Security policy generation method and related equipment
By building a security event feature rule library and a policy model library, and using evidence theory and Apriori association rule algorithm to generate security policies, the problem of insufficient coordinated response of security equipment in the power network is solved, and the coordinated response of full-scene network security protection is achieved.
Patent Information
- Application Number
- CN202510403241.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-01
- Publication Date
- 2025-07-08
AI Technical Summary
The log information and security incident behaviors cannot be shared between security equipment of different types, brands and models in the existing power network, and the lack of an effective collaborative response mechanism is possible, which cannot meet the construction needs of the full-scene network security protection system.
By building a security event feature rule library and a policy model library, data correlation analysis is performed using evidence theory and Apriori association rule algorithm to generate security policies, and achieve collaborative responses of heterogeneous devices.
The security event feature rule library and policy model library were effectively built, and the security policy was automatically generated and optimized, and the security event policy update was adapted to the security event policy update, which improved the collaborative response capabilities of network security.
Smart Images

Figure CN120281526A_ABST
Abstract
Description
Technical Field
[0001] One or more embodiments of the present application relate to the technical field of power network security, and in particular, to a security policy generation method and related devices. Background Art
[0002] In the development and application of power networks, how to respond to security events based on power network data and generate corresponding policies has always been a hot research issue.
[0003] In recent years, with the rapid development of network technologies in the power industry, the continuous development and progress of business digitization and informatization, there are also problems such as a large number of security devices, various types, and inconsistent protocols in network security products. Log information and security event behaviors cannot be shared among security devices of different types, brands, and models. There is a lack of an effective collaborative response mechanism among security events, and it cannot fully meet the construction requirements of a full-scenario network security protection system. Summary of the Invention
[0004] In view of this, the purpose of one or more embodiments of the present application is to propose a security policy generation method and related devices to solve the problems raised in the background art.
[0005] Based on the above purpose, one or more embodiments of the present application provide a security policy generation method, including:
[0006] In response to a security event satisfying any pre-stored trigger condition in the security event feature library, determining a measure action corresponding to the security event;
[0007] Generating a security policy according to the security event and the measure action.
[0008] Optionally, determining whether the security event satisfies any pre-stored trigger condition in the security event feature library includes:
[0009] Extracting the features of the security event;
[0010] In response to determining that the features of the security event belong to the trigger condition set, the security event satisfies the trigger condition.
[0011] Optionally, before determining the measure action corresponding to the security event, it further includes:
[0012] Extracting the security event features of the security events for training and constructing a trigger condition set;
[0013] Extracting the disposal measure features of the preset disposal measures and constructing a disposal measure set, where the disposal measures include measure actions;
[0014] Construct the mapping relationship between the security event and the handling measures according to the set of triggering conditions and the set of handling measures.
[0015] Optionally, determining the measure action corresponding to the security event includes:
[0016] Determine the measure action corresponding to the security event according to the characteristics of the security event and the mapping relationship between the security event and the handling measures.
[0017] Optionally, the mapping relationship is determined according to the set of triggering conditions and the set of measure actions through a preset association rule analysis algorithm.
[0018] Optionally, the security policy is expressed as policy(priority, subject, target, condition, trigger, action, flag, TTL);
[0019] Wherein, priority represents the priority of the security policy, subject represents the execution entity of the security policy, target represents the object of action of the security policy, condition represents the triggering condition of the security policy, trigger represents the trigger of the security policy, action represents the measure action of the security policy, flag represents the type of the security policy, its value is true or false, true means the execution entity executes the measure action on the object of action under the triggering condition, false means the execution entity prohibits executing the measure action on the object of action under the triggering condition, and TTL represents the valid time of the behavior of the security policy.
[0020] Optionally, store the security policy in the security policy library.
[0021] Optionally, perform an optimization operation on the security policy library, and the optimization operation includes performing at least one of conflict detection, standardization, anomaly analysis, and cross-security policy merging.
[0022] Optionally, the conflict detection includes modal conflict detection and / or corresponding conflict detection.
[0023] Optionally, the data of the security event is accessed through a standard interface.
[0024] Based on the same inventive concept, one or more embodiments of the present application also provide a security policy generation device, including:
[0025] A collaborative response module, configured to determine the measure action corresponding to the security event in response to the security event satisfying any pre-stored triggering condition in the security event feature library;
[0026] A policy automatic generation module, configured to generate a security policy according to the security event and the measure action.
