Network security detection method and device and electronic equipment
By replacing dependent attributes with placeholders in the detection rules and matching them after obtaining the attribute values, the problems of low detection efficiency and high resource utilization in the prior art are solved, and more efficient and accurate security detection is achieved.
Patent Information
- Application Number
- CN202510385127.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-28
- Publication Date
- 2025-07-11
AI Technical Summary
In the prior art, when performing secure detection of data in a business system based on detection rules, it is necessary to load each rule and obtain all relevant rule attributes to match, resulting in low detection efficiency and high resource utilization.
Placeholder replacement is used to detect dependent attributes in the copy of the rule, and match only after the dependency attribute obtains the specific attribute value. The actual attribute value is obtained through placeholder replacement and data listening functions to ensure that the rule takes effect and is detected when the conditions are met.
It improves detection efficiency, reduces memory usage and computing resource consumption, enhances the accuracy and system performance of security detection, and reduces false alarms and missed alarms.
Smart Images

Figure CN120301629A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security detection. Specifically, it relates to a method, device, and electronic device for network security detection. Background Art
[0002] In network security detection, it is usually necessary to use multiple event-related detection rules for security detection. The process of conventional multi-event correlation detection can include the following steps: loading datasets that match multiple rules into memory; determining whether the correlation attributes for different rules are the same; if they are the same, then determining other logical relationships.
[0003] Exemplarily, Rule A is used to detect the start of a certain process; Rule B is used to detect that a certain process has created a file in a temporary path; Rule C is used to detect that the file created in the temporary path has been started and has performed network outreach. In the above scenario, since the process name and file name are random, Rules A and B cannot be determined before correlation detection. Therefore, this correlation detection rule will load all temporary file creation events into memory. Therefore, the prior art will cause a large amount of detection data to be loaded into memory, occupying the service space and reducing the service response speed. At the same time, since the detection resources are used for the detection of irrelevant data, a large amount of computing resources are wasted, resulting in a low security detection efficiency.
[0004] In view of the problem that when performing security detection on data in a service system based on detection rules in the related art, it is necessary to load each rule and obtain all relevant rule attributes for matching, resulting in low detection efficiency and high resource occupancy, no effective solution has been proposed yet. Summary of the Invention
[0005] The main purpose of the present application is to provide a method, device, and electronic device for network security detection, so as to solve the problem that when performing security detection on data in a service system based on detection rules in the related art, it is necessary to load each rule and obtain all relevant rule attributes for matching, resulting in low detection efficiency and high resource occupancy.
[0006] To achieve the above object, according to one aspect of the present application, a method for detecting network security is provided. The method includes: replacing the dependent attributes in the rule copy with placeholders, and determining that the rule status of the rule copy is the first status, where the rule copy is a copy of the original detection rule in memory; the first status is the to-be-effective status; when the rule status of the rule copy is the first status and the attribute values of the dependent attributes corresponding to the placeholders in the rule copy are obtained, replacing the placeholders in the rule copy in memory with the attribute values, and determining that the rule status of the rule copy is the second status; where the second status is the effective status; matching the business system data with the attribute values of the dependent attributes of the rule copy in memory, and when the matching is successful, performing a security detection on the matching result according to the rule copy in the second status to obtain a security detection result.
[0007] Further, the dependent attributes include at least one of the following: environment-dependent attribute, pre-event attribute. The original detection rules include at least one of the following: first-type rules, second-type rules. The first-type rules are the rules that perform detection depending on the environment-dependent attribute. The second-type rules are the rules that perform detection depending on the target event attribute. The value of the target event attribute depends on the value of the pre-event attribute. The placeholders include at least one of the following: the first placeholder corresponding to the environment-dependent attribute, the second placeholder corresponding to the pre-event attribute.
[0008] Further, performing a security detection on the matching result according to the rule copy in the second status to obtain a security detection result includes: determining a first moment, and determining a target time period according to the first moment and a preset duration, where the first moment is the moment when the pre-event attribute is obtained; within the target time period, obtaining the attribute value of the target event attribute from the business system data, and matching the attribute value of the target event attribute with the attribute values of the dependent attributes; when the matching is successful, writing the attribute value of the target event attribute into memory, and determining the detection result according to the attribute value of the target event attribute and the rule copy in the second status.
[0009] Further, replacing the dependent attributes in the rule copy with placeholders includes: determining the association relationship between the dependent attributes; replacing the environment-dependent attribute in the rule copy with the first placeholder, and modifying the replaced rule copy according to the association relationship; or replacing the pre-event attribute in the rule copy with the second placeholder, and modifying the replaced rule copy according to the association relationship.
[0010] Further, replacing the placeholder in the rule copy in the memory with the attribute value includes: when the rule copy belongs to the first type of rules and the rule copy is in the first state, constructing a data monitoring function corresponding to the first placeholder in the rule copy; obtaining the attribute value of the environment-dependent attribute through the monitoring function corresponding to the first placeholder; and replacing the first placeholder in the rule copy in the memory with the attribute value of the environment-dependent attribute.
[0011] Further, replacing the placeholder in the rule copy in the memory with the attribute value includes: when the rule copy belongs to the second type of rules and the rule copy is in the first state, constructing a data monitoring function corresponding to the second placeholder in the rule copy; obtaining the attribute value of the pre-event attribute through the monitoring function corresponding to the second placeholder; and replacing the second placeholder in the rule copy in the memory with the attribute value of the pre-event attribute.
[0012] Further, after replacing the placeholder in the rule copy in the memory with the attribute value, the method further includes: determining each placeholder in the rule copy; when the attribute value of the dependent attribute corresponding to each placeholder in the rule copy cannot be obtained, setting the rule state of the rule copy to the invalid state or deleting the rule copy in the memory.
[0013] To achieve the above object, according to another aspect of the present application, a network security detection device is provided. The device includes: a first replacement unit, configured to replace the dependent attribute in the rule copy with a placeholder and determine that the rule state of the rule copy is the first state, where the rule copy is a copy of the original detection rule in the memory; the first state is the to-be-effective state; a second replacement unit, configured to, when the rule state of the rule copy is the first state and the attribute value of the dependent attribute corresponding to the placeholder in the rule copy is obtained, replace the placeholder in the rule copy in the memory with the attribute value and determine that the rule state of the rule copy is the second state; where the second state is the effective state; a detection unit, configured to match the service system data with the attribute value of the dependent attribute of the rule copy in the memory, and when the match is successful, perform a security detection on the match result according to the rule copy in the second state to obtain a security detection result.
[0014] Further, the dependent attribute includes at least one of the following: environment-dependent attribute, pre-event attribute. The original detection rule includes at least one of the following: first-class rule, second-class rule. The first-class rule is a rule for detection depending on the environment-dependent attribute, and the second-class rule is a rule for detection depending on the target event attribute. The value of the target event attribute depends on the value of the pre-event attribute. The placeholder includes at least one of the following: the first placeholder corresponding to the environment-dependent attribute, the second placeholder corresponding to the pre-event attribute.
