in the target log layer clue data, query the first IP address in the IP addresses of each module in the internal and external IP address correspondence that is the same as the IP address of the responding entity of the target log layer clue data, determine the external device corresponding to the module to which the first IP address belongs as the virtual initiating entity of the target log layer clue data, and determine the IP address of the external device corresponding to the module to which the first IP address belongs as the relevant information of the virtual initiating entity of the target log layer clue data and add it to the target log layer clue data, so as to complete the target log layer clue data; if the responding entity information is missing in the target log layer clue data, query the second IP address in the IP addresses of each external device in the internal and external IP address correspondence that is the same as the IP address of the initiating entity of the target log layer clue data, determine the module corresponding to the external device to which the second IP address belongs as the virtual responding entity of the target log layer clue data, and determine the IP address of the module corresponding to the external device to which the second IP address belongs as the relevant information of the virtual responding entity of the target log layer clue data and add it to the target log layer clue data, so as to complete the target log layer clue data.
[0071] Optionally, the entity relationship knowledge graph can be a knowledge graph containing the attribute information and associated historical log information of each entity associated with the business system. Each entity associated with the business system includes each module in the business system and each external device that has interacted with the business system. The associated historical log information of the entity can be each log information generated in the business system and associated with the entity.
[0072] Optionally, according to the entity relationship knowledge graph stored in the business system, virtual entities of the target log layer clue data are constructed, and relevant information of the virtual entities of the target log layer clue data is added to the target log layer clue data, including: if the initiating entity information is missing in the target log layer clue data, the third similarity algorithm is used to calculate the similarity between each log information in the associated historical log information of the external device in the entity relationship knowledge graph and the target log layer clue data; the external device to which the log information with the highest similarity belongs is determined as the virtual initiating entity of the target log layer clue data, and the attribute information of the external device to which the log information with the highest similarity belongs is determined as the relevant information of the virtual initiating entity of the target log layer clue data and added to the target log layer clue data, so as to complete the target log layer clue data; if the response entity information is missing in the target log layer clue data, the third similarity algorithm is used to calculate the similarity between each log information in the associated historical log information of the module in the entity relationship knowledge graph and the target log layer clue data; the module to which the log information with the highest similarity belongs is determined as the virtual response entity of the target log layer clue data, and the attribute information of the module to which the log information with the highest similarity belongs is determined as the relevant information of the virtual response entity of the target log layer clue data and added to the target log layer clue data, so as to complete the target log layer clue data.
[0073] Step 102: Aggregate each clue data according to the generation time in each clue data to obtain multiple attack event trees.
[0074] Among them, each attack event tree is composed of clue data belonging to the same attack event.
[0075] Optionally, each attack event tree can be a relationship network diagram composed of clue data belonging to the same attack event for representing the attack event.
[0076] Optionally, aggregating each clue data according to the generation time in each clue data to obtain multiple attack event trees includes: dividing the preset time period into multiple time windows according to the preset time window size, and determining the time window in which the generation time in each clue data is located; determining the clue data with the generation time in the same time window as the clue data belonging to the same attack event; for each group of clue data belonging to the same attack event, taking each clue data as a node, establishing a connection line between each node and its adjacent node, obtaining the connection edges between each node and its adjacent node, and aggregating all nodes and the connection edges between the nodes to obtain an attack event tree composed of clue data belonging to the same attack event.
[0077] Optionally, the preset time window size can be a preset duration. The preset time period can be divided into multiple time periods with a duration equal to the preset time window size starting from the start time of the preset time period. Each divided time period is a time window. Exemplarily, the preset time window size is 20 minutes.
[0078] Optionally, the clue data belonging to the same attack event is the clue data used to describe the same attack event. The time window in which the generation time in the clue data is located can refer to the time window that contains the generation time in the clue data. For each clue data, it can be detected whether each time window contains the generation time in the clue data, and the time window that contains the generation time in the clue data is determined as the time window in which the generation time in the clue data is located. The clue data whose generation times are included in the same time window are the clue data whose generation times are located in the same time window. Usually, the clue data whose generation times are located in the same time window belong to the same attack event.
[0079] Optionally, determining the clue data whose generation times are located in the same time window as the clue data belonging to the same attack event includes: performing the following operations for each time window: if there is at least one clue data whose generation time is located in the time window, then determine the clue data whose generation times are located in the time window as a group of clue data belonging to the same attack event; if there is no clue data whose generation time is located in the time window, then determine that the processing of the time window ends.
