Multi-SIEM system alarm processing method, device, equipment and medium
Through the alarm processing component on the main SIEM system side, the field mapping relationship and multi-language embedding model are used to automatically identify and manage the security logs of multi-SIEM systems, the problem of language and semantic differences between SIEM systems is solved, and efficient security event standardization and unified management are achieved.
Patent Information
- Application Number
- CN202510427711.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-07
- Publication Date
- 2025-07-08
AI Technical Summary
Previous Art In a multi-SIEM system environment, there are security log language and semantic differences between the SIEM systems of each branch and the SIEM system of the head office, resulting in complex unified management and waste of resources, and the inability to adapt to the rules of the headquarters SIEM system in a timely manner.
Through the alarm processing component on the main SIEM system side, the pre-established field mapping relationship and multilingual embedding model are used to automatically identify alarm information from the security log of the SIEM system, generate standard alarm logs and store them, and realize unified management of alarm information across systems.
It improves field recognition accuracy and standardization efficiency of security incidents, solves the problem of inconsistent security log language and semantics, and realizes unified management and efficient management of alarm data.
Smart Images

Figure CN120281627A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of security information management, and particularly relates to a method, device, equipment and medium for processing alarms in multiple SIEM systems. Background Art
[0002] A SIEM (Security Information and Event Management) system can be used to monitor, analyze and manage enterprise network security. During the security operation process of an enterprise organization, multiple SIEM systems from different manufacturers are usually used for security log collection and analysis. For example, for a global enterprise, its headquarters and each branch company may use different SIEM systems. Due to differences in the manufacturers and usage regions of these SIEM systems, in the security logs sent by each SIEM system, the languages and semantics of event fields and field values may all be different, thus increasing the complexity of the unified management of security events in the headquarters SIEM system for each branch company's SIEM system.
[0003] In existing technical solutions, generally, rule adjustments are made to security logs in the SIEM systems of each branch company, such as language adjustment, naming rule adjustment, etc., so that the security logs generated by the SIEM systems of each branch company can be adapted to the SIEM system of the head office.
[0004] However, if the existing technical solutions are adopted, a large amount of rule adjustment and adaptation work is required, and when the rules of the headquarters SIEM change, it is impossible to adapt to the changed rules in a timely manner, and the SIEM systems of the branch companies need to be re-adjusted for rules again, resulting in a certain waste of resources. Summary of the Invention
[0005] The present invention provides a method, device, equipment and medium for processing alarms in multiple SIEM systems, which can solve the problem of non-uniform languages and semantics of security logs in each SIEM system, improve the standardization efficiency of security events, and realize unified management of alarm data.
[0006] According to one aspect of the present invention, there is provided a method for processing alarms in multiple SIEM systems, which is executed by an alarm processing component configured on the main SIEM system side, and the main SIEM system is used to manage multiple slave SIEM systems, including:
[0007] When receiving a security log sent by a slave SIEM system, determine the original alarm information of at least one alarm content in the security log according to a pre-established field mapping relationship;
[0008] Determine a standard alarm information table according to the alarm content, and determine the target standard alarm information according to the original alarm information and the standard alarm information table;
[0009] Generate a standard alarm log according to the security log and the target standard alarm information, and store it for the main SIEM system to perform unified management of alarms based on the standard alarm log.
[0010] According to another aspect of the present invention, there is provided an alarm processing device for a multi-SIEM system, which is executed by an alarm processing component configured on the main SIEM system side. The main SIEM system is used to manage multiple slave SIEM systems, including:
[0011] An original alarm information acquisition module, configured to, when receiving a security log sent by a slave SIEM system, determine original alarm information of at least one alarm content in the security log according to a pre-established field mapping relationship;
[0012] A target standard alarm information acquisition module, configured to determine a standard alarm information table according to the alarm content, and determine target standard alarm information according to the original alarm information and the standard alarm information table;
[0013] A standard alarm log generation module, configured to generate a standard alarm log according to the security log and the target standard alarm information, and store it for the main SIEM system to perform unified management of alarms based on the standard alarm log.
[0014] According to another aspect of the present invention, there is provided an electronic device, which includes:
[0015] At least one processor; and
[0016] A memory communicatively connected to the at least one processor; wherein,
[0017] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the multi-SIEM system alarm processing method according to any embodiment of the present invention.
[0018] According to another aspect of the present invention, there is provided a computer-readable storage medium storing computer instructions for causing a processor to implement the multi-SIEM system alarm processing method according to any embodiment of the present invention when executed.
[0019] The technical solution of the embodiment of the present invention can automatically identify the fields in the security logs of each SIEM system that truly represent alarm information by determining the original alarm information of at least one alarm content according to the pre-established field mapping relationship, improving the field identification accuracy. By determining the target standard alarm information according to the original alarm information and the standard alarm information table, it can map the alarm information in various languages sent from different SIEM systems into normalized standard alarm information, improving the efficiency of security event standardization and solving the problem of inconsistent languages and semantics of the security logs of each SIEM system. By generating and storing the standard alarm log according to the security log and the target standard alarm information, unified management of alarm data standardization is achieved.