[0015] Further, the detection unit includes: a first determination subunit, configured to determine a first moment, and determine a target time period according to the first moment and a preset duration, where the first moment is the moment when the pre-event attribute is obtained; a first acquisition subunit, configured to acquire the attribute value of the target event attribute in the business system data, and match the attribute value of the target event attribute with the attribute value of the dependent attribute; a second determination subunit, configured to, in the case of successful matching, write the attribute value of the target event attribute into the memory, and determine the detection result according to the attribute value of the target event attribute and the rule copy in the second state.
[0016] Further, the first replacement unit includes: a third determination subunit, configured to determine the association relationship between the dependent attributes; a first replacement subunit, configured to replace the environment-dependent attribute in the rule copy with the first placeholder, and modify the replaced rule copy according to the association relationship; or a second replacement subunit, configured to replace the pre-event attribute in the rule copy with the second placeholder, and modify the replaced rule copy according to the association relationship.
[0017] Further, the second replacement unit includes: a first construction subunit, configured to construct a data listening function corresponding to the first placeholder in the rule copy when the rule copy belongs to the first-class rule and the rule copy is in the first state; a second acquisition subunit, configured to acquire the attribute value of the environment-dependent attribute through the listening function corresponding to the first placeholder; a third replacement subunit, configured to replace the first placeholder in the rule copy in the memory with the attribute value of the environment-dependent attribute.
[0018] Further, the second replacement unit includes: a second construction subunit, configured to construct a data monitoring function corresponding to the second placeholder in the rule copy when the rule copy belongs to the second type of rule and the rule copy is in the first state; a third acquisition subunit, configured to obtain the attribute value of the pre-event attribute through the monitoring function corresponding to the second placeholder; and a fourth replacement subunit, configured to replace the second placeholder of the rule copy in the memory with the attribute value of the pre-event attribute.
[0019] Further, the apparatus further includes: a determination unit, configured to determine each placeholder in the rule copy after replacing the placeholder in the rule copy in the memory with the attribute value; and a processing unit, configured to set the rule state of the rule copy to an invalid state or delete the rule copy in the memory when the attribute values of the dependent attributes corresponding to each placeholder in the rule copy cannot be obtained.
[0020] To achieve the above object, according to one aspect of the present application, there is provided a computer program product, including a computer program, where when the computer program is executed by a processor, it implements the network security detection method described in any one of the above, and when the computer program is executed by a processor, it implements the steps of the network security detection method in each embodiment of the present application.
[0021] To achieve the above object, according to one aspect of the present application, there is provided a computer-readable storage medium, where the computer-readable storage medium includes stored computer instructions, and when the computer instructions are executed by a processor, the network security detection method described in any one of the above is implemented.
[0022] To achieve the above object, according to one aspect of the present application, there is provided an electronic device, including one or more processors and a memory, where the memory is used to store one or more programs, and when the one or more programs are executed by the one or more processors, the one or more processors implement the network security detection method described in any one of the above.
[0023] By analyzing the dependent attributes in the original detection rules and using placeholder replacement, this application can perform detections using the rules while satisfying the dependencies, avoiding invalid detections when specific conditions are not met, thereby achieving the effect of improving the detection efficiency. At the same time, by obtaining the attribute values of the dependent attributes after placeholder replacement and replacing the placeholders in the rule copy with specific attribute values, the system resources are only used for data collection and security detection when the business system data matches the specific attribute values, significantly reducing the memory occupancy and consumption of computing resources. It can also perform more accurate security detections, reducing false positives and false negatives, achieving the effect of improving the accuracy of security detections, and further achieving the effect of significantly enhancing the security of the business system. This solves the problem in related technologies that when performing security detections on data in a business system based on detection rules, each rule needs to be loaded and all relevant rule attributes need to be obtained for matching, resulting in low detection efficiency and high resource occupancy. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] The drawings forming a part of this application are used to provide a further understanding of this application. The schematic embodiments of this application and their descriptions are used to explain this application and do not constitute an improper limitation of this application. In the drawings:
[0025] Figure 1 is a flowchart of a method for detecting network security provided in Embodiment 1 of this application;
[0026] Figure 2 is a schematic diagram of the system structure of an optional pre-placeholder association analysis system provided in Embodiment 1 of this application;
[0027] Figure 3 is a schematic diagram of the usage of memory space during association detection in the prior art provided in Embodiment 1 of this application;
[0028] Figure 4 is a schematic diagram of performing association event detection based on placeholders provided in Embodiment 1 of this application;
[0029] Figure 5 is a schematic diagram of a device for detecting network security provided in Embodiment 2 of this application;
[0030] Figure 6 is a schematic diagram of an electronic device for detecting network security provided in Embodiment 5 of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0031] It should be noted that, without conflict, the embodiments in this application and the features in the embodiments can be combined with each other. The following will refer to the drawings and combine the embodiments to detail this application.
[0032] It should be noted that the user information involved in this application (including but not limited to user device information, user personal information, collected data, used data, generated data, processed data, etc.) and data (including but not limited to data for analysis, stored data, displayed data, collected information, used information, generated information, processed information, etc.) are all information and data authorized by the user or fully authorized by all parties. Moreover, the processing of relevant data, such as collection, storage, use, processing, transmission, provision, disclosure, and application, complies with the relevant laws, regulations, and standards of relevant countries and regions, takes necessary confidentiality measures, does not violate public order and good customs, and provides corresponding operation entrances for users to choose to authorize or refuse. For example, there is an interface between this system and relevant users or institutions. Before obtaining relevant information, a request for acquisition needs to be sent to the aforementioned users or institutions through the interface, and relevant information can be obtained after receiving the consent information feedback from the aforementioned users or institutions.
[0033] It should be noted that this application provides corresponding operation entrances for users to choose to agree or refuse the automated decision-making results; if the user chooses to refuse, the expert decision-making process will be entered.
[0034] In order to enable those skilled in the art to better understand the solution of this application, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of this application.
[0035] It should be noted that the terms "first", "second", etc. in the specification, claims, and above-mentioned drawings of this application are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances for the embodiments of this application described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.
[0036] Embodiment 1
[0037] The present invention will be described below in conjunction with the preferred implementation steps. Figure 1 is a flowchart of a network security detection method provided according to Embodiment 1 of this application, as Figure 1 shown. The method includes the following steps:
[0038] Step S101, replace the dependent attributes in the rule copy using placeholder replacement rules, and determine that the rule status of the rule copy is the first status, where the rule copy is a copy of the original detection rule in memory; the first status is the to-be-effective status.
[0039] Before replacing the dependent attributes in the rule copy using placeholder replacement rules, the above method may further include: determining the original detection rule and analyzing the dependent attributes in the original detection rule.