[0080] Optionally, for each group of clue data belonging to the same attack event, each clue data in the group is used as a node. Sort the generation times in each node in chronological order from front to back to form a time series. For each node, the adjacent node of the node can refer to the node whose included generation time is adjacent to the generation time in the node in the time series. That the included generation time is adjacent to the generation time in the node in the time series can mean that the included generation time is in the time series one position before the generation time in the node or the included generation time is in the time series one position after the generation time in the node. Each node has at least one adjacent node. For each node, establish connections between the node and each of its adjacent nodes respectively to obtain the connection edges between the node and each adjacent node. Then gather all the nodes and the connection edges between the nodes to obtain the attack event tree formed by the group of clue data belonging to the same attack event. If the group only contains one clue data, the formed attack event tree is a relationship network diagram containing one node. If the group contains at least two clue data, the formed attack event tree is a relationship network diagram containing multiple nodes and the connection edges between the nodes.
[0081] Step 103: Aggregate each attack event tree according to the path information, identification information, and time information of each attack event tree to obtain one or more attack event forests.
[0082] Among them, each attack event forest is composed of attack event trees belonging to the same attack path. Each attack event forest can be a sequence of attack event trees composed of attack event trees belonging to the same attack path.
[0083] Optionally, aggregating each attack event tree according to the path information, identification information, and time information of each attack event tree to obtain one or more attack event forests includes: determining attack event trees with similar path information or the same identification information as attack event trees belonging to the same attack path; for each group of attack event trees belonging to the same attack path, sort each attack event tree in ascending order of time information to obtain an attack event forest composed of attack event trees belonging to the same attack path.
[0084] Optionally, the path information of the attack event tree may refer to the IP addresses included in each node in the attack event tree. Attack event trees with similar path information may refer to multiple attack event trees that have the same IP address among the included IP addresses. The identification information of the attack event tree may refer to the IP address or name of the initiating entity in each node of the attack event tree. Attack event trees with the same identification information are multiple attack event trees that have the same IP address or name of the initiating entity included.
[0085] Optionally, attack event trees belonging to the same attack path may refer to attack event trees whose represented attack events are attack events located in the same attack path. Generally, multiple attack event trees with similar path information or the same identification information are attack event trees belonging to the same attack path.
[0086] Optionally, the path information and identification information of each attack event tree can be compared, and attack event trees with similar path information or the same identification information are determined as attack event trees belonging to the same attack path, obtaining one or more groups of attack event trees belonging to the same attack path. For each attack event tree, if there are no other attack event trees with similar path information or the same identification information as this attack event tree, then the path of this attack event tree is determined as a group of attack event trees belonging to the same attack path, and the group contains one attack event tree.
[0087] Optionally, the time information of the attack event tree may refer to the earliest generation time among all the generation times included in each node of the attack event tree. For each group of attack event trees belonging to the same attack path, the attack event trees within the group are sorted in ascending order of time information, and the resulting sequence of attack event trees is the attack event forest composed of the attack event trees in this group that belong to the same attack path. The obtained attack event forest can be used to represent the attack path to which the group of attack event forests belongs. Each attack event tree in the attack event forest can be used to represent an attack event in the attack path.
[0088] Optionally, after aggregating the attack event trees according to the path information, identification information, and time information of each attack event tree to obtain one or more attack event forests, it further includes: complementing each attack event forest according to the known attack path information.
[0089] Optionally, the known attack path information may be composed of multiple complete attack event forests. Each complete attack event forest may refer to an attack event forest that has been confirmed and can be used to represent a complete attack path. Each complete attack event forest contains attack event trees used to represent each attack event in the attack path.
[0090] Optionally, complementing each attack event forest according to the known attack path information includes: performing the following operations on each attack event forest obtained by the current aggregation: detecting whether there is a target complete attack event forest similar to the attack event forest in each complete attack event forest of the known attack path information; if there is a target complete attack event forest similar to the attack event forest, then complement the attack event forest according to the target complete attack event forest; if there is no target complete attack event forest similar to the attack event forest, then it is determined that the attack event forest cannot be complemented according to the known attack path information.
[0091] Optionally, it is detected whether there is a target complete attack event forest similar to the attack event forest in each complete attack event forest in the known attack path information, including: performing the following operations for each complete attack event forest in the known attack path information: calculating the similarity between each attack event tree in the complete attack event forest and each attack event tree in the attack event forest according to the fourth similarity algorithm; if there is at least one attack event tree in the complete attack event forest whose similarity to the attack event tree in the attack event forest is greater than the target similarity threshold, it is determined that the complete attack event forest is the target complete attack event forest similar to the attack event forest; if there is no attack event tree in the complete attack event forest whose similarity to the attack event tree in the attack event forest is greater than the target similarity threshold, it is determined that the complete attack event forest is not the target complete attack event forest similar to the attack event forest. The fourth similarity algorithm can be an algorithm preset for calculating the similarity between two attack event trees. The target similarity threshold can be a preset similarity threshold. Exemplarily, the target similarity threshold is 0.75.
