Log association method and device
By obtaining user instructions and preset rules to filter logs, building a log chain for log association, solving the problems of association of massive log data and malicious behavior analysis, and achieving efficient log chain generation and attack behavior recognition.
Patent Information
- Application Number
- CN202410034182.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-09
- Publication Date
- 2025-07-11
AI Technical Summary
How to effectively associate massive log data and analyze malicious behavior based on the associated log data, it is difficult for the existing technology to achieve efficient log data association and malicious behavior analysis.
By obtaining user-triggered log association instructions, finding target alarm logs related to target alarm information, generating log chains based on the association relationship of target alarm logs, using preset rules to filter host logs with malicious behavior, and building log chains through the association relationship between process identifiers and network logs to analyze attack behavior.
实现了对目标告警的高效关联分析,能够准确识别和验证恶意行为,提高了安全分析的效率和准确性,减少了误报警。
Smart Images

Figure CN120295986A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular, to a log correlation method and apparatus. Background Art
[0002] In the digital age, with the rapid development of information technology, log data has become an important information source in aspects such as enterprise operation, system monitoring, and security protection. Log data records the running status, event responses, and abnormal situations of systems, application programs, and network devices, providing valuable information for analyzing and solving problems. However, in the face of a large amount of log data, how to effectively correlate the log data and analyze malicious behaviors based on the correlated log data has become an urgent problem to be solved. Summary of the Invention
[0003] Aiming at the problems existing in the prior art, the present invention provides a log correlation method and apparatus.
[0004] The present invention provides a log correlation method, including:
[0005] Obtaining a log correlation instruction triggered by a user, where the log correlation instruction includes target alarm information selected by the user in a target alarm;
[0006] Searching for at least one target alarm log related to the target alarm information in a plurality of alarm logs; the alarm logs are host logs matching a first preset rule, and the first preset rule is used to screen host logs with malicious behaviors;
[0007] Generating a log chain corresponding to the target alarm based on the correlation relationships of the target alarm logs.
[0008] According to the log correlation method provided by the present invention, the target alarm information includes a target process identifier;
[0009] The searching for at least one target alarm log related to the target alarm information in a plurality of alarm logs includes:
[0010] Searching for a first alarm log including the target process identifier in a plurality of the alarm logs;
[0011] In the case where the target process identifier is the process identifier in the first alarm log, check whether there is a second alarm log that uses the parent process identifier in the first alarm log as the process identifier among the first other alarm logs except the first alarm log in the multiple alarm logs. And in the case where there is a second alarm log that uses the parent process identifier in the first alarm log as the process identifier among the first other alarm logs, check whether there is a third alarm log that uses the parent process identifier in the second alarm log as the process identifier among the second other alarm logs except the second alarm log in the first other alarm logs. Repeat the above steps until there is no alarm log in the first remaining alarm logs that uses the parent process identifier in the last searched alarm log as the process identifier, so as to obtain a first alarm log set;
[0012] Check whether there is a fourth alarm log that uses the target process identifier as the parent process identifier among the first other alarm logs. And in the case where there is a fourth alarm log that uses the target process identifier as the parent process identifier among the first other alarm logs, check whether there is a fifth alarm log that uses the process identifier in the fourth alarm log as the parent process identifier among the third other alarm logs except the fourth alarm log in the first other alarm logs. Repeat the above steps until there is no alarm log in the second remaining alarm logs that uses the process identifier in the last searched alarm log as the parent process identifier, so as to obtain a second alarm log set;
[0013] Based on the first alarm log set, the second alarm log set and the first alarm log, determine the at least one target alarm log.
[0014] According to a log association method provided by the present invention, the method further includes:
[0015] In the case where the target process identifier is the parent process identifier in the first alarm log, check whether there is a sixth alarm log that uses the target process identifier as the process identifier among the first other alarm logs except the first alarm log in the multiple alarm logs. And in the case where there is a sixth alarm log that uses the target process identifier as the process identifier among the first other alarm logs, check whether there is a seventh alarm log that uses the parent process identifier in the sixth alarm log as the process identifier among the fourth other alarm logs except the sixth alarm log in the first other alarm logs. Repeat the above steps until there is no alarm log in the third remaining alarm logs that uses the parent process identifier in the last searched alarm log as the process identifier, so as to obtain a third alarm log set;
[0016] Search for an eighth alarm log in the first other alarm log that uses the process identifier in the first alarm log as the parent process identifier. When there is an eighth alarm log that uses the process identifier in the first alarm log as the parent process identifier, search for a ninth alarm log in the fifth other alarm log in the first other alarm log excluding the eighth alarm log that uses the process identifier in the eighth alarm log as the parent process identifier. Repeat the above steps until there is no alarm log in the fourth remaining alarm log that uses the process identifier in the last searched alarm log as the parent process identifier, to obtain a fourth alarm log set;
[0017] Based on the third alarm log set, the fourth alarm log set, and the first alarm log, determine the at least one target alarm log.