[0040] In the first embodiment, the original detection rule refers to the preset standard detection rules in an enterprise, security system or software for monitoring and detecting events or behaviors. These rules can be defined by security experts or system administrators and contain a series of conditions and parameters for identifying potential threats. For example, specific network traffic patterns, system operation behaviors, file access patterns, etc. The original detection rule directly reflects the intention and requirements of the security policy and is the basis for the security system to perform real-time monitoring and alarm. In this application, the original detection rule is a set of initial detection rules that are analyzed and transformed to introduce placeholders, so as to optimize the detection performance and detection efficiency.
[0041] After determining the original detection rule, analyze its dependent attributes, where the dependent attributes include at least one of the following: environmental dependent attributes (such as system status, software path), pre-event attributes (such as specific process startup). By identifying these dependent attributes, unnecessary detection rules can be filtered out by placeholders before the detection rule is matched with network traffic data, so as to optimize the rule matching process, avoid invalid detection, and save computing resources.
[0042] In the first embodiment, by copying the original rule to memory, the above-mentioned rule copy is obtained, and placeholders (such as %AdminUserNames%, %eventA.Image%, etc.) are used in the rule copy to replace the dependent attributes in the rule copy, and the rule can be temporarily placed in the to-be-effective status, that is, the above-mentioned first status, until the placeholder is replaced by the actual attribute value, thus avoiding rule matching under unknown or irrelevant conditions, achieving the effects of reducing invalid detection, reducing resource consumption, and improving detection efficiency and accuracy. For example, if the rule depends on the administrator username, the rule will not be applied to security detection before the actual administrator username is captured, thus avoiding unnecessary detection using system resources in the absence of administrator activities.
[0043] The dependent attribute here refers to the conditional attribute that the rule execution needs to depend on, including environmental dependent attributes (such as system status or configuration information), pre-event attributes (specific attributes of the previous event, used to associate the detection of the subsequent event).
[0044] Step S102, when the rule status of the rule copy is the first status and the attribute value of the dependent attribute corresponding to the placeholder in the rule copy is obtained, replace the placeholder in the rule copy in the memory with the attribute value, and determine that the rule status of the rule copy is the second status; where the second status is the effective status.
[0045] In the first embodiment, for each placeholder in the rule copy in the first status in the memory, such as %AdminUserNames% or %eventA.Image%, it is necessary to collect the actual values of the dependent attributes from the business system (or other production environments) in real time or regularly. For example, the user names of all administrators, or the paths of processes in a specific event. When the attribute value of the dependent attribute corresponding to the placeholder is successfully captured, it will replace the placeholder in the rule copy in the memory with the captured attribute value, and at the same time, it is necessary to set the rule status of the rule copy to the effective status, that is, the above-mentioned second status. For example, the placeholder %AdminUserNames% can be replaced with the real administrator user names, and %eventA.Image% can be replaced with "C:\Windows\system32\svchost.exe". The above replacement process ensures that the rule is specific and effective when participating in security detection, improves the accuracy and efficiency of detection, and at the same time reduces resource consumption.
[0046] Step S103, match the business system data with the attribute values of the dependent attributes of the rule copy in the memory, and when the match is successful, perform a security detection on the match result according to the rule copy in the second status to obtain a security detection result.
[0047] In the first embodiment, the business system data will be monitored in real time, and these data will be compared with the dependent attribute values stored in the memory. When the attribute value in the business system data matches the dependent attribute value stored in the memory, the attribute value in the business system data will be written into the memory, and the attribute value in the business system data will be matched with the currently effective rule copy, and the security detection logic will be used to obtain a security detection result.
[0048] Through the above process, it is ensured that only the business systems that match the dependent attribute values can be written into the memory, reducing the occupied space of the memory, saving system resources, improving system performance, and at the same time ensuring that only the business systems that match the dependent attribute values will be detected, improving the detection efficiency, and finally generating a security detection result for threat identification or abnormal behavior analysis.
[0049] Business system data includes, but is not limited to, network traffic data, log data, user operation records, file system activities, process behaviors, and other data. For example, detection rules can be used to detect file creation behaviors, user login behaviors, process startup behaviors, etc. in a certain business system. When the rules involve detecting user behaviors or system states, their dependent attributes (such as environment-dependent attributes or pre-event attributes) may be sourced from system logs or the current running environment; when the rules involve performing security detections on received user requests, their dependent attributes (such as environment-dependent attributes or pre-event attributes) may be sourced from network traffic data. Therefore, the application scope of the detection rules covers various types of data sources, aiming to perform effective and accurate correlation analysis on various security-related events to improve the overall performance of security detection.
[0050] It should be noted that the placeholders corresponding to the above-mentioned dependent attributes can apply the rules to different business systems according to the same rule standard, improving the applicable scope of security detection, thus achieving the effect of improving security monitoring.
[0051] In summary, the network security detection method provided in Embodiment 1 of the present application can use the rules for detection under the condition of meeting the dependencies by analyzing the dependent attributes in the original detection rules and using placeholder replacement, avoiding ineffective detections when specific conditions are not met, thus achieving the effect of improving detection efficiency. At the same time, by obtaining the attribute values of the dependent attributes after placeholder replacement and replacing the placeholders in the rule copy with specific attribute values, system resources are only used for data collection and security detection when the business system data matches the specific attribute values, significantly reducing memory occupancy and consumption of computing resources, and also enabling more accurate security detections, reducing false positives and false negatives, achieving the effect of improving the accuracy of security detection, and further achieving the effect of significantly enhancing the security of the business system, solving the problem in related technologies that when performing security detection on data in a business system based on detection rules, each rule needs to be loaded and all relevant rule attributes need to be obtained for matching, resulting in low detection efficiency and high resource occupancy.
[0052] Optionally, in the network security detection method provided in Embodiment 1 of the present application, the dependent attributes include at least one of the following: environment-dependent attributes, pre-event attributes, the original detection rules include at least one of the following: the first type of rules, the second type of rules, the first type of rules are rules that depend on environment-dependent attributes for detection, the second type of rules are rules that depend on target event attributes for detection, the value of the target event attribute depends on the value of the pre-event attribute, and the placeholders include at least one of the following: the first placeholder corresponding to the environment-dependent attribute, the second placeholder corresponding to the pre-event attribute.
[0053] In the first embodiment, the original detection rules can be divided into two main categories based on the types of attributes they depend on: the first type of rules and the second type of rules.
[0054] The first type of rules depends on environment-dependent attributes for detection, that is, the execution of the rules requires a specific state of the current system environment as a trigger condition or parameter. For example, detecting suspicious operations under a specific application path, where the application path is an environment-dependent attribute that changes with the system configuration. In the rule copy, this environment-dependent attribute will be replaced by the first placeholder (e.g., %TomcatInstallPath%), and it is not until the data monitoring function in the system captures the actual value of the environment-dependent attribute, such as the installation path of a certain application, that the first placeholder will be replaced by the specific path value, and the rule copy will thus change from the ineffective first state to the second state of participating in security detection.