[0092] Optionally, if only one target complete attack event forest similar to the attack event forest is determined, then the target complete attack event forest is determined as the final target complete attack event forest similar to the attack event forest. If multiple target complete attack event forests similar to the attack event forest are determined, then the target complete attack event forest containing the largest number of attack event trees whose similarity to the attack event trees in the attack event forest is greater than the target similarity threshold is determined as the final target complete attack event forest similar to the attack event forest. If no target complete attack event forest similar to the attack event forest is determined, it is determined that there is no target complete attack event forest similar to the attack event forest in each complete attack event forest in the known attack path information.
[0093] Optionally, the attack event forest is complemented according to the target complete attack event forest, including: adding the attack event trees in the target complete attack event forest whose similarity to the attack event trees in the attack event forest is less than or equal to the target similarity threshold to the attack event forest.
[0094] Step 104: Provide each attack event forest to the target user.
[0095] Optionally, providing each attack event forest to the target user includes: sending each attack event forest to the terminal device of the target user. The terminal device of the target user can refer to the terminal device used by the target user.
[0096] Optionally, provide each attack event forest to the target user, including: determining the confidence score of each attack event forest, and sending each attack event forest and the confidence score of each attack event forest to the terminal device of the target user. The confidence score of the attack event forest can be a value used to measure the accuracy of the attack event forest. The higher the confidence score of the attack event forest, the higher the accuracy of the attack event forest. The lower the confidence score of the attack event forest, the lower the accuracy of the attack event forest.
[0097] Optionally, determining the confidence score of each attack event forest includes: performing the following operations for each attack event tree: determining the integrity score, abnormality score, entity matching confidence, and threat information matching degree of the attack event forest; performing a weighted sum of the integrity score, abnormality score, entity matching confidence, and threat information matching degree of the attack event forest to obtain the confidence score of the attack event forest.
[0098] Optionally, the integrity score of the attack event forest can be a value that measures the completeness of the attack event forest based on a target complete attack event forest similar to the attack event forest. The higher the integrity score of the attack event forest, the higher the completeness of the attack event forest. The lower the integrity score of the attack event forest, the lower the completeness of the attack event forest.
[0099] Optionally, determining the integrity score of the attack event forest includes: if there is a target complete attack event forest similar to the attack event forest, use the following integrity score calculation formula to calculate the integrity score of the attack event forest:
[0100]
[0101] where P score is the integrity score of the attack event forest, N is the total number of attack event trees included in the target complete attack event forest similar to the attack event forest, W i is the weight coefficient of the i-th attack event tree in the pre-set target complete attack event forest, C i is a value used to represent whether there is an attack event tree in the attack event forest whose similarity to the i-th attack event tree in the target complete attack event forest is greater than the target similarity threshold. In the case where there is an attack event tree in the attack event forest whose similarity to the i-th attack event tree in the target complete attack event forest is greater than the target similarity threshold, C i is 1, and in the case where there is no attack event tree in the attack event forest whose similarity to the i-th attack event tree in the target complete attack event forest is greater than the target similarity threshold, C iis 0, where i = 1, 2, …, N. The integrity score calculation formula can be a pre-set formula for calculating the integrity score of the attack event forest based on a target complete attack event forest similar to the attack event forest. If there is no target complete attack event forest similar to the attack event forest, the integrity score of the attack event forest is determined to be 0.
[0102] Optionally, in a specific example, the total number of attack event trees included in the target complete attack event forest similar to the attack event forest is 4. The weight coefficient of the first attack event tree in the target complete attack event forest is 0.2. There is an attack event tree in the attack event forest with a similarity greater than the target similarity threshold to the first attack event tree in the target complete attack event forest, and the value representing whether there is an attack event tree in the attack event forest with a similarity greater than the target similarity threshold to the first attack event tree in the target complete attack event forest is 1. The weight coefficient of the second attack event tree in the target complete attack event forest is 0.3. There is no attack event tree in the attack event forest with a similarity greater than the target similarity threshold to the second attack event tree in the target complete attack event forest, and the value representing whether there is an attack event tree in the attack event forest with a similarity greater than the target similarity threshold to the second attack event tree in the target complete attack event forest is 0. The weight coefficient of the third attack event tree in the target complete attack event forest is 0.3. There is an attack event tree in the attack event forest with a similarity greater than the target similarity threshold to the third attack event tree in the target complete attack event forest, and the value representing whether there is an attack event tree in the attack event forest with a similarity greater than the target similarity threshold to the third attack event tree in the target complete attack event forest is 1. The weight coefficient of the fourth attack event tree in the target complete attack event forest is 0.2. There is no attack event tree in the attack event forest with a similarity greater than the target similarity threshold to the fourth attack event tree in the target complete attack event forest, and the value representing whether there is an attack event tree in the attack event forest with a similarity greater than the target similarity threshold to the fourth attack event tree in the target complete attack event forest is 0. The integrity score of the attack event forest calculated using the integrity score calculation formula is 0.5. The integrity score can be normalized to the range of 0 - 100.