[0027] Optionally, determining whether the security event satisfies any pre-stored triggering condition in the security event feature library includes:
[0028] Extracting the features of the security event;
[0029] In response to determining that the features of the security event belong to the set of triggering conditions, the security event satisfies the triggering condition.
[0030] Optionally, before determining the measure action corresponding to the security event, it further includes:
[0031] Extracting the security event features of the security events for training and constructing a set of triggering conditions;
[0032] Extracting the disposal measure features of the preset disposal measures and constructing a set of disposal measures, where the disposal measures include measure actions;
[0033] According to the set of triggering conditions and the set of disposal measures, constructing the mapping relationship between the security event and the disposal measures.
[0034] Optionally, the determining the measure action corresponding to the security event includes:
[0035] Determining the measure action corresponding to the security event according to the features of the security event and the mapping relationship between the security event and the disposal measures.
[0036] Optionally, the mapping relationship is determined according to the set of triggering conditions and the set of measure actions through a preset association rule analysis algorithm.
[0037] Optionally, the security policy is represented as policy(priority, subject, target, condition, trigger, action, flag, TTL);
[0038] Among them, priority represents the priority of the security policy, subject represents the execution entity of the security policy, target represents the object of action of the security policy, condition represents the trigger condition of the security policy, trigger represents the trigger of the security policy, action represents the measure action of the security policy, flag represents the type of the security policy, and its value is true or false. True means that the execution entity executes the measure action on the object of action under the trigger condition, and false means that the execution entity is prohibited from executing the measure action on the object of action under the trigger condition. TTL represents the effective time of the behavior of the security policy.
[0039] Optionally, it further includes:
[0040] Storing the security policy in a security policy library.
[0041] Optionally, it further includes:
[0042] Performing an optimization operation on the security policy library, and the optimization operation includes at least one of performing conflict detection, standardization, anomaly analysis, and cross-security policy merging.
[0043] Optionally, the conflict detection includes modal conflict detection and / or corresponding conflict detection.
[0044] Optionally, the data of the security event is accessed through a standard interface.
[0045] Based on the same inventive concept, one or more embodiments of the present application further provide an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the security policy generation method described in any one of the above.
[0046] Based on the same inventive concept, one or more embodiments of the present application further provide a non-transitory computer-readable storage medium. The non-transitory computer-readable storage medium stores computer instructions, and the computer instructions are used to cause the computer to execute the security policy generation method described in any one of the above.
[0047] As can be seen from the above, in the security policy generation method provided by one or more embodiments of the present application, by responding to a trigger condition pre-stored in the security event feature library triggered by any of the security events, the measure actions corresponding to the security events are determined; and a security policy is generated based on the security events and the measure actions. One or more embodiments of the present application preset a security event feature library, associate the trigger conditions of the measure actions with the measure actions, and generate a security policy based on the security events and the measure actions, thereby solving the problem of the lack of an effective response mechanism between security events and measure actions of different data sources.
[0048] A security policy generation device, an electronic device, and a computer-readable storage medium provided by the present application can all implement the steps of the above security policy generation method, and thus also have the beneficial effects of the above security policy generation method. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] In order to more clearly illustrate the technical solutions in one or more embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only one or more embodiments of the present application. For those of ordinary skill in the art, other drawings can also be obtained based on these drawings without creative efforts.
[0050] Figure 1 It is a flowchart of the security policy generation method for one or more embodiments of the present application;
[0051] Figure 2 It is a structural diagram of the security policy generation device for one or more embodiments of the present application;
[0052] Figure 3 It is a schematic diagram of the hardware structure of the electronic device for one or more embodiments of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0053] To make the objectives, technical solutions, and advantages of the present disclosure clearer and more understandable, the following further describes the present disclosure in detail with reference to specific embodiments and the accompanying drawings.
[0054] It should be noted that, unless otherwise defined, the technical terms or scientific terms used in one or more embodiments of this application should have the ordinary meaning understood by those of ordinary skill in the art to which this disclosure pertains. The terms "first", "second" and similar terms used in one or more embodiments of this application do not denote any order, quantity or importance, but are only used to distinguish different components. Words such as "including" or "comprising" mean that the elements or objects appearing before this word cover the elements or objects listed after this word and their equivalents, without excluding other elements or objects. Words such as "connected" or "coupled" are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. "Up", "down", "left", "right", etc. are only used to indicate relative position relationships, and when the absolute position of the object being described changes, the relative position relationship may also change accordingly.