[0055] The second type of rules can be further divided into the first sub-rule and the second sub-rule. The first sub-rule depends on the pre-event attributes of the pre-event (i.e., the occurrence state or its event attribute value of a certain event) for security detection to determine the execution of subsequent rules. The second sub-rule depends on the target-event attributes of the target event for security detection. There is a dependency relationship between the target event and the pre-event, that is, the occurrence of the target event depends on the pre-event. Therefore, the second sub-rule has an associated relationship with the first sub-rule.
[0056] Exemplarily, a certain detection rule is to detect abnormal operations after an abnormal login. Among them, the attributes of the abnormal login event (e.g., the user ID or login IP of the abnormal login) can be the above-mentioned pre-event attributes, and these pre-event attributes are represented by the second placeholder in the rule, such as %eventA.User%. When the pre-event occurs, the actual user ID captured in the business system is used to replace the second placeholder in the rule copy, thereby triggering the rule matching operation of the rule copy, so as to accurately match the target event and perform effective detection.
[0057] By using the first placeholder and the second placeholder, the detection rules can be dynamically adjusted according to the obtained actual attribute values, reducing the processing of irrelevant data, thereby optimizing the detection performance and resource utilization, and improving the efficiency and accuracy of security detection. This mechanism ensures that the rules will only be activated for effective detection when specific dependency conditions are met, which helps to improve the performance of correlation analysis and real-time security detection.
[0058] Optionally, in the network security detection method provided in the first embodiment of the present application, security detection is performed on the matching result according to the rule copy in the second state to obtain a security detection result, including: determining a first moment, and determining a target time period according to the first moment and a preset duration, where the first moment is the moment when the pre-event attribute is obtained; within the target time period, obtaining the attribute value of the target event attribute in the business system data, and matching the attribute value of the target event attribute with the attribute value of the dependent attribute; in the case of successful matching, writing the attribute value of the target event attribute into the memory, and determining the detection result according to the attribute value of the target event attribute and the rule copy in the second state.
[0059] In the first embodiment, it is necessary to determine the "first moment", that is, the exact time point when the pre-event attribute value (such as the start time of a certain process) is captured. Subsequently, according to the first moment and a preset duration (that is, the effective detection period for the association between the pre-event and the target event, for example, 5 minutes, 1 hour, 24 hours, etc., which is not specifically limited in the first embodiment), a target time period is calculated.
[0060] Within the target time period, the business system data will be monitored to find the data containing the target event attribute. These target event attributes may include subsequent operations related to the pre-event, such as file creation, network connection, etc. The system will match the attribute value of these target event attributes with the dependent attribute value stored in the memory, that is, check whether the target event matches the pre-event. If the matching is successful, it means that a valid associated event is found. At this time, the system writes the attribute value of the target event into the memory, and then performs security detection based on this attribute value and the second state (i.e., the "effective" state) of the rule copy to determine potential security risks or abnormal behaviors.
[0061] However, in the case where the attribute value of the target event attribute is not obtained within the target time period, the rule state of the rule copy is modified to the first state. Specifically, if no target event attribute value matching the pre-event attribute value is detected within the target time period, the rule state of the rule copy will be restored to the first state (i.e., the "not effective" state). This process effectively avoids the ineffective detection and resource waste of irrelevant events for a long time, ensures that the system resources focus on the current moment and the detection of possible security events in the future, thereby optimizing the association detection performance and enhancing the system's response speed and resource utilization rate.
[0062] Exemplarily, if a certain rule is to identify whether an operating system administrator account performs a specific operation, a rule copy of this rule is replicated in memory, and the administrator account in the rule copy in memory is replaced with a placeholder to obtain a rule copy in the first state. When it is captured that there is an operation of the administrator account in the business system, the user name of the administrator account is obtained, and the placeholder in the rule copy in the first state is replaced with the user name to obtain a rule copy in the second state. After the rule copy is in the second state, the operations of the administrator account are collected according to the rule copy. When it is collected that there is an operation of the administrator account in the business system, the administrator account performing the operation is compared with the user name of the administrator account stored in memory. If the comparison result is consistent, it is determined whether the operation of the administrator account matches the specific operation in the rule copy. If it matches, it is determined that there is a security threat (or abnormal behavior) in the business system, and an alarm message is generated; if it does not match, security detection continues.
[0063] Through the above process, only when an event (i.e., the target event) in the data stream of the business system matches the dependency attribute values stored in memory, and only on the premise of successful matching, will the key attribute values of the target event be written into memory. This mechanism means that the system does not load all received data into memory indiscriminately, but only stores those potentially meaningful data points associated with known security rules, achieving effective management of the system's memory resources, avoiding memory occupation by invalid data, and ensuring that the memory space is efficiently and reasonably used for storing and processing data truly related to security detection, thereby significantly improving the system's operation efficiency and resource utilization rate without affecting the detection quality.
[0064] At the same time, before all necessary attribute values are obtained, the rule copy remains in the "not in effect" state and does not consume detection resources. Once all attribute values are successfully matched and written into memory, the rule copy enters the "in effect" state for precise security detection. This mechanism avoids unnecessary traversal and comparison of massive data sets, greatly reduces the amount of data stored in memory, thereby saving the system's memory space and improving the detection efficiency and performance.
[0065] Optionally, in the network security detection method provided in the first embodiment of this application, replacing the dependency attributes in the rule copy with placeholders includes: determining the association relationship between the dependency attributes; replacing the environment dependency attributes in the rule copy with the first placeholder and modifying the replaced rule copy according to the association relationship; or, replacing the pre-event attributes in the rule copy with the second placeholder and modifying the replaced rule copy according to the association relationship.
[0066] In the first embodiment, it is necessary to analyze the original detection rules and determine the dependent attributes therein, which can be static environment-dependent attributes (such as the installation path of Tomcat) or dynamic pre-event attributes (such as the process path of a certain event).
[0067] Then, perform placeholder replacement on the rule copy in memory of the original detection rules. For the first type of rules, that is, single rules that depend on environment attributes, use the first placeholder (such as %TomcatInstallPath%) to replace the environment-dependent attributes. This step ensures that the rules remain flexible before obtaining the specific values of the environment attributes and will not fail due to environmental differences. For the second type of rules, that is, scenarios involving multi-rule associations, use the second placeholder to replace the pre-event attributes of the pre-event (such as %eventA.Image%).
[0068] Finally, after placeholder replacement, the association relationships between the replaced placeholders in the rule copy can be further modified and adjusted according to the association relationships between the dependent attributes in the same detection rule, where the association relationships include at least logical relationships, and the logical relationships include but are not limited to: and, or, and-or, etc.
[0069] Through this series of operations, it is ensured that the placeholders are replaced with specific attribute values, completing the orientation and concretization of the rules, so that the detection rules have the ability to dynamically adjust and optimize the detection logic according to the actual environment and events, improving the detection efficiency. At the same time, the original detection rules are transformed into a more flexible and adaptable rule copy in memory, which not only reduces ineffective detections but also improves the utilization efficiency of memory resources, thus overall enhancing the efficiency and performance of the security detection of the business system.