[0018] According to a log association method provided by the present invention, the method further includes:
[0019] Obtain a target network log that generates an alarm; the target network log is a log that matches a second preset rule, and the second preset rule is used to screen network logs with malicious behaviors;
[0020] Among multiple alarm logs, determine a fourth alarm log that matches the IP address of the host represented in the target network log and the generation time of the malicious behavior;
[0021] Associate the target network log and the fourth alarm log.
[0022] According to a log association method provided by the present invention, the method further includes:
[0023] Determine whether the fourth alarm log includes an operation behavior related to the malicious behavior corresponding to the target network log;
[0024] When it is determined that the fourth alarm log includes an operation behavior related to the malicious behavior corresponding to the target network log, determine that the alarm corresponding to the target network log is a real alarm.
[0025] According to a log association method provided by the present invention, the method further includes:
[0026] When it is determined that the fourth alarm log does not include an operation behavior related to the malicious behavior corresponding to the target network log, determine that the alarm corresponding to the target network log is a false alarm.
[0027] The present invention also provides a log association device, including:
[0028] A first acquisition unit, configured to acquire a log association instruction triggered by a user, where the log association instruction includes target alarm information selected by the user in a target alarm;
[0029] A search unit, configured to search for at least one target alarm log related to the target alarm information in multiple alarm logs; the alarm logs are host logs matching a first preset rule, and the first preset rule is used to filter host logs with malicious behaviors;
[0030] A generation unit, configured to generate a log chain corresponding to the target alarm information based on the association relationships of the target alarm logs.
[0031] The present invention further provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, where when the processor executes the program, the log association method as described in any one of the above is implemented.
[0032] The present invention further provides a non-transitory computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the log association method as described in any one of the above is implemented.
[0033] The present invention further provides a computer program product, including a computer program, and when the computer program is executed by a processor, the log association method as described in any one of the above is implemented.
[0034] The log association method and device provided by the present invention acquire a log association instruction triggered by a user, which includes target alarm information selected by the user in a target alarm, search for at least one target alarm log related to the target alarm information in multiple alarm logs, and form a log chain corresponding to the target alarm based on the association relationships of the target alarm logs. It can be seen that the present invention forms a log chain based on the target alarm information, and the target alarm logs associated in the log chain are all host logs matching the first preset rule. In this way, the entire attack behavior can be analyzed based on the association relationships between the target alarm logs in the log chain. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0036] Figure 1 is one of the schematic flowcharts of the log association method provided by the embodiment of the present invention;
[0037] Figure 2It is a schematic structural diagram of an electronic device provided by an embodiment of the present invention;
[0038] Figure 3 It is the second schematic flowchart of the log association method provided by an embodiment of the present invention;
[0039] Figure 4 It is the third schematic flowchart of the log association method provided by an embodiment of the present invention;
[0040] Figure 5 It is the fourth schematic flowchart of the log association method provided by an embodiment of the present invention;
[0041] Figure 6 It is a schematic structural diagram of a log association device provided by an embodiment of the present invention;
[0042] Figure 7 It is a schematic physical structure diagram of an electronic device provided by the present invention. Detailed implementation manners
[0043] To make the objectives, technical solutions and advantages of the present invention clearer, the technical solutions in the present invention will be clearly and completely described below with reference to the accompanying drawings in the present invention. Obviously, the described embodiments are some but not all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present invention without creative efforts shall fall within the protection scope of the present invention.
[0044] The following combines Figures 1-5 to describe the log association method of the present invention. The execution subject of this log association method can be an electronic device such as a computer or a terminal, or a log association determination device provided in the electronic device, and the log association determination device can be implemented by software, hardware or a combination of both.
[0045] Figure 1 It is the first schematic flowchart of the log association method provided by an embodiment of the present invention. As Figure 1 shown, the log association method includes the following steps:
[0046] Step 101, obtain a log association instruction triggered by a user, where the log association instruction includes target alarm information selected by the user in a target alarm.
[0047] Among them, Figure 2 It is a schematic structural diagram of an electronic device provided by an embodiment of the present invention. As Figure 2As shown in the figure, a Logmanager and at least one Agent are installed on the electronic device. Among them, the Logmanager includes a Logcenter, at least one first preset Rule, an Association Analysis Engine Log Analysis, and a Log Display Module Log Show; the first preset Rule may include information such as attack types and threat levels. The Agent is used to collect sysmon logs. The sysmon logs are records for different operations of the operating system formulated by Microsoft and send the sysmon logs to the Logcenter. The sysmon logs contain host IP information. When the Logcenter captures the sysmon logs, it matches the sysmon logs with multiple first preset rules, analyzes information such as the log operation type, process, and user of the sysmon logs through the first preset rules to determine the matching result. When a sysmon log matches a certain first preset rule, it indicates that there is a malicious behavior in the operation of the sysmon log, and then an alarm corresponding to the sysmon log is generated. In the present invention, the sysmon log that generates the alarm is called an alarm log. For each sysmon log captured by the Logcenter, it is matched with multiple first preset rules, so multiple alarm logs can be obtained; the Association Analysis Engine Log Analysis is used to execute the association analysis method described in the present invention, and the Log Display Module Log Show is used to display the finally generated log chain.
