Security event response method and device, computer equipment and storage medium
Through the integrated security incident response method of instant messaging platform, security personnel and new personnel handle alarm events on one platform, solving the problem of low operational efficiency caused by multi-system handover and achieving efficient security incident handling.
Patent Information
- Application Number
- CN202510776285.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-11
- Publication Date
- 2025-07-22
AI Technical Summary
In the prior art, security operators need to frequently switch between multiple independent systems when handling security incidents, resulting in inefficient operation.
By implementing the response method of security incidents in the instant messaging platform, security personnel can process alarm event information on one platform and add auxiliary personnel through the interface input commands. The instant messaging platform will automatically send the alarm event information to the new personnel terminal. The new personnel enter the processing information through the interface and send it back to the platform to complete the event processing.
It realizes efficient handling of security incidents without frequent switching between multiple systems, improving operational efficiency.
Smart Images

Figure CN120358076A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular, to a method, device, computer device, and storage medium for responding to security incidents. Background Art
[0002] With the continuous growth of the speed and scale of network attacks, relying solely on manual response to security incidents has become difficult to meet the modern network security requirements. In related technologies, a Security Operations Center (SOC) is used to issue event alerts for corresponding security incidents for security operation personnel to handle the incidents. However, various security systems are usually independent of each other and lack unified management. When security operation personnel judge and handle incidents, they need to frequently switch between multiple systems, seriously affecting the operation efficiency. Summary of the Invention
[0003] Based on this, it is necessary to provide a method, device, computer device, and storage medium for responding to security incidents that can improve operation efficiency for the above technical problems.
[0004] In a first aspect, the present application provides a method for responding to security incidents, which is applied to an instant messaging platform. The method includes: in response to the alarm event information sent by the security operation platform, sending the alarm event information to the security personnel terminal; wherein, the security personnel terminal displays a first event processing interface based on the alarm event information; in response to the personnel addition instruction input on the first event processing interface, sending the personnel addition instruction to the security operation platform; wherein, the security operation platform determines the new personnel information based on the personnel addition instruction; determining the new personnel terminal based on the new personnel information, and sending the alarm event information to the new personnel terminal; wherein, the new personnel terminal displays a second event processing interface based on the alarm event information; in response to the first event processing information input on the second event processing interface, sending the first event processing information to the security operation platform; wherein, the first event processing information is used for the security operation platform to process the event based on the alarm event information.
[0005] In one embodiment, after the step of responding to the alarm event information sent by the security operation platform, the method further includes: sending the alarm event information to the responsible person terminal; wherein, the responsible person terminal displays an operation judgment interface based on the alarm event information; in response to the personal operation instruction input on the operation judgment interface, sending the personal operation information to the security personnel terminal.
[0006] In one embodiment, after the step of sending the alarm event information to the responsible person's terminal, the method further includes: in response to a non-self-operation instruction input on the operation judgment interface, sending non-self-operation information to the security personnel's terminal through a group; wherein, the group is used for information interaction between the security personnel's terminal and the responsible person's terminal at the same time; in response to second event processing information input on the group, sending the second event processing information to the security operation platform; wherein, the second event processing information is used for the security operation platform to perform event processing based on the alarm event information.
[0007] In one embodiment, after the step of sending the alarm event information to the responsible person's terminal, the method further includes: in the case where the self-operation instruction or the non-self-operation instruction is not received within a preset time, sending an alarm prompt message to the responsible person's terminal and the security personnel's terminal through the group; wherein, the preset time is determined by the event level of the alarm event information.
[0008] In one embodiment, after the step of responding to the self-operation instruction input on the operation judgment interface, the method further includes: in response to an application for whitelisting instruction input on the operation judgment interface, sending the application for whitelisting instruction to the security operation platform; wherein, the security operation platform schedules an office automation system to generate a whitelisting work order based on the application for whitelisting instruction; sending whitelisting judgment information to the security personnel's terminal; wherein, the whitelisting judgment information is determined by the whitelisting work order, and the security personnel's terminal displays a whitelisting judgment interface based on the whitelisting judgment information; in response to a whitelisting approval instruction input on the whitelisting judgment interface, sending the whitelisting approval instruction to the security operation platform; wherein, the security operation platform performs a blocking process or a whitelisting process based on the whitelisting approval instruction.