[0070] Optionally, in the network security detection method provided in the first embodiment of this application, using the attribute value to replace the placeholder in the rule copy in memory includes: when the rule copy belongs to the first type of rules and the rule copy is in the first state, constructing a data monitoring function corresponding to the first placeholder in the rule copy; obtaining the attribute value of the environment-dependent attribute through the monitoring function corresponding to the first placeholder; using the attribute value of the environment-dependent attribute to replace the first placeholder in the rule copy in memory.
[0071] In the first embodiment, after using the first placeholder to replace the environment-dependent attribute in the rule copy, that is, when the rule copy is in the first state, it is necessary to construct a data monitoring function corresponding to the first placeholder in the rule copy, aiming to capture the environment-dependent attributes on which the rule depends in real time or at regular intervals. For example, construct a data monitoring function for the placeholder "%AdminUserNames%" corresponding to the environment-dependent attribute to capture all administrator user names in the system.
[0072] The function of the data monitoring function is to capture the environment-dependent attributes related to the first placeholder in real time or at regular intervals. For example, the set of administrator account names in the system. Only when the data monitoring function successfully obtains these attribute values and fills them in the position of the first placeholder, will the rule status of the rule copy change from the first state (inactive state) to the second state (executable state), and the rule copy can be formally put into security detection. After the data monitoring function ensures that the placeholder captures the actual value, it triggers the rule for rule matching, that is, the above-mentioned security detection operation, thereby improving the pertinence and efficiency of security detection.
[0073] By controlling the activation conditions of the rules, it is ensured that only after the placeholder is replaced by the specific attribute value and the rule status changes from "not in effect" to "participate in rule matching", will the targeted security detection of the business system data start, reducing the ineffective detection caused by environmental mismatch, thereby improving the detection efficiency, reducing resource waste, and enhancing the overall performance of the security detection system.
[0074] Optionally, in the network security detection method provided in the first embodiment of the present application, replacing the placeholder in the rule copy in the memory with the attribute value includes: when the rule copy belongs to the second type of rule and the rule copy is in the first state, constructing a data monitoring function corresponding to the second placeholder in the rule copy; obtaining the attribute value of the pre-event attribute through the monitoring function corresponding to the second placeholder; replacing the second placeholder in the rule copy in the memory with the attribute value of the pre-event attribute.
[0075] In the first embodiment, after using the second placeholder to replace the pre-event attribute in the rule copy, that is, when the rule copy is in the first state, it is necessary to construct a data monitoring function corresponding to the second placeholder in the rule copy, the purpose of which is to capture the pre-event attributes on which the rule depends in real time or at regular intervals. For example, construct a data monitoring function for the placeholder "%eventA.Image%" corresponding to the pre-event attribute to monitor the specific process startup event.
[0076] The function of the data monitoring function is to capture the environmental status related to the second placeholder in real time or at regular intervals. For example, the attribute value of a certain event. Only when the data monitoring function successfully obtains these attribute values and fills them in the position of the second placeholder, will the rule status of the rule copy change from the first state (inactive state) to the second state (executable state), and the rule copy can be formally put into security detection.
[0077] By controlling the activation conditions of the rules, it is ensured that targeted security detection of the business system data only starts after the placeholder is replaced by specific attribute values and the rule status changes from "not in effect" to "participating in rule matching", reducing ineffective detections caused by untriggered preconditions, thereby improving the detection efficiency, reducing resource waste, and enhancing the overall performance of the security detection system.
[0078] Optionally, in the network security detection method provided in the first embodiment of this application, after replacing the placeholder in the rule copy in memory with an attribute value, the above method further includes: determining each placeholder in the rule copy; in the case where the attribute values of the dependent attributes corresponding to each placeholder in the rule copy cannot be obtained, setting the rule status of the rule copy to the invalid status, or deleting the rule copy from memory.
[0079] In the first embodiment, when obtaining the attribute values of the dependent attributes corresponding to the placeholders in the rule copy through the data listening function, it is necessary to identify all the placeholders included in the rule copy, and these placeholders represent the dependent attributes that need to be determined before rule matching. If it is found that any placeholder in the rule copy cannot successfully obtain its corresponding attribute value when attempting to obtain the attribute values of the dependent attributes corresponding to all placeholders (for example, the Tomcat installation path or the administrator account name does not exist in the current system), it is determined that the rule copy cannot be effectively executed in the current environment.
[0080] In this case, to avoid invalid rules occupying system resources, the rule copy can be deleted from memory, and the rule status of the rule copy can also be set to the invalid status. Through the above steps, not only the detection accuracy is improved, but also resource waste caused by environmental mismatch is avoided, enhancing the overall efficiency and performance of the system.
[0081] Optionally, in the first embodiment of this application, the schematic diagram of the system structure of the pre-placeholder association analysis system of this application can be as Figure 2 shown, and the pre-placeholder association analysis system includes a placeholder construction module and a pre-placeholder detection module.
[0082] The placeholder construction module is responsible for analyzing and identifying the dependent attributes in the detection rules, whether it is the dependence on the environment (such as system configuration, software installation path, etc.) or the dependence on other event attributes (such as pre-event attributes). Once the dependent attributes are identified, it abstracts these attributes into placeholders and modifies the rules to add placeholder conditions. At the same time, this module also constructs a data listening function for continuously monitoring and capturing the actual attribute values of these dependent attributes, thereby providing necessary information for the pre-placeholder detection module.
[0083] After the pre-placeholder detection module detects a detection rule containing placeholders (i.e., a rule copy in the first state), it determines whether to enable the rule by judging whether the placeholders have been filled with actual values. If the placeholder is empty, the rule remains in a pending effective state, and data collection and rule matching for this rule copy are not performed. Once the placeholder is assigned a value, the rule state of this rule copy will be updated to the second state, and precise data matching and correlation detection will be performed based on the filled attribute values. This avoids the loading and processing of irrelevant data and significantly improves the detection efficiency and performance.
[0084] The pre-placeholder correlation analysis system pre-processes rule dependencies through the placeholder construction module and dynamically adjusts the rule state and detection process through the pre-placeholder detection module, achieving effective management and optimization of resources during the security detection process.
[0085] Optionally, in the first embodiment, a schematic diagram of the memory space usage during correlation detection in the prior art can be as Figure 3 shown. Figure 3 "Behavior A" in represents a pre-event, and its attribute values may be relied on by the detection rules of the target event. Figure 3 "Behavior B1", "Behavior B2", "Behavior B3", "Behavior B4", and "Behavior B5" in represent the target events. Each event may need to perform correlation detection with "Behavior A". During correlation detection, all target event data that may be related to "Behavior A" (regardless of whether it is truly relevant) will be loaded into the memory, that is, the above "Behavior B1", "Behavior B2", "Behavior B3", "Behavior B4", and "Behavior B5" will be loaded into the memory and matched with the data of "Behavior A" to determine whether there is a certain correlation between them. This correlation detection method in the prior art will cause a large consumption of memory resources in practical applications, especially when the frequency of occurrence of "Behavior A" is high, or the amount of data of "Behavior B" type events is extremely large, which significantly reduces the system performance.