[0055] As described in the background art section, currently, a multi-source heterogeneous security log correlation analysis technology based on big data and a method for generating a linkage disposal strategy for heterogeneous device security events based on machine learning have been realized. The correlation analysis of multi-source heterogeneous security logs is achieved by using big data analysis technology, security capability software automatic orchestration technology, and security device collaborative defense technology. In-depth network security management is realized based on machine learning, and the correlation analysis and collaborative response of security devices with different manufacturers and different technical routes are achieved.
[0056] In the related art, there is a problem that there is no effective collaborative response mechanism between security events, and the construction requirements of the full-scenario network security protection system cannot be fully met. Specifically, although the related art can provide users with the entire threat life cycle management, covering pre-event warning, in-event detection, and post-event traceability, to help users control the security situation of the entire network and enhance the security guarantee ability of the information system, it cannot effectively build a security event feature rule base, build a policy model base, automatically generate and optimize policies, realize the collaborative response of intelligent analysis of heterogeneous security devices, and support automated linkage disposal.
[0057] In the process of implementing the present disclosure, the applicant found that by introducing the evidence theory and the Apriori association rule algorithm, it is possible to complete the research on the data association analysis technology of heterogeneous device security events and realize the association analysis of security alerts and policies. Based on this, the present application proposes an intelligent analysis network security collaborative response device. Through multi-source heterogeneous data collection and preprocessing, the network security collaborative response device is based on business feature extraction to realize the feature analysis and extraction of security events such as threat intelligence, attack behavior, and security alerts, construct a security event behavior feature rule model library, establish a collection policy model library, a security monitoring policy library, and a defense policy library through modeling analysis and association analysis, and then perform policy generation and collaborative response binding through security event trigger response rules, time scheduling, etc.; effectively construct a feature rule library; construct a policy model library; automatically generate policies and optimize policies to adapt to security event policy updates, policy convergence, and other collaborative response devices.
[0058] Reference Figure 1 , the security policy generation method of one or more embodiments of the present application includes the following steps:
[0059] Step S101: In response to a security event satisfying any pre-stored trigger condition in the security event feature library, determine the measure action corresponding to the above security event.
[0060] In this step, by judging whether the obtained security event data responds to the trigger condition, the measure action corresponding to the security event is determined.
[0061] The above security event can be determined by abnormal behaviors detected by intelligent protocol recognition technology. The above detection behavior can be based on actively collected or passively received data, and the detection behavior can include identifying one or more of Web attacks, DDOS attacks, vulnerability scans, and brute force cracking. The present application does not limit the specific detection behavior. The present application can support the detection of abnormal behaviors of various protocols, including protocols such as HTTP, STMP, FTP, MODBUS, and TELNET. The present application does not limit some types.
[0062] In some embodiments, the above security event data can be accessed into the collaborative response system through a standard interface as the basis for collaborative response. For example, data is received through Syslog or Kafka, APT methods. The meaning, type, and length of the fields must be clearly defined in the interface specification. The data transmission encryption method between the security device and the collaborative response system during data reporting should be clearly defined in the access specification, and the authentication method of the interface should be clearly defined.
[0063] In some embodiments, the above security event data can be preprocessed first. The preprocessing may include the following operations: data parsing, data redundancy removal, data reduction, and data merging. The present application does not limit the specific content of the preprocessing operations.
[0064] Optionally, the above security event feature library stores a set of trigger conditions and a set of measure actions. The above set of trigger conditions consists of security event features, and the set of measure actions consists of measure action features. In some embodiments, there is an association relationship between the elements in the above set of trigger conditions and the elements in the set of measure actions, and this association relationship can be obtained through association analysis using SIEM technology, SOAR technology, and the Apriori association rule analysis algorithm.
[0065] Specifically, in some embodiments, the construction operation of the security event feature library includes: obtaining security event data from different sources, and based on the particle swarm algorithm, searching for the optimized exponential weights of different data sources according to the competition and cooperation relationships among individuals in the population; through a decision tree, based on the characteristics of different types of security event data, classifying the above security data and extracting the data characteristics of different types of data; based on the category of the data, constructing different rule models to implement a feature rule library including an expert knowledge library, an information parameter library, and a feature rule model. Optionally, after obtaining the security event data, the data can be screened to filter out non-security data and mine information such as real network attack behaviors and threat intelligence.
[0066] Specifically, during the establishment process of the feature rule library, the data can be analyzed for association through the Apriori association rule analysis algorithm.
