Exception handling method, computing device, storage medium and program product

Through computing equipment monitoring and automatic control of security equipment to handle exception events, the problem of low exception handling efficiency in the prior art is solved, and efficient and low-cost exception handling is achieved.

CN120295854APending Publication Date: 2025-07-11HENAN QINWEI DIGITAL TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510228825.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-27
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

In the prior art, the exception handling efficiency of security devices is low, and it is necessary to deploy agents on each security device and rely on manual intervention, resulting in inefficient processing.

Method used

The computing device monitors abnormal events of the security device, generates abnormal features, and determines target instructions based on the characteristics, and automatically controls the security device to handle abnormal events, reducing agent programs and manual intervention.

Benefits of technology

It improves exception handling efficiency, reduces the probability of human error, reduces the cost of exception handling, and improves the reliability and stability of security equipment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120295854A_ABST
    Figure CN120295854A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides an exception handling method, computing equipment, a storage medium and a program product, the method is applied to the computing equipment, the computing equipment is connected with safety equipment, or the safety equipment runs on the computing equipment, and the method comprises the steps that after an exception event corresponding to the safety equipment is determined, the exception event is sent to the computing equipment; generating an abnormal feature corresponding to the abnormal event; determining a target instruction according to the abnormal features; and controlling the safety equipment to execute the target instruction so as to enable the safety equipment to process the abnormal event. The method can improve the exception handling efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present application relate to the technical field of computing devices, and in particular, to an exception handling method, a computing device, a storage medium, and a program product. Background Art

[0002] Exception handling of security devices is an important link to ensure the safe operation of security devices.

[0003] In related technologies, a proxy program can be deployed on each security device, and the status information, performance data, etc. of the security device can be collected through the proxy program, so that business personnel can perform exception handling on the security device according to the status information, performance data, etc. of the security device. However, in the above method, the exception handling efficiency is relatively low. Summary of the Invention

[0004] Embodiments of the present application provide an exception handling method, a computing device, a storage medium, and a program product, which are used to solve the technical problem of relatively low exception handling efficiency.

[0005] In a first aspect, an exception handling method provided by an embodiment of the present application is applied to a computing device, and the computing device is connected to a security device or a security device runs on the computing device. The method includes:

[0006] After determining an exception event corresponding to the security device, generate an exception feature corresponding to the exception event;

[0007] Determine a target instruction according to the exception feature;

[0008] Control the security device to execute the target instruction so that the security device processes the exception event.

[0009] In the above solution, the computing device can generate an exception feature corresponding to the exception event after determining the exception event corresponding to the security device; can determine the target instruction according to the exception feature, and can control the security device to execute the target instruction so that the security device processes the exception event. In the above solution, the computing device can interface with one or more security devices, can determine the exception events of each security device, and can control the security device to execute the target instruction to automatically process the exception events. Through the above method, the exception handling efficiency can be improved.

[0010] In a possible implementation manner, the determining the target instruction according to the exception feature includes:

[0011] Determine whether there is a first feature in the feature library, and the similarity between the first feature and the exception feature is greater than or equal to a preset threshold. The feature library includes multiple features and the instructions corresponding to each feature;

[0012] If the first feature exists in the feature library, determine the instruction corresponding to the first feature as the target instruction.

[0013] If the first feature does not exist in the feature library, generate the target instruction according to the abnormal feature.

[0014] In the above solution, the instruction corresponding to the first feature can be determined as the target instruction, or the target instruction can be generated according to the abnormal feature, achieving the purpose of generating the target instruction.

[0015] In a possible implementation manner, determining whether the first feature exists in the feature library includes:

[0016] Determine at least one keyword included in the abnormal feature;

[0017] According to the at least one keyword, determine whether the first feature exists in the feature library;

[0018] Wherein, the first feature includes the at least one keyword.

[0019] In the above solution, whether the first feature exists in the feature library can be determined according to the keyword included in the abnormal feature, achieving the purpose of determining whether the first feature exists in the feature library.

[0020] In a possible implementation manner, generating the target instruction according to the abnormal feature includes:

[0021] Input the abnormal feature into a preset algorithm so that the preset algorithm outputs the target instruction; or,

[0022] Determine the abnormal type corresponding to the abnormal feature, and generate the target instruction according to the abnormal type, where the abnormal type is a software update type, a configuration update type, or a fault type.

[0023] In the above solution, the target instruction can be determined by a preset algorithm, or the target instruction can be determined according to the type of the abnormal feature, achieving the purpose of determining the target instruction.

[0024] In a possible implementation manner, determining the abnormal type corresponding to the abnormal feature includes:

[0025] Determine whether the abnormal type is a preset type, where the preset type is a software update type or a configuration update type;

[0026] If the abnormal type is not the preset type, determine the abnormal type as the fault type.

[0027] In the above solution, the type of the abnormal feature can be determined, achieving the purpose of determining the type of the abnormal feature.

[0028] In a possible implementation, determining whether the exception type is a preset type includes:

[0029] Obtaining the current software code of the security device and / or configuration information;

[0030] If the software code indicates that there is a software vulnerability in the security device, determining that the exception type is a software update type;

[0031] If the configuration information indicates that there is a configuration error in the security device, determining that the exception type is a configuration update type.

[0032] In the above solution, the exception type can be determined according to the software code or configuration information of the security device, achieving the purpose of determining the exception type.

[0033] In a possible implementation, generating the target instruction according to the exception type includes:

[0034] If the exception type is the software update type, generating a first instruction for instructing to install a software patch;

[0035] If the exception type is the configuration update type, generating a second instruction for instructing to restore the default configuration;

[0036] If the exception type is the fault type, generating a third instruction for instructing to update the current software code of the security device to a historical software code, where the security device does not have the exception event when running the historical software code.

[0037] In the above solution, the target instruction can be generated according to the exception type, achieving the purpose of generating the target instruction.

[0038] In a possible implementation, the method further includes:

[0039] Updating the exception feature and the target instruction generated according to the exception feature to the feature library.