[0086] The introduction of the pre-placeholder mechanism in this application is precisely to solve this problem in the prior art. By using placeholders in the rules and filling in the actual values only when "Behavior B" is detected to activate the related rule detection, it avoids the loading of irrelevant data, saves memory space, and improves the detection efficiency.
[0087] Optionally, in the first embodiment, a schematic diagram of the correlation event detection based on placeholders in this application can be as Figure 4 shown. Through the comparison of three scenarios, it highlights how the pre-placeholder detection model optimizes memory usage and detection efficiency.
[0088] In the first scenario (as Figure 4 in "the placeholder is empty and no data is collected"),Figure 4 The behaviors B1 and B2 on the left represent target events. Without the placeholder for the attribute value of the specific preceding event behavior A being filled, the detection rule will not be activated. This means that the system will not collect data related to B1 and B2, avoiding loading a large amount of irrelevant data into memory when there is no clear association, thus saving system resources.
[0089] In the second scenario (such as Figure 4 the "placeholder association detection memory space" in it), after the placeholder of the preceding event behavior A is filled, the detection rule for the target event behavior B3 is activated, and the relevant attributes of behavior B1 are collected into the memory space for preparation of association detection, thereby accurately filtering and loading relevant data, improving the accuracy and efficiency of association analysis.
[0090] In the third scenario (such as Figure 4 the "placeholder attribute value does not match, directly discard" in it), Figure 4 After the placeholder representing the preceding event behavior A on the right is filled, the detection rules for the target event behaviors B4 and B5 are activated. However, when the attribute values of B4 and B5 are matched, the attribute value corresponding to the placeholder does not match the actual attribute values of B4 and B5 events. In this case, B4 and B5 events will not be loaded into memory for further detection but will be directly filtered and discarded by the system. This step avoids processing irrelevant data, further optimizing memory usage and detection speed.
[0091] Figure 4 The three scenarios shown together present how the pre-placeholder mechanism effectively controls the process of data collection and detection, ensuring that only when specific association conditions are met, relevant data will be loaded into memory for detection, thereby avoiding ineffective occupation of resources and improving the efficiency of security detection.
[0092] It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order from here.
[0093] Embodiment 2
[0094] Embodiment 2 of the present application also provides a network security detection device. It should be noted that the network security detection device in Embodiment 2 of the present application can be used to execute the network security detection method provided in Embodiment 1 of the present application. The following introduces the network security detection device provided in Embodiment 2 of the present application.
[0095] Figure 5It is a schematic diagram of a network security detection device according to Embodiment 2 of the present application. As Figure 5 shown, the device includes: a first replacement unit 501, a second replacement unit 502, and a detection unit 503.
[0096] Specifically, the first replacement unit 501 is configured to replace the dependent attributes in the rule copy with placeholders and determine that the rule status of the rule copy is the first status, where the rule copy is a copy of the original detection rule in the memory; the first status is the to-be-effective status.
[0097] The second replacement unit 502 is configured to, when the rule status of the rule copy is the first status and the attribute value corresponding to the placeholder in the rule copy is obtained, replace the placeholder in the rule copy in the memory with the attribute value and determine that the rule status of the rule copy is the second status; where the second status is the effective status.
[0098] The detection unit 503 is configured to match the service system data with the attribute values of the dependent attributes of the rule copy in the memory, and when the match is successful, perform a security detection on the match result according to the rule copy in the second status to obtain a security detection result.
[0099] The network security detection device provided in Embodiment 2 of the present application, based on the above-mentioned first replacement unit 501, second replacement unit 502, and detection unit 503, can use the rule for detection when the dependency is satisfied by analyzing the dependent attributes in the original detection rule and using placeholder replacement, avoiding ineffective detection when specific conditions are not met, thereby achieving the effect of improving the detection efficiency. At the same time, by obtaining the attribute value of the dependent attribute after placeholder replacement and by using the specific attribute value to replace the placeholder in the rule copy, it is ensured that the system resources are only used for data collection and security detection when the service system data matches the specific attribute value, significantly reducing the memory occupancy and the consumption of computing resources, and also being able to perform more accurate security detection, reducing false positives and false negatives, achieving the effect of improving the accuracy of security detection, and further achieving the effect of significantly enhancing the security of the service system, solving the problem in the related art that when performing security detection on the data in the service system based on the detection rule, each rule needs to be loaded and all related rule attributes need to be obtained for matching, resulting in low detection efficiency and high resource occupancy.
[0100] Optionally, in the network security detection device provided in the second embodiment of the present application, the dependent attributes include at least one of the following: environment-dependent attributes, pre-event attributes. The original detection rules include at least one of the following: the first type of rules, the second type of rules. The first type of rules are the rules for detection depending on the environment-dependent attributes, and the second type of rules are the rules for detection depending on the target event attributes. The value of the target event attributes depends on the value of the pre-event attributes. The placeholders include at least one of the following: the first placeholder corresponding to the environment-dependent attributes, the second placeholder corresponding to the pre-event attributes.
[0101] Optionally, in the network security detection device provided in the second embodiment of the present application, the above-mentioned detection unit 503 includes: a first determination subunit, configured to determine a first moment, and determine a target time period according to the first moment and a preset duration, where the first moment is the moment when the pre-event attributes are obtained; a first acquisition subunit, configured to acquire the attribute value of the target event attributes in the business system data, and match the attribute value of the target event attributes with the attribute value of the dependent attributes; a second determination subunit, configured to, in the case of successful matching, write the attribute value of the target event attributes into the memory, and determine the detection result according to the attribute value of the target event attributes and the rule copy in the second state.
[0102] Optionally, in the network security detection device provided in the second embodiment of the present application, the above-mentioned first replacement unit 501 includes: a third determination subunit, configured to determine the association relationship between the dependent attributes; a first replacement subunit, configured to replace the environment-dependent attributes in the rule copy with the first placeholder, and modify the replaced rule copy according to the association relationship; or, a second replacement subunit, configured to replace the pre-event attributes in the rule copy with the second placeholder, and modify the replaced rule copy according to the association relationship.
[0103] Optionally, in the network security detection device provided in the second embodiment of the present application, the above-mentioned second replacement unit 502 includes: a first construction subunit, configured to construct a data listening function corresponding to the first placeholder in the rule copy when the rule copy belongs to the first type of rules and the rule copy is in the first state; a second acquisition subunit, configured to acquire the attribute value of the environment-dependent attributes through the listening function corresponding to the first placeholder; a third replacement subunit, configured to replace the first placeholder in the rule copy in the memory with the attribute value of the environment-dependent attributes.
[0104] Optionally, in the network security detection device provided in the second embodiment of the present application, the above-mentioned second replacement unit 502 includes: a second construction subunit, configured to construct a data monitoring function corresponding to the second placeholder in the rule copy when the rule copy belongs to the second type of rule and the rule copy is in the first state; a third acquisition subunit, configured to obtain the attribute value of the pre-event attribute through the monitoring function corresponding to the second placeholder; a fourth replacement subunit, configured to replace the second placeholder of the rule copy in the memory with the attribute value of the pre-event attribute.
