Alarm reduction processing method and device, computer equipment, readable storage medium and program product
By matching and filtering out invalid alarm information, the enterprise security operation center's response efficiency to security incidents is improved, and the problem of real attack incident identification in the processing of massive alarm messages is solved.
Patent Information
- Application Number
- CN202510706461.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-29
- Publication Date
- 2025-07-11
AI Technical Summary
When facing massive alarm messages, it is difficult for the enterprise security operation center to efficiently identify real attack events, resulting in a decrease in security incident response efficiency.
By obtaining the current alarm information, matching the alarm information sample in the alarm information attribute table, obtaining asset-related attributes, determining whether the alarm information is an asset-related alarm, and filtering out the current alarm information when the target asset of the asset-related alarm does not match the alarm-related assets.
Improve the efficiency of response to security incidents, reduce invalid alarm information, and ensure that security operation personnel focus on handling potential threats.
Smart Images

Figure CN120301700A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technologies, and particularly to an alarm reduction processing method, apparatus, computer device, computer-readable storage medium, and computer program product. Background Art
[0002] In the digital age, the complexity and frequency of network attacks are increasing continuously, and ensuring the security of business systems has become the focus of enterprise security operations. Among them, in enterprise security operations, various security devices and software such as firewalls, intrusion detection systems, and anti-virus software are usually used to alarm network attacks. However, the enterprise security operation center usually needs to process a large number of alarm messages, making it difficult to efficiently identify and quickly respond to real attack events, resulting in a decline in the response efficiency to security events. Summary of the Invention
[0003] Based on this, it is necessary to provide an alarm reduction processing method, apparatus, computer device, computer-readable storage medium, and computer program product for the above technical problems.
[0004] In a first aspect, this application provides an alarm reduction processing method, including:
[0005] Obtain current alarm information;
[0006] Match the current alarm information with alarm information samples in an alarm information attribute table;
[0007] If there is a matching alarm information sample, obtain the asset association attribute of the alarm information sample in the alarm information attribute table;
[0008] If the asset association attribute indicates that the alarm information sample is an asset-related alarm, match the alarm-related assets of the alarm information sample with the attack target assets of the current alarm information;
[0009] If the alarm-related assets and the attack target assets do not match, filter out the current alarm information.
[0010] In one embodiment, after matching the current alarm information with the alarm information samples in the alarm information attribute table, the method further includes: if there is no matching alarm information sample, obtaining the vulnerability information corresponding to the current alarm information; if the vulnerability information indicates that the security vulnerability corresponding to the current alarm information is an asset-related vulnerability, determining the alarm-related assets of the current alarm information according to the asset-related information of the security vulnerability, and obtaining an asset association attribute indicating that the current alarm information is an asset-related alarm; if the vulnerability information indicates that the security vulnerability corresponding to the current alarm information is an asset-unrelated vulnerability, obtaining an asset association attribute indicating that the current alarm information is an asset-unrelated alarm; adding the current alarm information and the asset association attribute to the alarm information attribute table.
[0011] In one embodiment, before matching the alarm-related assets of the alarm information sample with the attack target assets of the current alarm information, the method includes: obtaining the attack target identifier of the current alarm information; querying the network assets corresponding to the attack target identifier according to the network asset exposure information of the protected entity, and determining the attack target assets of the current alarm information.
[0012] In one embodiment, before querying the network assets corresponding to the attack target identifier according to the network asset exposure information of the protected entity and determining the attack target assets of the current alarm information, the method includes: using the asset management system and attack surface management tool of the protected entity to obtain the external network exposure identifiers of the protected entity; performing port detection operations on each of the external network exposure identifiers to obtain the open port information of each of the external network exposure identifiers and the asset identification results of each open port; associatively storing each of the external network exposure identifiers, the open port information, and the asset identification results as the network asset exposure information.
[0013] In one embodiment, matching the alarm-related assets of the alarm information sample with the attack target assets of the current alarm information includes: comparing the alarm-related assets with the asset identifiers of the attack target assets; if the asset identifiers do not match, determining that the alarm-related assets and the attack target assets do not match; if the asset identifiers match, comparing the alarm-related assets with the asset versions of the attack target assets; if the asset versions do not match, determining that the alarm-related assets and the attack target assets do not match.
[0014] In one embodiment, before matching the current alarm information with the alarm information samples in the alarm information attribute table, the method includes: determining the attack target assets of the current alarm information; if the attack target assets correspond to a bucket service, filtering out the current alarm information.
[0015] In a second aspect, the present application further provides an alarm reduction processing device, including:
[0016] An alarm acquisition module, configured to acquire current alarm information;
[0017] A sample matching module, configured to match the current alarm information with alarm information samples in an alarm information attribute table;
[0018] An attribute acquisition module, configured to, if there is a matching alarm information sample, acquire the asset association attribute of the alarm information sample in the alarm information attribute table;
[0019] An asset matching module, configured to, if the asset association attribute indicates that the alarm information sample is an asset-related alarm, match the alarm-related asset of the alarm information sample with the attack target asset of the current alarm information;
[0020] An alarm filtering module, configured to, if the alarm-related asset and the attack target asset do not match, filter the current alarm information.