[0040] In the above solution, the exception feature and the target instruction generated according to the exception feature can be updated to the feature library. In this way, the feature library can be optimized, the determination duration of the subsequent target instruction can be shortened, the subsequent exception handling efficiency can be improved, and further the reliability of the security device is relatively high, and the subsequent exception event has a relatively small impact on the business of the security device.

[0041] In a possible implementation, the method further includes:

[0042] Determine the resolution result of the abnormal event, where the resolution result is success or failure;

[0043] Send the resolution result to the preset device corresponding to the operation and maintenance personnel.

[0044] In the above solution, the resolution result can be sent to the preset device corresponding to the operation and maintenance personnel, so that the operation and maintenance personnel can know the resolution result of the abnormal event.

[0045] In a possible implementation manner, the method further includes:

[0046] Send the abnormal feature to the preset device corresponding to the operation and maintenance personnel.

[0047] In the above solution, the abnormal feature can be sent to the preset device corresponding to the operation and maintenance personnel, so that the operation and maintenance personnel can know the abnormal feature of the security device.

[0048] In a second aspect, an embodiment of the present application provides an abnormal processing device. The abnormal processing device is applied to a computing device. The computing device is connected to a security device or a security device runs on the computing device. The abnormal processing device includes a determination module, a generation module, and a control module. Among them,

[0049] After the determination module determines the abnormal event corresponding to the security device, the generation module is used to generate the abnormal feature corresponding to the abnormal event;

[0050] The determination module is further used to determine a target instruction according to the abnormal feature;

[0051] The control module is used to control the security device to execute the target instruction, so that the security device processes the abnormal event.

[0052] In the above solution, after the computing device determines the abnormal event corresponding to the security device, it can generate the abnormal feature corresponding to the abnormal event; it can determine the target instruction according to the abnormal feature, and can control the security device to execute the target instruction, so that the security device processes the abnormal event. In the above solution, the computing device can dock with one or more security devices, can determine the abnormal events of each security device, and can control the security device to execute the target instruction to automatically process the abnormal events. Through the above method, the efficiency of abnormal processing can be improved.

[0053] In a possible implementation manner, the determination module is specifically used for,

[0054] Determine whether there is a first feature in the feature library, where the similarity between the first feature and the abnormal feature is greater than or equal to a preset threshold. The feature library includes multiple features and the instructions corresponding to each feature;

[0055] If the first feature exists in the feature library, determine the instruction corresponding to the first feature as the target instruction.

[0056] If the first feature does not exist in the feature library, generate the target instruction according to the abnormal feature.

[0057] In the above solution, the instruction corresponding to the first feature can be determined as the target instruction, or the target instruction can be generated according to the abnormal feature, achieving the purpose of generating the target instruction.

[0058] In a possible implementation, the determining module is specifically configured to,

[0059] Determine at least one keyword included in the abnormal feature;

[0060] According to the at least one keyword, determine whether the first feature exists in the feature library;

[0061] Wherein, the first feature includes the at least one keyword.

[0062] In the above solution, it is possible to determine whether the first feature exists in the feature library according to the keyword included in the abnormal feature, achieving the purpose of determining whether the first feature exists in the feature library.

[0063] In a possible implementation, the determining module is specifically configured to,

[0064] Input the abnormal feature into a preset algorithm so that the preset algorithm outputs the target instruction; or,

[0065] Determine the abnormal type corresponding to the abnormal feature, and generate the target instruction according to the abnormal type, where the abnormal type is a software update type, a configuration update type, or a fault type.

[0066] In the above solution, the target instruction can be determined through a preset algorithm, or the target instruction can be determined according to the type of the abnormal feature, achieving the purpose of determining the target instruction.

[0067] In a possible implementation, the determining module is specifically configured to,

[0068] Determine whether the abnormal type is a preset type, where the preset type is a software update type or a configuration update type;

[0069] If the abnormal type is not the preset type, determine the abnormal type as the fault type.

[0070] In the above solution, the type of the abnormal feature can be determined, achieving the purpose of determining the type of the abnormal feature.

[0071] In a possible implementation manner, the determining module is specifically configured to,

[0072] Obtain the current software code and / or configuration information of the security device;

[0073] If the software code indicates that there is a software vulnerability in the security device, determine that the exception type is the software update type;

[0074] If the configuration information indicates that there is a configuration error in the security device, determine that the exception type is the configuration update type.

[0075] In the above solution, the exception type can be determined according to the software code or configuration information of the security device, achieving the purpose of determining the exception type.

[0076] In a possible implementation manner, the determining module is specifically configured to,

[0077] If the exception type is the software update type, generate a first instruction for instructing to install a software patch;

[0078] If the exception type is the configuration update type, generate a second instruction for instructing to restore the default configuration;

[0079] If the exception type is the fault type, generate a third instruction for instructing to update the current software code of the security device to the historical software code, and the security device does not have the exception event when running the historical software code.

[0080] In the above solution, the target instruction can be generated according to the exception type, achieving the purpose of generating the target instruction.

[0081] In a possible implementation manner, the exception handling device further includes an update module and a sending module, where,

[0082] The update module is used to update the exception feature and the target instruction generated according to the exception feature to the feature library.

[0083] In the above solution, the exception feature and the target instruction generated according to the exception feature can be updated to the feature library. In this way, the feature library can be optimized, the determination duration of the subsequent target instruction can be shortened, the subsequent exception handling efficiency can be improved, and thus the reliability of the security device is relatively high, and the impact of subsequent exception events on the business of the security device is relatively small.

[0084] In a possible implementation manner,

[0085] The determining module is further used to determine the solution result of the exception event, and the solution result is success or failure;

[0086] The sending module is configured to send the solution result to a preset device corresponding to the operation and maintenance personnel.

[0087] In the above solution, the solution result can be sent to a preset device corresponding to the operation and maintenance personnel, so that the operation and maintenance personnel can know the solution result of the abnormal event.

[0088] In a possible implementation, the sending module is further configured to

[0089] send the abnormal feature to a preset device corresponding to the operation and maintenance personnel.