[0009] In one embodiment, the security operation platform is used to obtain log information sent by multiple security devices, and the security operation platform is used to determine the alarm event information according to the multiple log information.
[0010] In one embodiment, the log information includes at least one of: data security risk log, threat intelligence risk log, dynamic decision-making and disposal log, virus killing log, compliance baseline log, and security device health monitoring log.
[0011] Second aspect, the present application further provides a response device for security events, which is applied to an instant messaging platform. The device includes: a first alarm information sending module, configured to send the alarm event information to a security personnel terminal in response to the alarm event information sent by the security operation platform; wherein, the security personnel terminal displays a first event processing interface based on the alarm event information; an adding instruction sending module, configured to send the personnel adding instruction to the security operation platform in response to the personnel adding instruction input on the first event processing interface; wherein, the security operation platform determines the newly added personnel information based on the personnel adding instruction; a second alarm information sending module, configured to determine the newly added personnel terminal based on the newly added personnel information, and send the alarm event information to the newly added personnel terminal; wherein, the newly added personnel terminal displays a second event processing interface based on the alarm event information; an event processing information sending module, configured to send the first event processing information to the security operation platform in response to the first event processing information input on the second event processing interface; wherein, the first event processing information is used for the security operation platform to process the event based on the alarm event information.
[0012] Third aspect, the present application further provides a computer device. The computer device includes a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, the steps of the above method are implemented.
[0013] Fourth aspect, the present application further provides a computer-readable storage medium. The computer-readable storage medium stores a computer program thereon, and when the computer program is executed by a processor, the steps of the above method are implemented.
[0014] For the above security event response method, device, computer device and storage medium, the alarm event information sent by the security operation platform is responded to through the instant messaging platform and sent to the security personnel terminal. When the security personnel determines that others are needed to assist in the processing, a personnel adding instruction is input through the first event processing interface. At this time, the instant messaging platform will send the personnel adding instruction to the security operation platform so that the security operation platform determines the newly added personnel information. After the instant messaging platform determines the newly added personnel terminal based on the newly added personnel information, the alarm event information is sent to the newly added personnel terminal. After the newly added personnel inputs the first event processing information through the second event processing interface, the instant messaging platform will send the first event processing information to the security operation platform, enabling the security operation platform to process the event based on the alarm event information, thereby completing the response processing of the security event. The security personnel and the newly added personnel of the present application can complete the handling of the alarm event through the instant messaging platform without frequently switching between multiple systems, thereby improving the operation efficiency. Description of the Drawings
[0015] Figure 1 It is an application environment diagram of the response method for security events in an embodiment;
[0016] Figure 2 It is a schematic flowchart of the response method for security events in an embodiment;
[0017] Figure 3 It is a schematic flowchart of the process for self-operation in an embodiment;
[0018] Figure 4 It is a schematic flowchart of the process for non-self-operation in an embodiment;
[0019] Figure 5 It is a schematic flowchart of the process for giving an alarm prompt in an embodiment;
[0020] Figure 6 It is a schematic flowchart of the process for adding a whitelist in an embodiment;
[0021] Figure 7 It is a schematic diagram of the modules of the response device for security events in an embodiment;
[0022] Figure 8 It is an internal structure diagram of a computer device in an embodiment. Detailed implementation manners
[0023] In order to make the objectives, technical solutions and advantages of the present application clearer and more understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0024] The response method for security events provided by the embodiments of the present application can be applied to an application environment as shown in Figure 1 . Among them, the security operation platform is communicatively connected to a plurality of security devices, and the security operation platform is also communicatively connected to an instant messaging platform. The instant messaging platform is communicatively connected to user terminals (security personnel terminals and new personnel terminals) to perform information interaction among various devices and platforms. The terminal device can be a personal computer, a laptop computer, a smart phone, a tablet computer, etc.
[0025] In one embodiment, as shown in Figure 2 , a response method for security events is provided. Taking the case where the method is applied to the instant messaging platform in Figure 1 as an example, the method includes the following steps:
[0026] Step S111, in response to the alarm event information sent by the security operation platform, send the alarm event information to the security personnel terminal.