[0048] Exemplarily, when the user needs to view all the logs related to the target alarm, the user can select the target alarm information from all the field information included in the target alarm. The target alarm information may be a process identifier. When the electronic device obtains the selection operation of the user for the target alarm information, it determines that the log association instruction triggered by the user is obtained.
[0049] Step 102: Search for at least one target alarm log related to the target alarm information in multiple alarm logs; the alarm log is a host log that matches the first preset rule, and the first preset rule is used to screen the host logs with malicious behaviors.
[0050] Exemplarily, the alarm log includes the following fields: process identifier processid, process name image, command line command for starting the process, parent process identifier parentprocessid, etc.; when the electronic device obtains the log association instruction input by the user, it searches for the alarm log including the target alarm information among multiple previously generated alarm logs, and continues to search for other alarm logs related to the alarm log among multiple previously generated alarm logs, and so on, until all the alarm logs are found, and all the found alarm logs are determined as the target alarm logs related to the target alarm information.
[0051] Step 103, generate a log chain corresponding to the target alarm based on the association relationships of the target alarm logs.
[0052] Exemplarily, the above association relationship can be the association relationship between processes (such as the call relationship), or the chronological order of the logs. Thus, when obtaining all the target alarm logs related to the target alarm information, a log chain corresponding to the target alarm can be generated based on the association relationship between processes in the target alarm logs, or the target alarm logs can be sorted in chronological order to obtain a log chain including multiple target alarm logs. For example, the obtained target alarm log 1 includes that the web service process http.exe calls cmd.exe to create a process, and the target alarm log 2 includes that the process cmd.exe calls ipconfig.exe to create a process. Then, the log chain can include the call relationship between the identifier 1 corresponding to the web service process http.exe and the identifier 2 corresponding to the process cmd.exe, and the call relationship between the identifier 2 corresponding to the process cmd.exe and the identifier 3 corresponding to the process ipconfig.exe.
[0053] Furthermore, after generating the log chain corresponding to the target alarm, the log chain can be displayed through the log display module LogShow. In addition, the log display module Log Show can also display the alarm information corresponding to each target alarm log in the log chain, facilitating analysts to comprehensively analyze the attack behavior based on the association relationships between the target alarm logs and the association relationships between the alarm information.
[0054] The log association method provided by the present invention obtains a log association instruction triggered by a user, which includes target alarm information selected by the user in a target alarm, searches for at least one target alarm log related to the target alarm information in multiple alarm logs, and forms a log chain corresponding to the target alarm based on the association relationships of the target alarm logs. It can be seen that the present invention forms a log chain based on the target alarm information, and the target alarm logs associated in the log chain are all host logs that match the first preset rule. In this way, the entire attack behavior can be analyzed based on the association relationships between the target alarm logs in the log chain.
[0055] In one embodiment, the target alarm information includes a target process identifier; Figure 3 FIG. 2 is a second flowchart of the log association method provided by an embodiment of the present invention. As Figure 3 shown, the above step 102 searches for at least one target alarm log related to the target alarm information in multiple alarm logs, and can be specifically implemented through the following steps:
[0056] Step 1021: Determine a first alarm log including the target process identifier in multiple alarm logs.
[0057] Among them, the target process identifier can be understood as the target process ID.
[0058] Exemplarily, traverse each alarm log to determine whether the target process identifier is included in the alarm log, and determine the alarm log including the target process identifier as the first alarm log.
[0059] It should be noted that the target alarm information may also include the target process identifier and time period information at the same time. In this case, it is necessary to determine a first alarm log that includes the target process identifier and whose operation time is within the time period information in multiple alarm logs.
[0060] Step 1022: When the target process identifier is the process identifier in the first alarm log, search for a second alarm log whose process identifier is the parent process identifier in the first alarm log among the first other alarm logs other than the first alarm log in multiple alarm logs. And when there is a second alarm log whose process identifier is the parent process identifier in the first alarm log among the first other alarm logs, search for a third alarm log whose process identifier is the parent process identifier in the second alarm log among the second other alarm logs other than the second alarm log in the first other alarm logs. Repeat the above steps until there is no alarm log in the first remaining alarm logs whose process identifier is the parent process identifier in the last searched alarm log, and obtain a first alarm log set.