[0090] In the above solution, the abnormal feature can be sent to a preset device corresponding to the operation and maintenance personnel, so that the operation and maintenance personnel can know the abnormal feature of the security device.

[0091] In a third aspect, an embodiment of the present application provides a computing device, including: a memory, a processor;

[0092] The memory stores computer-executable instructions;

[0093] The processor executes the computer-executable instructions stored in the memory, so that the processor executes the first aspect and / or various possible implementation manners of the first aspect as described above.

[0094] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, in which computer-executable instructions are stored, and when the computer-executable instructions are executed by a processor, they are used to implement the first aspect and / or various possible implementation manners of the first aspect as described above.

[0095] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the first aspect and / or various possible implementation manners of the first aspect as described above. BRIEF DESCRIPTION OF THE DRAWINGS

[0096] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present application, and those of ordinary skill in the art can obtain other drawings without creative efforts based on these drawings.

[0097] Figure 1 It is a schematic diagram of an application scenario provided by an embodiment of the present application;

[0098] Figure 2 It is a schematic diagram of an abnormal handling method provided by an embodiment of the present application;

[0099] Figure 3 A flowchart showing a method for exception handling provided by an embodiment of the present application;

[0100] Figure 4 A flowchart showing another method for exception handling provided by an embodiment of the present application;

[0101] Figure 5 A flowchart showing yet another method for exception handling provided by an embodiment of the present application;

[0102] Figure 6 A structural diagram of an exception handling device provided by an embodiment of the present application;

[0103] Figure 7 A structural diagram of another exception handling device provided by an embodiment of the present application;

[0104] Figure 8 A structural diagram of a computing device provided by an embodiment of the present application. Detailed implementation manners

[0105] Here, exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with the embodiments of the present application. On the contrary, they are merely examples of devices and methods consistent with some aspects of the embodiments of the present application as detailed in the appended claims.

[0106] For ease of understanding, first, technical terms related to the embodiments of the present application will be explained.

[0107] Monitoring: In the operation and maintenance of security devices, monitoring refers to continuously tracking and collecting the operating status, performance indicators, log information, etc. of security devices. Through monitoring, it is possible to promptly discover whether a security device is operating normally, whether there is abnormal traffic or attack behavior, etc.

[0108] Instruction: In the operation and maintenance of security devices, an instruction can be a configuration command, a policy update command, etc. sent to a security device. These instructions are used to adjust the operating parameters of the security device and update the security policy to adapt to changing security requirements.

[0109] Security policy: It is one of the core contents of the operation and maintenance of security devices. It includes access control policies, encryption policies, backup policies, etc., and is used to regulate the operation of security devices and protect the security of networks and systems.

[0110] Security: In the operation and maintenance of security devices, security refers to protecting networks, systems, and data from unauthorized access, tampering, damage, or leakage. This is achieved through measures such as reasonably configuring security devices, regularly updating security policies, and promptly handling security incidents.

[0111] Operation and maintenance of security devices: It refers to the comprehensive management and maintenance of security devices, including work such as device installation, configuration, monitoring, troubleshooting, performance optimization, and security policy updates. The purpose is to ensure that security devices can continuously, stably, and effectively protect the security of networks and systems.

[0112] For ease of understanding, the following combines Figure 1 to illustrate the application scenarios involved in the embodiments of this application.

[0113] Figure 1 This is a schematic diagram of an application scenario provided by the embodiments of this application. Please refer to Figure 1 During the operation of security devices, anomalies may occur. Handling anomalies in security devices with anomalies is an important means to ensure the secure operation of security devices. The process of handling anomalies in security devices with anomalies can also be referred to as the operation and maintenance process of security devices.

[0114] A security device can be a hardware or software device used to protect the security of networks and systems. For example, a security device can be an electronic device, or a security device can also be a firewall, intrusion detection system, or antivirus software running in an electronic device, etc.; an electronic device can be a server, or a Virtual Private Network (VPN) device, etc.

[0115] In the related art, an agent program can be deployed in each security device. The agent program can be used to collect the status information and performance data of the security device, etc., to achieve the purpose of monitoring the security device. Business personnel can perform anomaly handling based on the status information and performance data of the security device, etc.

[0116] However, in the above method, an agent program needs to be deployed on each security device, which requires a relatively long time to deploy the agent program and requires manual processing by business personnel, resulting in low anomaly handling efficiency.

[0117] In view of this, the embodiments of this application propose an anomaly handling method to improve the anomaly handling efficiency. The following combines Figure 2 to illustrate the anomaly handling method provided by the embodiments of this application.

[0118] Figure 2 This is a schematic diagram of an anomaly handling method provided by the embodiments of this application. Please refer to Figure 2, a computing device can be connected to one or more security devices. For example, multiple security devices can be Security Device 1, Security Device 2, Security Device 3, ……, and Security Device N, where N can be an integer greater than 1. For example, the computing device can be a computer, a server, etc.

[0119] The computing device can be used to monitor each security device, and can control the security device to perform exception handling after an exception event occurs in the security device. For example, the exception event can be an abnormal operating state of the security device, etc.

[0120] Figure 2 In the shown computing device, a security operation and maintenance monitoring system can run. The computing device can monitor the security device through the security operation and maintenance monitoring system and control the security device to perform exception handling.

[0121] It should be noted that the computing device can be an electronic device independent of any one security device, or the computing device can be any one security device. Figure 2 Taking the computing device as an electronic device independent of any one security device as an example for illustration does not constitute a limitation on the technical solution provided by the embodiments of the present application. If the computing device is an electronic device independent of any one security device, the computing device can be an electronic device deployed with a security operation and maintenance monitoring system; if the computing device is any one security device, the computing device can be a security device deployed with a security operation and maintenance monitoring system.

[0122] In the exception handling method provided by the embodiments of the present application, the computing device can monitor multiple security devices and can control multiple security devices to perform exception handling, without deploying an agent program on each security device, and can reduce manual intervention, improving the exception handling efficiency.