[0027] Specifically, the security operation platform is used to obtain the log information sent by security devices, and then process the log information based on a preset filtering engine to identify security events (such as malicious programs, risky operations, etc.) and obtain corresponding alarm event information. The alarm event information contains key contents such as the type, level, occurrence time, and relevant asset information of the event. After detecting the alarm event information, the security operation platform will send the alarm event information to the instant messaging platform.
[0028] After receiving the alarm event information sent by the security operation platform, the instant messaging platform, according to the previous settings, first pushes the alarm event information to the security personnel terminal. The security personnel terminal is the terminal device of security operation personnel. After receiving the corresponding alarm event information, the security personnel terminal will display the alarm event information on the first event processing interface according to the preset display rules (such as message push, pop-up prompt, etc.). The first event processing interface is an interface with interaction ability and display ability. The security operation personnel determine whether to process and what kind of processing to perform based on the alarm information displayed on the first event processing interface. In some embodiments, when the security operation personnel input corresponding event processing information through the first event processing interface, the security personnel terminal will send the event processing information to the instant messaging platform, and then the instant messaging platform will forward the event processing information to the security operation platform to complete the corresponding event processing. The event processing information includes the confirmation of the alarm event, disposal means, disposal suggestions, etc.
[0029] Step S112: In response to the personnel addition instruction input on the first event processing interface, send the personnel addition instruction to the security operation platform.
[0030] Specifically, the first event processing interface in this embodiment can obtain the personnel addition instruction, and the personnel addition instruction is used to instruct the security operation platform to determine the new personnel information. For example, a "Add processing personnel" button is displayed on the first event processing interface. After the security operation personnel determine that they cannot handle the current alarm event themselves, they can trigger the personnel addition instruction through the first event processing interface. After receiving the personnel addition instruction, the instant messaging platform will send the personnel addition instruction to the security operation platform. In some embodiments, the personnel addition instruction includes: alarm event type, security personnel ID, etc.
[0031] Step S113: Determine the new personnel terminal based on the new personnel information, and send the alarm event information to the new personnel terminal.
[0032] Specifically, after the security operation platform obtains the personnel addition instruction, it determines the information of the newly added personnel according to the preset personnel relationship (such as the organizational structure). For example, it can use the security personnel ID in the personnel addition instruction to take their direct superior as the information of the newly added personnel; or, according to the alarm event type in the personnel addition instruction, it determines the personnel who can handle the corresponding security event and takes their personnel information as the information of the newly added personnel. After the security operation platform determines the information of the newly added personnel, it will send the information of the newly added personnel to the instant messaging platform.
[0033] After the instant messaging platform obtains the information of the newly added personnel sent by the security operation platform, it determines the terminals of the newly added personnel that need subsequent processing according to the corresponding relationship between the information of the newly added personnel and the terminals of the newly added personnel. After the instant messaging platform determines the terminals of the newly added personnel, it sends the alarm event information to the terminals of the newly added personnel again. After the terminals of the newly added personnel obtain the alarm event information, they will display the alarm event information on the second event processing interface according to the preset display rules (such as message push, pop-up prompt, etc.). The second event processing interface is an interface with interaction ability and display ability. The newly added personnel determine whether to handle and what kind of handling to perform through the alarm information displayed on the second event processing interface.
[0034] Step S114, in response to the first event processing information input on the second event processing interface, send the first event processing information to the security operation platform.
[0035] Specifically, when the newly added personnel input the corresponding first event processing information through the second event processing interface, the terminal of the newly added personnel will send the first event processing information to the instant messaging platform. After the instant messaging platform receives the first event processing information, it forwards it to the security operation platform, so that the security operation platform can complete the corresponding event processing. The first event processing information includes the confirmation of the alarm event, the disposal means, the disposal suggestions, etc.