[0021] In a third aspect, the present application further provides a computer device, including a memory and a processor, where the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:
[0022] Acquire current alarm information;
[0023] Match the current alarm information with alarm information samples in an alarm information attribute table;
[0024] If there is a matching alarm information sample, acquire the asset association attribute of the alarm information sample in the alarm information attribute table;
[0025] If the asset association attribute indicates that the alarm information sample is an asset-related alarm, match the alarm-related asset of the alarm information sample with the attack target asset of the current alarm information;
[0026] If the alarm-related asset and the attack target asset do not match, filter the current alarm information.
[0027] In a fourth aspect, the present application further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the following steps are implemented:
[0028] Acquire current alarm information;
[0029] Match the current alarm information with alarm information samples in an alarm information attribute table;
[0030] If there is a matching alarm information sample, obtain the asset association attribute of the alarm information sample from the alarm information attribute table;
[0031] If the asset association attribute indicates that the alarm information sample is an asset-related alarm, match the alarm-related asset of the alarm information sample with the attack target asset of the current alarm information;
[0032] If the alarm-related asset does not match the attack target asset, filter out the current alarm information.
[0033] In a fifth aspect, the present application also provides a computer program product, including a computer program, which when executed by a processor implements the following steps:
[0034] Obtain the current alarm information;
[0035] Match the current alarm information with the alarm information samples in the alarm information attribute table;
[0036] If there is a matching alarm information sample, obtain the asset association attribute of the alarm information sample from the alarm information attribute table;
[0037] If the asset association attribute indicates that the alarm information sample is an asset-related alarm, match the alarm-related asset of the alarm information sample with the attack target asset of the current alarm information;
[0038] If the alarm-related asset does not match the attack target asset, filter out the current alarm information.
[0039] The above-mentioned alarm reduction processing method, device, computer device, computer-readable storage medium, and computer program product first obtain the current alarm information, then match the current alarm information with the alarm information samples in the alarm information attribute table. If there is a matching alarm information sample, obtain the asset association attribute of the alarm information sample in the alarm information attribute table. If the asset association attribute indicates that the alarm information sample is an asset-related alarm, match the alarm-related asset of the alarm information sample with the attack target asset of the current alarm information. If the alarm-related asset and the attack target asset do not match, filter out the current alarm information. In this solution, after obtaining the current alarm information, by matching the information with the alarm information samples in the alarm information attribute table, it is possible to efficiently identify whether the current alarm information is an asset-related alarm using historical data. Among them, in the case of determining that the current alarm information is an asset-related alarm, by matching the attack target asset of the current alarm information with the alarm-related asset of the alarm information sample, it is possible to determine whether the attack target asset of the current alarm information is a network asset that can be affected by the corresponding network attack. In the case of determining that the attack target asset does not match the alarm-related asset, it can be determined that the network attack corresponding to the current alarm information is ineffective against the attack target asset, so that the current alarm information can be filtered out to achieve the reduction of ineffective alarm information, which is beneficial to improving the response efficiency to security events. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for the description in the embodiments of the present application or related technologies. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.
[0041] Figure 1 It is a schematic flowchart of the alarm reduction processing method in one embodiment;
[0042] Figure 2 It is a schematic flowchart of updating the alarm information attribute table in one embodiment;
[0043] Figure 3 It is a schematic flowchart of obtaining network asset exposure information in one embodiment;
[0044] Figure 4 It is a schematic flowchart of matching the alarm-related asset with the attack target asset in one embodiment;
[0045] Figure 5 It is a schematic flowchart of the alarm reduction processing method in another embodiment;
[0046] Figure 6It is a structural block diagram of an alarm reduction processing device in an embodiment;
[0047] Figure 7 It is an internal structure diagram of a computer device in an embodiment. Detailed implementation manners
[0048] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0049] Specifically, in network security protection, the protected entity (which can be an enterprise) usually sets up a Security Operation Center (SOC) to be responsible for round-the-clock monitoring, detection and response to network security incidents and threats within the organization. The SOC usually uses security products such as intrusion detection systems and security information and event management (SIEM) systems to perform real-time analysis on the security data of the protected entity to identify potential attacks and take corresponding measures for processing to ensure the security and compliance of information assets. Among the Internet attacks faced by the protected entity, some attacks such as Advanced Persistent Threat (APT) are usually launched by professional attackers and have clear attack targets. However, among the attacks faced by the protected entity in daily life, there are also a large number of ineffective attacks that do not affect the attack target. The alarm information generated by security products for this type of attack is likely to interfere with the SOC's response to security incidents. Based on this, the present application provides an alarm reduction processing method, which is beneficial to improving the response efficiency of the protected entity to security incidents by reducing the alarm information of ineffective attacks.