[0020] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. Brief Description of the Drawings
[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0022] Figure 1 It is a flowchart of a multi-SIEM system alarm processing method provided in Embodiment 1 of the present invention;
[0023] Figure 2 It is a schematic diagram of a SIEM system environment provided in the embodiment of the present invention;
[0024] Figure 3 It is a flowchart of a multi-SIEM system alarm processing method provided in Embodiment 2 of the present invention;
[0025] Figure 4 It is a schematic structural diagram of a multi-SIEM system alarm processing device provided in Embodiment 3 of the present invention;
[0026] Figure 5 It is a schematic structural diagram of an electronic device for implementing the multi-SIEM system alarm processing method of the embodiment of the present invention. Detailed Embodiments
[0027] To enable those skilled in the art to better understand the solution of the present invention, the following will clearly and completely describe the technical solution in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention.
[0028] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order different from those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0029] Embodiment 1
[0030] Figure 1 It is a flowchart of a method for processing alarms in a multi-SIEM system provided in Embodiment 1 of the present invention. This embodiment is applicable to the situation of standardizing alarm information in security logs sent from a SIEM system to adapt to the alarm information rules of the main SIEM system. This method can be executed by a multi-SIEM system alarm processing device, and the multi-SIEM system alarm processing device can be implemented in the form of hardware and / or software and is generally configured in the alarm processing component on the main SIEM system side.
[0031] As Figure 1 shown, the method includes:
[0032] S110. When receiving the security log sent from the SIEM system, determine the original alarm information of at least one alarm content in the security log according to the pre-established field mapping relationship.
[0033] It can be understood that the present invention is applicable to scenarios where a main SIEM system manages multiple slave SIEM systems, especially applicable to some global enterprises where the SIEM system manufacturers and languages used by the headquarters and each branch are different. Taking this situation as an example, the SIEM system used by the headquarters can be used as the main SIEM system, and the SIEM systems used by each branch can be used as slave SIEM systems. When a security event occurs in a slave SIEM system, the slave SIEM system will generate security logs for the management personnel of the slave SIEM system to view. However, at the same time, the security logs need to be reported to the main SIEM system for unified management by the management personnel of the head office. However, due to the differences in language and semantics between SIEM systems, the same type of security event may be regarded as different alarm events due to different languages and semantics. For example, for DNS (Domain Name System) anomaly events, the Chinese SIEM system may name them as "abnormal DNS request" or "malicious domain name request", and the English SIEM system may name them as "Suspicious DNS request" or "Anomalous DNS request". For different expressions, it may be difficult for the main SIEM system to distinguish whether they belong to the same type of security event, which increases the difficulty in aspects such as classification, reminder, and storage of security events. Moreover, for large enterprises with relatively scattered branches, their slave SIEM systems may be deployed in multiple countries using minority languages. As a result, the main SIEM system may collect security logs in multiple different languages such as Spanish, Portuguese, Japanese, Korean, etc. When the management personnel of the main SIEM system view the security logs, they cannot quickly and effectively obtain security event information, which increases the difficulty of unified management and reduces the efficiency of security event management.
[0034] Optionally, the alarm processing component can be configured in the local network environment on the main SIEM system side. When a security event occurs in a slave SIEM system, the slave SIEM system generates security logs according to its own rules. The security logs can be stored and displayed in the slave SIEM system and synchronously sent to the alarm processing component. After being processed by the alarm processing component, they are sent to the database of the main SIEM system for storage, and the processed security logs can also be displayed on the visualization panel of the main SIEM system. The advantage of not adjusting the security log rules of the slave SIEM system is that there is no need to adapt and transform the slave SIEM system, which reduces the adaptation cost and can be applicable to the SIEM system environments of each enterprise that have been deployed. Moreover, most of the management personnel of the slave SIEM system are already familiar with the semantic expressions of the slave SIEM system, and some management personnel may only use the language used by the slave SIEM system and are not familiar with the language used by the main SIEM system. If a transformation is carried out, it may cause difficulties for the management personnel of the slave SIEM system to use.
[0035] Figure 2 It is a schematic diagram of an optional SIEM system environment. As Figure 2 shown, SIEM A, SIEM B, and SIEM N can represent different slave SIEM systems. The slave SIEM systems can send security logs to the alarm processing component. After being processed by the alarm processing component, they are sent to the master SIEM system.
[0036] Among them, according to the pre-established field mapping relationship, determining the original alarm information of at least one alarm content in the security log may include:
[0037] According to the field mapping relationship, identifying the alarm information fields of at least one alarm content in the security log, and determining the field values of the alarm information fields as the original alarm information; among them, the field mapping relationship includes the description forms of the alarm information fields of each slave SIEM system under each alarm content.
[0038] Optionally, the alarm content may include an alarm name and an alarm type. The alarm information field of the alarm name is the alarm name field, and the alarm information field of the alarm type is the alarm type field.
[0039] Optionally, the field mapping relationship may include the description forms of the alarm name fields of each slave SIEM system and the description forms of the alarm type fields of each slave SIEM system. For example, for the alarm name, each slave SIEM system may describe the alarm name field in forms such as Name1, NameA, Alarm Name, etc. For the alarm type, each slave SIEM system may describe the alarm type field in forms such as Type1, TypeA, Alarm Type, etc.