[0123] In addition, in the above method, manual intervention is reduced, making the probability of human errors lower and saving human resources.

[0124] In addition, without deploying an agent program on each security device, the exception handling cost is lower.

[0125] The technical solution of the embodiments of the present application will be described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments.

[0126] Figure 3It is a schematic flowchart of an exception handling method provided by an embodiment of the present application. The execution subject of this method can be a computing device or a processor set in the computing device. The computing device can be, for example, a server. The processor in the computing device can be, for example, the CPU in the server. For ease of understanding, in the following, the execution subject being the computing device is taken as an example for illustration. Please refer to Figure 3 , this method may include:

[0127] S301. After determining an exception event corresponding to a security device, generate an exception feature corresponding to the exception event.

[0128] The execution subject of this embodiment can be a computing device, and the computing device can be connected to a security device, or a security device can run on the computing device.

[0129] The number of security devices can be one or more. Among them, multiple can be two or more.

[0130] The exception event can be that the operating state of the security device is abnormal, the user behavior corresponding to the security device is abnormal, or the traffic received by the security device is abnormal, etc.

[0131] The abnormal operating state of the security device means that the resource occupancy rate of the security device is too high, the alarm frequency of the security device is high, or the security policy matching failure rate of the security device is high, etc.

[0132] For example, the situation where the resource occupancy rate of the security device is too high can be that the usage rate of the central processing unit (CPU) of the security device is too high; or the memory occupancy rate of the security device is too high, etc.

[0133] For another example, the situation where the security policy matching failure rate of the security device is high can be that when the security device applies a predefined security policy, the proportion of traffic that fails to match the security policy is high.

[0134] The abnormal user behavior corresponding to the security device means that the time when the user logs in to the security device is abnormal, the location where the user logs in to the security device is abnormal, or the operation behavior after the user logs in to the security device is abnormal, etc.

[0135] For example, the situation where the operation behavior after the user logs in to the security device is abnormal can be that the user deletes a large number of files in a short period, modifies key system configurations, or frequently accesses resources beyond its authority, etc.

[0136] The abnormal traffic received by the security device means that the size of the traffic received by the security device is abnormal, the source and destination of the traffic received by the security device are abnormal, the traffic protocol and port received by the security device are abnormal, etc.

[0137] For example, the situation where the size of the traffic received by the security device is abnormal can be: the traffic received by the security device exceeds the size range of the normal service traffic; or, the traffic received by the security device is less than the size range of the normal service traffic within a preset time period, etc.

[0138] For another example, the situation where the source and destination of the traffic received by the security device are abnormal can be: the traffic received by the security device comes from a malicious Internet Protocol (IP) address; or, the destination of the traffic received by the security device is a key system or a storage area of key data, etc.

[0139] In this embodiment, the computing device can monitor the operating state of the security device, the user behavior corresponding to the security device, and the traffic received by the security device in real time. If the computing device determines that the operating state of the security device is abnormal, or determines that the user behavior corresponding to the security device is abnormal, or determines that the traffic received by the security device is abnormal, the computing device can determine the abnormal event corresponding to the security device.

[0140] Specifically, a normal model can be built in advance based on the data monitored when the security device is operating normally. The computing device monitors the operating state of the security device, the user behavior corresponding to the security device, and the traffic received by the security device in real time, and can compare the monitored data with the normal model. If the monitored data matches the normal model, it can be determined that there is no abnormal event for the security device, and the model can continue to be updated with the monitored data. If the monitored data does not match the normal model, the abnormal event can be determined based on the monitored data.

[0141] The abnormal feature can be used to indicate the abnormal event.

[0142] In this embodiment, the computing device can generate an abnormal feature according to the abnormal event.

[0143] Specifically, the computing device can perform semantic analysis on the operation log information corresponding to the abnormal event through natural language processing technology and generate an abnormal feature. For example, if the computing device determines that the CPU usage rate of the security device is too high, an abnormal feature can be generated, and the abnormal feature can be: high CPU usage rate.

[0144] In this embodiment, the computing device can monitor the security device in real time, which can make the time interval between the occurrence time of the abnormal event and the time when the computing device determines the abnormal event relatively short, further improving the operation and maintenance efficiency and making the stability and reliability of the security device better.

[0145] Optionally, after determining the abnormal feature, the computing device can also send the abnormal feature to a preset device corresponding to the operation and maintenance personnel so that the operation and maintenance personnel can know the abnormal feature of the security device.

[0146] S302. Determine the target instruction according to the abnormal feature.

[0147] The target instruction can be an instruction that enables the security device to handle abnormal events.

[0148] In this embodiment, the computing device can determine whether there is a first feature in the feature library, where the similarity between the first feature and the abnormal feature is greater than or equal to a preset threshold. The feature library includes multiple features and the instructions corresponding to each feature. If there is a first feature in the feature library, the instruction corresponding to the first feature is determined as the target instruction. If there is no first feature in the feature library, the target instruction is generated according to the abnormal feature.

[0149] The feature library can be a pre-set database. The feature library can include multiple features and the instructions corresponding to each feature.

[0150] Next, taking the feature library as shown in Table 1 as an example, the feature library is described exemplarily.

[0151] Table 1

[0152]

[0153] As shown in Table 1, the feature library can include traffic features, user behavior features, running state features, etc.

[0154] As shown in Table 1, the traffic features can include: large received traffic, small received traffic, abnormal source of received traffic, abnormal destination of received traffic, and abnormal traffic protocol and port, etc. The instruction corresponding to large received traffic can be instruction a, the instruction corresponding to small received traffic can be instruction b, the instruction corresponding to abnormal source of received traffic can be instruction c, the instruction corresponding to abnormal destination of received traffic can be instruction d, and the instruction corresponding to abnormal traffic protocol and port can be instruction e.

[0155] As shown in Table 1, the user behavior features can include: abnormal user login time, abnormal user login location, and abnormal user operation behavior, etc. The instruction corresponding to abnormal user login time can be instruction f, the instruction corresponding to abnormal user login location can be instruction g, and the instruction corresponding to abnormal user operation behavior can be instruction h.