[0067] The Apriori association rule analysis algorithm is a classic data mining algorithm for mining frequent item sets and association rules. This association rule belongs to single-dimensional, single-layer, and Boolean association rules in terms of classification. All item sets with a support greater than the minimum support are called frequent item sets, simply referred to as frequent sets. It is implemented by restricting candidate generation to discover frequent item sets, and generating strong association rules from the frequent item sets, and these rules must be greater than or equal to the minimum support and the minimum confidence.
[0068] The core idea of the frequent item set of the Apriori association rule analysis algorithm is to mine frequent item sets through two stages: candidate set generation and downward closure detection of episodes, and measure the discovery of frequent item sets through support, confidence, and lift. The implementation method for discovering frequent item sets is:
[0069] Step S201: Scan the data set to obtain all the data that has appeared, as candidate 1-item sets;
[0070] Step S202: Mine frequent k-itemsets, scan and calculate the support of candidate k-itemsets, and prune the candidate k-itemsets by pruning method to remove the data sets with support lower than the minimum support α to obtain frequent k-itemsets. If the frequent k-itemsets are empty, return the set of frequent (k - 1)-itemsets as the algorithm result and end the algorithm.
[0071] Step S203: Based on the frequent k-itemsets, link to generate candidate (k + 1)-itemsets, and use Step S202 to iteratively obtain the result of (k = k + 1)-itemsets.
[0072] The Apriori association rule analysis algorithm generates association rules in the form of generating association rules from frequent itemsets. The process of generating association rules is as follows:
[0073] Step S301: For each frequent itemset I, generate all non-empty subsets of I.
[0074] Step S302: For each non-empty subset s of I, if support(l) / support(s) ≥ min_conf, then output the rule "s(l - s)". Here, min_conf is the minimum confidence threshold.
[0075] The frequent itemset discovery of the Apriori association rule analysis algorithm measures the discovery of frequent itemsets through support, confidence, and lift. Support is the proportion of the number of occurrences of one or several related things in the dataset to the total dataset. To put it simply, it is the probability of one or several related things occurring. If you want to analyze two related data A and B, the calculation method is:
[0076]
[0077] Confidence represents the probability of another thing occurring when one thing occurs, that is, conditional probability. The calculation method is:
[0078]
[0079] It can also be extended to the association confidence of multiple data by analogy. For example, for three data A, B, and C, the confidence of X for B and C is:
[0080]
[0081] Lift represents the ratio of the probability of containing A simultaneously under the condition of containing B to the overall probability of A occurring, that is:
[0082]
[0083] If the lift is greater than 1, then B→A is a valid strong association rule. If the lift is less than or equal to 1, then B→A is an invalid strong association rule. In a special case, if A and B are independent, then Lift(B→A) = 1 because P(A|B) = P(A) at this time. Generally speaking, to select the frequent data sets in a data set, it is necessary to customize the evaluation criteria. The most commonly used evaluation criteria are the custom support, or a combination of the custom support and confidence.
[0084] Step S102: Generate a security policy according to the above security events and the above measure actions.
[0085] As described above, according to the above security event feature library, the generation of the security policy can be triggered. Specifically, according to the feature rule library, the security event behaviors can be analyzed through association analysis technologies such as support vector machines, probabilistic statistical analysis, D-S evidence theory, and data mining, as well as the collaborative response configuration of the network topology and the collaborative response configuration of the disposal measures of the heterogeneous security devices associated with the analysis platform, the behavior features are extracted, and the single mapping or multi-mapping relationship between the security threats and security measures is captured to trigger the automatic generation of the policy.
[0086] The description form of the trigger condition and action of the automatic policy generation in the above content can be "execute the measure action in response to the trigger condition" (if condition then action, IETF). The above security policy can be expressed as policy(priority, subject, target, condition, trigger, action, flag, TTL). Among them, priority represents the priority of the security policy, ranging from 0 to 255, and the smaller the number, the higher the priority. Subject represents the execution entity of the security policy, target represents the object of action of the security policy, condition represents the trigger condition of the security policy, trigger represents the trigger of the security policy, action represents the measure action of the security policy, flag represents the type of the security policy, and its value is true or false. True means that the execution entity executes the measure action on the object of action under the trigger condition, and false means that the execution entity prohibits executing the measure action on the object of action under the trigger condition. TTL represents the effective time of the behavior of the security policy, and the unit is seconds.
[0087] In some embodiments, the technical solution of the present application may further include: storing the security policy in a security policy library. Specifically, the above security policy library may include a collection security policy library, a monitoring security policy library, and a defense security policy library. The specific structures of the above various types of security policy libraries are defined according to the security policy classification.
[0088] In addition, since security incidents change with the upgrade of the power grid, security policies also need to be optimized in real time accordingly.