[0040] Optionally, each description form of the alarm name fields in the field mapping relationship can be separately identified in the security log. When any description form of the alarm name field is identified, it is determined that the alarm name field is identified. Similarly, each description form of the alarm type fields in the field mapping relationship can be separately identified in the security log. When any description form of the alarm type field is identified, it is determined that the alarm type field is identified.
[0041] Optionally, the alarm information fields and the field values of the alarm information fields are stored correspondingly. After the alarm information fields are identified, the field values of the alarm information fields can be obtained. For example, in the security log of SIEM A, it may store Name1: Anomalous DNS request, where Name1 is the alarm name field and Anomalous DNS request is the field value of the alarm name field.
[0042] Optionally, the security log may include "Alarm Name Field: Original Alarm Name; Alarm Type Field: Level Indicator, Original Alarm Type"; the field value of the alarm name field can be used as the original alarm name; according to the field value of the alarm type, the original alarm type at at least one level can be determined. In the field value of the alarm type, at least one level indicator and the original alarm type corresponding to each level indicator are included. The level indicators include Level 1, Level 2, and Level 3. For example, "TypeA: Level1 Network Attack, Level2 Vulnerability Exploitation, Level3 SQL Injection" can indicate that the Level 1 classification of the alarm type is network attack, the Level 2 classification is vulnerability exploitation, and the Level 3 classification is SQL injection. Among them, network attack, vulnerability exploitation, and SQL injection are the original alarm types at different levels respectively, but it is not limited to the necessity of having the original alarm types at Level 1, Level 2, and Level 3 simultaneously. There may also be only Level 1, only Level 2, or both Level 1 and Level 2, etc. These situations are not listed one by one here.
[0043] S120. Determine the standard alarm information table according to the alarm content, and determine the target standard alarm information according to the original alarm information and the standard alarm information table.
[0044] Optionally, when the alarm content includes the alarm name and the alarm type, the standard alarm information table includes a standard alarm name table and an alarm type mapping table. Determine the target standard alarm name corresponding to the original alarm name according to the currently maintained standard alarm name table and the original alarm name, and determine the target standard alarm type at at least one level according to the alarm category mapping table and the original alarm type at at least one level.
[0045] Optionally, the standard alarm information table includes a standard alarm information column and alarm information columns in multiple different languages; the standard alarm information table also includes similarity information columns in multiple different languages.
[0046] Optionally, in the standard alarm name table, the alarm information column can refer to the alarm name column. Each row in the standard alarm name column records a standard alarm name. In the alarm name column in the target language, each row records the target language alarm name that matches the standard alarm name in that row. There can be multiple target language alarm names. The next column of the alarm name column in the target language is the similarity information column in the target language. In the similarity information column in the target language, each row records the similarity between each target language alarm name in that row and the standard alarm name in that row. Table 1 is an optional standard alarm name table.
[0047] Table 1
[0048]
[0049] As shown in Table 1, the first column is the column of standard alarm names. Data tampering, abnormal operations of privileged users, and malware propagation are the standard alarm names respectively. The second and third columns are the columns of English alarm names and English similarity information respectively. The fourth and fifth columns are the columns of French alarm names and French similarity information respectively, and so on. Other language alarm name columns and similarity information columns can be added later, which are not redundantly shown here. The standard alarm name recorded in the second row of the standard alarm name column is "Data tampering". Taking the English alarm name column as an example, three English expressions are recorded in its second row, all of which can represent data tampering. The English similarity information column records the similarities between these three English expressions and the Chinese "Data tampering". That is, the similarity between "data tampering" and "Data tampering" is 99%, and the similarity between "data falsification" and "Data tampering" is 95%. This is only for illustrative purposes here.
[0050] Optionally, the alarm type mapping table can be divided into multiple tables of different levels. There is 1 table for the level-1 alarm type mapping table. When N standard alarm types are recorded in the level-1 alarm mapping table, there are N tables for the level-2 alarm type mapping table. For the target level-1 standard alarm type in the level-1 alarm mapping table, all the level-2 standard alarm types under the target level-1 standard alarm type are recorded in its corresponding level-2 alarm type mapping table. The number of level-3 alarm type mapping tables depends on the number of standard alarm types in each level-2 alarm type mapping table. Similar to the foregoing content, it will not be elaborated.
[0051] In a specific example, when 3 standard alarm types are recorded in the level-1 alarm mapping table, there are 3 level-2 alarm mapping tables. If the numbers of standard alarm types recorded in these 3 level-2 alarm mapping tables are 2, 4, and 3 respectively, then there are a total of 2 + 4 + 3 = 9 level-3 alarm mapping tables.
[0052] Optionally, in the alarm type mapping table, the alarm information column can refer to the alarm type column. Each row in the standard alarm type column records a standard alarm type. In the alarm type column of the target language, each row records the target language alarm types that match the standard alarm type in that row. There can be multiple target language alarm types. The next column of the alarm type column in the target language is the similarity information column in the target language. In the similarity information column in the target language, each row records the similarities between the respective target language alarm types in that row and the standard alarm type in that row. Table 2 is an optional level-1 alarm type mapping table.
[0053] As shown in Table 2, the level-1 standard alarm types include network intrusion, host attack, and identity attack. For each standard alarm type, there are multiple description methods in different languages and forms. Only exemplary explanations are provided here.