[0036] The response method for the above security incidents responds to the alarm event information sent by the security operation platform through an instant messaging platform and sends the alarm event information to the security personnel terminal. When the security personnel determine that others are needed to assist in handling, they input a personnel addition instruction through the first event processing interface. At this time, the instant messaging platform will send the personnel addition instruction to the security operation platform so that the security operation platform can determine the newly added personnel information. After the instant messaging platform determines the newly added personnel terminal through the newly added personnel information, it will send the alarm event information to the newly added personnel terminal. After the newly added personnel input the first event processing information through the second event processing interface, the instant messaging platform will send the first event processing information to the security operation platform, enabling the security operation platform to process the event based on the alarm event information, thereby completing the response processing of the security incident. The security personnel and the newly added personnel in this application can complete the handling of alarm events through the instant messaging platform without frequently switching between multiple systems, thus improving the operation efficiency.
[0037] In one embodiment, as Figure 3 shown, after the step of responding to the alarm event information sent by the security operation platform in step S111, the response method for the security incident further includes:
[0038] Step S121, sending the alarm event information to the responsible person terminal.
[0039] Specifically, in this embodiment, the user terminal further includes a responsible person terminal, and the responsible person terminal is the terminal device of the person directly related to the alarm event information, and it is generally the responsible person of the corresponding security device. After the instant messaging platform obtains the alarm event information sent by the security operation platform, it will simultaneously send the alarm event information to the responsible person terminal. After receiving the alarm event information, the responsible person terminal will display an operation judgment interface based on the alarm event information according to the preset display rules. The operation judgment interface is used to judge whether the relevant alarm event information is triggered by the responsible person or an authorized user. For example, buttons such as "operated by myself" and "not operated by myself" can be displayed in the operation judgment interface, and corresponding instructions are triggered through the buttons; or the user can input corresponding instructions in the chat window.
[0040] Step S122, in response to the "operated by myself" instruction input through the operation judgment interface, sending the "operated by myself" information to the security personnel terminal.
[0041] Specifically, the responsible person determines whether this operation is their own by operating and judging the relevant content of the alarm event displayed on the operation judgment interface. If it is their own operation, the responsible person can input their own operation instruction through the operation judgment interface. After the instant messaging platform receives the corresponding operation instruction of the responsible person, it will send the corresponding operation information of the responsible person to the security personnel terminal to prompt the security operation personnel that this security event is triggered by the responsible person's own operation. For example, the operation information of the responsible person is a text message such as "This is my own operation, please confirm".
[0042] In one embodiment, as Figure 4 shown, after the step of sending the alarm event information to the responsible person's terminal in step S121, the response method for the security event further includes:
[0043] Step S123, in response to a non-own operation instruction input on the operation judgment interface, send the non-own operation information to the security personnel terminal through a group.
[0044] Specifically, after the instant messaging platform sends the alarm event information to the responsible person's terminal, if the responsible person determines that it is not their own operation, the responsible person can input a non-own operation instruction through the operation judgment interface. After the instant messaging platform receives the corresponding non-own operation instruction, it will automatically create a group for information interaction between the security personnel terminal and the responsible person's terminal. In some other embodiments, direct communication can also be established between the security personnel terminal and the responsible person's terminal to synchronize relevant information.
[0045] Step S124, in response to the second event processing information input through the group, send the second event processing information to the security operation platform.
[0046] Specifically, both the security personnel terminal and the responsible person's terminal can input the second event processing information through the group. The second event processing information is used for the security operation platform to perform event processing based on the alarm event information. When the instant messaging platform receives the corresponding second event processing information, it will forward it to the security operation platform, enabling the security operation platform to complete the corresponding event processing. The second event processing information includes confirmation of the alarm event, disposal means, disposal suggestions, etc.
[0047] In one embodiment, as Figure 5 shown, after the step of sending the alarm event information to the responsible person's terminal in step S121, the response method for the security event further includes:
[0048] Step S125, in the case of not receiving the own operation instruction or the non-own operation instruction within the preset time, send an alarm prompt message to the responsible person's terminal and the security personnel terminal through the group.
[0049] Specifically, when the instant messaging platform sends the alarm event information to the responsible person's terminal, the responsible person's terminal will display an operation judgment interface based on the alarm event information according to the preset display rules. If the instant messaging platform does not receive the operation instruction of the person himself or the operation instruction of a non-person within the preset time, it means that the responsible person has not disposed of it in time. At this time, the instant messaging platform will automatically create a group and then send an alarm prompt message to the responsible person's terminal and the security personnel's terminal through the group to prompt the relevant personnel to dispose of this alarm. It can be understood that the preset time is determined by the event level of the alarm event information. The higher the event level of the alarm event information, the shorter the preset time, and it can be set according to the specific response time requirements.