[0061] Exemplarily, assume that the target process identifier is Process B, and the multiple alarm logs include Alarm Log 1, Alarm Log 2, Alarm Log 3, Alarm Log 4, Alarm Log 5, and Alarm Log 6. Among them, Alarm Log 1 includes Process E calling Process A, Alarm Log 2 includes Process A calling Process B, Alarm Log 3 includes Process B calling Process C, Alarm Log 4 includes Process C calling Process D, Alarm Log 5 includes Process A calling Process F, and Alarm Log 6 includes Process D calling Process F. Then, the first alarm log including the target process identifier can be Alarm Log 2 or Alarm Log 3. Taking Alarm Log 2 as an example of the first alarm log, it is determined that the target process identifier is Process B, and Process B is the process identifier in Alarm Log 2. Then, check whether there is a second alarm log in the first other alarm logs except Alarm Log 2 that uses the parent process identifier Process A in Alarm Log 2 as the process identifier. It can be determined that the second alarm log is Alarm Log 1. Continue to check whether there is a third alarm log in the second other alarm logs except Alarm Log 2 and Alarm Log 1 that uses the parent process identifier Process E in Alarm Log 1 as the process identifier. It is determined that no third alarm log that uses the parent process identifier Process E in Alarm Log 1 as the process identifier is found. Then, it is determined that the final first alarm log set includes Alarm Log 1.
[0062] Step 1023: Check whether there is a fourth alarm log in the first other alarm logs that uses the target process identifier as the parent process identifier. In the case where there is a fourth alarm log in the first other alarm logs that uses the target process identifier as the parent process identifier, check whether there is a fifth alarm log in the third other alarm logs except the fourth alarm log in the first other alarm logs that uses the process identifier in the fourth alarm log as the parent process identifier. Repeat the above steps until there is no alarm log in the second remaining alarm logs that uses the process identifier in the last searched alarm log as the parent process identifier, to obtain the second alarm log set.
[0063] Exemplarily, following the example in step 1022, search for a fourth warning log in the first other warning log except warning log 2 that has the target process identifier B in warning log 2 as the parent process identifier. It can be determined that the fourth warning log is warning log 3. Then continue to search for a fifth warning log in the third other warning log except warning log 2 and warning log 3 that has the process identifier process C in warning log 3 as the parent process identifier. It can be determined that the fifth warning log is warning log 4. Then continue to search for a warning log in the other warning logs except warning log 2, warning log 3, and warning log 4 that has the process identifier process D in warning log 4 as the parent process identifier. It is determined that no warning log with the process identifier process D in warning log 4 as the parent process identifier is found. Then it is determined that the final second warning log set includes warning log 3 and warning log 4.
[0064] Step 1024: Based on the first warning log set, the second warning log set, and the first warning log, determine the at least one target warning log.
[0065] Exemplarily, when obtaining the first warning log set and the second warning log set, determine each warning log in the first warning log set, each warning log in the second warning log set, and the first warning log as the target warning logs related to the target warning information. Then following the examples in step 1022 and step 1023, the finally determined target warning logs include warning log 1, warning log 2, warning log 3, and warning log 4. Further, the association relationship of each target warning log is that warning log 1 includes process E calling process A, warning log 2 includes process A calling process B, warning log 3 includes process B calling process C, and warning log 4 includes process C calling process D. Then the generated log chain is warning log 1 - warning log 2 - warning log 3 - warning log 4.
[0066] In one embodiment, Figure 4 is the third flowchart of the log association method provided by the embodiment of the present invention. As Figure 4 shown, the above step 102 searches for at least one target warning log related to the target warning information in multiple warning logs, and can be specifically implemented through the following steps:
[0067] Step 1025: When the target process identifier is the parent process identifier in the first warning log, check whether there is a sixth warning log with the target process identifier as the process identifier among the first other warning logs except the first warning log among the multiple warning logs. When there is a sixth warning log with the target process identifier as the process identifier in the first other warning logs, check whether there is a seventh warning log with the parent process identifier in the sixth warning log as the process identifier among the fourth other warning logs except the sixth warning log in the first other warning logs. Repeat the above steps until there is no warning log with the parent process identifier in the last searched warning log as the process identifier in the third remaining warning logs, to obtain the third warning log set.
[0068] Exemplarily, assume that the target process identifier is process A, and the multiple warning logs include warning log 1, warning log 2, warning log 3, warning log 4, warning log 5, and warning log 6. Among them, warning log 1 includes process E calling process A, warning log 2 includes process A calling process B, warning log 3 includes process B calling process C, warning log 4 includes process C calling process D, warning log 5 includes process A calling process F, and warning log 6 includes process D calling process F. Then, the first warning log including the target process identifier can be warning log 1 or warning log 2. Taking warning log 2 as an example of the first warning log, it is determined that the target process identifier is process A, and process A is the parent process identifier in warning log 2. Then, check whether there is a sixth warning log with the parent process identifier process A in warning log 2 as the process identifier among the first other warning logs except warning log 2. It can be determined that the sixth warning log is warning log 1. Continue to check whether there is a seventh warning log with the parent process identifier process E in warning log 1 as the process identifier among the fourth other warning logs except warning log 2 and warning log 1. It is determined that there is no seventh warning log with the parent process identifier process E in warning log 1 as the process identifier. Then, it is determined that the final first warning log set includes warning log 1.
