A city network security multidimensional monitoring management system and method
The city network security multi-dimensional monitoring and management system solves the problem of security products operating independently, realizes centralized management and multi-dimensional monitoring of the city network, improves threat detection and tracing capabilities, reduces operation and maintenance difficulty, and improves analysis efficiency and accuracy.
Patent Information
- Application Number
- CN202510444092.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-10
- Publication Date
- 2026-01-09
- Estimated Expiration
- 2045-04-10
AI Technical Summary
In urban networks, security products operate independently, making it difficult to form a cohesive force. Massive security incidents cannot be maintained, the ability to detect unknown threats is limited, and there is a lack of effective means. Security incidents lack tools to support rapid post-incident handling, tracing, and attack path reconstruction. Various types of security products are difficult to operate and manage in a unified manner, making it impossible to achieve multi-dimensional monitoring and management.
This paper proposes a multi-dimensional monitoring and management system for urban cybersecurity, including a threat perception probe, a full-traffic collector, and a threat perception system. Through centralized management, unified monitoring, and unified upgrades, combined with threat detection, evidence collection and tracing, and coordinated response, it achieves efficient management and multi-dimensional monitoring of various security products.
It enables centralized management of urban cybersecurity, improves threat detection and tracing capabilities, achieves efficient management and multi-dimensional monitoring of various security products, reduces the workload of operations and maintenance personnel, and improves the efficiency and accuracy of threat analysis.
Smart Images

Figure CN120342674B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, in particular to a city network security multi-dimensional monitoring management system and method. BACKGROUND
[0002] In the field of city network, a large number of security products are deployed therein, such as terminal antivirus software products, network boundary protection firewalls, IPS products, network detection IDS, sandbox products, etc. The security products are difficult to form a combined force in a separate battle. Mass security events cannot be maintained, and certain attack clues are missed. Unknown threat detection capability is limited, and APT attack detection lacks effective means. Security events lack post-disaster rapid disposal, tracing, attack path restoration tool support. Various security products are difficult to be uniformly operated and managed, and it is impossible to realize multi-dimensional monitoring and management of city network security. SUMMARY
[0003] The present application aims to at least solve one of the above technical problems. To this end, the purpose of the present application is to propose a city network security multi-dimensional monitoring management system and method, to avoid the separate battle of each security product, to concentrate management, to improve threat detection capability, to trace the source, to realize efficient management of various security products, and to realize multi-dimensional monitoring and management of city network security.
[0004] To achieve the above purpose, the embodiment of the present application proposes a city network security multi-dimensional monitoring management system, comprising:
[0005] A threat perception probe is deployed at the center of the monitored city network unit and each node bypass, and is used for threat detection processing;
[0006] A full-flow collector is deployed at the center of the monitored city network unit and each node bypass, and is used for evidence tracing processing;
[0007] A threat perception system is used for centralized management of the threat perception probe and the full-flow collector of each node; the centralized management includes unified monitoring, unified management, unified upgrade, centralized strategy issuing, threat analysis and threat hunting.
[0008] According to some embodiments of the present application, the threat perception probe comprises:
[0009] A threat perception module is used for overall perception of the overall security situation of the current monitored network, and automatically gives high, medium and low security ratings; global perception capability and threat perception capability of the monitored network are provided;
[0010] The threat detection module adopts a bidirectional detection engine and realizes three-in-one detection based on the combination of event feature detection, threat intelligence detection and sandbox detection; various attack types such as malware exploitation, suspicious behavior, attack exploitation, attack detection, mining events and APT attack events can be detected, and advanced attacks such as DNS malicious domain name request, DGA domain name and DNS tunnel can be detected; encrypted traffic can be detected; protocol metadata can be extracted and detected;
[0011] The scenario analysis module is used for presetting intelligent analysis scenarios and performing scenario analysis processing.
[0012] The multi-dimensional threat analysis module is used for multi-dimensional threat analysis of attack events.
[0013] The asset awareness module is used for asset discovery, detail configuration based on traffic and analysis of asset vulnerability.
[0014] The unknown threat detection module is used for detecting unknown threat behaviors by combining dynamic detection and static detection.
[0015] The threat intelligence detection module has a built-in threat intelligence library for threat intelligence collision, has a separate threat intelligence perspective, and can perform one-key cloud search and view intelligence labels.
[0016] The linkage disposal module is used for disposing alarms in a monitored area, can filter according to a disposal state, supports adding a whitelist, one-key whitening of business triggered alarms, linkage with same brand IPS, WAF, firewall and full-flow trace evidence equipment to block attack behaviors, and linkage with same brand leak scanning equipment to create a leak scanning task in an alarm event interface to verify vulnerabilities of monitored attack events.
[0017] According to some embodiments of the application, the multi-dimensional threat analysis module comprises:
[0018] The first analysis module is used for threat analysis of attack events from different professional perspectives; the professional perspectives include: attacker perspective, attacked person perspective, feature event perspective, sample perspective, threat intelligence perspective, ATT&CK perspective and horizontal movement analysis.