[0050] In one embodiment, as Figure 1 shown, an alarm reduction processing method is provided. In this embodiment, an example is given where this method is applied to a server. It can be understood that this method can also be applied to a terminal, and can also be applied to a system including a terminal and a server, and is implemented through the interaction between the terminal and the server. In this embodiment, the method includes the following steps:
[0051] Step S101, obtain the current alarm information.
[0052] Among them, the current alarm information can be the information sent by the security products deployed in the security operation center of the protected entity, which can be used to indicate the attack information of the network attack currently encountered by the network assets of the protected entity. Exemplarily, the current alarm information can include, but is not limited to, the alarm name, the attack target identifier of the current attack, the attack type, security vulnerabilities, etc. Among them, the attack target identifier can include information such as the Internet Protocol Address (IP address), domain name, port, etc. being attacked; the attack type can be used to indicate the attack means of the current attack (such as SQL injection, etc.); the security vulnerability can be used to indicate the security vulnerability exploited by the current attack, which can be a security vulnerability for a specific network asset or a security vulnerability unrelated to a specific network asset.
[0053] Step S102, match the current alarm information with the alarm information samples in the alarm information attribute table.
[0054] Among them, the alarm information attribute table can be used to store multiple alarm information samples and their corresponding asset association attributes. Among them, the alarm information samples can include the alarm information processed by the security operation center in the historical period, and the asset association attributes can be used to indicate whether the security vulnerabilities corresponding to the alarm information samples are related to specific network assets. Exemplarily, the historical period can be half a year.
[0055] Exemplarily, in this step, the alarm name of the current alarm information can be matched with the alarm name of the alarm information samples in the alarm information attribute table. If the alarm name information of the two is the same, it can be determined that the current alarm information matches the alarm information sample; otherwise, it can be determined that the current alarm information does not match the alarm information sample.
[0056] Step S103, if there is a matching alarm information sample, obtain the asset association attribute of the alarm information sample in the alarm information attribute table.
[0057] Among them, when it is determined that there is an alarm information sample in the alarm information attribute table that matches the current alarm information, the asset association attribute of this alarm information sample can be obtained in the alarm information attribute table. Among them, the asset association attribute can be used to indicate whether the security vulnerabilities corresponding to the alarm information samples are related to specific network assets.
[0058] Exemplarily, the security vulnerability corresponding to the alarm information may be a security vulnerability for a specific type of product. For example, it may include but is not limited to: an unauthorized access vulnerability in a certain type of enterprise middleware platform due to improper configuration of the access control mechanism; a vulnerability in the login interface of a certain type of office automation system where there is a defect in the authentication logic, allowing an attacker to bypass the authentication process and obtain administrator privileges; a vulnerability in a certain type of Web container where the resources under a specific path are not properly protected, resulting in the leakage of sensitive configuration information; a vulnerability in a certain type of database management tool in a specific version that lacks necessary input validation, allowing arbitrary code to be remotely executed. Among them, when the alarm information sample is such alarm information, its corresponding asset association attribute may indicate that the alarm information sample is an asset-related alarm.
[0059] Exemplarily, the security vulnerability corresponding to the alarm information may also be a security vulnerability that has nothing to do with specific network assets. For example, it may include but is not limited to: vulnerabilities such as SQL injection or directory traversal attacks that any Web application deployed in a network environment may face without sufficient input validation; vulnerabilities faced by Web systems with a login function that are subject to brute force cracking attempts. Among them, when the alarm information sample is such alarm information, its corresponding asset association attribute may indicate that the alarm information sample is an asset-unrelated alarm.
[0060] Optionally, in the alarm information attribute table, an asset-related alarm sub-table and an asset-unrelated alarm sub-table may also be set respectively according to the asset association attributes of each alarm information sample. The asset-related alarm sub-table is used to store alarm information samples whose asset association attributes indicate asset-related alarms, and the asset-unrelated alarm sub-table is used to store alarm information samples whose asset association attributes indicate asset-unrelated alarms.
[0061] Step S104, if the asset association attribute indicates that the alarm information sample is an asset-related alarm, then match the alarm-related assets of the alarm information sample with the attack target assets of the current alarm information.
[0062] Among them, for an alarm information sample whose asset association attribute indicates an asset-related alarm, the alarm information attribute table may simultaneously associate and store the relevant information of the alarm-related assets corresponding to the alarm information sample. The alarm-related assets may be the specific network assets targeted by the security vulnerability corresponding to the alarm information sample. For example, assuming that the security vulnerability corresponding to the alarm information sample is an unauthorized access vulnerability in a certain type of enterprise middleware platform due to improper configuration of the access control mechanism, then the alarm-related assets corresponding to the alarm information sample are that type of enterprise middleware platform; another example, assuming that the security vulnerability corresponding to the alarm information sample is a vulnerability in the login interface of a certain type of office automation system where there is a defect in the authentication logic, allowing an attacker to bypass the authentication process and obtain administrator privileges, then the alarm-related assets corresponding to the alarm information sample are that type of office automation system.