[0156] As shown in Table 1, the running state features can include: high resource utilization rate, high alarm frequency, and high security policy matching failure rate, etc. The instruction corresponding to high resource utilization rate can be instruction i, the instruction corresponding to high alarm frequency can be instruction j, and the instruction corresponding to high security policy matching failure rate can be instruction k.

[0157] The preset threshold can be set according to actual needs. For example, the preset threshold can be 98%, or 95%, etc.

[0158] Specifically, if there is a first feature in the feature library, the computing device can determine the instruction corresponding to the first feature as the target instruction; if there are multiple first features in the feature library, the computing device can determine the first feature with the highest similarity to the abnormal feature among the multiple first features, and can determine the instruction corresponding to the first feature with the highest similarity as the target instruction; if there is no first feature in the feature library, the computing device can generate a target instruction according to the abnormal feature.

[0159] For example, a preset algorithm can run in the computing device, and the preset algorithm can be used to generate a target instruction according to the abnormal feature. The computing device can generate a target instruction through the preset algorithm.

[0160] S303. Control the security device to execute the target instruction so that the security device processes the abnormal event.

[0161] If the computing device and the security device are two independent devices, the computing device can send the target instruction to the security device to control the security device to execute the target instruction; if the security device runs on the computing device, the computing device can directly control the security device to execute the target instruction.

[0162] For example, if the source of the traffic received by the security device is abnormal and the target instruction is to block the traffic from the source, the security device can block the traffic from the source according to the target instruction.

[0163] Optionally, if the computing device needs to send the target instruction to the security device, encryption technology, or authentication technology, etc. can be used to make the sending accuracy and security of the target instruction relatively high.

[0164] In this embodiment, there are at least the following two situations for controlling the security device to execute the target instruction:

[0165] Situation 1. After determining the target instruction, directly control the security device to execute the target instruction.

[0166] In this case, the execution speed of the target instruction can be relatively fast, and the operation and maintenance efficiency can be further improved.

[0167] Situation 2. Control the security device to execute the target instruction according to the attribute of the target instruction.

[0168] The attribute of the target instruction can be an ordinary instruction or an important instruction.

[0169] If the attribute of the target instruction is an ordinary instruction, the computing device can directly control the security device to execute the target instruction after determining the target instruction. If the attribute of the target instruction is an important instruction, the computing device can send the target instruction to the preset device corresponding to the operation and maintenance personnel after determining the target instruction, and can control the security device to execute the target instruction after receiving the confirmation execution response sent by the preset device.

[0170] In this case, the correctness of the target instruction can be ensured, resulting in a relatively high operation and maintenance accuracy.

[0171] It should be noted that the attributes of each instruction also exist in the feature library. If the target instruction is an instruction in the feature library, the computing device can determine the attribute of the target instruction according to the feature library. Additionally, if the target instruction is generated by the computing device according to the abnormal feature, the attribute of the target instruction can be preset as an important instruction, so that the correctness of the target instruction can be relatively high.

[0172] In the abnormal handling method provided in this embodiment, the computing device can generate an abnormal feature corresponding to the abnormal event after determining the abnormal event corresponding to the security device; can determine the target instruction according to the abnormal feature, and can control the security device to execute the target instruction so that the security device can handle the abnormal event. In the above method, the computing device can interface with one or more security devices, can determine the abnormal event of each security device, and can control the security device to execute the target instruction to automatically handle the abnormal event. Through the above method, the efficiency of abnormal handling can be improved.

[0173] Based on the above embodiment, the following will be combined with Figure 4 to further describe the abnormal handling method provided in the embodiments of the present application.

[0174] Figure 4 FIG. is a schematic flowchart of another abnormal handling method provided in the embodiments of the present application. The execution subject of this method can be a computing device or a processor provided in the computing device. The computing device can be, for example, a server. The processor in the computing device can be, for example, the CPU in the server. For ease of understanding, in the following, the execution subject is taken as the computing device as an example for description. Please refer to Figure 4 and this method may include:

[0175] S401. After determining the abnormal event corresponding to the security device, generate an abnormal feature corresponding to the abnormal event.

[0176] It should be noted that the specific implementation manner of S401 can refer to S301, which will not be elaborated here.

[0177] S402. Determine whether there is a first feature in the feature library.

[0178] If the first feature exists in the feature library, execute S403;

[0179] If the first feature does not exist in the feature library, execute S404.

[0180] In this embodiment, the computing device may determine at least one keyword included in the abnormal feature; according to the at least one keyword, determine whether the first feature exists in the feature library; wherein, the first feature includes at least one keyword.

[0181] In this embodiment, the specific manner in which the computing device determines at least one keyword of the abnormal feature is not limited. For example, the computing device may determine at least one keyword through a pre-trained language model, or may determine at least one keyword through a keyword extraction algorithm (Rapid Automatic Keyword Extraction, RAKE), etc.

[0182] In this embodiment, the feature library may also store the keywords corresponding to each feature. In the specific implementation process, the computing device may determine the similarity between the abnormal feature and each feature in the feature library according to at least one keyword included in the abnormal feature and the keywords corresponding to each feature in the feature library, and may determine whether the first feature exists according to the similarity between the abnormal feature and each feature in the feature library.

[0183] S403. Determine the instruction corresponding to the first feature as the target instruction.

[0184] In this embodiment, if the first feature exists in the feature library, the computing device may determine the instruction corresponding to the first feature as the target instruction.

[0185] S404. Generate a target instruction according to the abnormal feature.

[0186] In this embodiment, there are at least two methods for the computing device to generate a target instruction according to the abnormal feature. In the specific implementation process, method 1 may be executed first. If the target instruction can be obtained through method 1, the computing device may not execute method 2. If the target instruction cannot be obtained through method 1, the computing device may continue to execute method 2 to obtain the target instruction. The two methods for generating a target instruction according to the abnormal feature may include:

[0187] Method 1: Input the abnormal feature to a preset algorithm so that the preset algorithm outputs a target instruction.