[0105] Optionally, in the network security detection device provided in the second embodiment of the present application, the above-mentioned device further includes: a second determination unit, configured to determine each placeholder in the rule copy after replacing the placeholder in the rule copy in the memory with the attribute value; a processing unit, configured to set the rule state of the rule copy to an invalid state or delete the rule copy in the memory when the attribute value of the dependent attribute corresponding to each placeholder in the rule copy cannot be obtained.
[0106] The network security detection device includes a processor and a memory. The above-mentioned first replacement unit 501, second replacement unit 502, detection unit 503, etc. are all stored in the memory as program units, and the corresponding functions are implemented by the processor executing the above program units stored in the memory.
[0107] The processor contains a kernel, and the kernel is used to retrieve the corresponding program unit from the memory. One or more kernels can be set, and the security detection efficiency of the business system data can be improved by adjusting the kernel parameters.
[0108] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of, for example, read-only memory (ROM) or flash memory (flash RAM), and the memory includes at least one storage chip.
[0109] Embodiment 3 of the present invention provides a computer-readable storage medium, on which a program is stored, and when the program is executed by a processor, a network security detection method is implemented.
[0110] Embodiment 4 of the present invention provides a processor, and the processor is used to run a program, and when the program runs, a network security detection method is executed.
[0111] As Figure 6As shown in the figure, Embodiment 5 of the present invention provides an electronic device. The device includes a processor, a memory, and a program stored in the memory and executable on the processor. When the processor executes the program, the following steps are implemented: replacing the dependent attributes in the rule copy with placeholders, and determining that the rule status of the rule copy is the first status, where the rule copy is a copy of the original detection rule in the memory; the first status is the to-be-effective status; when the rule status of the rule copy is the first status and the attribute values of the dependent attributes corresponding to the placeholders in the rule copy are obtained, replacing the placeholders in the rule copy in the memory with the attribute values, and determining that the rule status of the rule copy is the second status; where the second status is the effective status; matching the business system data with the attribute values of the dependent attributes of the rule copy in the memory, and when the matching is successful, performing a security detection on the matching result according to the rule copy in the second status to obtain a security detection result.
[0112] When the processor executes the program, the following steps are also implemented: the dependent attributes include at least one of the following: environment-dependent attributes, pre-event attributes, the original detection rules include at least one of the following: first-type rules, second-type rules, the first-type rules are rules that perform detection depending on the environment-dependent attributes, the second-type rules are rules that perform detection depending on the target event attributes, the value of the target event attribute depends on the value of the pre-event attribute, and the placeholders include at least one of the following: the first placeholder corresponding to the environment-dependent attribute, the second placeholder corresponding to the pre-event attribute.
[0113] When the processor executes the program, the following steps are also implemented: performing a security detection on the matching result according to the rule copy in the second status to obtain a security detection result, including: determining a first moment, and determining a target time period according to the first moment and a preset duration, where the first moment is the moment when the pre-event attribute is obtained; within the target time period, obtaining the attribute value of the target event attribute in the business system data, and matching the attribute value of the target event attribute with the attribute values of the dependent attributes; when the matching is successful, writing the attribute value of the target event attribute into the memory, and determining the detection result according to the attribute value of the target event attribute and the rule copy in the second status.
[0114] When the processor executes the program, the following steps are also implemented: replacing the dependent attributes in the rule copy with placeholders, including: determining the association relationship between the dependent attributes; replacing the environment-dependent attributes in the rule copy with the first placeholder, and modifying the replaced rule copy according to the association relationship; or, replacing the pre-event attributes in the rule copy with the second placeholder, and modifying the replaced rule copy according to the association relationship.
[0115] When the processor executes the program, the following steps are also implemented: replacing the placeholder in the rule copy in the memory with the attribute value, including: when the rule copy belongs to the first type of rule and the rule copy is in the first state, constructing a data monitoring function corresponding to the first placeholder in the rule copy; obtaining the attribute value of the environment-dependent attribute through the monitoring function corresponding to the first placeholder; replacing the first placeholder in the rule copy in the memory with the attribute value of the environment-dependent attribute.
[0116] When the processor executes the program, the following steps are also implemented: replacing the placeholder in the rule copy in the memory with the attribute value, including: when the rule copy belongs to the second type of rule and the rule copy is in the first state, constructing a data monitoring function corresponding to the second placeholder in the rule copy; obtaining the attribute value of the pre-event attribute through the monitoring function corresponding to the second placeholder; replacing the second placeholder in the rule copy in the memory with the attribute value of the pre-event attribute.
[0117] When the processor executes the program, the following steps are also implemented: after replacing the placeholder in the rule copy in the memory with the attribute value, the above method further includes: determining each placeholder in the rule copy; when the attribute value of the dependent attribute corresponding to each placeholder in the rule copy cannot be obtained, setting the rule state of the rule copy to the invalid state or deleting the rule copy from the memory.
[0118] The device in this article can be a server, a PC, a PAD, a mobile phone, etc.
[0119] This application also provides a computer program product, which when executed on a data processing device is adapted to execute a program initialized with the following method steps: replacing the dependent attribute in the rule copy with a placeholder and determining that the rule state of the rule copy is the first state, where the rule copy is a copy of the original detection rule in the memory; the first state is the to-be-effective state; when the rule state of the rule copy is the first state and the attribute value of the dependent attribute corresponding to the placeholder in the rule copy is obtained, replacing the placeholder in the rule copy in the memory with the attribute value and determining that the rule state of the rule copy is the second state; where the second state is the effective state; matching the business system data with the attribute value of the dependent attribute of the rule copy in the memory, and when the match is successful, performing a security detection on the match result according to the rule copy in the second state to obtain a security detection result.
[0120] When executed on a data processing device, it is also suitable for executing a program initialized with the following method steps: The dependency attributes include at least one of the following: environment-dependent attributes, pre-event attributes. The original detection rules include at least one of the following: the first type of rules, the second type of rules. The first type of rules are the rules for detection depending on the environment-dependent attributes, and the second type of rules are the rules for detection depending on the target event attributes. The value of the target event attributes depends on the value of the pre-event attributes. The placeholders include at least one of the following: the first placeholder corresponding to the environment-dependent attributes, the second placeholder corresponding to the pre-event attributes.
[0121] When executed on a data processing device, it is also suitable for executing a program initialized with the following method steps: performing a security detection on the matching result according to the rule copy in the second state to obtain a security detection result, including: determining a first moment, and determining a target time period according to the first moment and a preset duration, where the first moment is the moment when the pre-event attributes are obtained; within the target time period, obtaining the attribute value of the target event attributes in the business system data, and matching the attribute value of the target event attributes with the attribute value of the dependency attributes; in the case of successful matching, writing the attribute value of the target event attributes into the memory, and determining the detection result according to the attribute value of the target event attributes and the rule copy in the second state.