[0063] Among them, after obtaining the asset association attribute corresponding to the alarm information sample matched by the current alarm information, if the asset association attribute indicates that the alarm information sample is an asset-related alarm, it can be determined that the security vulnerability corresponding to the alarm information sample is related to a specific network asset, and thus it can also be determined that the network attack corresponding to the current alarm information is a network attack related to a specific network asset. Therefore, in this step, the alarm-related assets of the alarm information sample can be queried and determined in the alarm information attribute table to determine the network assets that can be affected by the network attack corresponding to the current alarm information.
[0064] Subsequently, the attack target asset of the current alarm information can be matched with the alarm-related assets to determine whether the attack target asset is a network asset that can be affected by the network attack. Among them, the attack target asset can be the network asset corresponding to the attack target of the current attack, and it can be obtained by querying information such as the IP address, domain name, and port included in the attack target identifier. Among them, when the attack target asset and the alarm-related assets are different assets, it can be determined that they do not match; otherwise, it can be determined that they match. Exemplarily, for example, if the alarm-related assets are a certain type of office automation system and the attack target asset is a storage bucket, it can be determined that the alarm-related assets and the attack target asset do not match.
[0065] Step S105, if the alarm-related assets and the attack target asset do not match, filter out the current alarm information.
[0066] Among them, in the case of determining that the alarm-related assets and the attack target asset do not match, it can be determined that the attack target of the current attack will not be affected by the attack, so the current attack is an invalid attack, that is, there is no need to perform response processing on the current alarm information. Therefore, the current alarm information can be filtered out.
[0067] In the above alarm reduction processing method, after obtaining the current alarm information, by matching the information with the alarm information samples in the alarm information attribute table, it is possible to efficiently identify whether the current alarm information is an asset-related alarm using historical data. Among them, in the case of determining that the current alarm information is an asset-related alarm, by matching the attack target asset of the current alarm information with the alarm-related assets of the alarm information sample, it is possible to determine whether the attack target asset of the current alarm information is a network asset that can be affected by the corresponding network attack. In the case of determining that the attack target asset and the alarm-related assets do not match, it can be determined that the network attack corresponding to the current alarm information is ineffective against the attack target asset, so the current alarm information can be filtered out to achieve the reduction of invalid alarm information, which is beneficial to improving the response efficiency to security events.
[0068] In an exemplary embodiment, such as Figure 2As shown, after matching the current alarm information with the alarm information samples in the alarm information attribute table, it further includes:
[0069] Step S201, if there is no matching alarm information sample, obtain the vulnerability information corresponding to the current alarm information.
[0070] Among them, when it is determined that there is no alarm information sample in the alarm information attribute table that matches the current alarm information, the vulnerability information corresponding to the current alarm information can be obtained. Among them, the vulnerability information may include the name of the security vulnerability targeted by the current attack. Exemplarily, the common format of the vulnerability name may be "product name + problem description + year / version information (optional)". Optionally, for some security vulnerabilities, the vulnerability information may further include a vulnerability number, such as a Common Vulnerabilities and Exposures (CVE) number, etc.
[0071] Among them, according to the vulnerability information, it can be determined whether the security vulnerability corresponding to the current alarm information is a vulnerability existing in a specific network asset (i.e., "asset-related vulnerability") or a general security vulnerability unrelated to a specific network asset (i.e., "asset-unrelated vulnerability").
[0072] Step S202, if the vulnerability information indicates that the security vulnerability corresponding to the current alarm information is an asset-related vulnerability, determine the alarm-related asset of the current alarm information according to the asset-related information of the security vulnerability, and obtain the asset association attribute indicating that the current alarm information is an asset-related alarm.
[0073] In this step, when it is determined that the security vulnerability corresponding to the current alarm information is an asset-related vulnerability, the asset association attribute for the current alarm information can be obtained as an asset-related alarm. At the same time, the alarm-related asset of the current alarm information can be determined according to the asset-related information corresponding to the security vulnerability. Among them, the asset-related information corresponding to the security vulnerability may include information such as the asset identifier and asset version of the specific network asset corresponding to the vulnerability, which can be extracted from the vulnerability name or queried from a public security vulnerability library using the vulnerability name or vulnerability number.
[0074] Step S203, if the vulnerability information indicates that the security vulnerability corresponding to the current alarm information is an asset-unrelated vulnerability, obtain the asset association attribute indicating that the current alarm information is an asset-unrelated alarm.
[0075] In this step, when it is determined that the security vulnerability corresponding to the current alarm information is an asset-unrelated vulnerability, the asset association attribute for the current alarm information can be obtained as an asset-unrelated alarm.
[0076] Step S204, add the current alarm information and the asset association attribute to the alarm information attribute table.
[0077] Among them, after obtaining the asset association attribute of the current alarm information, the current alarm information and the asset association attribute can be added to the alarm information attribute table, so that the current alarm information can become an alarm information sample in the alarm information attribute table. Exemplarily, when the asset association attribute of the current alarm information indicates that the information is an asset-related alarm, the relevant information of the alarm-related asset of the current alarm information (such as asset identifier, asset version, etc.) can also be associated and stored in the alarm information attribute table.