[0069] Step 1026: Check whether there is an eighth warning log with the process identifier in the first warning log as the parent process identifier among the first other warning logs. When there is an eighth warning log with the process identifier in the first warning log as the parent process identifier, check whether there is a ninth warning log with the process identifier in the eighth warning log as the parent process identifier among the fifth other warning logs except the eighth warning log in the first other warning logs. Repeat the above steps until there is no warning log with the process identifier in the last searched warning log as the parent process identifier in the fourth remaining warning logs, to obtain the fourth warning log set.
[0070] Exemplarily, following the example in step 1025, check whether there is an eighth warning log in the first other warning log except warning log 2 that uses process B in warning log 2 as the parent process identifier. It can be determined that the eighth warning log is warning log 3. Then continue to check whether there is a ninth warning log in the fifth other warning log except warning log 2 and warning log 3 that uses process C, the process identifier in warning log 3, as the parent process identifier. It can be determined that the ninth warning log is warning log 4. Then continue to check whether there is a warning log in the other warning logs except warning log 2, warning log 3, and warning log 4 that uses process D, the process identifier in warning log 4, as the parent process identifier. It is determined that no warning log that uses process D, the process identifier in warning log 4, as the parent process identifier is found. Then it is determined that the final second warning log set includes warning log 3 and warning log 4.
[0071] Step 1027: Based on the third warning log set, the fourth warning log set, and the first warning log, determine the at least one target warning log.
[0072] Exemplarily, when obtaining the third warning log set and the fourth warning log set, determine each warning log in the third warning log set, each warning log in the fourth warning log set, and the first warning log as target warning logs related to the target warning information. Following the examples in step 1025 and step 1026, the finally determined target warning logs include warning log 1, warning log 2, warning log 3, and warning log 4. Further, the association relationships of the target warning logs are that warning log 1 includes process E calling process A, warning log 2 includes process A calling process B, warning log 3 includes process B calling process C, and warning log 4 includes process C calling process D. Then the generated log chain is warning log 1 - warning log 2 - warning log 3 - warning log 4.
[0073] For another example, all target alert logs include alert log 11 and alert log 12. Among them, alert log 11 includes the web service process http.exe calling the process cmd.exe to create a process. The identifier of the web service process http.exe is identifier 1, and the identifier of the process cmd.exe is identifier 2. Alert log 12 includes the process cmd.exe calling the process ipconfig.exe to create a process. The identifier of the process cmd.exe is identifier 2, and the identifier of the process ipconfig.exe is identifier 3. If the alert type of the target alert is that a system command is executed using the web service, and the user selects the value of the process field in the target alert, that is, the target process identifier is identifier 1 corresponding to the web service process http.exe. If it is found that alert log 11 includes identifier 1 among all alert logs, then alert log 11 is determined as the first alert log; the process identifier to be associated is identifier 2 corresponding to cmd.exe, and it is found that alert log 12 includes identifier 2, so alert log 12 is determined as the second alert log. At this time, since all alert logs have been traversed, finally both the first alert log and the second alert log are used as the target alert logs associated with the target alert.
[0074] In this embodiment, first, a first alert log including the target process identifier is determined among multiple alert logs, and then it is checked whether there is an alert log in other alert logs that uses the process identifier in the first alert log as the parent process identifier or the process identifier, and so on. Finally, all target alert logs related to the target alert are obtained, thereby realizing the correlation analysis of all logs related to the target alert.
[0075] In one embodiment, Figure 5 is the fourth flowchart of the log correlation method provided by the embodiment of the present invention. As Figure 5 shown, the log correlation method further includes the following steps:
[0076] Step 501, obtain the target network log that generates the alert; the target network log is a log that matches the second preset rule, and the second preset rule is used to screen network logs with malicious behaviors.
[0077] Among them, network traffic analysis tools such as Tianyan will monitor network traffic logs in real time and match the monitored network traffic logs with multiple second preset rules. When a network traffic log matches a certain second preset rule, it means that there is a malicious behavior in the operation of this network traffic log, and then an alert corresponding to this network traffic log is generated. The present invention refers to the network traffic log that generates the alert as the target network log. For each network traffic log monitored by network traffic analysis tools such as Tianyan, it is matched with multiple second preset rules, so multiple target network logs can be obtained.
[0078] Exemplarily, the alarms corresponding to the target network logs may include fields such as alarm type, source Internet Protocol (IP), destination IP, threat name, and the generation time of malicious behavior, etc.
[0079] Step 502: Among the multiple alarm logs, determine a fourth alarm log that matches the IP address representing the host and the generation time of the malicious behavior in the target network log.