[0054] As shown in the example of Table 2, there can be three level-2 alarm type mapping tables, which are respectively used to record the level-2 alarm types of network intrusion, host attack, and identity attack.
[0055] Table 2
[0056]
[0057] Among them, determining the target standard alarm information according to the original alarm information and the standard alarm information table may include:
[0058] Determine the first language to which the original alarm information belongs, and determine whether the original alarm information has been recorded in the alarm information column of the first language;
[0059] If so, determine the target standard alarm information according to the row position and the standard alarm information column where the original alarm information is located in the standard alarm information table;
[0060] If not, calculate the similarity between the original alarm information and each standard alarm information through a multilingual embedding model, and determine the target standard alarm information according to the similarity calculation result.
[0061] Optionally, regardless of whether the original alarm information is the original alarm name or the original alarm type, the standard alarm information can be determined through the above method. The first language is the language used for the original alarm information. If the original alarm information has been recorded in the alarm information column of the first language, the standard alarm information at the same row position in the standard alarm information column is determined according to the row where the original alarm information is located.
[0062] Furthermore, when the original alarm information is not recorded in the standard alarm information table, the original alarm information is converted into the second language used by the main SIEM system through a multilingual embedding model, and the similarity between the converted original alarm information and each standard alarm information is calculated, and the target standard alarm information is determined according to the similarity calculation result.
[0063] Optionally, the target standard alarm information can be determined according to the original alarm name and the standard alarm name table, specifically including: determining the first language to which the original alarm name belongs, and determining whether the original alarm name has been recorded in the alarm name column of the first language;
[0064] If so, determine the target standard alarm name according to the row position and the standard alarm name column where the original alarm name is located in the standard alarm name table;
[0065] If not, calculate the similarity between the original alarm name and each standard alarm name through a multilingual embedding model, and determine the target standard alarm name according to the similarity calculation result.
[0066] Optionally, according to the original alarm type and the alarm type mapping table, the target standard alarm information can be determined, specifically including: determining the first language to which the original alarm type belongs and the first level of the original alarm type, and judging whether the original alarm type of the first level has been recorded in the first language alarm type column of the alarm type mapping table of the first level;
[0067] If so, determine the target standard alarm type of the first level according to the row position of the original alarm type in the alarm type mapping table and the standard alarm type column, and when there is a secondary original alarm type, repeat the above operation according to the secondary alarm type mapping table corresponding to the target standard alarm type of the first level;
[0068] If not, calculate the similarity between the original alarm type and each standard alarm type in the alarm type mapping table of the first level through a multilingual embedding model, and determine the target standard alarm type of the first level according to the similarity calculation result.
[0069] Optionally, the first level is the highest level of the original alarm type recorded in the security log. If the original alarm types of level 1, level 2, and level 3 are recorded at the same time, level 1 is the highest level. If only the original alarm type of level 3 is recorded, level 3 is the highest level. This is only for illustrative purposes here.
[0070] It can be understood that since multiple levels of original alarm types may be recorded in the security log, therefore, starting from the highest level for matching, first determine the standard alarm type of the highest level. If there are secondary original alarm types, then determine the secondary alarm type mapping table. According to the secondary original alarm type and the secondary alarm type mapping table, determine the secondary standard alarm type. If there are still final-level original alarm types, then further determine the final-level alarm type mapping table, and repeat the above operation, which will not be elaborated here.
[0071] The advantage of such a setting is that: by establishing an alarm category mapping table across SIEM systems and combining a multilingual embedding model, it is possible to perform a normalization classification process on the alarm classifications in different SIEM systems. By introducing a hierarchical classification method and further classifying the alarm types by level, it can ensure that the alarms in different SIEM systems can be classified according to a unified rule, so that the main SIEM system can manage them according to the uniformly divided categories, and at the same time enable the main SIEM system to clarify the priority of each alarm and improve the alarm processing efficiency.
[0072] S130. Generate a standard alarm log based on the security log and the target standard alarm information, and store it for the main SIEM system to perform unified management of alarms according to the standard alarm log.
[0073] Optionally, the original security log, the target standard alarm information, and the identifier of the slave SIEM system that sent the security log can be packaged together to generate a standard alarm log, which is stored in the database on the main SIEM side.
[0074] Optionally, the target standard alarm information may include the target standard alarm name and the target standard alarm types at at least one level.
[0075] Optionally, the main SIEM system can perform unified classification management of the standard alarm logs according to the target standard alarm information in each standard alarm log in the database. For example, on the panel of the main SIEM system, the alarm name, alarm type, and the identifier of the slave SIEM system are displayed to the user. At this time, both the alarm name and the alarm type are adapted to the alarm rules of the main SIEM system, which can facilitate the management personnel of the main SIEM system to intuitively observe the alarm situations of each slave SIEM system and effectively improve the management efficiency.