[0078] In this embodiment, when there is no alarm information sample in the alarm information attribute table that matches the current alarm information, adding the current alarm information and its corresponding asset association attribute to the alarm information attribute table can realize the update of the alarm information attribute table, which is beneficial to improving the subsequent alarm reduction efficiency.
[0079] In an exemplary embodiment, before matching the alarm-related asset of the alarm information sample with the attack target asset of the current alarm information, it includes: obtaining the attack target identifier of the current alarm information; according to the network asset exposure information of the protected entity, querying the network asset corresponding to the attack target identifier to determine the attack target asset of the current alarm information.
[0080] Among them, the network asset exposure information of the protected entity may include the access identifiers (such as IP addresses, domain names, ports, etc.) exposed by the protected entity, and the asset identifiers of the network assets corresponding to each exposed access identifier. Among them, when there are multiple versions of the network asset, the network asset exposure information may also include the asset version of the network asset corresponding to the exposed access identifier. Exemplarily, the information fields of the network asset exposure information may include: IP address / domain name, port, protocol, asset name, asset version number, etc.
[0081] Among them, after obtaining the current alarm information, the attack target identifier corresponding to the current attack can be extracted therefrom, and the attack target identifier may include information such as the IP address, domain name, port, etc. being attacked. Then, the attack target identifier can be used to query in the network asset exposure information to determine the network asset that matches it, so that the attack target asset of the current alarm information can be determined.
[0082] In an exemplary embodiment, as Figure 3 shown, before querying the network asset corresponding to the attack target identifier according to the network asset exposure information of the protected entity to determine the attack target asset of the current alarm information, it may include:
[0083] Step S301: Use the asset management system and attack surface management tool of the protected entity to obtain the external network exposure identifier of the protected entity.
[0084] Among them, by collecting and maintaining the network exposure information of the protected entity, the corresponding network asset exposure information can be obtained.
[0085] Specifically, in this step, the asset management system of the protected entity and / or the attack surface management tool can be used to obtain the external network exposure identifier of the protected entity.
[0086] Among them, the asset management system can be a system deployed by the protected entity for managing network assets, which can store the relevant information of each network asset of the protected entity and the external network exposure status of each network asset, so that the access identifiers (such as IP addresses, domain names, etc.) exposed by the protected entity to the outside can be exported from the asset management system.
[0087] Among them, the attack surface management tool can, under the authorization of the protected entity, monitor the network assets exposed by the protected entity on the external network from the perspective of an attacker. By using the attack surface management tool, when the asset management of the protected entity is not perfect enough, the access identifiers exposed by the protected entity on the external network can be discovered and collected more comprehensively.
[0088] It can be understood that the external network exposure identifier of the protected entity can also be obtained by combining the sorting results of the access identifiers exposed by the protected entity on the external network by the asset management system and the attack surface management tool.
[0089] Step S302: Perform port detection operations on each external network exposure identifier to obtain the open port information of each external network exposure identifier and the asset identification results of each open port.
[0090] Among them, for each external network exposure identifier obtained in the previous step, port detection operations can be performed on it respectively. Among them, when performing port detection operations on the external network exposure identifier, port scanning can be performed on it to verify the open ports, and the open port information of each external network exposure identifier can be obtained. Subsequently, asset identification tools can be used to identify the services, components, and versions of each open port to obtain the asset identification results of each open port. Exemplarily, some examples of network assets can include, but are not limited to, a VPN system of a certain manufacturer, a Web server running a specific service, a search engine platform based on a specific service, etc. Exemplarily, for some network assets, the corresponding asset identification results can also include the asset version number of the network asset.
[0091] Step S303: Associatively store each external network exposure identifier, open port information, and asset identification result as network asset exposure information.
[0092] Among them, after obtaining the external network exposure identifiers of the protection entity, the open port information of each external network exposure identifier, and the asset identification results of each open port, they can be associated and stored as the network asset exposure information of the protection entity. Exemplarily, the information fields of the network asset exposure information may include: IP address / domain name, port, protocol, asset name, asset version number, etc.
[0093] In this embodiment, by using a variety of tools to collect the external network exposure identifiers of the protection entity, and performing port detection and asset identification for each external network exposure identifier, a comprehensive combing of the network assets exposed by the protection entity can be achieved. Subsequently, the obtained network asset exposure information can be used to provide accurate query results for the attack target assets corresponding to the attack target identifiers.
[0094] In an exemplary embodiment, as Figure 4 shown, matching the assets related to the alarm in the alarm information sample with the attack target assets of the current alarm information may include:
[0095] Step S401, comparing the asset identifiers of the assets related to the alarm and the attack target assets.
[0096] Among them, when matching the assets related to the alarm and the attack target assets, the asset identifiers of the two can be compared first. The asset identifier can be the name of the network asset. Among them, when the asset identifiers of the two do not match, it can be transferred to step S402, and when the asset identifiers of the two match, it can be transferred to step S403.
[0097] Step S402, if the asset identifiers do not match, it is determined that the assets related to the alarm and the attack target assets do not match.