[0019] The second analysis module is used for adopting an ATT&CK tactic matrix analysis perspective, automatically labeling the color depth of the matrix according to the number of alarm events in the matrix tactic, and the matrix includes: investigation, resource deployment, initial access, execution, persistence, privilege escalation, defense bypass, credential acquisition, discovery, lateral movement, collection, command control, information stealing and influence, and the matrix can be drilled down to the corresponding alarm event details.
[0020] The aggregation module is used for alarm aggregation of attackers, attacked assets and alarm events, and can view attacker IP, geographical position, hit intelligence type, recent attack time, attacked IP, attack times, attack success times and attack type, and supports viewing attacker TOP and attacker geographical position distribution TOP, and alarm filtering according to various dimensions.
[0021] According to some embodiments of the present application, the full-flow collector comprises:
[0022] The full-flow storage module is used for recording each network flow data packet from layer 2 to layer 7 based on classification identification technology, and indexing all network data; and provides session log retrieval functions combined with protocol metadata and DPI;
[0023] The forensics module is used for forensics tracing of Pcap packets and metadata;
[0024] The flow playback module is used for playing back historical flow data packets in the form of a network video recorder, providing analysis for security products, and can configure flexible playback strategies, and can restore network flow from layer 2 to layer 7, and can perform lossless and ordered playback as required.
[0025] According to some embodiments of the present application, the unified monitoring comprises basic information of the managed security products, CPU / memory disk usage, interface flow, running time, system version and feature library version.
[0026] According to some embodiments of the present application, the unified management comprises grouping management, state monitoring, single sign-on, feature library upgrade management, DNS management, NTP management, configuration backup and automatic inspection operation of the accessed node security products.
[0027] According to some embodiments of the present application, the threat analysis comprises scenario analysis and multi-dimensional correlation analysis; wherein,
[0028] The scenario analysis is based on an intelligent event correlation analysis engine, and all normalized log streams are counted, and a plurality of scenario correlation analysis functions are provided, including attacker perspective, attacked victim perspective and alarm perspective.
[0029] The multi-dimensional correlation analysis is based on a first type event engine for correlation matching, identifying known attacks, and obtaining a first multi-dimensional correlation analysis result; and based on a second type event engine for correlation matching, identifying unknown attacks, and obtaining a second multi-dimensional correlation analysis result.
[0030] According to some embodiments of the present application, the first type event engine is used for correlation matching, identifying known attacks, and obtaining a first multi-dimensional correlation analysis result, comprising:
[0031] The first type event engine obtains event information, performs continuous wavelet transform and multi-layer wavelet decomposition on the event information, determines low-frequency components and high-frequency components, extracts statistical features of each layer of wavelet coefficients, and obtains multi-scale features corresponding to the event information;
[0032] According to each event dimension, feature data related to the event dimension is screened from the multi-scale features corresponding to the event information, and the feature data under each event dimension is classified to generate static event features and dynamic event features;
[0033] The static event features under each event dimension are subjected to correlation evaluation to generate a first correlation evaluation result, and the dynamic event features under each event dimension are subjected to change trend analysis and correlation evaluation to generate a second correlation evaluation result;
[0034] Based on the first correlation evaluation result and the second correlation evaluation result, a preset multi-dimensional data relationship graph is queried to determine a plurality of correlation nodes and node attributes of each correlation node;
[0035] Based on the plurality of correlation nodes and the node attributes of each correlation node, a correlation path graph is generated to obtain a first multi-dimensional correlation analysis result.
[0036] According to some embodiments of the present application, based on the second type event engine, unknown attacks are identified to obtain a second multi-dimensional correlation analysis result, including:
[0037] The second type event engine provides a visual rule editor based on rule-based correlation analysis, defines correlation rules based on logical expressions and statistical conditions, all log fields can participate in correlation, supports the establishment of single event rules and multi-event rules, and realizes single event correlation and multi-event correlation;
[0038] The second type event engine performs real-time correlation analysis on threat intelligence information and specific information of security events based on threat intelligence-based correlation analysis; the threat intelligence information includes malicious IP addresses, malicious URLs, and malicious domain names; and the specific information of the security events includes source addresses, destination addresses, request domain names, and payload content;
[0039] The second type engine performs scene-based correlation analysis, and comprehensively considers and presents scene-based correlation functions including asset attributes, original message content, geographic location information, attack chains, and time sequences;
[0040] According to the rule-based correlation analysis result, the threat intelligence-based correlation analysis result, and the scene-based correlation analysis result, a second multi-dimensional correlation analysis result is obtained.
[0041] According to some embodiments of the present application, a monitoring management method of a city network security multi-dimension monitoring management system comprises the following steps:
[0042] Performing threat detection processing based on threat perception probes deployed at the center and bypass of each node of the monitored city network unit;
[0043] Performing evidence tracing processing based on full-flow collectors deployed at the center and bypass of each node of the monitored city network unit;
[0044] Concentratedly managing the threat perception probes and full-flow collectors of each node based on the threat perception system; the concentrated management comprises unified monitoring, unified management, unified upgrading, centralized strategy issuing, threat analysis and threat hunting.