[0076] The technical solution of the embodiment of the present invention can automatically identify the fields in the security logs of each SIEM system that truly represent alarm information by determining the original alarm information of at least one alarm content in the security log according to the pre-established field mapping relationship, improving the field recognition accuracy. By determining the target standard alarm information according to the original alarm information and the standard alarm information table, the alarm information in various languages sent by different slave SIEM systems can be mapped into normalized standard alarm information, improving the standardization efficiency of security events and solving the problem of non-uniformity of the languages and semantics of the security logs of each SIEM system. By generating and storing the standard alarm log based on the security log and the target standard alarm information, unified management of alarm data standardization is realized.
[0077] Embodiment Two
[0078] Figure 3 It is a flowchart of a method for processing alarms in a multi-SIEM system provided by the second embodiment of the present invention. Based on the above embodiment, this embodiment specifically describes the method for obtaining the target standard alarm information. As Figure 3 shown, the method includes:
[0079] S210. When receiving the security log sent by the slave SIEM system, identify the alarm information fields of at least one alarm content in the security log according to the field mapping relationship, and determine the field values of the alarm information fields as the original alarm information.
[0080] Among them, the field mapping relationship includes the description forms of the alarm information fields of each slave SIEM system under each alarm content.
[0081] Optionally, when the alarm content includes an alarm name and an alarm type, the alarm information fields include an alarm name field and an alarm type field, and the field mapping relationship includes the description forms of the alarm name field by each slave SIEM system and the description forms of the alarm type field by each slave SIEM system.
[0082] Optionally, the alarm content is not limited to the alarm name and the alarm type, and may also be the alarm time, compliance information, event source, etc. The present invention can be implemented only by creating a standard alarm information table corresponding to each alarm content.
[0083] S220. Determine a standard alarm information table according to the alarm content.
[0084] S230. Determine the first language to which the original alarm information belongs, and determine whether the original alarm information has been recorded in the alarm information column of the first language; if so, execute step S240; if not, execute step S250.
[0085] S240. Determine the target standard alarm information according to the row position of the original alarm information in the standard alarm information table and the standard alarm information column; execute step S260.
[0086] S250. Calculate the similarity between the original alarm information and each standard alarm information through a multilingual embedding model, and determine the target standard alarm information according to the similarity calculation result; execute step S260.
[0087] Among them, calculating the similarity between the original alarm information and each standard alarm information through a multilingual embedding model, and determining the target standard alarm information according to the similarity calculation result may include:
[0088] Through the multilingual embedding model, convert the original alarm information into the information description in the second language used by the main SIEM system, and calculate the similarity between the information description in the second language and each standard alarm information respectively;
[0089] Determine whether there is a standard alarm information with a similarity greater than a preset value;
[0090] If so, among the standard alarm information with a similarity greater than the preset value, determine the target standard alarm information, and record the original alarm information and the similarity between the original alarm information and the target standard alarm information in the standard alarm information table;
[0091] If not, determine the target standard alarm information according to the original alarm information and update the standard alarm information table.
[0092] It is understandable that the language used in the standard alarm message column is the secondary language used by the main SIEM system. By using a multilingual embedding model to convert the original alarm message into an information description in the secondary language, the matching accuracy of similarity can be improved.
[0093] Optionally, if there is only one standard alarm message with a similarity greater than the preset value, then determine this standard alarm message as the target standard alarm message. If there are multiple standard alarm messages with a similarity greater than the preset value, the standard alarm message with the highest similarity can be determined as the target standard alarm message, or the target standard alarm message can be selected by voting among multiple standard alarm messages through a voting mechanism.
[0094] Furthermore, record the original alarm message in the alarm message column in the first language, and the specific recording position is the row where the target standard alarm message is located in the alarm message column in the first language, and record the similarity in the same row in the similarity information column in the first language.
[0095] Taking Table 1 as an example, if the original alarm message is an alarm name in French, and the privilege user abnormal operation recorded in the third row of Table 1 is the target standard alarm message, and the similarity between the original alarm message and the privilege user abnormal operation is 90%, which is greater than the similarity threshold, then record the original alarm message in the third row of the fourth column of Table 1, that is, the third row in the French alarm name column, and record the similarity in the third row of the fifth column of Table 1, that is, the third row in the French similarity information column. This is only for illustrative purposes.
[0096] Optionally, the similarity threshold can be a preset value, such as 80%. When the similarity between the original alarm message and any standard alarm message is greater than 80%, then the target standard alarm message can be determined among the standard alarm messages. Otherwise, it is determined that there is no matching standard alarm message in the standard alarm message table.
[0097] Optionally, when there is no standard alarm message in the standard alarm message table that matches the original alarm message, it may indicate that the information in the standard alarm message table is not comprehensive enough and needs to be supplemented. At this time, through the multilingual embedding model, convert the original alarm message from the first language to the second language used in the standard alarm message, and determine the conversion result as the target standard alarm message. At the same time, store the conversion result in the last row of the standard alarm message column in the standard alarm message table, thereby updating the standard high-advance information table.
[0098] Optionally, the multilingual embedding model can be a library with efficient text classification capabilities and word vector learning capabilities. The multilingual embedding model can process texts in multiple languages, without complex processing of different languages, and can achieve efficient text classification or prediction functions.
[0099] The advantage of this setting is that by using a multilingual embedding model to calculate the similarity between the original alarm information and the standard alarm information, the alarm information in various languages sent by different SIEM systems can be mapped to the unified standard alarm information under the security event rules of the main SIEM system, effectively bridging the language and semantic differences, achieving the normalization of alarm information, and thus reducing the confusion in security event recognition caused by expression differences.