[0080] Exemplarily, since the network traffic corresponding to the network traffic logs is usually encrypted, it is not possible to see what operations are performed on the host just from the network traffic level. Therefore, it is necessary to obtain the target network logs of the alarms that the user needs to focus on the specific operations of the host, extract the IP address representing the host and the generation time of the malicious behavior in the target network logs, determine whether there are alarm logs in the multiple alarm logs that match the IP address of the host and the generation time of the malicious behavior, and when it is determined that there are alarm logs in the multiple alarm logs that match the IP address of the host and the generation time of the malicious behavior, determine the matching alarm log as the fourth alarm log.
[0081] Step 503: Associate the target network log and the fourth alarm log.
[0082] Exemplarily, when the fourth alarm log is found, determine the fourth alarm log as the host log associated with the target network log. Since the fourth alarm log represents the called process and the specific operations executed by the process, the analyst can know the specific malicious operations performed on the host by analyzing the fourth alarm log. For example, the content of the fourth alarm log determined by the association analysis engine to be associated with the target network log is as follows: First, the apache.exe process created the cmd.exe process, and then the cmd.exe process, as the main process, created the ifconfig.exe process, and finally caused the ifconfig command to be successfully executed and return the execution result. Thus, it can be known from the fourth alarm log the specific malicious operations performed on the host.
[0083] In this embodiment, it is possible to find the alarm logs corresponding to the target network logs based on the IP address representing the host and the generation time of the malicious behavior in the target network logs, which is convenient for the analyst to know the specific malicious operations performed on the host by analyzing the alarm logs corresponding to the target network logs, thereby improving the security analysis efficiency.
[0084] In one embodiment, after the above step 503, the log association method further includes the following steps:
[0085] Determine whether the fourth warning log includes operation behaviors related to malicious behaviors corresponding to the target network log; in the case where it is determined that the fourth warning log includes operation behaviors related to malicious behaviors corresponding to the target network log, determine that the warning corresponding to the target network log is a real warning; in the case where it is determined that the fourth warning log does not include operation behaviors related to malicious behaviors corresponding to the target network log, determine that the warning corresponding to the target network log is a false warning.
[0086] Exemplarily, when the fourth warning log corresponding to the target network log is found, analyze the call relationship of the processes and the specific operations of the processes in the fourth warning log to determine whether the fourth warning log includes operation behaviors related to malicious behaviors corresponding to the target network log. When it is determined that the fourth warning log includes operation behaviors related to malicious behaviors corresponding to the target network log, it indicates that there are truly malicious behaviors in the operations of the target network log. At this time, determine that the warning corresponding to the target network log is a real warning, rather than a misreported warning; when it is determined that the fourth warning log does not include operation behaviors related to malicious behaviors corresponding to the target network log, it indicates that there are no malicious behaviors in the operations of the target network log. At this time, determine that the warning corresponding to the target network log is a false warning, that is, a misreported warning, thereby realizing the filtering of warnings generated by network logs.
[0087] In this embodiment, it is possible to assist in determining whether the warning corresponding to the target network log is a real warning based on the warning log corresponding to the target network log, realizing the verification of the warning corresponding to the target network log and improving the accuracy of the warning.
[0088] The log association device provided by the present invention will be described below. The log association device described below can be correspondingly referred to the log association method described above.
[0089] Figure 6 is a schematic structural diagram of the log association device provided by an embodiment of the present invention, as Figure 6 shown, the log association device 600 includes a first acquisition unit 601, a search unit 602, and a generation unit 603; where:
[0090] The first acquisition unit 601 is configured to acquire a log association instruction triggered by a user, and the log association instruction includes target warning information selected by the user in a target warning;
[0091] The search unit 602 is configured to search for at least one target warning log related to the target warning information in a plurality of warning logs; the warning log is a host log matching a first preset rule, and the first preset rule is used to screen host logs with malicious behaviors;
[0092] A generating unit 603, configured to generate a log chain corresponding to the target alarm information based on the association relationships of the target alarm logs.
[0093] The log association device provided by the present invention obtains a log association instruction triggered by a user, which includes target alarm information selected by the user in a target alarm, searches for at least one target alarm log related to the target alarm information in a plurality of alarm logs, and forms a log chain corresponding to the target alarm based on the association relationships of the target alarm logs. It can be seen that the present invention forms a log chain based on the target alarm information, and the target alarm logs associated in the log chain are all host logs that match a first preset rule. In this way, the entire attack behavior can be analyzed based on the association relationships between the target alarm logs in the log chain.