[0045] The present application proposes a city network security multi-dimension monitoring management system and method, which avoids that each security product fights independently, and thus improves the threat detection capability, traces and sources, realizes efficient management of various security products, and performs multi-dimension monitoring management on city network security.
[0046] Other features and advantages of the present application will be set forth in the following description, and in part will become apparent to those skilled in the art from the description, or can be learned by practice of the present application. The objects and other advantages of the present application can be achieved and obtained by means of the structure particularly pointed out in the written description and the accompanying drawings.
[0047] The technical solutions of the present application will be further described in detail below with the help of the accompanying drawings and embodiments. BRIEF DESCRIPTION OF DRAWINGS
[0048] The accompanying drawings are used to provide further understanding of the present application, and constitute a part of the specification, and are used to explain the present application together with embodiments of the present application, and do not constitute a limitation on the present application. In the drawings:
[0049] Figure 1 is a block diagram of a city network security multi-dimension monitoring management system according to an embodiment of the present application;
[0050] Figure 2 is a schematic diagram of a city network security multi-dimension monitoring management system according to another embodiment of the present application;
[0051] Figure 3 is a flow chart of a city network security multi-dimension monitoring management method according to an embodiment of the present application. DETAILED DESCRIPTION
[0052] The preferred embodiments of the present application will be described below in conjunction with the accompanying drawings, and it should be understood that the preferred embodiments described herein are only used to explain and illustrate the present application, and do not constitute a limitation on the present application.
[0053] As Figures 1-2 shown, the embodiment of the present application proposes a city network security multi-dimensional monitoring management system, comprising:
[0054] A threat perception probe is deployed in the center and bypass of each node of the monitored city network unit, and is used for threat detection processing;
[0055] A full-flow collector is deployed in the center and bypass of each node of the monitored city network unit, and is used for evidence tracing processing;
[0056] A threat perception system is used for centralized management of the threat perception probe and the full-flow collector of each node; the centralized management includes unified monitoring, unified management, unified upgrade, centralized strategy issuing, threat analysis and threat hunting.
[0057] The working principle of the above technical solution is that the city network security multi-dimensional monitoring management system comprises a threat perception probe, a full-flow collector and a threat perception system. The threat perception probe and the full-flow collector of the composition scheme are respectively deployed to collect user business traffic, the threat perception probe is responsible for threat detection, and the full-flow collector is responsible for evidence tracing. When the threat perception probe product discovers a threat behavior, the full-flow collector can be linked to realize one-key automatic attack full-amount message evidence collection and rapid attack research and analysis. For each stage of the attack chain, the original data can be retrieved through the full-flow collector, and finally the complete attack process can be traced from the clues.
[0058] The above technical solution has the beneficial effects that each security product avoids fighting separately, thereby realizing centralized management, improving threat detection capability, tracing and tracing, realizing efficient management of various types of security products, and multi-dimensional monitoring and management of city network security.
[0059] According to some embodiments of the present application, the threat perception probe comprises:
[0060] A threat perception module is used for overall perception of the overall security situation of the current monitored network, and automatically gives high, medium and low security ratings; and provides global perception capability and threat perception capability of the monitored network;
[0061] A threat detection module adopts a bidirectional detection engine, and realizes trinity detection in a manner of combining event feature detection, threat intelligence detection and sandbox detection; detects various attack types such as malicious software utilization, suspicious behavior, attack utilization, attack detection, mining events and APT attack events, and can simultaneously detect high-level attacks such as DNS malicious domain name request, DGA domain name and DNS tunnel; detects encrypted traffic; and extracts and detects protocol metadata;
[0062] A scene analysis module is configured to preset intelligent analysis scenes and perform scene analysis processing.
[0063] A multi-dimensional threat analysis module is configured to perform multi-dimensional threat analysis on attack events.
[0064] An asset awareness module is configured to perform asset discovery, detail configuration and analysis of asset vulnerability based on asset traffic.
[0065] An unknown threat detection module is configured to detect unknown threat behaviors by combining dynamic detection and static detection.
[0066] A threat intelligence detection module is configured to perform threat intelligence collision by using a built-in threat intelligence library, has a separate threat intelligence perspective, and can perform one-key cloud search and view intelligence labels.
[0067] A linkage disposal module is configured to dispose of alarms in a monitored area, can filter according to a disposal state, supports adding a whitelist, one-key whitening of business triggered alarms, linkage with same brand IPS, WAF, firewall and full-traffic trace evidence devices to block attack behaviors, and linkage with same brand leak scanning devices to create a leak scanning task on an alarm event interface to verify vulnerabilities of monitored attack events.
[0068] The working principle and beneficial effects of the above technical solutions are as follows: the threat awareness module provides global awareness capability for the monitored network, can show attack times, attack trends, high-value events, attack stage analysis, global map attack direction and attack trends, provides threat awareness capability for external attacks, horizontal attacks, malicious external connections, details of compromised hosts, security posture of transmission files and the like of the monitored network, and can view external attack trends, internal network zombie worm event quantity, internal network scanning event quantity, attack IP TOP, attacked IP TOP, external connection country TOP, external connection C2 TOP, external connection host TOP and external connection trend chart and the like threat information.