[0103] Optionally, the abnormality score of the attack event forest can be a value that measures the degree of abnormality of the abnormal situation caused by the attack path represented by the attack event forest based on abnormality metrics. The higher the abnormality score of the attack event forest, the higher the degree of abnormality of the abnormal situation caused by the attack path represented by the attack event forest. The lower the abnormality score of the attack event forest, the lower the degree of abnormality of the abnormal situation caused by the attack path represented by the attack event forest. The abnormality metrics can be multiple pre-set metrics for evaluating abnormal situations in the business system. Exemplarily, the abnormality metrics include the Central Processing Unit (CPU) usage rate, network traffic, and the number of login failures. The CPU usage rate can refer to the CPU usage rate of the CPU in the business system. The network traffic can refer to the traffic of the network used by the business system. The number of login failures can refer to the number of failures of external devices to log in to modules in the business system. Some nodes of the attack event trees in the attack event forest will contain the abnormality metrics recorded during the occurrence of the attack event.
[0104] Optionally, determining the abnormality score of the attack event forest includes: using the following abnormality score calculation formula to calculate the abnormality score of the attack event forest:
[0105]
[0106] where, A score is the abnormality score of the attack event forest, M is the total number of abnormality metrics, Y j is the weight coefficient of the j-th abnormality metric among all abnormality metrics, X j is the maximum value among all the j-th abnormality metrics included in the attack event forest, μ j is the average value of multiple pre-observed j-th abnormality metrics within the normal value range, σ j is the standard deviation of multiple pre-observed j-th abnormality metrics within the normal value range, and j = 1, 2, … M. The integrity score calculation formula can be a pre-set calculation formula for calculating the abnormality score of the attack event forest based on abnormality metrics.
[0107] Optionally, in a specific example, the total number of abnormal indicators is 3. The first abnormal indicator is CPU usage rate, the second abnormal indicator is network traffic, and the third abnormal indicator is the number of login failures. The unit of network traffic is MB. The weight coefficient of the first abnormal indicator is 0.4, the maximum value of all the first abnormal indicators included in the attack event forest is 0.95, the average value of multiple first abnormal indicators observed in advance within the normal value range is 0.5, the standard deviation of multiple first abnormal indicators observed in advance within the normal value range is 0.2, and D1 is 2.25. The weight coefficient of the second abnormal indicator is 0.3, the maximum value of all the second abnormal indicators included in the attack event forest is 2000, the average value of multiple second abnormal indicators observed in advance within the normal value range is 500, the standard deviation of multiple second abnormal indicators observed in advance within the normal value range is 600, and D2 is 2.5. The weight coefficient of the third abnormal indicator is 0.3, the maximum value of all the third abnormal indicators included in the attack event forest is 10, the average value of multiple third abnormal indicators observed in advance within the normal value range is 2, the standard deviation of multiple third abnormal indicators observed in advance within the normal value range is 3, and D3 is 2.67. 2.67 is the value obtained after rounding. The abnormality score of the attack event forest calculated using the abnormality score calculation formula is 2.45. 2.45 is the value obtained after rounding. The abnormality score can be normalized to the range of 0 - 100.
[0108] Optionally, the entity matching confidence of the attack event forest can be a value that measures the degree of association between the target complete attack event forest similar to the attack event forest and the initiating entity in the attack event forest. The higher the entity matching confidence of the attack event forest, the higher the degree of association between the target complete attack event forest similar to the attack event forest and the initiating entity in the attack event forest. The lower the entity matching confidence of the attack event forest, the lower the degree of association between the target complete attack event forest similar to the attack event forest and the initiating entity in the attack event forest.