[0188] In this method, the preset algorithm may be pre-trained. When a target instruction needs to be generated, the computing device may input the abnormal feature to the preset algorithm so that the preset algorithm can output a target instruction.

[0189] For example, the preset algorithm may be trained according to the operation logs of multiple security devices and other relevant data.

[0190] In this method, target instructions can be quickly generated, further improving the operation and maintenance efficiency.

[0191] Method 2: Determine the exception type corresponding to the exception feature, and generate target instructions according to the exception type.

[0192] The exception type is a software update type, a configuration update type, or a fault type.

[0193] In this method, the computing device can determine whether the exception type is a preset type. The preset type is a software update type or a configuration update type. If the exception type is not the preset type, determine that the exception type is a fault type.

[0194] When determining whether the exception type is a preset type, the computing device can obtain the current software code of the security device and / or configuration information. If the software code indicates that there is a software vulnerability in the security device, determine that the exception type is a software update type. If the configuration information indicates that there is a configuration error in the security device, determine that the exception type is a configuration update type.

[0195] Specifically, after obtaining the current software code of the security device, the computing device can determine whether there is a software vulnerability in the security device according to the current software code of the security device. If there is a software vulnerability in the security device, the computing device can determine that the exception type is a software update type. After obtaining the configuration information of the security device, the computing device can determine whether there is a configuration error in the security device according to the configuration information of the security device. If there is a configuration error in the security device, the computing device can determine that the abnormal device is a configuration update type.

[0196] When generating target instructions according to the exception type, if the exception type is a software update type, generate a first instruction, and the first instruction is used to indicate installing a software patch. If the exception type is a configuration update type, generate a second instruction, and the second instruction is used to indicate restoring the default configuration. If the exception type is a fault type, generate a third instruction, and the third instruction is used to indicate updating the current software code of the security device to the historical software code, and no abnormal event occurs when the security device runs the historical software code.

[0197] Through this method, target instructions can be generated when the preset algorithm cannot output target instructions, so as to realize the operation and maintenance of the security device.

[0198] It should be noted that the computing device can also execute Method 2 periodically to make the stability of each security device better. For example, it can periodically scan the software code of each security device and / or periodically obtain the configuration information of each security device, etc.

[0199] In this embodiment, after obtaining the target instruction through Method 1 or Method 2, the computing device can also update the abnormal feature and the target instruction generated according to the abnormal feature to the feature library. In this way, the feature library can be optimized, the determination duration of subsequent target instructions can be shortened, the subsequent abnormal handling efficiency can be improved, and thus the reliability of the security device is relatively high, and the business impact of subsequent abnormal events on the security device is relatively small.

[0200] S405. Control the security device to execute the target instruction so that the security device processes the abnormal event.

[0201] For example, if the target instruction is the first instruction, the computing device can control the security device to install software patches; if the target instruction is the third instruction, the computing device can control the security device to run the historical software code.

[0202] Optionally, before executing the target instruction, the software code and configuration data of the security device at present can also be backed up. The backed-up software code and configuration data can be stored in the security device or in other electronic devices. For example, the other electronic device can be a remote server.

[0203] In this embodiment, the computing device can also monitor the execution progress of the target instruction to determine the solution result of the abnormal event according to the execution progress of the target instruction, and the solution result is success or failure. The computing device can also send the solution result to the preset device corresponding to the operation and maintenance personnel so as to facilitate the operation and maintenance personnel to know the solution result of the abnormal event.

[0204] Optionally, if the solution result is failure and the target instruction is the instruction corresponding to the first feature, the computing device can also re-execute S404 - S405 to generate a target instruction according to the abnormal feature and control the security device to execute the target instruction.

[0205] In this embodiment, the computing device can also count the solution result of each abnormal event and the target instruction corresponding to the abnormal event to obtain a statistical result. If there is a target instruction with a solution result of failure and a relatively high failure frequency, the computing device can also send the statistical result to the preset device corresponding to the operation and maintenance personnel so as to facilitate the operation and maintenance personnel to intervene.

[0206] In the exception handling method provided in this embodiment, after the computing device determines an exception event corresponding to the security device, it generates an exception feature corresponding to the exception event; it can determine whether there is a first feature in the feature library; if there is a first feature in the feature library, it can determine the instruction corresponding to the first feature as the target instruction; if there is no first feature in the feature library, it can generate a target instruction according to the exception feature; and it can control the security device to execute the target instruction so that the security device processes the exception event. In the above method, the computing device can interface with one or more security devices, can determine the exception events of each security device, and can control the security device to execute the target instruction to automatically process the exception event. Through the above method, the exception handling efficiency can be improved.

[0207] Based on any of the above embodiments, the following combines Figure 5 , and illustrates the exception handling method provided in the embodiments of the present application through specific examples.

[0208] Figure 5 FIG. is a schematic flowchart of another exception handling method provided in the embodiments of the present application. The execution subject of this method can be a computing device or a processor provided in the computing device. The computing device can be, for example, a server. The processor in the computing device can be, for example, the CPU in the server. For ease of understanding, in the following, the execution subject is taken as an example of a computing device for description. Please refer to Figure 5 , this method may include:

[0209] S501. After determining that the traffic received by the security device is abnormal, generate an abnormal feature.

[0210] In this embodiment, it is assumed that the computing device monitors that: the number of data packets received by the target port of the security device within one minute is greater than 1,000,000. The computing device determines, according to the monitored data, that the exception event corresponding to the security device is abnormal received traffic.

[0211] The target port can be any port on the security device that can receive traffic.

[0212] The computing device can obtain the log corresponding to the exception event for semantic analysis and generate an exception feature: the target port receives a large amount of unknown traffic.

[0213] S502. Determine the target instruction according to the exception feature.

[0214] The computing device can first determine whether there is a first feature in the feature library.

[0215] In this embodiment, it is assumed that there is a first feature in the feature library, and the computing device can determine the instruction corresponding to the first feature as the target instruction. It is assumed that the target instruction is to block access to the target port.