[0100] Among them, recording the original alarm information and the similarity between the original alarm information and the target standard alarm information in the standard alarm information table may include:
[0101] Determine the target row position storing the target standard alarm information according to the standard alarm information table;
[0102] According to the target row position, record the original alarm information in the alarm information column of the first language, and record the similarity between the original alarm information and the target standard alarm information in the similarity information column of the first language.
[0103] Among them, determining the target standard alarm information according to the original alarm information and updating the standard alarm information table may include:
[0104] Determine the information description in the second language as the target standard alarm information, and record the information description in the second language as the newly added standard alarm information at the end row of the standard alarm information column in the standard alarm information table.
[0105] The advantage of this setting is that by updating the standard alarm information table during use, the adaptive update of the standard alarm information table can be achieved to improve the accuracy and conversion efficiency of alarm information normalization mapping.
[0106] S260. Generate and store a standard alarm log according to the security log and the target standard alarm information for the main SIEM system to perform unified management of alarms based on the standard alarm log.
[0107] The technical solution of the embodiment of the present invention can map the alarm information in various languages sent by different SIEM systems into unified standard alarm information under the security event rules of the main SIEM system by calculating the similarity between the original alarm information and each standard alarm information through a multilingual embedding model, and determining the target standard alarm information according to the similarity calculation result. It can effectively bridge the language and semantic differences, achieve the normalization of alarm information, and thus reduce the confusion in security event recognition caused by expression differences. By recording the original alarm information and the similarity between the original alarm information and the target standard alarm information in the standard alarm information table when it is determined that there is no standard alarm information with a similarity greater than the threshold, the adaptive update of the standard alarm information table can be realized to improve the accuracy and conversion efficiency of the alarm information normalization mapping.
[0108] Further, the multi-SIEM system alarm processing method may further include:
[0109] Extract the alarm rule configuration in the main SIEM system and parse it to obtain the standard alarm information under each alarm content respectively, and establish a standard alarm information table under each alarm content;
[0110] Obtain historical security log samples, and identify the alarm information fields and alarm information field values under each alarm content in the historical security log samples;
[0111] Establish a field mapping relationship according to the alarm information fields under each alarm content in the historical security log samples;
[0112] Calculate the similarity between the alarm information field values and the standard alarm information under each alarm content in the historical security log samples through a multilingual embedding model, and update each standard alarm information table according to the similarity calculation result.
[0113] Optionally, after determining the standard alarm information under each alarm content, the standard alarm information columns in the standard alarm information tables under each alarm content can be determined.
[0114] Specifically, the alarm rule configuration of the main SIEM system may include multiple standard alarm names used by the main SIEM system and each standard alarm type under each level. According to the parsed information, a standard alarm name table can be created, and the content of the standard alarm name column in the standard alarm name table can be determined. At the same time, a standard alarm type table can be created, and the standard alarm type column in the standard alarm type table under each level, as well as the association relationship between the standard alarm type tables of different levels, can be determined.
[0115] Optionally, the historical security log samples can refer to the historical security logs from each slave SIEM system. For the identification method of historical security log samples, it can be the manual annotation method or matching through regular expressions, etc. Since this step belongs to the creation stage of the field mapping relationship, only accuracy needs to be ensured. By identifying the alarm information fields in the historical security log samples, the description of the alarm information fields for each slave SIEM system regarding different alarm contents can be determined, thereby establishing the field mapping relationship under each alarm content.
[0116] Specifically, in the historical security log samples, the descriptions of the alarm name field and the alarm type field for each slave SIEM system can be identified, and the mapping relationships of the alarm name field and the alarm type field are established respectively.
[0117] Optionally, according to the alarm information field values extracted from the historical security log samples, the similarity between the alarm information field values and the standard alarm information can be calculated one by one, and based on the similarity calculation results, the alarm information field values and the similarities are stored in the corresponding positions in the standard alarm information table.
[0118] Embodiment 3
[0119] Figure 4 This is a schematic structural diagram of a multi-SIEM system alarm processing device provided in Embodiment 3 of the present invention. As Figure 4 shown, the device includes: a raw alarm information acquisition module 310, a target standard alarm information acquisition module 320, and a standard alarm log generation module 330.
[0120] The raw alarm information acquisition module 310 is configured to, when receiving the security log sent by the slave SIEM system, determine the raw alarm information of at least one alarm content in the security log according to the pre-established field mapping relationship.
[0121] The target standard alarm information acquisition module 320 is configured to determine the standard alarm information table according to the alarm content, and determine the target standard alarm information according to the raw alarm information and the standard alarm information table.
[0122] The standard alarm log generation module 330 is configured to generate and store the standard alarm log according to the security log and the target standard alarm information, so that the master SIEM system can perform unified management of alarms according to the standard alarm log.