[0098] Among them, in the case where the asset identifiers of the assets related to the alarm and the attack target assets do not match, it can be determined that the two are different network assets. Thus, in this step, it can be determined that the assets related to the alarm and the attack target assets do not match.
[0099] Step S403, if the asset identifiers match, compare the asset versions of the assets related to the alarm and the attack target assets.
[0100] Among them, in the case where the asset identifiers of the assets related to the alarm and the attack target assets match, the asset versions of the two can be further compared. Among them, the asset version of the assets related to the alarm can be the range of asset versions affected by the security vulnerability of the network asset. When the asset version of the attack target asset falls within this asset version range, it can be determined that the asset version of the attack target asset matches the asset version of the assets related to the alarm.
[0101] It can be understood that when the relevant information of the alarm-related asset and / or the attack target asset does not include the asset version, it is not necessary to compare the asset versions, and it can be directly determined that the two match when the asset identifiers of the two are the same.
[0102] Step S404, if the asset versions do not match, it is determined that the alarm-related asset and the attack target asset do not match.
[0103] Among them, when the asset identifiers of the alarm-related asset and the attack target asset match, but the asset versions do not match, it can be determined that the alarm-related asset and the attack target asset do not match, which means that the attack target asset will not be affected by the corresponding security vulnerability.
[0104] It can be understood that when the asset versions of the alarm-related asset and the attack target asset match, it can be determined that the alarm-related asset and the attack target asset match.
[0105] In this embodiment, by sequentially matching the asset identifiers and asset versions of the alarm-related asset and the attack target asset, an accurate evaluation of the match between the alarm-related asset and the attack target asset can be achieved, which is beneficial to improving the accuracy of alarm message reduction.
[0106] In an exemplary embodiment, before matching the current alarm information with the alarm information samples in the alarm information attribute table, it includes: determining the attack target asset of the current alarm information; if the attack target asset corresponds to a bucket service, filtering the current alarm information.
[0107] Specifically, a bucket is a basic container in cloud storage services, which can be used to organize and manage the stored data, allowing users to store and classify files (called objects) in a logical manner, and ensuring that each bucket has a unique name in the same service.
[0108] Among them, the bucket service usually only provides the storage function of files and does not include service logic that can be remotely executed. Therefore, even if an attacker tries to attack its IP address, domain name or open port, since the attack target lacks an exploitable execution entry, it is usually difficult for both asset-related attacks and asset-unrelated attacks to affect the bucket service. Thus, after obtaining the current alarm information, it can be first determined whether the corresponding attack target asset corresponds to a bucket service, and when it is determined that the attack target asset corresponds to a bucket service, the current alarm information can be directly filtered out without subsequent matching processing.
[0109] In this embodiment, for network assets such as bucket services that are not easily affected by network attacks, when it is determined that the attack target asset of the current alarm information corresponds to a bucket service, it is directly filtered out, which can improve the filtering efficiency of alarm information and reduce the processing cost of the system.
[0110] In an exemplary embodiment, as Figure 5 shown, a method for alarm reduction processing is provided, including the following steps:
[0111] Step S501, obtain the external network exposure identifier of the protected entity.
[0112] Among them, the external network exposure identifier can be exported from the asset management system of the protected entity, and / or the external network exposure identifier of the protected entity can be discovered and collected by using an attack surface management tool.
[0113] Step S502, perform port detection operations on each external network exposure identifier to obtain the open port information of each external network exposure identifier and the asset identification results of each open port, and store the external network exposure identifiers, open port information, and asset identification results in an associated manner as network asset exposure information.
[0114] Step S503, count historical alarm information to obtain an alarm information sample, and construct an alarm information attribute table.
[0115] Among them, the alarm information attribute table can include an asset-related alarm sub-table and an asset-unrelated alarm sub-table. The alarm information samples can be classified according to the asset association attribute of the alarm information sample. The alarm information samples with the asset association attribute indicating asset-related alarms are stored in the asset-related alarm sub-table, and the alarm information samples with the asset association attribute indicating asset-unrelated alarms are stored in the asset-unrelated alarm sub-table. Among them, the asset-related alarm sub-table can store the alarm-related assets corresponding to the alarm information samples at the same time.
[0116] Step S504, establish an alarm reduction strategy to reduce the alarm information.
[0117] Among them, the alarm reduction strategy can include an alarm perspective reduction strategy and an asset perspective reduction strategy.
[0118] From the alarm perspective, after obtaining the current alarm information, it can be matched with the alarm information samples in the alarm information attribute table. If there is a matching alarm information sample, then the asset association attribute of the alarm information sample in the alarm information attribute table is obtained. Then, in the case where the asset association attribute indicates that the alarm information sample is an asset-related alarm, the alarm-related assets of the alarm information sample are matched with the attack target asset of the current alarm information, and in the case where it is determined that the alarm-related assets and the attack target asset do not match, the current alarm information is filtered out.