[0069] The threat detection module adopts a bidirectional detection engine. Compared with the traditional detection method, it can directly give the success of the attack result, and at the same time save the alarm data packet, provide threat tracing and evidence collection capability. It adopts event feature detection + threat intelligence detection + sandbox detection combination, with trinity detection capability. It can detect attack types such as malware exploitation, suspicious behavior, attack exploitation, attack detection, mining events, APT attack events, etc. At the same time, it can detect DNS malicious domain name request, DGA domain name, DNS tunnel and other advanced attacks. In the face of encrypted traffic, the threat perception probe can not only decrypt the TLS encrypted traffic by importing the certificate, but also support JA3 fingerprint detection method to detect malicious software. It supports protocol metadata extraction detection, and can extract metadata from common protocols such as TCP, HTTP, DNS, ICMP, SMTP, POP3, FTP, SMB, IP, TLS, UDP, PPTP, L2TP, MySQL, Telnet, ARP, WebMail, MSSQL, Oracle, IPSecVPN, IMAP, IPV6, etc.
[0070] The scenario analysis module has at least 15 intelligent analysis scenarios, including lost mainframe scenario, attack chain restoration analysis scenario, internal network weak password scenario, vulnerability awareness scenario, externally open high-risk port scenario, active external malicious domain name scenario, DGA domain name scenario, DNS hidden tunnel scenario, malicious email behavior analysis scenario, virtual currency mining special analysis scenario, internal network zombie worm attack scenario, brute force cracking scenario, scanning and detection scenario, DDOS attack scenario, WEB attack detection scenario, suspicious behavior scenario, etc. The threat perception probe can find effective supply and valuable clues from the alarm, and can restore the attack chain completely. Using the current deterministic clue as the center, taking the event name, event label, attacker, attacked, attack result, etc. as the basic information origin point, search forward and backward, find the deterministic clue associated suspicious behavior clues by using historical traffic data, so as to expand the line analysis of the whole attack chain, and generate attack behavior portrait by mapping with ATT&CK model, form a web visualization topology supporting self-defined.
[0071] Through intelligent scenario analysis, the security monitoring capability is projected to each business scenario to meet the multi-dimensional security monitoring demand. For example, the threat perception probe has a mining special analysis scenario to meet the national efforts to crack down on virtual currency mining. Through the mining analysis scenario, you can intuitively view the mining coin distribution pie chart, mining stage statistics chart, mining trend chart and mining host activity, view mining alarm information, mining time, mining host address, mining pool address, mining stage, mining duration and other mining event information, and intuitively locate all mining hosts in the monitoring area.
[0072] The asset awareness module can discover assets based on traffic, automatically assigning discovered assets to corresponding asset groups according to their IP range. It supports both public and private network use and allows for detailed asset configuration, including asset name, asset group, asset type, internal network tag, important asset label, external IP label, system information, location information, asset operation service, responsible person, contact information, and physical location. It can analyze asset vulnerabilities, including high-risk port access, weak password login events, and asset vulnerability detection. Users can view information such as the most recent access time, accessing IP, accessing account, weak password used, accessed asset IP, asset group, asset name, login protocol, password strength, and number of accesses for assets logged in with weak passwords. It also supports downloading the original packets of weak password login processes, providing tracing and evidence preservation.
[0073] The unknown threat detection module employs a combination of dynamic and static detection methods to detect unknown threat behaviors. It has sandbox detection capabilities for over 100 file formats, supports custom file types, and can restore and sandbox-detect files transmitted via SMTP, IMAP, FTP, POP3, SMB, and HTTP. The sandbox can automatically output sample reports, and both sandbox sample reports and original samples can be downloaded. The sample reports automatically display malicious threat tags, and the system can automatically provide a malicious score based on the malicious sample behavior. The malicious behavior of the sample can be expanded with a single click.
[0074] It can inspect compressed files, supporting at least 10 layers of decompression. It can detect anti-sandbox malicious samples, identifying at least five types of anti-sandbox behaviors. It also supports displaying malicious code types with Chinese labels for further sample analysis. It features over seventy virtual sandbox detection environments to meet various unknown threat detection scenarios, and supports full coverage of Windows, Linux, Android, and Kylin operating systems.
[0075] It supports displaying malicious code types using Chinese tags and allows searching by Chinese tags. Customizable YARA rules are available for detection. It can detect network behavior of file samples, record network communication sessions during file execution, and support online viewing of communication session details such as destination IP, destination port, hexadecimal and ASCII format data packet content. It can download files based on sensitive behaviors such as releasing PE files, deleting folders, modifying files, copying itself, and infecting files; it supports detailed recording of file system monitoring operations, including detection of actions such as writing to, deleting, and reading files (folders).
[0076] The threat awareness probe offers a wealth of security analysis reports, providing users and operations personnel with comprehensive reporting content. It supports both manual generation of single reports and periodic report generation, significantly reducing maintenance costs and the workload of administrators.