[0123] The technical solution of the embodiment of the present invention can automatically identify the fields in the security logs of each SIEM system that truly represent alarm information by determining the original alarm information of at least one alarm content according to the pre-established field mapping relationship, improving the field recognition accuracy. By determining the target standard alarm information according to the original alarm information and the standard alarm information table, the alarm information in various languages sent from different SIEM systems can be mapped into normalized standard alarm information, improving the efficiency of security event standardization and solving the problem of inconsistent languages and semantics in the security logs of each SIEM system. By generating and storing standard alarm logs according to the security logs and the target standard alarm information, unified management of alarm data standardization is realized.
[0124] Based on the above embodiments, the original alarm information acquisition module 310 is specifically configured to:
[0125] According to the field mapping relationship, identify the alarm information fields of at least one alarm content in the security log, and determine the field values of the alarm information fields as the original alarm information; wherein, the field mapping relationship includes the description forms of the alarm information fields of each SIEM system under each alarm content.
[0126] Based on the above embodiments, the standard alarm information table includes a standard alarm information column and multiple alarm information columns in different languages;
[0127] The target standard alarm information acquisition module 320 may be specifically configured to:
[0128] Determine the first language to which the original alarm information belongs, and determine whether the original alarm information has been recorded in the alarm information column of the first language;
[0129] If so, determine the target standard alarm information according to the row position of the original alarm information in the standard alarm information table and the standard alarm information column;
[0130] If not, calculate the similarity between the original alarm information and each standard alarm information through a multilingual embedding model, and determine the target standard alarm information according to the similarity calculation result.
[0131] Based on the above embodiments, the target standard alarm information acquisition module 320 may further include:
[0132] The similarity calculation unit is configured to convert the original alarm information into an information description in the second language used by the main SIEM system through a multilingual embedding model, and calculate the similarity between the information description in the second language and each standard alarm information respectively;
[0133] A standard alarm information selection unit, configured to determine whether there is a standard alarm information with a similarity greater than a preset value;
[0134] A first information processing unit, configured to, if so, determine a target standard alarm information among the standard alarm information with a similarity greater than the preset value, and record the original alarm information and the similarity between the original alarm information and the target standard alarm information in the standard alarm information table;
[0135] A second information processing unit, configured to, if not, determine a target standard alarm information according to the original alarm information, and update the standard alarm information table.
[0136] Based on the above embodiments, the first information processing unit may specifically be configured to:
[0137] Recording the original alarm information and the similarity between the original alarm information and the target standard alarm information in the standard alarm information table includes:
[0138] Determine the target row position storing the target standard alarm information according to the standard alarm information table;
[0139] According to the target row position, record the original alarm information in the alarm information column of the first language, and record the similarity between the original alarm information and the target standard alarm information in the similarity information column of the first language.
[0140] Based on the above embodiments, the second information processing unit may specifically be configured to:
[0141] Determine the information description in the second language as the target standard alarm information, and record the information description in the second language as a newly added standard alarm information at the end row of the standard alarm information column in the standard alarm information table.
[0142] Based on the above embodiments, it may further include an initial information creation module, configured to:
[0143] Extract the alarm rule configuration in the main SIEM system and parse it, respectively obtain the standard alarm information under each alarm content, and establish a standard alarm information table for each alarm content;
[0144] Obtain historical security log samples, and identify the alarm information fields and alarm information field values under each alarm content in the historical security log samples;
[0145] Establish a field mapping relationship according to the alarm information fields under each alarm content in the historical security log samples;
[0146] Through a multilingual embedding model, calculate the similarity between the alarm information field values under each alarm content in the historical security log samples and the standard alarm information, and update each standard alarm information table according to the similarity calculation results.
[0147] The multi-SIEM system alarm processing device provided by the embodiments of the present invention can execute the multi-SIEM system alarm processing method provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the method.
[0148] Embodiment 4
[0149] Figure 5 The structural schematic diagram of an electronic device 10 that can be used to implement the embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as, for example, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, for example, personal digital processors, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0150] As Figure 5 shown, the electronic device 10 includes at least one processor 11, and a memory communicatively connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc. Among them, the memory stores a computer program executable by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. The input / output (I / O) interface 15 is also connected to the bus 14.
[0151] A plurality of components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a disk, an optical disc, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0152] The processor 11 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the multi-SIEM system alarm processing method as described in the embodiments of the present invention. That is:
[0153] When receiving a security log sent from the SIEM system, determine the original alarm information of at least one alarm content in the security log according to a pre-established field mapping relationship;
[0154] Determine a standard alarm information table according to the alarm content, and determine the target standard alarm information according to the original alarm information and the standard alarm information table;
[0155] Generate and store a standard alarm log according to the security log and the target standard alarm information, so that the main SIEM system can perform unified management of alarms according to the standard alarm log.
[0156] In some embodiments, the multi-SIEM system alarm processing method can be implemented as a computer program, which is tangibly included in a computer-readable storage medium, such as the storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the multi-SIEM system alarm processing method described above can be executed. Alternatively, in other embodiments, the processor 11 can be configured to execute the multi-SIEM system alarm processing method in any other suitable manner (for example, by means of firmware).
[0157] The various embodiments of the systems and techniques described above in this specification can be implemented in digital electronic circuitry, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems-on-chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be a special-purpose or general-purpose programmable processor that receives data and instructions from, and transmits data and instructions to, a storage system, at least one input device, and at least one output device.