[0109] Optionally, determine the entity matching confidence of the attack event forest, including: sending the attribute information of each initiating entity in the attack event forest and the target complete attack event forest similar to the attack event forest to the terminal device of the target technician, so that the target technician can feedback the attribute information of the initiating entity in the target complete attack event forest that is similar to each initiating entity in the attack event forest through the terminal device; for each initiating entity in the attack event forest, calculate the similarity between the attribute information of the initiating entity and the attribute information of the initiating entity in the target complete attack event forest that is similar to the initiating entity through the fifth similarity algorithm; use the following entity matching confidence calculation formula to calculate the entity matching confidence of the attack event forest:
[0110]
[0111] where E score is the entity matching confidence of the attack event forest, K is the total number of initiating entities in the attack event forest, E k is the k-th initiating entity in the attack event forest, E′ k is the initiating entity in the target complete attack event forest that is similar to the k-th initiating entity in the attack event forest and is similar to the attack event forest, Sim(E k , E′ k ) is the similarity between the attribute information of E k and the attribute information of E′ k , and k = 1, 2,..., K. The entity matching confidence calculation formula can be a pre-set formula for calculating the entity matching confidence of the attack event forest. The target technician can be a technician used to assist in determining the initiating entity in the target complete attack event forest that is similar to each initiating entity in the attack event forest. For each initiating entity in the attack event forest, the initiating entity in the target complete attack event forest that is similar to the initiating entity and is similar to the attack event forest can refer to the initiating entity in the target complete attack event forest that is similar to the attack event forest and has the highest possibility of being the same initiating entity as the initiating entity. The fifth similarity algorithm can be a pre-set algorithm for calculating the similarity between the attribute information of two initiating entities. If there is no target complete attack event forest similar to the attack event forest, determine that the entity matching confidence of the attack event forest is 0.
[0112] Optionally, in a specific example, the total number of initiating entities in the attack event forest is 3. The similarity between the attribute information of the first initiating entity in the attack event forest and the attribute information of the initiating entity similar to the first initiating entity in the attack event forest in the target complete attack event forest similar to the attack event forest is 0.33. The similarity between the attribute information of the second initiating entity in the attack event forest and the attribute information of the initiating entity similar to the second initiating entity in the attack event forest in the target complete attack event forest similar to the attack event forest is 0.6. The similarity between the attribute information of the third initiating entity in the attack event forest and the attribute information of the initiating entity similar to the third initiating entity in the attack event forest in the target complete attack event forest similar to the attack event forest is 0.8. The entity matching confidence of the attack event forest calculated using the matching confidence calculation formula is 0.577. 0.577 is the value obtained after rounding. The entity matching confidence can be normalized to the range of 0 - 100.
[0113] Optionally, the threat information matching degree of the attack event forest can be a value that measures the degree of association between the attack event forest and known threat entities. The known threat entities can be external devices that have been predicted to initiate attack events. The attribute information of the known threat entities is stored in the business system. The higher the threat information matching degree of the attack event forest, the higher the degree of association between the attack event forest and the known threat entities. The lower the threat information matching degree of the attack event forest, the lower the degree of association between the attack event forest and the known threat entities.
[0114] Optionally, determining the threat information matching degree of the attack event forest includes: for each initiating entity in the attack event forest, calculating the similarity between the attribute information of the initiating entity and the attribute information of the known threat entities through the fifth similarity algorithm; determining the maximum value among the calculated similarities as the threat information matching degree of the attack event forest. The threat information matching degree of the attack event forest can be expressed as: T score = max(Sim(I, TI)), where T score is the threat information matching degree of the attack event forest, Sim(I, TI) is the similarity between the attribute information of each initiating entity in the attack event forest and the attribute information of the known threat entities calculated, and max(Sim(I, TI)) is the maximum value among the similarities between the attribute information of each initiating entity in the attack event forest and the attribute information of the known threat entities calculated.
[0115] Optionally, in a specific instance, the maximum value of the similarity between the attribute information of each initiating entity in the calculated attack event forest and the attribute information of known threat entities is 0.8, thereby determining that the threat information matching degree of the attack event forest is 0.8. The threat information matching degree can be normalized to a value between 0 and 100.
[0116] Optionally, a weighted sum of the integrity score, abnormality score, entity matching confidence, and threat information matching degree of the attack event forest is calculated to obtain the confidence score of the attack event forest, including: using the following confidence score formula to perform a weighted sum of the integrity score, abnormality score, entity matching confidence, and threat information matching degree of the attack event forest to obtain the confidence score of the attack event forest:
[0117] S C = αP score + βA score + γE score + δT score ,
[0118] where S C is the confidence score of the attack event forest, P score is the integrity score of the attack event forest, A score is the abnormality score of the attack event forest, E score is the entity matching confidence of the attack event forest, T score is the threat information matching degree of the attack event forest, and α, β, γ, δ are preset weight coefficients, and α + β + γ + δ = 1.
[0119] Optionally, in a specific instance, α is 0.4, β is 0.3, γ is 0.2, and δ is 0.1. The normalized integrity score of the attack event forest is 50. The normalized abnormality score of the attack event forest is 97.2. The normalized entity matching confidence of the attack event forest is 57.7. The normalized threat information matching degree of the attack event forest is 80. The confidence score of the attack event forest calculated using the confidence score formula is 68.7.