[0077] The threat perception probe has a data reporting function, supports sending sample detection logs, feature detection logs, metadata logs and JA3 fingerprint logs to a threat perception system through a Kafka interface, and performs secondary unified analysis and display by a set center.
[0078] According to some embodiments of the application, the multi-dimensional threat analysis module comprises:
[0079] The first analysis module is configured to perform threat analysis on the attack event from different professional perspectives, and the professional perspectives include an attacker perspective, an attacked party perspective, a feature event perspective, a sample perspective, a threat intelligence perspective, an ATT&CK perspective and a horizontal movement analysis.
[0080] The second analysis module is configured to adopt an ATT&CK tactic matrix analysis perspective, automatically label the color depth of the matrix according to the number of alarm events in the matrix tactic, and the matrix includes investigation, resource deployment, initial access, execution, persistence, privilege escalation, defense bypass, credential acquisition, discovery, lateral movement, collection, command control, information stealing and influence, and the matrix can be drilled down to the alarm event details.
[0081] The aggregation module is configured to perform alarm aggregation on the attacker, the attacked asset and the alarm event, and can view the attacker IP, the geographic location, the hit intelligence type, the latest attack time, the attacked party IP, the attack times, the attack success times and the attack type, support viewing the attacker TOP and the attacker geographic location distribution TOP, and support alarm filtering according to various dimensions.
[0082] According to some embodiments of the application, the full-flow collector comprises:
[0083] The full-flow storage module is configured to record each network flow data packet from the layer 2 to the layer 7 based on the classification recognition technology, and establish an index for all network data; and provide a session log retrieval function combined with protocol metadata and DPI.
[0084] The forensics module is configured to realize forensics tracing for the Pcap packet and the metadata.
[0085] The flow playback module is configured to play back the historical flow data packet in the form of a network video recorder, provide the security product for analysis, and can configure a flexible playback strategy to restore the network flow from the layer 2 to the layer 7, and perform lossless and ordered playback as needed.
[0086] The working principle and beneficial effects of the above technical solution are: in order to more comprehensively forensics attack behavior, the full-flow collector classifies and identifies each network flow data packet from layer 2 to layer 7, records all network data, and establishes an index to ensure that the original scene of the network security event can be restored completely and truly. At the same time, the full-flow storage module also provides a session log retrieval function combined with protocol metadata and DPI. The session log records the start and end state of the protocol session and the detailed statistics related to the flow, and combines the DPI technology to complete the accurate classification of specific applications. Through the retrieval of the session log, accurate data related to the activity can be efficiently extracted from the massive data, helping security analysts and investigators to quickly find the original evidence of anomalies and threats, and realizing non-controversial evidence extraction.
[0087] Real-time storage records the flow data of the entire network, which brings great challenges to the storage and retrieval performance of the product. At present, many security products on the market have a common shortcoming, that is, when faced with large amount of data backtracking query, they are very slow, even slow to the extent that the product cannot be used.
[0088] The original message forensics module of the full-flow collector has an independent self-developed high-performance storage and retrieval algorithm, has the fastest data retrieval performance in the industry, and the retrieval speed can reach 5TB / s, which can realize second-speed forensics of threats and improve the efficiency of threat analysis.
[0089] The metadata forensics tracing module can analyze the application protocol layer of network flow in real time and full amount, extract metadata for network operation and security operation personnel to perform attack positioning and tracing analysis. After accurate protocol identification by the DPI engine, the metadata analysis engine extracts key fields of the application protocol to generate metadata.
[0090] The full-flow system can extract the application layer protocol of the metadata as follows:
[0091] HTTP: More than 60 fields of HTTP request host, URL, cookie, method, and response status code.
[0092] MAIL: More than 20 fields of SMTP, I MAP, POP3 protocol of mail transmission, sender and receiver of mail, subject of mail, name and type of attachment.
[0093] DNS: More than 20 fields of DNS query type, domain name, and domain name resolution address.
[0094] Database protocol: More than 20 fields of commands and results of common database operations such as MYSQL and ORACLE.
[0095] Socks5 proxy: version of Socks5 proxy, authentication method, command code, target host information, etc.
[0096] FTP: login user of FTP, operation command and result.
[0097] TELNET: TELNET login user and operation command.
[0098] SSH: more than 20 fields of client and server version information of SSH login and server key type.
[0099] TLS: more than 20 fields of version, encryption suite and certificate information of TLS and SSL encryption transmission.
[0100] Customization: users can configure the fields to be extracted according to needs, and can customize the parsing rules to realize flexible parsing of application layer metadata.
[0101] Security personnel can quickly trace the attack behavior according to the application layer metadata characteristics.
[0102] According to some embodiments of the application, the unified monitoring includes basic information of the managed security products, CPU / memory disk usage, interface traffic, running time, system version and feature library version.
[0103] The technical scheme has the beneficial effects that the workload of operation and maintenance personnel is greatly reduced, and the purpose of unified monitoring in one interface is achieved.
[0104] According to some embodiments of the application, the unified management includes grouping management, state monitoring, single sign-on, feature library upgrade management, DNS management, NTP management, configuration backup and automatic inspection operation of the accessed node security products.