[0089] In some embodiments, the optimization of the security policy library specifically includes: based on the trigger condition set, response action set and construction of the feature rule library and the policy library, optimizing the policy according to different policies and scenarios. Optionally, the policy optimization technology can manage, detect conflicts and optimize and merge the above three policies based on the different characteristics and linkage implementation mechanisms of the collection policy, attack monitoring policy and defense policy.
[0090] That is to say, the optimization of the security policy library can be achieved through the following operations:
[0091] Policy conflict detection. Policy conflicts include modal conflicts and application-related conflicts. At present, the existing policy conflict detection methods are mainly based on the static analysis of the triple of subject, object and measure, lacking effective means to judge event overlap, and the research on application-related conflicts is relatively insufficient.
[0092] Policy optimization and merging. In the optimization scenario of the collaborative response policy, simple analysis is not applicable to the management of a large amount of policy data. Therefore, management algorithms are needed to manage the policy set automatically or semi-automatically. The specific content of optimization and merging includes: standardization, scanning all policies and converting non-standard policies into standard policies; anomaly analysis, using algorithms to automatically analyze the relationship between newly inserted policies and existing policies in the policy model library. If there is a situation of mutual shielding or redundancy between the policy and the existing policies, then the policy is an abnormal policy and needs to prompt manual judgment or make other corresponding dispositions. Currently, the commonly used anomaly detection methods include: rule conflict detection based on decision trees, rule conflict detection algorithms based on induction, anomaly detection algorithms based on firewall decision tables, anomaly detection algorithms based on bit vectors, etc.; cross-merging. If there are a large number of cross-policies in the policy set, then filtering a packet may require multiple matches to find a completely matching policy, which greatly reduces the efficiency of policy execution. Therefore, such cross-policies need to be merged, and continuous policies are merged to reduce the number of policies and improve the working efficiency of security devices.
[0093] Modal conflicts in policy conflict detection technology refer to inconsistencies in policy descriptions. Such inconsistencies occur when two or more policies with opposite signs act on the same subject, object, and measure. According to the types of conflicting policies, modal conflicts can be divided into three types: authorization policy conflict - an authorization policy conflict occurs when a positive authorization policy and a negative authorization policy have the same subject, object, and measure; duty policy conflict - a duty policy conflict occurs when a positive duty policy requires a subject to perform a specific measure, while another negative duty policy (also called a restraint policy) prohibits the subject from performing this measure; duty and authorization policy conflict - a duty and authorization policy conflict occurs when a duty policy requires a subject to perform a specific measure, but there is a negative authorization policy that prohibits the subject from performing the measure.
[0094] Most modal conflicts can be detected by the static method of enumerating conflict characteristic attributes. If there is an intersection in the conflict characteristic attributes of two or more policies in the policy model library, then there is a modal conflict between them; most application-related conflicts cannot be detected by static methods. From the description of application-related conflict types, it can be found that the key to generating application-related conflicts is that there are the same associated objects between policies. Therefore, a dynamic method of attaching attribute labels to policy associated objects can be used to detect application-related conflicts.
[0095] Application-related conflicts in policy conflict detection technology usually refer to conflicts between policies and external constraints of policies, that is, the content of the policy conflicts with situations that are clearly stipulated not to occur in the external constraints. According to the differences in external constraint objectives, application-related conflicts can be divided into the following five types: subject association conflict - refers to the conflict caused by the same subject of two authorization policies when performing measures on different object sets; object association conflict - refers to the behavior that different subjects performing different measures on the same object may cause conflicts; measure association conflict - refers to the behavior that different subjects performing the same measure on the same object may cause conflicts; subject-object association conflict - when the objects and subjects of two positive authorization policies overlap, some measures may be defined as conflicts by the administrator's application; subject-object self-association conflict - external constraints may make special requirements for the subjects and objects of policies, that is, the so-called self-management problem. For example, it is required that the administrator cannot perform operations on himself.
[0096] Security event data such as security alerts, threat intelligence, and attack behaviors are accessed into the collaborative response system through standard interfaces as the basis for collaborative response, and data is received through Syslog or Kafka, APT methods. In the interface specification, the meanings, types, and lengths of fields must be clearly defined. In the access specification, the data transmission encryption method between the security device and the collaborative response system during the data reporting process should be clearly defined, and the authentication method of the interface should be clarified.