[0094] Based on any of the above embodiments, the target alarm information includes a target process identifier; specifically, the searching unit 602 is configured to:
[0095] Determine a first alarm log including the target process identifier in a plurality of the alarm logs;
[0096] When the target process identifier is the process identifier in the first alarm log, search for a second alarm log whose process identifier is the parent process identifier in the first alarm log among the first other alarm logs except the first alarm log in the plurality of alarm logs, and when there is a second alarm log whose process identifier is the parent process identifier in the first alarm log in the first other alarm logs, search for a third alarm log whose process identifier is the parent process identifier in the second alarm log among the second other alarm logs except the second alarm log in the first other alarm logs, and repeat the above steps until there is no alarm log in the first remaining alarm logs whose process identifier is the parent process identifier in the last searched alarm log, to obtain a first alarm log set;
[0097] Search for a fourth alarm log whose parent process identifier is the target process identifier in the first other alarm logs, and when there is a fourth alarm log whose parent process identifier is the target process identifier in the first other alarm logs, search for a fifth alarm log whose process identifier is the parent process identifier in the fourth alarm log among the third other alarm logs except the fourth alarm log in the first other alarm logs, and repeat the above steps until there is no alarm log in the second remaining alarm logs whose process identifier is the parent process identifier in the last searched alarm log, to obtain a second alarm log set;
[0098] Determine the at least one target alert log based on the first alert log set, the second alert log set, and the first alert log.
[0099] Based on any of the above embodiments, the searching unit 602 is further specifically configured to:
[0100] When the target process identifier is the parent process identifier in the first alert log, search for a sixth alert log with the target process identifier as the process identifier in the first other alert logs other than the first alert log among the multiple alert logs, and when there is a sixth alert log with the target process identifier as the process identifier in the first other alert logs, search for a seventh alert log with the parent process identifier of the sixth alert log as the process identifier in the fourth other alert logs other than the sixth alert log in the first other alert logs, and repeat the above steps until there is no alert log with the parent process identifier of the last searched alert log as the process identifier in the third remaining alert logs, to obtain a third alert log set;
[0101] Search for an eighth alert log with the process identifier in the first alert log as the parent process identifier in the first other alert logs, and when there is an eighth alert log with the process identifier in the first alert log as the parent process identifier, search for a ninth alert log with the process identifier of the eighth alert log as the parent process identifier in the fifth other alert logs other than the eighth alert log in the first other alert logs, and repeat the above steps until there is no alert log with the process identifier of the last searched alert log as the parent process identifier in the fourth remaining alert logs, to obtain a fourth alert log set;
[0102] Determine the at least one target alert log based on the third alert log set, the fourth alert log set, and the first alert log.
[0103] Based on any of the above embodiments, the log correlation device 600 further includes:
[0104] A second obtaining unit, configured to obtain a target network log that generates an alert; the target network log is a log that matches a second preset rule, and the second preset rule is used to screen network logs with malicious behaviors;
[0105] A first determining unit, configured to determine a fourth alert log that matches the IP address of the host characterized in the target network log and the generation time of the malicious behavior among the multiple alert logs;
[0106] An association unit for associating the target network log with the fourth warning log.
[0107] Based on any of the above embodiments, the log association device 600 further includes:
[0108] A second determination unit for determining whether the fourth warning log includes an operation behavior related to malicious behavior corresponding to the target network log;
[0109] A third determination unit for determining that the warning corresponding to the target network log is a true warning when it is determined that the fourth warning log includes an operation behavior related to malicious behavior corresponding to the target network log.
[0110] Based on any of the above embodiments, the log association device 600 further includes:
[0111] A fourth determination unit for determining that the warning corresponding to the target network log is a false warning when it is determined that the fourth warning log does not include an operation behavior related to malicious behavior corresponding to the target network log.
[0112] Figure 7 It is a schematic diagram of the physical structure of an electronic device provided by an embodiment of the present invention. As Figure 7 shown, the electronic device may include: a processor 710, a communication interface 720, a memory 730, and a communication bus 740. Among them, the processor 710, the communication interface 720, and the memory 730 complete mutual communication through the communication bus 740. The processor 710 can call the logical instructions in the memory 730 to execute a log association method, which includes: obtaining a log association instruction triggered by a user, where the log association instruction includes target warning information selected by the user in a target warning;
[0113] Searching for at least one target warning log related to the target warning information in multiple warning logs; the warning log is a host log matching a first preset rule, and the first preset rule is used to screen host logs with malicious behavior;
[0114] Generating a log chain corresponding to the target warning based on the association relationship of each target warning log.
[0115] In addition, when the logical instructions in the above-mentioned memory 730 are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs that can store program codes.
[0116] On the other hand, the present invention also provides a computer program product. The computer program product includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the log association method provided by the above-mentioned various methods. The method includes: obtaining a log association instruction triggered by a user, where the log association instruction includes target alarm information selected by the user in a target alarm;
[0117] finding at least one target alarm log related to the target alarm information in a plurality of alarm logs; the alarm logs are host logs that match a first preset rule, and the first preset rule is used to screen host logs with malicious behaviors;
[0118] generating a log chain corresponding to the target alarm based on the association relationships of the target alarm logs.
[0119] In yet another aspect, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it is configured to execute the log association method provided by the above-mentioned various methods. The method includes: obtaining a log association instruction triggered by a user, where the log association instruction includes target alarm information selected by the user in a target alarm;
[0120] finding at least one target alarm log related to the target alarm information in a plurality of alarm logs; the alarm logs are host logs that match a first preset rule, and the first preset rule is used to screen host logs with malicious behaviors;
[0121] generating a log chain corresponding to the target alarm based on the association relationships of the target alarm logs.