[0105] The technical scheme has the beneficial effects that all the accessed security products can be uniformly operated through the centralized management function, and time and labor are saved.
[0106] In an embodiment, unified upgrade: since network security is a dynamic process, the upgrade of the feature library / signature library / intelligence library is extremely important for most security products. In the traditional method, it is quite cumbersome to upgrade the feature library of a large number of security products of different types, and if the configuration is set to be upgraded by each product independently, there are more Internet exposure surfaces, and the access control strategy has to be reconfigured every time with the online of new products or network changes, which increases the operation and maintenance burden.
[0107] The threat perception system itself can be a unified upgrade center of all nodes. On one hand, it can synchronize upgrade packages of various security products from the cloud through an agent or direct connection, and users only need to configure the access permission of the central management sub-center to meet the feature library demand of all products. New online security products also do not need to change the access control rules, and the upgrade server can be directly pointed to the central management sub-center. On the other hand, it will configure and actively respond to the upgrade request of each product, and form a statistical record for the operation and maintenance personnel to analyze.
[0108] In an embodiment, unified policy delivery: the threat perception system supports unified policy delivery function.
[0109] According to some embodiments of the present application, the threat analysis includes scenario analysis and multi-dimensional correlation analysis; wherein,
[0110] The scenario analysis is based on an intelligent event correlation analysis engine, and all normalized log streams are counted and a variety of scenario correlation analysis functions are provided, including attacker perspective, attacked perspective, and alarm perspective.
[0111] The multi-dimensional correlation analysis is based on a first type event engine for correlation matching to identify known attacks and obtain a first multi-dimensional correlation analysis result; and based on a second type event engine for correlation matching to identify unknown attacks and obtain a second multi-dimensional correlation analysis result.
[0112] The working principle of the above technical solution is that the scenario analysis facilitates the display of a specific scene to a security analyst. The first type event engine is an engine for identifying known attacks. The second type event engine is an engine for identifying unknown attacks and is used for predicting unknown attacks.
[0113] The above technical solution has the beneficial effects that the scenario analysis and multi-dimensional correlation analysis are jointly analyzed, and the efficiency and accuracy of threat analysis are improved. Different engines are used for correlation matching of known attacks and unknown attacks in multi-dimensional correlation analysis, and the accuracy of attack identification is improved.
[0114] According to some embodiments of the present application, the first type event engine is used for correlation matching to identify known attacks and obtain a first multi-dimensional correlation analysis result, including:
[0115] The first type event engine obtains event information, performs continuous wavelet transform and multi-layer wavelet decomposition on the event information, determines low-frequency components and high-frequency components, extracts statistical features of each layer of wavelet coefficients, and obtains multi-scale features corresponding to the event information.
[0116] According to each event dimension, the feature data related to the event dimension is screened from the multi-scale feature corresponding to the event information, and the feature data under each event dimension is classified to generate static event features and dynamic event features;
[0117] The static event features under each event dimension are associatedly evaluated to generate a first association evaluation result, and the dynamic event features under each event dimension are analyzed for change trend and associatedly evaluated to generate a second association evaluation result;
[0118] Based on the first association evaluation result and the second association evaluation result, a preset multi-dimensional data relationship graph is queried to determine a plurality of association nodes and node attributes of each association node;
[0119] Based on the plurality of association nodes and the node attributes of each association node, an association path graph is generated to obtain a first multi-dimensional association analysis result.
[0120] The working principle and beneficial effects of the above technical solution are as follows: The first type event engine decomposes the event signal into subbands of different frequencies through continuous wavelet transform (CWT), and the low-frequency component (approximation coefficient) reflects the event baseline behavior, and the high-frequency component (detail coefficient) captures the mutation feature, thereby obtaining the multi-scale feature corresponding to the event information.
[0121] According to each event dimension, the feature data related to the event dimension is screened from the multi-scale feature corresponding to the event information, and the feature data under each event dimension is classified to generate static event features and dynamic event features; for static features (such as event duration and intensity), the inherent properties are described by statistical distribution. The cosine similarity or Jaccard coefficient is used to measure the similarity between feature vectors. Dynamic features (such as change rate and periodicity) need to be combined with time series analysis (such as ARIMA model) to evaluate the evolution trend. The time lag relationship between features is analyzed through cross-correlation function, for example, the time delay mode of malicious software propagation. Based on the first association evaluation result and the second association evaluation result, a preset multi-dimensional data relationship graph is queried, and the static and dynamic combination is used to accurately determine a plurality of association nodes and node attributes of each association node; based on the plurality of association nodes and the node attributes of each association node, an association path graph is generated to obtain a first multi-dimensional association analysis result. The association analysis capability for known attacks is improved, and the dependence on manual rule maintenance is reduced.
[0122] According to some embodiments of the application, based on the second type event engine, unknown attacks are identified to obtain a second multi-dimensional association analysis result, including:
[0123] The second type of event engine is rule-based correlation analysis, which provides a visual rule editor to define correlation rules based on logical expressions and statistical conditions. All log fields can participate in the correlation, and it supports the creation of single-event rules and multi-event rules to achieve single-event correlation and multi-event correlation.