[0120] The technical solution of the embodiment of the present invention obtains each clue data within a preset time period regularly, and each clue data is clue data of the log layer or clue data of the alarm layer; then aggregates each clue data according to the generation time in each clue data to obtain a plurality of attack event trees, and each attack event tree is composed of clue data belonging to the same attack event; aggregates each attack event tree according to the path information, identification information, and time information of each attack event tree to obtain one or more attack event forests, and each attack event forest is composed of attack event trees belonging to the same attack path, and provides each attack event forest to the target user, solving the problem that the clue data processing solution of the attack event in the related technology cannot regularly aggregate the clue data of the attack event, aggregate the clue data belonging to the same attack event, and aggregate the clue data of the attack event belonging to the same attack path, making it difficult to capture long-term latent attacks in the business system, resulting in low detection and response capabilities of the business system to potential threats. It can regularly aggregate each clue data according to the time information of the clue data of each attack event that has occurred within the preset time period to obtain a plurality of attack event trees composed of clue data belonging to the same attack event, and aggregate each attack event tree according to the path information, identification information, and time information of each obtained attack event tree to obtain one or more attack event forests composed of attack event trees belonging to the same attack path, so as to regularly aggregate the clue data of the attack event, aggregate the clue data belonging to the same attack event, and aggregate the clue data of the attack event belonging to the same attack path. It can provide each attack event forest containing the clue data of the attack event belonging to the same attack path obtained after aggregation to relevant technical personnel, so that the relevant technical personnel can timely analyze and determine whether there is a long-term latent attack on the business system based on the clue data of the attack event belonging to the same attack path in each attack event forest, improving the detection and response capabilities of the business system to potential threats.
[0121] Embodiment 2
[0122] Figure 2 It is a flowchart of a method for processing clue data of an attack event provided by Embodiment 2 of the present invention. The embodiment of the present invention can be combined with each optional solution in one or more of the above embodiments. As Figure 2 shown, the method includes:
[0123] Step 201, regularly obtain each clue data within a preset time period.
[0124] Among them, each clue data is clue data of the log layer or clue data of the alarm layer.
[0125] Optionally, after obtaining each piece of lead data within a preset time period at regular intervals, the following operations are further included: for each piece of target log layer lead data with missing entity information among the pieces of lead data, perform the following operations: determine the complete log information that matches the target log layer lead data; construct a virtual entity for the target log layer lead data according to the entity information in the complete log information, and add the relevant information of the virtual entity of the target log layer lead data to the target log layer lead data. Thereby, the log layer lead data with missing entity information can be complemented, and the correlation ability of the lead data can be improved.
[0126] Step 202: Aggregate each piece of lead data according to the generation time in each piece of lead data to obtain multiple attack event trees.
[0127] Among them, each attack event tree is composed of lead data belonging to the same attack event.
[0128] Step 203: Aggregate each attack event tree according to the path information, identification information, and time information of each attack event tree to obtain one or more attack event forests.
[0129] Among them, each attack event forest is composed of attack event trees belonging to the same attack path.
[0130] Step 204: Complete each attack event forest according to the known attack path information.
[0131] Step 205: Determine the confidence score of each attack event forest, and send each attack event forest and the confidence score of each attack event forest to the terminal device of the target user.
[0132] The technical solution of the embodiment of the present invention can complete each attack event forest of the lead data containing attack events belonging to the same attack path obtained after aggregation according to the known attack path information, improve the correlation ability of the lead data, and can provide each attack event forest and the confidence score of each attack event forest to the target user to help the target user discover long-term latent attacks on the business system, improve the detection ability and response ability of the business system to potential threats, and reduce the losses of the business system.
[0133] Embodiment III
[0134] Figure 3 It is a schematic structural diagram of a device for processing lead data of an attack event provided in Embodiment III of the present invention. The device can be configured in the business system of an enterprise. As Figure 3 shown, the device includes: a data acquisition module 301, a first aggregation module 302, a second aggregation module 303, and an information providing module 304.
[0135] Among them, the data acquisition module 301 is used to regularly acquire each clue data within a preset time period; among them, each clue data is log layer clue data or alarm layer clue data; the first aggregation module 302 is used to aggregate each clue data according to the generation time in each clue data to obtain multiple attack event trees; among them, each attack event tree is composed of clue data belonging to the same attack event; the second aggregation module 303 is used to aggregate each attack event tree according to the path information, identification information and time information of each attack event tree to obtain one or more attack event forests; among them, each attack event forest is composed of attack event trees belonging to the same attack path; the information providing module 304 is used to provide each attack event forest to the target user.