[0122] When executed on a data processing device, it is also suitable for executing a program initialized with the following method steps: replacing the dependency determination attributes in the rule copy with placeholders, including: determining the association relationship between the dependency attributes; replacing the environment-dependent attributes in the rule copy with the first placeholder, and modifying the replaced rule copy according to the association relationship; or, replacing the pre-event attributes in the rule copy with the second placeholder, and modifying the replaced rule copy according to the association relationship.
[0123] When executed on a data processing device, it is also suitable for executing a program initialized with the following method steps: replacing the placeholders in the rule copy in the memory with attribute values, including: in the case where the rule copy belongs to the first type of rules and the rule copy is in the first state, constructing a data listening function corresponding to the first placeholder in the rule copy; obtaining the attribute value of the environment-dependent attributes through the listening function corresponding to the first placeholder; replacing the first placeholder in the rule copy in the memory with the attribute value of the environment-dependent attributes.
[0124] When executed on a data processing device, it is also suitable for executing a program initialized with the following method steps: replacing placeholders in a rule copy in memory with attribute values, including: when the rule copy belongs to the second type of rules and the rule copy is in the first state, constructing a data listening function corresponding to a second placeholder in the rule copy; obtaining the attribute value of the pre-event attribute through the listening function corresponding to the second placeholder; and replacing the second placeholder in the rule copy in memory with the attribute value of the pre-event attribute.
[0125] When executed on a data processing device, it is also suitable for executing a program initialized with the following method steps: after replacing placeholders in a rule copy in memory with attribute values, the above method further includes: determining each placeholder in the rule copy; when the attribute values of the dependent attributes corresponding to each placeholder in the rule copy cannot be obtained, setting the rule state of the rule copy to an invalid state or deleting the rule copy from memory.
[0126] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0127] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0128] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including instruction means, and the instruction means implement the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0129] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide for implementing the steps in a process Figure 1 one process or multiple processes and / or blocks Figure 1 steps of the functions specified in one block or multiple blocks.
[0130] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.
[0131] The memory may include non-permanent memory in the computer-readable medium, in the form of random access memory (RAM) and / or non-volatile memory such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of a computer-readable medium.
[0132] Computer-readable media includes permanent and non-permanent, removable and non-removable media and can store information by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transitory media such as modulated data signals and carrier waves.
[0133] It should also be noted that the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, commodity or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the statement "comprising one..." does not exclude the presence of additional identical elements in the process, method, commodity or device comprising the element.
[0134] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0135] The above are only the embodiments of the present application and are not used to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.
Claims
1. A method for detecting network security, characterized in that, Including: Replacing the dependent attributes in the rule copy with placeholders and determining that the rule status of the rule copy is the first status, where the rule copy is a copy of the original detection rule in memory; the first status is the to-be-effective status; When the rule status of the rule copy is the first status and the attribute value of the dependent attribute corresponding to the placeholder in the rule copy is obtained, replacing the placeholder in the rule copy in memory with the attribute value and determining that the rule status of the rule copy is the second status; where the second status is the effective status; Matching the business system data with the attribute values of the dependent attributes of the rule copy in memory, and when the matching is successful, performing a security detection on the matching result according to the rule copy in the second status to obtain a security detection result.
2. The method according to claim 1, wherein The dependent attributes include at least one of the following: environment-dependent attributes, pre-event attributes. The original detection rules include at least one of the following: first-class rules, second-class rules. The first-class rules are rules that perform detection depending on the environment-dependent attributes. The second-class rules are rules that perform detection depending on the target event attributes. The value of the target event attribute depends on the value of the pre-event attribute. The placeholders include at least one of the following: the first placeholder corresponding to the environment-dependent attribute, the second placeholder corresponding to the pre-event attribute.
3. The method according to claim 2, wherein Performing a security detection on the matching result according to the rule copy in the second status to obtain a security detection result, including: Determining a first moment and determining a target time period according to the first moment and a preset duration, where the first moment is the moment when the pre-event attribute is obtained; Within the target time period, obtaining the attribute value of the target event attribute in the business system data and matching the attribute value of the target event attribute with the attribute value of the dependent attribute; When the matching is successful, writing the attribute value of the target event attribute into memory and determining the detection result according to the attribute value of the target event attribute and the rule copy in the second status.
4. The method according to claim 2, wherein Replacing the dependent attributes in the rule copy with placeholders, including: Determining the association relationship between the dependent attributes; Replacing the environment-dependent attribute in the rule copy with the first placeholder and modifying the replaced rule copy according to the association relationship; or Replacing the pre-event attribute in the rule copy with the second placeholder and modifying the replaced rule copy according to the association relationship.
5. The method according to claim 2, wherein Replacing the placeholder in the rule copy in memory with the attribute value, including: When the rule copy belongs to the first-class rules and the rule copy is in the first status, constructing a data monitoring function corresponding to the first placeholder in the rule copy; Obtaining the attribute value of the environment-dependent attribute through the monitoring function corresponding to the first placeholder; Replacing the first placeholder in the rule copy in memory with the attribute value of the environment-dependent attribute.
6. The method according to claim 2, wherein Replacing the placeholder in the rule copy in memory with the attribute value, including: When the rule copy belongs to the second type of rules and the rule copy is in the first state, construct a data monitoring function corresponding to the second placeholder in the rule copy; Obtain the attribute value of the pre-event attribute through the monitoring function corresponding to the second placeholder; Replace the second placeholder of the rule copy in the memory with the attribute value of the pre-event attribute.
7. The method according to any one of claims 4 to 6, characterized in that, After replacing the placeholder in the rule copy in the memory with the attribute value, the method further includes: Determine each placeholder in the rule copy; If the attribute value of the dependency attribute corresponding to each placeholder in the rule copy cannot be obtained, set the rule state of the rule copy to the invalid state or delete the rule copy in the memory.
8. A detection device for network security, characterized in that, Includes: A first replacement unit for replacing the dependency attribute in the rule copy with a placeholder and determining that the rule state of the rule copy is the first state, where the rule copy is a copy of the original detection rule in the memory; the first state is the to-be-effective state; A second replacement unit for, when the rule state of the rule copy is the first state and the attribute value of the dependency attribute corresponding to the placeholder in the rule copy is obtained, replacing the placeholder in the rule copy in the memory with the attribute value and determining that the rule state of the rule copy is the second state; where the second state is the effective state; A detection unit for matching the business system data with the attribute value of the dependency attribute of the rule copy in the memory, and when the matching is successful, performing a security detection on the matching result according to the rule copy in the second state to obtain a security detection result.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes stored computer instructions, where when the computer instructions are executed by a processor, the network security detection method according to any one of claims 1 to 7 is implemented.
10. An electronic device, characterized in that, Includes one or more processors and a memory, the memory is used to store one or more programs, where when the one or more programs are executed by the one or more processors, the one or more processors implement the network security detection method according to any one of claims 1 to 7.