[0097] The full - life - cycle management of policies includes the management of the entire process from policy creation to submission, review, release, update, deletion, etc. During the policy generation process, it is necessary to consider the extraction of attack features, the triggering of defense actions, and their mutual mapping relationships. The factors that cause policy updates include changes in threat types, security defense measures, and network topologies, as well as optimization and merging changes between policies. Timeliness and linkage should be achieved during policy updates. Policy deletion refers to the policies that are merged during policy optimization and merging, or the policies that are no longer applicable due to changes in threats and security measures.
[0098] It can be understood that this method can be executed by any device, equipment, platform, or device cluster with computing and processing capabilities.
[0099] The technical carriers involved in the payment described in the embodiments of this application can include, for example, Near Field Communication (NFC), WIFI, 3G / 4G / 5G, POS machine card - swiping technology, two - dimensional code scanning technology, bar - code scanning technology, Bluetooth, infrared, Short Message Service (SMS), Multimedia Message Service (MMS), etc.
[0100] The biometric features involved in the biometric identification described in the embodiments of this application can include, for example, eye patterns, voiceprints, fingerprints, palm prints, heartbeats, pulses, chromosomes, DNA, human bite marks, etc. Among them, eye patterns can include biometric features such as irises and scleras.
[0101] It should be noted that the method of one or more embodiments of this application can be executed by a single device, such as a computer or a server. The method of this embodiment can also be applied to a distributed scenario and completed by multiple devices cooperating with each other. In such a distributed scenario, one of the multiple devices can only execute one or more steps of the method of one or more embodiments of this application, and these multiple devices will interact with each other to complete the described method.
[0102] It should be noted that the above - described specific embodiments of this application are described. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be executed in a different order than in the embodiments and still achieve the desired result. Additionally, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired result. In certain embodiments, multi - tasking and parallel processing are also possible or may be advantageous.
[0103] Based on the same inventive concept, corresponding to the method of any of the above embodiments, the present application further provides a security policy generation device.
[0104] As Figure 2 shown, the device includes:
[0105] A collaborative response module 11, configured to determine a measure action corresponding to the security event in response to the security event satisfying any pre-stored trigger condition in the security event feature library;
[0106] A policy automatic generation module 12, configured to generate a security policy according to the security event and the measure action.
[0107] Optionally, determining whether the security event satisfies any pre-stored trigger condition in the security event feature library includes:
[0108] Extracting the features of the security event;
[0109] In response to determining that the features of the security event belong to the trigger condition set, the security event satisfies the trigger condition.
[0110] Optionally, before determining the measure action corresponding to the security event, it further includes:
[0111] Extracting the security event features of the security events for training and constructing a trigger condition set;
[0112] Extracting the disposal measure features of the preset disposal measures and constructing a disposal measure set, where the disposal measures include measure actions;
[0113] According to the trigger condition set and the disposal measure set, constructing a mapping relationship between the security event and the disposal measure.
[0114] Optionally, determining the measure action corresponding to the security event includes:
[0115] According to the features of the security event and the mapping relationship between the security event and the disposal measure, determining the measure action corresponding to the security event.
[0116] Optionally, the mapping relationship is determined according to the trigger condition set and the measure action set through a preset association rule analysis algorithm.
[0117] Optionally, the security policy is represented as policy(priority, subject, target, condition, trigger, action, flag, TTL);
[0118] Among them, "priority" represents the priority of the above security policy, "subject" represents the execution entity of the above security policy, "target" represents the object of action of the above security policy, "condition" represents the trigger condition of the above security policy, "trigger" represents the trigger of the above security policy, "action" represents the measure action of the above security policy, "flag" represents the type of the above security policy, and its value is true or false. True means that the above execution entity executes the above measure action on the above object of action under the above trigger condition, and false means that the above execution entity prohibits executing the above measure action on the above object of action under the above trigger condition. "TTL" represents the effective time of the behavior of the above security policy.
[0119] Optionally, it further includes: storing the above security policy in a security policy library.
[0120] Optionally, it further includes:
[0121] Performing an optimization operation on the above security policy library, and the above optimization operation includes at least one of performing conflict detection, standardization, anomaly analysis, and cross-security policy merging.
[0122] Optionally, the above conflict detection includes modal conflict detection and / or corresponding conflict detection.
[0123] Optionally, the data of the above security event is accessed through a standard interface.
[0124] For the convenience of description, when describing the above device, various modules are described separately according to their functions. Of course, when implementing one or more embodiments of the present application, the functions of each module can be implemented in the same or multiple software and / or hardware.
[0125] The device of the above embodiment is used to implement the corresponding method in the foregoing embodiment, and has the beneficial effects of the corresponding method embodiment, which will not be elaborated here.