[0119] From the perspective of assets, before matching the current alarm information with the alarm information samples in the alarm information attribute table, the attack target asset of the current alarm information can be determined first, and the current alarm information can be filtered out when it is determined that the attack target asset corresponds to the bucket service.
[0120] In actual use, the reduction can be mainly carried out from the alarm perspective. If a situation that conforms to the asset perspective is encountered, the alarms irrelevant to the assets can be further reduced.
[0121] Step S505: When the current alarm information does not match the alarm information samples in the alarm information attribute table, update the alarm information attribute table according to the current alarm information.
[0122] Among them, when the current alarm information does not match the alarm information samples in the alarm information attribute table, the current alarm information and its asset association attributes can be added to the alarm information attribute table to update the alarm information attribute table.
[0123] This embodiment can achieve the following beneficial effects:
[0124] 1. By associating the reduction of alarm information with assets and using the asset-based alarm reduction method, this solution can efficiently filter out the alarm information corresponding to network attacks that will not affect the attacked target, enabling security operation personnel to focus more on handling alarm information that may cause harm, ensuring that real security incidents can be responded to in a timely manner, and thus improving the overall security protection ability.
[0125] 2. From the perspective of assets, this solution reduces relevant alarm information for network assets such as bucket services that are not easily affected by network attacks, which is beneficial to further improving the reduction efficiency of alarm information.
[0126] 3. By using historical alarm information to establish an alarm information attribute table and performing matching based on the alarm information samples in the alarm information attribute table during alarm reduction, this solution can narrow the range of alarm information samples to be matched to the alarm information that has actually generated alarms, without having to match the huge amount of alarm data built into the security product, which is beneficial to improving the matching efficiency of the current alarm information and then enhancing the overall response efficiency to security incidents.
[0127] It should be understood that although the steps in the flowcharts involved in the above embodiments are sequentially shown according to the indication of the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same moment, but can be executed at different moments. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.
[0128] Based on the same inventive concept, an embodiment of the present application further provides an alarm reduction processing device for implementing the alarm reduction processing method involved above. The solution provided by this device to solve the problem is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the alarm reduction processing device provided below can refer to the limitations on the alarm reduction processing method in the above text, and will not be repeated here.
[0129] In an exemplary embodiment, as Figure 6 shown, an alarm reduction processing device 600 is provided, including:
[0130] An alarm acquisition module 601, configured to acquire current alarm information;
[0131] A sample matching module 602, configured to match the current alarm information with alarm information samples in an alarm information attribute table;
[0132] An attribute acquisition module 603, configured to, if there is a matching alarm information sample, acquire the asset association attribute of the alarm information sample in the alarm information attribute table;
[0133] An asset matching module 604, configured to, if the asset association attribute indicates that the alarm information sample is an asset-related alarm, match the alarm-related asset of the alarm information sample with the attack target asset of the current alarm information;
[0134] An alarm filtering module 605, configured to filter the current alarm information if the alarm-related asset and the attack target asset do not match.
[0135] In an exemplary embodiment, the device further includes: a vulnerability acquisition module, configured to acquire vulnerability information corresponding to the current alarm information if there is no matching alarm information sample; a first attribute determination module, configured to, if the vulnerability information indicates that the security vulnerability corresponding to the current alarm information is an asset-related vulnerability, determine the alarm-related assets of the current alarm information according to the asset-related information of the security vulnerability, and obtain an asset association attribute indicating that the current alarm information is an asset-related alarm; a second attribute determination module, configured to, if the vulnerability information indicates that the security vulnerability corresponding to the current alarm information is an asset-unrelated vulnerability, obtain an asset association attribute indicating that the current alarm information is an asset-unrelated alarm; an information addition module, configured to add the current alarm information and the asset association attribute to the alarm information attribute table.
[0136] In an exemplary embodiment, the device further includes: a target identifier determination module, configured to acquire an attack target identifier of the current alarm information; a target asset determination module, configured to query, according to the network asset exposure information of a protection subject, the network asset corresponding to the attack target identifier, and determine the attack target asset of the current alarm information.
[0137] In an exemplary embodiment, the device further includes: an exposure identifier determination module, configured to acquire an external network exposure identifier of the protection subject by using the asset management system and the attack surface management tool of the protection subject; an exposed asset identification module, configured to perform port detection operations on each of the external network exposure identifiers to obtain open port information of each of the external network exposure identifiers and an asset identification result of each open port; an exposure information acquisition module, configured to associatively store each of the external network exposure identifiers, the open port information, and the asset identification result as the network asset exposure information.
[0138] In an exemplary embodiment, the asset matching module 604 is configured to: compare the alarm-related assets with the asset identifiers of the attack target assets; if the asset identifiers do not match, determine that the alarm-related assets and the attack target assets do not match; if the asset identifiers match, compare the asset versions of the alarm-related assets and the attack target assets; if the asset versions do not match, determine that the alarm-related assets and the attack target assets do not match.
[0139] In an exemplary embodiment, the device further includes: a target asset determination module, configured to determine the attack target asset of the current alarm information; the alarm filtering module 605 is further configured to filter the current alarm information if the attack target asset corresponds to a bucket service.