[0124] The second type of event engine is based on the correlation analysis of threat intelligence, which performs real-time correlation analysis between threat intelligence information and security event-specific information; the threat intelligence information includes malicious IP addresses, malicious URLs, and malicious domain names; the security event-specific information includes source address, destination address, request domain name, and payload content;
[0125] The second type of event engine is based on scenario-based correlation analysis, which comprehensively considers and presents scenario-based correlation functions including asset attributes, original message content, geographical location information, attack chain, and time sequence.
[0126] Based on the results of rule-based correlation analysis, threat intelligence-based correlation analysis, and scenario-based correlation analysis, the second multi-dimensional correlation analysis results are obtained.
[0127] The working principle and beneficial effects of the above technical solution: The rule editor allows users to define association rules through logical expressions and statistical conditions. These rules can be applied to a single event (single-event rule) or multiple events (multi-event rule). Logical expressions involve the comparison and combination of event attributes, while statistical conditions involve the frequency and trend of event occurrence. Real-time association between threat intelligence information (such as malicious IP addresses, URLs, and domain names) and security event-specific information (such as source address, destination address, request domain name, and payload content) helps to quickly identify known threat patterns. This association involves exact matching (such as IP address matching) or fuzzy matching (such as domain name similarity detection). Contextualized association functionality comprehensively considers factors such as asset attributes, original message content, geographical location information, attack chains, and time sequences. This analysis helps to understand the full picture of an attack, including the attacker's target, attack path, and attack timeline. Combining the results of the above three association analyses, multi-dimensional association analysis results are generated. These results include information on attack type, attack source, attack target, and attack impact, helping security teams to comprehensively assess threats and take appropriate measures. The association matching method based on the second-type event engine, by combining rules, threat intelligence, and scenario analysis, can comprehensively identify unknown attacks and generate detailed, multi-dimensional association analysis results. This method improves the accuracy and efficiency of threat detection.
[0128] like Figure 3 As shown, according to some embodiments of the present invention, a monitoring and management method for a multi-dimensional monitoring and management system for urban network security includes steps S1-S3:
[0129] S1, threat detection processing based on threat perception probes deployed at the center and bypass of each node of the monitored city network unit;
[0130] S2, evidence tracing processing based on full-flow collectors deployed at the center and bypass of each node of the monitored city network unit;
[0131] S3, centralized management of the threat perception probes and full-flow collectors of each node based on the threat perception system; the centralized management includes unified monitoring, unified management, unified upgrading, centralized policy issuing, threat analysis and threat hunting.
[0132] The beneficial effects of the above technical solutions are: avoiding the individual battles of various security products, and then centralized management, improving the threat detection capability, tracing and tracing, realizing the efficient management of various security products, and multi-dimensional monitoring and management of city network security.
[0133] Obviously, those skilled in the art can make various modifications and variations to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application also intends to include these modifications and variations.
Claims
1. A city network security multi-dimensional monitoring management system, characterized in that, The application relates to a threat perception system for a city network, comprising: a threat perception probe arranged on a bypass of a city network unit center and each node of a monitored city network, used for threat detection processing; a full-flow collector arranged on a bypass of a city network unit center and each node of a monitored city network, used for forensics tracing processing; a threat perception system used for centralized management of threat perception probes and full-flow collectors of each node; the centralized management comprises unified monitoring, unified management, unified upgrading, centralized strategy issuing, threat analysis and threat hunting; the threat perception probe comprises: a threat perception module used for overall perception of a current monitored network security situation, automatic high, medium and low security rating, global perception and threat perception of the monitored network; a threat detection module adopting a bidirectional detection engine, based on a combination of event feature detection, threat intelligence detection and sandbox detection to realize three-in-one detection; the module is used for detection of various attack types such as malicious software utilization, suspicious behavior, attack utilization, attack detection, mining events and APT attack events, detection of DNS malicious domain name requests, DGA domain names and DNS tunnel advanced attacks, detection of encrypted traffic and extraction and detection of protocol metadata; a scenario analysis module used for preset intelligent analysis scenarios and scenario analysis processing; a multi-dimensional threat analysis module used for multi-dimensional threat analysis of attack events; an asset perception module used for asset discovery, detail configuration and analysis of asset vulnerability based on flow; an unknown threat detection module used for detection of unknown threat behaviors by combining dynamic detection and static detection; a threat intelligence detection module with a built-in threat intelligence database for threat intelligence collision, a separate threat intelligence perspective and one-key cloud checking of threat intelligence labels; a linkage disposal module used for disposal of alarms in a monitored region, filtering according to disposal states, adding a white list, one-key white adding of business triggered alarms, linkage with same brand IPS, WAF, firewall and full-flow forensics tracing equipment for linkage blocking of attack behaviors, linkage with same brand leak scanning equipment for one-key creation of a leak scanning task for verification of monitored attack events; the multi-dimensional threat analysis module comprises: a first analysis module used for threat analysis of attack events from different professional perspectives; the professional