[0136] The technical solution of the embodiment of the present invention is to regularly acquire each clue data within a preset time period, and each clue data is log layer clue data or alarm layer clue data; then aggregate each clue data according to the generation time in each clue data to obtain multiple attack event trees, and each attack event tree is composed of clue data belonging to the same attack event; aggregate each attack event tree according to the path information, identification information and time information of each attack event tree to obtain one or more attack event forests, and each attack event forest is composed of attack event trees belonging to the same attack path, and provide each attack event forest to the target user, solving the problem that the clue data processing solution of attack events in the related technology cannot regularly aggregate the clue data of attack events, aggregate the clue data belonging to the same attack event, aggregate the clue data of attack events belonging to the same attack path, and it is difficult to capture long-term latent attacks in the business system, resulting in low detection ability and response ability of the business system to potential threats. It can regularly aggregate each clue data according to the time information of the clue data of each attack event that has occurred within the preset time period to obtain multiple attack event trees composed of clue data belonging to the same attack event, and aggregate each attack event tree according to the path information, identification information and time information of each obtained attack event tree to obtain one or more attack event forests composed of attack event trees belonging to the same attack path, so as to regularly aggregate the clue data of attack events, aggregate the clue data belonging to the same attack event, aggregate the clue data of attack events belonging to the same attack path, and can provide each attack event forest containing the clue data of attack events belonging to the same attack path obtained after aggregation to relevant technical personnel, so that relevant technical personnel can timely analyze and determine whether there is a long-term latent attack against the business system based on the clue data of attack events belonging to the same attack path in each attack event forest, and improve the detection ability and response ability of the business system to potential threats.
[0137] In an alternative implementation manner of the embodiment of the present invention, optionally, the data acquisition module 301 is further configured to: for each piece of target log layer clue data lacking entity information among the respective clue data, perform the following operations: determine the complete log information matching the target log layer clue data; construct a virtual entity of the target log layer clue data according to the entity information in the complete log information, and add the relevant information of the virtual entity of the target log layer clue data to the target log layer clue data.
[0138] In an alternative implementation manner of the embodiment of the present invention, optionally, the first aggregation module 302 is specifically configured to: divide the preset time period into multiple time windows according to the preset time window size, and determine the time window where the generation time in each piece of clue data is located; determine the clue data with the generation time in the same time window as the clue data belonging to the same attack event; for each group of clue data belonging to the same attack event, use each piece of clue data as a node, establish a connection line between each node and its adjacent node, obtain the connection edges between each node and its adjacent node, and converge all the nodes and the connection edges between the nodes to obtain an attack event tree composed of the clue data belonging to the same attack event.
[0139] In an alternative implementation manner of the embodiment of the present invention, optionally, the second aggregation module 303 is specifically configured to: determine the attack event trees with similar path information or the same identification information as the attack event trees belonging to the same attack path; for each group of attack event trees belonging to the same attack path, sort the respective attack event trees in the order of time information from front to back to obtain an attack event forest composed of the attack event trees belonging to the same attack path.
[0140] In an alternative implementation manner of the embodiment of the present invention, optionally, the clue data processing device for attack events further includes: a completion module, configured to complete each attack event forest according to the known attack path information.
[0141] In an alternative implementation manner of the embodiment of the present invention, optionally, the information providing module 304 is specifically configured to: determine the confidence score of each attack event forest, and send each attack event forest and the confidence score of each attack event forest to the terminal device of the target user.
[0142] The clue data processing device for attack events provided by the embodiment of the present invention can execute the clue data processing method for attack events provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the method.
[0143] Embodiment Four
[0144] Figure 4 FIG. 1 shows a schematic structural diagram of an electronic device 10 that can be used to implement the clue data processing method for attack events in embodiments of the present invention. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, electronic devices, blade electronic devices, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0145] As Figure 4 shown, the electronic device 10 includes at least one processor 11, and a memory communicatively connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc. The memory stores a computer program executable by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. The input / output (I / O) interface 15 is also connected to the bus 14.
[0146] Multiple components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disc, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0147] The processor 11 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the clue data processing method for attack events.
[0148] In some embodiments, the method for processing clue data of an attack event may be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as a storage unit. In some embodiments, part or all of the computer program may be loaded and / or installed onto the heterogeneous hardware accelerator via the ROM and / or the communication unit. When the computer program is loaded into the RAM and executed by the processor, one or more steps of the method for processing clue data of the attack event described above may be executed. Alternatively, in other embodiments, the processor may be configured to execute the method for processing clue data of the attack event by any other suitable means (e.g., by means of firmware).
[0149] The various embodiments of the systems and techniques described above in this document may be implemented in digital electronic circuitry, integrated circuit systems, field programmable gate arrays (FPGA), application specific integrated circuits (ASIC), application specific standard products (ASSP), system on a chip (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include: being implemented in one or more computer programs executable and / or interpretable on a programmable system including at least one programmable processor, which may be a special-purpose or general-purpose programmable processor that receives data and instructions from a storage system, at least one input device, and at least one output device, and transmits the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0150] The computer program for implementing the method of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer programs are executed by the processor, the functions / operations specified in the flowchart and / or block diagram are implemented. The computer programs may be executed entirely on the machine, partially on the machine, as a stand-alone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or electronic device.