[0216] Optionally, the number of target instructions may be multiple, where multiple may be two or more. For example, the number of target instructions may be 2. The first target instruction may be: determining whether the traffic of the target port is abnormal according to the log, and the second target instruction may be: blocking access to the target port.

[0217] In this embodiment, the target instruction may be in the form of a script, or in the form of a Linux command, etc.

[0218] S503. Control the security device to execute the target instruction so that the security device processes the abnormal event.

[0219] Specifically, if the target instruction is to block access to the target port, the computing device may control the security device to block access to the target port. If the target instructions are: determining whether the traffic of the target port is abnormal according to the log, and blocking access to the target port, the computing device may control the security device to determine whether the traffic of the target port is abnormal according to the log, and may block access to the target port when it is determined that the traffic of the target port is abnormal.

[0220] In this embodiment, before executing the target instruction, the computing device may also back up the current software code and configuration data of the security device.

[0221] Specifically, the computing device may use the tape archive (tar) command to package the current software code and configuration data of the security device to obtain the data to be backed up, and may store the data to be backed up in the security device or a remote server. For example, the computing device may use the secure copy (scp) command to store the data to be backed up in the remote server.

[0222] In this embodiment, the computing device may also determine the solution result of the abnormal event. If the solution result is a failure, the computing device may re-determine the target instruction according to the method shown in S404, and control the security device to execute the target instruction.

[0223] In the abnormal handling method provided in this embodiment, the computing device may generate an abnormal feature after determining that the traffic received by the security device is abnormal; may determine the target instruction according to the abnormal feature; and may control the security device to execute the target instruction so that the security device processes the abnormal event. In the above method, the purpose of automatically handling the abnormal event of the security device can be achieved, and the abnormal handling efficiency is improved.

[0224] Figure 6 This is a schematic structural diagram of an abnormal handling device provided in an embodiment of the present application. The abnormal handling device 10 is applied to a computing device, and the computing device is connected to a security device, or a security device runs on the computing device. Please refer to Figure 6, the exception handling device 10 includes a determination module 11, a generation module 12, and a control module 13. Among them,

[0225] After the determination module 11 determines an exception event corresponding to a security device, the generation module 12 is used to generate an exception feature corresponding to the exception event;

[0226] The determination module 11 is further configured to determine a target instruction according to the exception feature;

[0227] The control module 13 is used to control the security device to execute the target instruction, so that the security device processes the exception event.

[0228] The exception handling device provided in this embodiment can execute the method shown in any of the above method embodiments, and its implementation principle and technical effects are similar, which will not be elaborated here in this embodiment.

[0229] In a possible implementation manner, the determination module 11 is specifically configured to,

[0230] Determine whether there is a first feature in the feature library, where the similarity between the first feature and the exception feature is greater than or equal to a preset threshold. The feature library includes multiple features and instructions corresponding to each feature;

[0231] If the first feature exists in the feature library, determine the instruction corresponding to the first feature as the target instruction.

[0232] If the first feature does not exist in the feature library, generate the target instruction according to the exception feature.

[0233] In a possible implementation manner, the determination module 11 is specifically configured to,

[0234] Determine at least one keyword included in the exception feature;

[0235] According to the at least one keyword, determine whether the first feature exists in the feature library;

[0236] Wherein, the first feature includes the at least one keyword.

[0237] In a possible implementation manner, the determination module 11 is specifically configured to,

[0238] Input the exception feature into a preset algorithm, so that the preset algorithm outputs the target instruction; or,

[0239] Determine the exception type corresponding to the exception feature, and generate the target instruction according to the exception type. The exception type is a software update type, a configuration update type, or a fault type.

[0240] In a possible implementation, the determining module 11 is specifically configured to,

[0241] Determine whether the exception type is a preset type, where the preset type is a software update type or a configuration update type;

[0242] If the exception type is not the preset type, determine that the exception type is a fault type.

[0243] In a possible implementation, the determining module 11 is specifically configured to,

[0244] Obtain the current software code and / or configuration information of the security device;

[0245] If the software code indicates that there is a software vulnerability in the security device, determine that the exception type is a software update type;

[0246] If the configuration information indicates that there is a configuration error in the security device, determine that the exception type is a configuration update type.

[0247] In a possible implementation, the determining module 11 is specifically configured to,

[0248] If the exception type is the software update type, generate a first instruction for instructing to install a software patch;

[0249] If the exception type is the configuration update type, generate a second instruction for instructing to restore the default configuration;

[0250] If the exception type is the fault type, generate a third instruction for instructing to update the current software code of the security device to a historical software code, where the security device does not have the exception event when running the historical software code.

[0251] Figure 7 This is a schematic structural diagram of another exception handling device provided by an embodiment of the present application. On Figure 6 this basis, the exception handling device 10 further includes an update module 14 and a sending module 15, where,

[0252] The update module 14 is configured to update the exception feature and the target instruction generated according to the exception feature to the feature library.

[0253] In a possible implementation,

[0254] The determining module 11 is further configured to determine the solution result of the exception event, where the solution result is success or failure;

[0255] The sending module 15 is configured to send the solution result to a preset device corresponding to the operation and maintenance personnel.

[0256] In a possible implementation, the sending module 15 is further configured to

[0257] send the abnormal feature to a preset device corresponding to the operation and maintenance personnel.

[0258] The abnormal handling device provided in this embodiment can execute the method shown in any of the above method embodiments. The implementation principle and technical effects are similar, and will not be elaborated here.

[0259] Figure 8 FIG. is a schematic structural diagram of a computing device provided in an embodiment of the present application. As Figure 8 shown, the computing device 20 may include: a processor 21 and a memory 22. Among them, the processor 21 and the memory 22 can communicate; exemplarily, the processor 21 and the memory 22 communicate through a communication bus 23. The memory 22 is used to store computer execution instructions, and the processor 21 is used to call the computer execution instructions in the memory to execute the abnormal handling method shown in any of the above method embodiments.

[0260] Optionally, the computing device 20 may further include a communication interface, and the communication interface may include a transmitter and / or a receiver.