[0126] Figure 3 FIG. shows a more specific schematic diagram of the hardware structure of an electronic device provided in this embodiment. The device may include: a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. Among them, the processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040 are communicatively connected to each other inside the device through the bus 1050.
[0127] The processor 1010 can be implemented in the form of a general-purpose CPU (Central Processing Unit), a microprocessor, an Application Specific Integrated Circuit (ASIC), or one or more integrated circuits, etc., and is used to execute relevant programs to implement the technical solutions provided in the embodiments of the present application.
[0128] The memory 1020 can be implemented in the form of a ROM (Read Only Memory), a RAM (Random Access Memory), a static storage device, a dynamic storage device, etc. The memory 1020 can store an operating system and other application programs. When implementing the technical solutions provided in the embodiments of the present application through software or firmware, the relevant program codes are stored in the memory 1020 and are called and executed by the processor 1010.
[0129] The input / output interface 1030 is used to connect to an input / output module to implement information input and output. The input / output module can be configured as a component in the device (not shown in the figure) or can be externally connected to the device to provide corresponding functions. Among them, the input device can include a keyboard, a mouse, a touch screen, a microphone, various sensors, etc., and the output device can include a display, a speaker, a vibrator, an indicator light, etc.
[0130] The communication interface 1040 is used to connect to a communication module (not shown in the figure) to implement communication interaction between this device and other devices. Among them, the communication module can implement communication in a wired manner (such as USB, network cable, etc.) or can implement communication in a wireless manner (such as a mobile network, WIFI, Bluetooth, etc.).
[0131] The bus 1050 includes a path for transmitting information between various components of the device (such as the processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040).
[0132] It should be noted that although the above device only shows the processor 1010, the memory 1020, the input / output interface 1030, the communication interface 1040, and the bus 1050, in the specific implementation process, this device may also include other components necessary for normal operation. In addition, those skilled in the art can understand that the above device may also only include the components necessary to implement the solutions of the embodiments of the present application, and does not necessarily include all the components shown in the figure.
[0133] The electronic device in the above embodiment is used to implement the corresponding method in the foregoing embodiment and has the beneficial effects of the corresponding method embodiment, which will not be elaborated here.
[0134] The computer-readable medium of this embodiment includes both permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic tape magnetic disk storage or other magnetic storage devices, or any other non-transitory medium that can be used to store information that can be accessed by a computing device.
[0135] Those of ordinary skill in the art should understand that the discussion of any of the above embodiments is merely exemplary and is not intended to imply that the scope of the present disclosure (including the claims) is limited to these examples; within the concept of the present disclosure, the technical features in the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other variations in different aspects of one or more embodiments of the present application as described above, and for the sake of brevity, they are not provided in detail.
[0136] In addition, for the sake of simplicity of description and discussion, and in order not to make one or more embodiments of the present application difficult to understand, the well-known power / ground connections to integrated circuit (IC) chips and other components may or may not be shown in the provided drawings. Further, the devices may be shown in block diagram form in order to avoid making one or more embodiments of the present application difficult to understand, and this also takes into account the fact that the details of the implementation of these block diagram devices are highly dependent on the platform on which one or more embodiments of the present application are to be implemented (i.e., these details should be fully within the understanding of those skilled in the art). In the case where specific details (such as circuits) are set forth to describe exemplary embodiments of the present disclosure, it will be apparent to those skilled in the art that one or more embodiments of the present application can be implemented without these specific details or with variations of these specific details. Therefore, these descriptions should be considered illustrative rather than restrictive.
[0137] Although the present disclosure has been described in connection with specific embodiments of the present disclosure, many alternatives, modifications, and variations of these embodiments will be apparent to those of ordinary skill in the art based on the foregoing description. For example, other memory architectures (such as dynamic RAM (DRAM)) can be used with the embodiments discussed.
[0138] One or more embodiments of the present application are intended to cover all such substitutions, modifications, and variations that fall within the broad scope of the appended claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of one or more embodiments of the present application shall be included within the scope of protection of the present disclosure.
Claims
1. A security policy generation method, characterized in that, Including: Determine a measure action corresponding to the security event in response to the security event satisfying any pre - stored trigger condition in the security event feature library; Generate a security policy according to the security event and the measure action.
2. The method according to claim 1, characterized in that, Judging whether the security event satisfies any pre - stored trigger condition in the security event feature library includes: Extract the features of the security event; In response to determining that the features of the security event belong to the trigger condition set, the security event satisfies the trigger condition.