[0151] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0152] In order to provide interaction with a user, the systems and techniques described herein can be implemented on a heterogeneous hardware accelerator that has: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the heterogeneous hardware accelerator. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, speech input, or tactile input).
[0153] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data electronic device), or a computing system that includes middleware components (e.g., an application electronic device), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected to each other by any form or medium of digital data communication (e.g., a communication network). Examples of the communication network include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0154] A computing system may include a client and an electronic device. The client and the electronic device are generally far from each other and usually interact via a communication network. The relationship between the client and the electronic device is generated by computer programs running on respective computers and having a client-electronic device relationship with each other. The electronic device may be a cloud electronic device, also known as a cloud computing electronic device or a cloud host, which is a host product in a cloud computing service system, and solves the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.
[0155] It should be understood that various forms of processes shown above can be used, steps can be reordered, added or deleted. For example, the steps recited in the present invention can be executed in parallel, sequentially or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is made herein.
[0156] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method for processing clue data of an attack event, characterized in that: include: Regularly obtain each clue data within a preset time period; wherein each clue data is log layer clue data or alarm layer clue data; Aggregate each clue data according to the generation time in each clue data to obtain multiple attack event trees; wherein each attack event tree is composed of clue data belonging to the same attack event; Aggregating each attack event tree according to the path information, identification information and time information of each attack event tree to obtain one or more attack event forests; wherein each attack event forest is composed of attack event trees belonging to the same attack path; Provide each attack event forest to the target user.
2. The method for processing clue data of attack events according to claim 1, characterized in that: After regularly obtaining the data of each clue within the preset time period, it also includes: For each target log layer clue data with missing entity information in each clue data, perform the following operations: Determine the complete log information that matches the target log layer clue data; According to the entity information in the complete log information, a virtual entity of the target log layer clue data is constructed, and relevant information of the virtual entity of the target log layer clue data is added to the target log layer clue data.
3. The method for processing clue data of attack events according to claim 1, characterized in that: Aggregate each clue data according to its generation time to obtain multiple attack event trees, including: Dividing the preset time period into multiple time windows according to the preset time window size, and determining the time window where the generation time in each clue data is located; Determine clue data generated in the same time window as clue data belonging to the same attack event; For each group of clue data belonging to the same attack event, each clue data is taken as a node, and a connection is established between each node and the adjacent node to obtain the connection edge between each node and the adjacent node. The connection edges between all nodes are aggregated to obtain an attack event tree composed of clue data belonging to the same attack event.
4. The method for processing clue data of attack events according to claim 1, characterized in that: Aggregate each attack event tree according to the path information, identification information, and time information of each attack event tree to obtain one or more attack event forests, including: Determine attack event trees with similar path information or identical identification information as attack event trees belonging to the same attack path; For each group of attack event trees belonging to the same attack path, the attack event trees are sorted in order from front to back according to the time information, and an attack event forest consisting of the attack event trees belonging to the same attack path is obtained.
5. The method for processing clue data of attack events according to claim 1, characterized in that: After aggregating each attack event tree according to the path information, identification information and time information of each attack event tree to obtain one or more attack event forests, the method further includes: Based on the known attack path information, each attack event forest is completed.
6. The method for processing clue data of attack events according to claim 1, characterized in that: Provide each attack event forest to the target user, including: A confidence score of each attack event forest is determined, and each attack event forest and the confidence score of each attack event forest are sent to a terminal device of a target user.
7. A clue data processing device for attack events, characterized in that: include: The data acquisition module is used to periodically acquire various clue data within a preset time period; wherein each clue data is log layer clue data or alarm layer clue data; A first aggregation module is used to aggregate each clue data according to the generation time in each clue data to obtain multiple attack event trees; wherein each attack event tree is composed of clue data belonging to the same attack event; A second aggregation module is used to aggregate each attack event tree according to the path information, identification information and time information of each attack event tree to obtain one or more attack event forests; wherein each attack event forest is composed of attack event trees belonging to the same attack path; The information providing module is used to provide each attack event forest to the target user.
8. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively coupled to the at least one processor; The memory stores a computer program executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the method for processing clue data of an attack event according to any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the method for processing clue data of an attack event according to any one of claims 1 to 6 when executed.
10. A computer program product, characterized in that The computer program product comprises a computer program, and when the computer program is executed by a processor, the computer program implements the method for processing clue data of an attack event according to any one of claims 1 to 6.