[0158] The computer program for implementing the methods of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the computer programs, when executed by the processor, cause the functions / operations specified in the flowchart and / or block diagram to be implemented. The computer program can be executed entirely on the machine, partly on the machine, as a stand-alone software package partly on the machine and partly on a remote machine or entirely on the remote machine or server.
[0159] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0160] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and a pointing device (e.g., a mouse or a trackball) through which the user can provide input to the electronic device. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0161] The systems and techniques described herein can be implemented in a computing system including backend components (e.g., as a data server), or a computing system including middleware components (e.g., an application server), or a computing system including frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system including any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected with each other by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), blockchain network, and the Internet.
[0162] The computing system can include a client and a server. The client and the server are generally remote from each other and typically interact through a communication network. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system and solves the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.
[0163] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps recited in the present invention can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is made herein.
[0164] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method for processing alarms in a multi-Security Information and Event Management (SIEM) system, characterized in that, It is executed by an alarm handling component configured on the main SIEM system side. The main SIEM system is used to manage multiple slave SIEM systems, including: When receiving security logs sent by a slave SIEM system, determine the original alarm information of at least one alarm content in the security logs according to a pre-established field mapping relationship; Determine a standard alarm information table according to the alarm content, and determine the target standard alarm information according to the original alarm information and the standard alarm information table; Generate and store a standard alarm log according to the security logs and the target standard alarm information for the main SIEM system to perform unified alarm management according to the standard alarm log.
2. The method according to claim 1, wherein, Determine the original alarm information of at least one alarm content in the security logs according to a pre-established field mapping relationship, including: According to the field mapping relationship, identify the alarm information fields of at least one alarm content in the security logs, and determine the field values of the alarm information fields as the original alarm information; wherein, the field mapping relationship includes the description forms of the alarm information fields of each slave SIEM system under each alarm content.
3. The method according to claim 1, characterized in that The standard alarm information table includes a standard alarm information column and alarm information columns in multiple different languages; Among them, determining the target standard alarm information according to the original alarm information and the standard alarm information table includes: Determine the first language to which the original alarm information belongs, and judge whether the original alarm information is recorded in the alarm information column of the first language; If so, determine the target standard alarm information according to the row position of the original alarm information in the standard alarm information table and the standard alarm information column; If not, calculate the similarity between the original alarm information and each standard alarm information through a multilingual embedding model, and determine the target standard alarm information according to the similarity calculation result.
4. The method according to claim 3, characterized in that Calculating the similarity between the original alarm information and each standard alarm information through a multilingual embedding model, and determining the target standard alarm information according to the similarity calculation result, including: Through the multilingual embedding model, convert the original alarm information into an information description in the second language used by the main SIEM system, and calculate the similarity between the information description in the second language and each standard alarm information respectively; Judge whether there is a standard alarm information with a similarity greater than a preset value; If so, determine the target standard alarm information among the standard alarm information with a similarity greater than the preset value, and record the original alarm information and the similarity between the original alarm information and the target standard alarm information in the standard alarm information table; If not, determine the target standard alarm information according to the original alarm information and update the standard alarm information table.
5. The method according to claim 4, characterized in that, The standard alarm information table also includes similarity information columns in multiple different languages; Recording the original alarm information and the similarity between the original alarm information and the target standard alarm information in the standard alarm information table includes: According to the standard alarm information table, determine the target row position where the target standard alarm information is stored; Record the original alarm information in the alarm information column of the first language according to the target line position, and record the similarity between the original alarm information and the target standard alarm information in the similarity information column of the first language.
6. The method according to claim 4, wherein Determine the target standard alarm information according to the original alarm information, and update the standard alarm information table, including: Determine the information description in the second language as the target standard alarm information, and use the information description in the second language as the newly added standard alarm information, and record it at the end of the standard alarm information column in the standard alarm information table.
7. The method according to claim 1, wherein It also includes: Extract the alarm rule configuration in the main SIEM system and parse it, respectively obtain the standard alarm information under each alarm content, and establish a standard alarm information table under each alarm content; Obtain historical security log samples, and identify the alarm information fields and alarm information field values under each alarm content in the historical security log samples; Establish a field mapping relationship according to the alarm information fields under each alarm content in the historical security log samples; Through the multilingual embedding model, calculate the similarity between the alarm information field values and the standard alarm information under each alarm content in the historical security log samples, and update each standard alarm information table according to the similarity calculation results.
8. A multi-SIEM system alarm processing device, characterized in that, It is executed by the alarm processing component configured on the main SIEM system side, and the main SIEM system is used to manage multiple slave SIEM systems, including: The original alarm information acquisition module is used to determine the original alarm information of at least one alarm content in the security log according to the pre-established field mapping relationship when receiving the security log sent by the slave SIEM system; The target standard alarm information acquisition module is used to determine the standard alarm information table according to the alarm content, and determine the target standard alarm information according to the original alarm information and the standard alarm information table; The standard alarm log generation module is used to generate and store the standard alarm log according to the security log and the target standard alarm information, so that the main SIEM system can perform unified management of alarms according to the standard alarm log.
9. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor, so that the at least one processor can execute the multi-SIEM system alarm processing method according to any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable the processor to implement the multi-SIEM system alarm processing method according to any one of claims 1-7 when executed.