[0261] The computing device 20 may be the computing device shown in any of the above method embodiments, and may execute the abnormal handling method shown in any of the above method embodiments.

[0262] Optionally, the above-mentioned processor may be a CPU, or may also be a GPU, a Baseboard Management Controller (BMC), other general-purpose processors, a Digital Signal Processor (DSP), or an Application Specific Integrated Circuit (ASIC), etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present application can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules in the processor.

[0263] An embodiment of the present application provides a computer-readable storage medium, on which computer execution instructions are stored; the computer execution instructions are used to implement the abnormal handling method as described in any of the above embodiments.

[0264] An embodiment of the present application provides a computer program product, which includes a computer program. When the computer program is executed, it causes a computer to execute the above-mentioned exception handling method.

[0265] All or part of the steps of implementing the above method embodiments can be completed by hardware related to program instructions. The foregoing program can be stored in a readable memory. When the program is executed, it executes the steps including the above method embodiments; and the foregoing memory (storage medium) includes: read-only memory (abbreviation: ROM), RAM, flash memory, hard disk, solid state drive, magnetic tape, floppy disk, optical disc, and any combination thereof.

[0266] The embodiments of the present application are described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processing unit of a general-purpose computer, a special-purpose computer, an embedded processing machine, or other programmable terminal devices to generate a machine, so that the instructions executed by the processing unit of the computer or other programmable terminal devices generate a device for implementing the functions specified in Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.

[0267] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable terminal devices to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the functions specified in Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.

[0268] These computer program instructions can also be loaded onto a computer or other programmable terminal devices, so that a series of operation steps are executed on the computer or other programmable devices to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable devices provide steps for implementing the functions specified in Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.

[0269] Obviously, those skilled in the art can make various modifications and variations to the embodiments of the present application without departing from the spirit and scope of the embodiments of the present application. Thus, if these modifications and variations of the embodiments of the present application fall within the scope of the claims of the present application and their equivalent technologies, the embodiments of the present application are also intended to include these modifications and variations.

[0270] In the embodiments of the present application, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising that element. The term "or" and its variants may mean "and / or". In the embodiments of the present application, terms such as "first", "second", etc. are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. In the embodiments of the present application, "a plurality of" means two or more. "And / or" describes the association relationship of associated objects and indicates that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally indicates that the associated objects before and after are in an "or" relationship.

[0271] After considering the specification and the invention disclosed in practice, those skilled in the art will readily conceive of other embodiments of the present application. The embodiments of the present application are intended to cover any variations, uses or adaptive changes of the embodiments of the present application, which follow the general principles of the embodiments of the present application and include the common general knowledge or conventional technical means in the technical field not disclosed in the embodiments of the present application.

Claims

1. An exception handling method, characterized in that, Applied to a computing device, where the computing device is connected to a security device or a security device is running on the computing device, the method includes: After determining an abnormal event corresponding to the security device, generating an abnormal feature corresponding to the abnormal event; Determining a target instruction according to the abnormal feature; Controlling the security device to execute the target instruction so that the security device processes the abnormal event.

2. The method according to claim 1, characterized in that, The determining a target instruction according to the abnormal feature includes: Determining whether there is a first feature in the feature library, where the similarity between the first feature and the abnormal feature is greater than or equal to a preset threshold, and the feature library includes multiple features and instructions corresponding to each feature; If the first feature exists in the feature library, determining the instruction corresponding to the first feature as the target instruction; If the first feature does not exist in the feature library, generating the target instruction according to the abnormal feature.

3. The method according to claim 2, characterized in that The determining whether there is a first feature in the feature library includes: Determining at least one keyword included in the abnormal feature; Determining whether the first feature exists in the feature library according to the at least one keyword; Wherein, the first feature includes the at least one keyword.

4. The method according to claim 2 or 3, characterized in that, The generating the target instruction according to the abnormal feature includes: Inputting the abnormal feature into a preset algorithm so that the preset algorithm outputs the target instruction; or, Determining the abnormal type corresponding to the abnormal feature and generating the target instruction according to the abnormal type, where the abnormal type is a software update type, a configuration update type or a fault type.

5. The method according to claim 4, wherein The determining the abnormal type corresponding to the abnormal feature includes: Determining whether the abnormal type is a preset type, where the preset type is a software update type or a configuration update type; If the abnormal type is not the preset type, determining the abnormal type as a fault type.

6. The method according to claim 5, characterized in that The determining whether the abnormal type is a preset type includes: Obtaining the current software code of the security device and / or configuration information; If the software code indicates that there is a software vulnerability in the security device, determining the abnormal type as a software update type; If the configuration information indicates that there is a configuration error in the security device, determining the abnormal type as a configuration update type.

7. The method according to any one of claims 4 to 6, characterized in that The generating the target instruction according to the abnormal type includes: If the abnormal type is the software update type, generating a first instruction for instructing to install a software patch; If the abnormal type is the configuration update type, generating a second instruction for instructing to restore the default configuration; If the abnormal type is the fault type, generating a third instruction for instructing to update the current software code of the security device to a historical software code, where the security device does not have the abnormal event when running the historical software code.

8. The method according to any one of claims 2-7, characterized in that, The method further includes: Updating the abnormal feature and the target instruction generated according to the abnormal feature to the feature library.

9. The method according to any one of claims 1-8, characterized in that, The method further includes: Determining the solution result of the abnormal event, where the solution result is success or failure; Sending the solution result to a preset device corresponding to the operation and maintenance personnel.

10. The method according to claim 9, wherein The method further includes: Sending the abnormal feature to a preset device corresponding to the operation and maintenance personnel.

11. A computing device, characterized in that, Including: A memory and a processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory, so that the processor executes the method according to any one of claims 1-10.

12. A computer-readable storage medium, characterized in that, Computer-executable instructions are stored in the computer-readable storage medium, and when the computer-executable instructions are executed by a processor, they are used to implement the method according to any one of claims 1-10.

13. A computer program product, characterized in that, Including a computer program, which implements the method according to any one of claims 1-10 when executed by a processor.