3. The method according to claim 2, wherein Before determining the measure action corresponding to the security event, it further includes: Extract the security event features of the training security event and construct a trigger condition set; Extract the handling measure features of the preset handling measures and construct a handling measure set, where the handling measures include measure actions; Construct a mapping relationship between the security event and the handling measure according to the trigger condition set and the handling measure set.
4. The method according to claim 3, characterized in that, The determination of the measure action corresponding to the security event includes: Determine the measure action corresponding to the security event according to the features of the security event and the mapping relationship between the security event and the handling measure.
5. The method according to claim 3, characterized in that, The mapping relationship is determined according to the trigger condition set and the measure action set through a preset association rule analysis algorithm.
6. The method according to claim 1, characterized in that, The security policy is expressed as policy(priority, subject, target, condition, trigger, action, flag, TTL); Wherein, priority represents the priority of the security policy, subject represents the execution subject of the security policy, target represents the object of action of the security policy, condition represents the trigger condition of the security policy, trigger represents the trigger of the security policy, action represents the measure action of the security policy, flag represents the type of the security policy, its value is true or false, true means the execution subject executes the measure action on the object of action under the trigger condition, false means the execution subject prohibits executing the measure action on the object of action under the trigger condition, and TTL represents the valid time of the behavior of the security policy.
7. The method according to claim 1, wherein It further includes: Store the security policy in the security policy library.
8. The method according to claim 1, characterized in that, It further includes: Perform an optimization operation on the security policy library, and the optimization operation includes performing at least one of conflict detection, standardization, anomaly analysis, and cross - security policy merging.
9. The method according to claim 8, characterized in that, The conflict detection includes modal conflict detection and / or corresponding conflict detection.
10. The method according to claim 1, characterized in that The data of the security event is accessed through a standard interface.
11. A security policy generation device, characterized in that, Including: A collaborative response module, configured to determine a measure action corresponding to the security event in response to the security event satisfying any pre - stored trigger condition in the security event feature library; A policy automatic generation module, configured to generate a security policy according to the security event and the measure action.
12. The device according to claim 11, wherein Judging whether the security event satisfies any pre - stored trigger condition in the security event feature library includes: Extract the features of the security event; In response to determining that the characteristics of the security event belong to the set of trigger conditions, the security event meets the trigger conditions.
13. The device according to claim 12, characterized in that, Before determining the measure action corresponding to the security event, it further includes: Extracting the security event characteristics of the security events for training and constructing a set of trigger conditions; Extracting the measure characteristics of the preset handling measures and constructing a set of handling measures, where the handling measures include measure actions; Constructing the mapping relationship between the security event and the handling measures according to the set of trigger conditions and the set of handling measures.
14. The device according to claim 13, characterized in that, The determination of the measure action corresponding to the security event includes: Determining the measure action corresponding to the security event according to the characteristics of the security event and the mapping relationship between the security event and the handling measures.
15. The device according to claim 13, characterized in that, The mapping relationship is determined according to the set of trigger conditions and the set of measure actions through a preset association rule analysis algorithm.
16. The device according to claim 11, characterized in that, The security policy is represented as policy(priority, subject, target, condition, trigger, action, flag, TTL); Among them, priority represents the priority of the security policy, subject represents the execution entity of the security policy, target represents the object of action of the security policy, condition represents the trigger condition of the security policy, trigger represents the trigger of the security policy, action represents the measure action of the security policy, flag represents the type of the security policy, and its value is true or false. True means that the execution entity executes the measure action on the object of action under the trigger condition, and false means that the execution entity prohibits executing the measure action on the object of action under the trigger condition. TTL represents the valid time of the behavior of the security policy.
17. The device according to claim 11, characterized in that, It further includes: Storing the security policy in the security policy library.
18. The device according to claim 11, characterized in that, It further includes: Performing an optimization operation on the security policy library, and the optimization operation includes performing at least one of conflict detection, standardization, anomaly analysis, and cross-security policy merging.
19. The device according to claim 18, characterized in that, The conflict detection includes modal conflict detection and / or corresponding conflict detection.
20. The device according to claim 11, characterized in that, The data of the security event is accessed through a standard interface.
21. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the method according to any one of claims 1 to 9.
22. A non-transitory computer-readable storage medium, characterized in that, The non-transitory computer-readable storage medium stores computer instructions, and the computer instructions are used to make the computer execute the method according to any one of claims 1 to 9.
Citation Information
Cited By
Block chain-based information security intelligent management system and method
CN120639515A