perspectives comprise an attacker perspective, an attacked person perspective, a feature event perspective, a sample perspective, a threat intelligence perspective, an ATT&CK perspective and horizontal movement analysis; a second analysis module used for analysis of an ATT&CK tactic matrix perspective, automatic marking of matrix color depth according to alarm event quantity of a matrix tactic, and the matrix comprises investigation, resource deployment, initial access, execution, persistence, privilege escalation, defense bypass, credential acquisition, discovery, horizontal movement, collection, command control, information stealing and influence, and the matrix can be drilled into corresponding alarm event details. The aggregation module is used for alarm aggregation of attackers, attacked assets and alarm events, and can view attacker IP, geographical position, hit intelligence type, latest attack time, attacked IP, attack times, attack success times and attack type, and supports viewing attacker TOP and attacker geographical position distribution TOP, and alarm filtering according to various dimensions; The full-flow collector comprises: The full-flow storage module is used for recording each network flow data packet from layer 2 to layer 7 based on a classification recognition technology, and indexing all network data; and provides a session log retrieval function combined with protocol metadata and DPI; The evidence module is used for evidence tracing of Pcap packets and metadata; The flow playback module is used for playing back historical flow data packets in the form of a network video recorder, providing analysis for security products, and can configure flexible playback strategies, and can restore network flow from layer 2 to layer 7, and can perform lossless and ordered playback as required; The threat analysis comprises scenario analysis and multi-dimensional correlation analysis; wherein, The scenario analysis is based on an intelligent event correlation analysis engine, and all normalized log streams are counted, and a plurality of scenario correlation analysis functions are provided, including an attacker perspective, an attacked asset perspective and an alarm perspective; The multi-dimensional correlation analysis is based on a first type event engine for correlation matching, identifying known attacks, and obtaining a first multi-dimensional correlation analysis result; and based on a second type event engine for correlation matching, identifying unknown attacks, and obtaining a second multi-dimensional correlation analysis result.
2. The urban network security multi-dimensional monitoring management system of claim 1, wherein, The unified monitoring comprises basic information of managed security products, CPU / memory / disk usage, interface flow, running time, system version and feature library version.
3. The urban network security multi-dimensional monitoring management system of claim 1, wherein, The unified management comprises grouping management, state monitoring, single sign-on, feature library upgrade management, DNS management, NTP management, configuration backup and automatic inspection operation of the accessed node security products.
4. The urban network security multi-dimensional monitoring management system of claim 1, wherein, The first type event engine obtains event information, performs continuous wavelet transform and multi-layer wavelet decomposition on the event information, determines low-frequency components and high-frequency components, extracts statistical features of each layer wavelet coefficient, and obtains multi-scale features corresponding to the event information; According to each event dimension, feature data related to the event dimension is screened from the multi-scale features corresponding to the event information, and the feature data under each event dimension is classified to generate static event features and dynamic event features; The static event features under each event dimension are subjected to correlation evaluation to generate a first correlation evaluation result; and the dynamic event features under each event dimension are subjected to change trend analysis and correlation evaluation to generate a second correlation evaluation result; Based on the first correlation evaluation result and the second correlation evaluation result, a preset multi-dimensional data relationship graph is queried to determine a plurality of correlation nodes and node attributes of each correlation node; Based on the plurality of correlation nodes and the node attributes of each correlation node, a correlation path graph is generated to obtain the first multi-dimensional correlation analysis result. 5. The urban network security multi-dimensional monitoring management system of claim 1, wherein, Based on the second type of event engine for correlation matching, identify unknown attacks, get the second multi-dimensional correlation analysis results, including: Second type of event engine based on rule-based correlation analysis, provides a visual rule editor, define based on logical expressions and statistical conditions of the correlation rules, all log fields can participate in the correlation, support to establish single event rules and multi-event rules, to achieve single event correlation and multi-event correlation; Second type of event engine based on threat intelligence correlation analysis, real-time correlation analysis of threat intelligence information and security event specific information; The threat intelligence information includes malicious IP address, malicious URL, malicious domain name; The security event specific information includes source address, destination address, request domain name, payload content; Second type of event engine based on scene correlation analysis, comprehensive consideration and presentation of scene-based correlation function including asset attributes, original message content, geographic location information, attack chain, timing; According to the rule-based correlation analysis results, the threat intelligence correlation analysis results and the scene-based correlation analysis, get the second multi-dimensional correlation analysis results.
6. The monitoring management method of the urban network security multi-dimension monitoring management system according to any one of claims 1-5, characterized in that, Including: Based on the threat detection processing of the threat perception probe deployed in the center and each node bypass of the monitored city network unit; Based on the evidence tracing processing of the full flow collector deployed in the center and each node bypass of the monitored city network unit; Based on the threat perception system for centralized management of the threat perception probe and the full flow collector of each node; The centralized management includes unified monitoring, unified management, unified upgrade, centralized strategy issuing, threat analysis and threat hunting.
Citation Information
Patent Citations
Comprehensive urban network space governance system
CN107958322A
Network security perception system and method, and readable storage medium
CN107995162A