[0140] Each module in the above alarm reduction processing device can be implemented in whole or in part by software, hardware, or a combination thereof. Each of the above modules can be embedded in the processor of the computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each of the above modules.
[0141] In an exemplary embodiment, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 7 shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data such as current alarm information and an alarm information attribute table. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals through a network connection. When the computer program is executed by the processor, it implements an alarm reduction processing method.
[0142] Those skilled in the art can understand that Figure 7 the structure shown in
[0143] is only a block diagram of some structures related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0144] In an embodiment, a computer device is further provided, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the steps in the above method embodiments are implemented.
[0144] In an embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by the processor, the steps in the above method embodiments are implemented.
[0145] In an embodiment, a computer program product is provided, including a computer program. When the computer program is executed by the processor, the steps in the above method embodiments are implemented.
[0146] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.
[0147] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in this application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., and are not limited thereto. The processors involved in the embodiments provided in this application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, data processing logics based on quantum computing, artificial intelligence (AI) processors, etc., and are not limited thereto.
[0148] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this application.
[0149] The above embodiments only express several implementation manners of this application, and their descriptions are relatively specific and detailed. However, it should not be construed as a limitation on the patent scope of this application. It should be noted that for those of ordinary skill in the art, without departing from the concept of this application, several deformations and improvements can still be made, and these all belong to the protection scope of this application. Therefore, the protection scope of this application shall be subject to the appended claims.
Claims
1. An alarm reduction processing method, characterized in that, The method includes: Obtaining current alarm information; Matching the current alarm information with alarm information samples in an alarm information attribute table; If there is a matching alarm information sample, obtaining the asset association attribute of the alarm information sample in the alarm information attribute table; If the asset association attribute indicates that the alarm information sample is an asset-related alarm, matching the alarm-related assets of the alarm information sample with the attack target assets of the current alarm information; If the alarm-related assets and the attack target assets do not match, filtering the current alarm information.
2. The method according to claim 1, wherein After matching the current alarm information with the alarm information samples in the alarm information attribute table, it further includes: If there is no matching alarm information sample, obtaining the vulnerability information corresponding to the current alarm information; If the vulnerability information indicates that the security vulnerability corresponding to the current alarm information is an asset-related vulnerability, determining the alarm-related assets of the current alarm information according to the asset-related information of the security vulnerability, and obtaining an asset association attribute indicating that the current alarm information is an asset-related alarm; If the vulnerability information indicates that the security vulnerability corresponding to the current alarm information is an asset-unrelated vulnerability, obtaining an asset association attribute indicating that the current alarm information is an asset-unrelated alarm; Adding the current alarm information and the asset association attribute to the alarm information attribute table.
3. The method according to claim 1, wherein Before matching the alarm-related assets of the alarm information sample with the attack target assets of the current alarm information, it includes: Obtaining the attack target identifier of the current alarm information; Querying the network asset corresponding to the attack target identifier according to the network asset exposure information of the protected entity, and determining the attack target assets of the current alarm information.
4. The method according to claim 3, wherein Before querying the network asset corresponding to the attack target identifier according to the network asset exposure information of the protected entity and determining the attack target assets of the current alarm information, it includes: Using the asset management system and attack surface management tool of the protected entity to obtain the external network exposure identifiers of the protected entity; Performing port detection operations on each of the external network exposure identifiers to obtain the open port information of each of the external network exposure identifiers and the asset identification results of each open port; Associatively storing each of the external network exposure identifiers, the open port information, and the asset identification results as the network asset exposure information.
5. The method according to claim 1, characterized in that, The matching of the alarm-related assets of the alarm information sample with the attack target assets of the current alarm information includes: Comparing the asset identifiers of the alarm-related assets with the attack target assets; If the asset identifiers do not match, determining that the alarm-related assets and the attack target assets do not match; If the asset identifiers match, comparing the asset versions of the alarm-related assets with the attack target assets; If the asset versions do not match, determining that the alarm-related assets and the attack target assets do not match.
6. The method according to any one of claims 1 to 5, characterized in that Before matching the current alarm information with the alarm information samples in the alarm information attribute table, it includes: Determining the attack target assets of the current alarm information; If the attacked target asset corresponds to a bucket service, filter the current alarm information.
7. An alarm reduction processing device, characterized in that, The device includes: An alarm acquisition module, configured to acquire current alarm information; A sample matching module, configured to match the current alarm information with alarm information samples in an alarm information attribute table; An attribute acquisition module, configured to, if there is a matching alarm information sample, acquire the asset association attribute of the alarm information sample in the alarm information attribute table; An asset matching module, configured to, if the asset association attribute indicates that the alarm information sample is an asset-related alarm, match the alarm-related asset of the alarm information sample with the attacked target asset of the current alarm information; An alarm filtering module, configured to, if the alarm-related asset and the attacked target asset do not match, filter the current alarm information.
8. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 6 are implemented.
10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 6 are implemented.