[0122] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative work.
[0123] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on this understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0124] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A log correlation method, characterized in that, Including: Obtain a log association instruction triggered by a user, where the log association instruction includes target alarm information selected by the user in a target alarm; Search for at least one target alarm log related to the target alarm information in multiple alarm logs; the alarm logs are host logs that match a first preset rule, and the first preset rule is used to filter host logs with malicious behaviors; Generate a log chain corresponding to the target alarm based on the association relationships of the target alarm logs.
2. The log association method according to claim 1, wherein The target alarm information includes a target process identifier; The searching for at least one target alarm log related to the target alarm information in multiple alarm logs includes: Search for a first alarm log including the target process identifier in multiple alarm logs; When the target process identifier is the process identifier in the first alarm log, search for whether there is a second alarm log with the parent process identifier in the first alarm log as the process identifier in a first other alarm log other than the first alarm log among the multiple alarm logs, and when there is a second alarm log with the parent process identifier in the first alarm log as the process identifier in the first other alarm log, search for whether there is a third alarm log with the parent process identifier in the second alarm log as the process identifier in a second other alarm log other than the second alarm log in the first other alarm log, and repeat the above steps until there is no alarm log with the parent process identifier in the last searched alarm log as the process identifier in the first remaining alarm log, to obtain a first alarm log set; Search for whether there is a fourth alarm log with the target process identifier as the parent process identifier in the first other alarm log, and when there is a fourth alarm log with the target process identifier as the parent process identifier in the first other alarm log, search for whether there is a fifth alarm log with the process identifier in the fourth alarm log as the parent process identifier in a third other alarm log other than the fourth alarm log in the first other alarm log, and repeat the above steps until there is no alarm log with the process identifier in the last searched alarm log as the parent process identifier in the second remaining alarm log, to obtain a second alarm log set; Determine the at least one target alarm log based on the first alarm log set, the second alarm log set, and the first alarm log.
3. The log association method according to claim 2, wherein The method further includes: When the target process identifier is the parent process identifier in the first warning log, check whether there is a sixth warning log with the target process identifier as the process identifier in the first other warning logs among the multiple warning logs. When there is a sixth warning log with the target process identifier as the process identifier in the first other warning logs, check whether there is a seventh warning log with the parent process identifier in the sixth warning log as the process identifier in the fourth other warning logs except the sixth warning log in the first other warning logs. Repeat the above steps until there is no warning log with the parent process identifier in the last searched warning log as the process identifier in the third remaining warning logs, to obtain a third set of warning logs; Check whether there is an eighth warning log with the process identifier in the first warning log as the parent process identifier in the first other warning logs. When there is an eighth warning log with the process identifier in the first warning log as the parent process identifier, check whether there is a ninth warning log with the process identifier in the eighth warning log as the parent process identifier in the fifth other warning logs except the eighth warning log in the first other warning logs. Repeat the above steps until there is no warning log with the process identifier in the last searched warning log as the parent process identifier in the fourth remaining warning logs, to obtain a fourth set of warning logs; Based on the third set of warning logs, the fourth set of warning logs, and the first warning log, determine the at least one target warning log.
4. The log association method according to claim 1, wherein The method further includes: Obtain a target network log that generates a warning; the target network log is a log that matches a second preset rule, and the second preset rule is used to screen network logs with malicious behaviors; Among the multiple warning logs, determine a fourth warning log that matches the IP address of the host represented in the target network log and the generation time of the malicious behavior; Associate the target network log with the fourth warning log.
5. The log association method according to claim 4, wherein The method further includes: Determine whether the fourth warning log includes an operation behavior related to the malicious behavior corresponding to the target network log; When it is determined that the fourth warning log includes an operation behavior related to the malicious behavior corresponding to the target network log, determine that the warning corresponding to the target network log is a real warning.
6. The log association method according to claim 5, wherein The method further includes: When it is determined that the fourth warning log does not include an operation behavior related to the malicious behavior corresponding to the target network log, determine that the warning corresponding to the target network log is a false warning.
7. A log correlation device, characterized in that It includes: A first acquisition unit, configured to acquire a log association instruction triggered by a user, where the log association instruction includes target warning information selected by the user in a target warning; A search unit, configured to search for at least one target alarm log related to the target alarm information from multiple alarm logs; the alarm logs are host logs matching a first preset rule, and the first preset rule is used to screen host logs with malicious behaviors. A generation unit, configured to generate a log chain corresponding to the target alarm information based on the association relationships of the target alarm logs.
8. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein When the processor executes the program, it implements the log association method according to any one of claims 1 to 6.
9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the log association method according to any one of claims 1 to 6.
10. A computer program product comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the log association method according to any one of claims 1 to 6.