[0050] In one embodiment, as Figure 6 shown, after the step of responding to the operation instruction of the person himself input in the operation judgment interface in step S122, the response method of the security event further includes:
[0051] Step S126, in response to the application for whitelisting instruction input in the operation judgment interface, send the application for whitelisting instruction to the security operation platform.
[0052] Specifically, in this embodiment, after the responsible person inputs the operation instruction of the person himself in the operation judgment interface, the responsible person's terminal can also receive the application for whitelisting instruction, and the application for whitelisting instruction is used to instruct the security operation platform to dispatch the office automation system to generate a whitelisting work order. For example, after the responsible person inputs the operation instruction of the person himself in the operation judgment interface, the operation judgment interface will display buttons of "Apply for Whitelisting" and "Cancel Whitelisting", and trigger the corresponding instructions through the buttons. When the responsible person inputs the application for whitelisting instruction through the operation judgment interface, the instant messaging platform will obtain the corresponding application for whitelisting instruction and forward it to the security operation platform. After receiving the application for whitelisting instruction, the security operation platform will dispatch the office automation system to generate a whitelisting work order based on the application for whitelisting instruction. The security operation platform of this embodiment can interact with the office automation system. The security operation platform determines the corresponding applicant information, application reason, whitelisting time limit, etc. according to the obtained application for whitelisting instruction, and controls the office automation system to generate a whitelisting work order based on this information. It can be understood that the whitelisting work order includes the information of the approval personnel.
[0053] Step S127, send the whitelisting judgment information to the security personnel's terminal.
[0054] Specifically, when the office automation system performs process approval on the whitelisting work order based on the information of the approvers, when it is determined that the security operation personnel are required to approve the whitelisting work order, the office automation system will send the corresponding control instruction to the security operation platform. After receiving the corresponding control instruction, the security operation platform will send the whitelisting judgment information determined by the whitelisting work order to the security personnel terminal through the instant messaging platform. After receiving the whitelisting judgment information, the security personnel terminal displays the whitelisting judgment interface based on the whitelisting judgment information. For example, after displaying the information in the corresponding whitelisting work order, "Approve Whitelisting" and "Reject Whitelisting" buttons are displayed.
[0055] Step S128, in response to the whitelisting approval instruction input on the whitelisting judgment interface, send the whitelisting approval instruction to the security operation platform.
[0056] Specifically, after the security operation personnel input the corresponding whitelisting approval instruction through the whitelisting judgment interface, the security personnel terminal will send the whitelisting approval instruction (such as the approve whitelisting instruction, reject whitelisting instruction, further review instruction, etc.) to the instant messaging platform. After obtaining the whitelisting approval instruction, the instant messaging platform forwards it to the security operation platform. After receiving the whitelisting approval instruction, the security operation platform performs blocking processing or whitelisting processing based on the whitelisting approval instruction.
[0057] In one embodiment, the security operation platform is used to obtain the log information sent by multiple security devices, and the security operation platform is used to determine the alarm event information based on the multiple log information. Specifically, after the security device generates the log information, the rule engine in the security operation platform can generate the alarm event information according to the preset alarm and filtering rules, in combination with multi-source log data, enriched asset information, and threat intelligence. In one embodiment, the log information includes: data security risk log, threat intelligence risk log, dynamic decision-making and disposal log, virus killing log, compliance baseline log, security device health monitoring log, etc. By filtering low-risk and false alarm reports through the security operation platform, the response efficiency of security operations can be significantly improved.
[0058] In one embodiment, a log collection component (such as syslog, Apache Kafka) is used to collect and forward the log information sent by multiple security devices. The log collection component can send the collected log information to the data analysis component (such as SIEM). After the data analysis component performs normalization processing on the log information, it pushes it to the distributed stream processing component (such as Kafka) in the security operation platform. When the security operation platform needs to use the log information, it can directly pull the log information from the distributed stream processing component.
[0059] The following describes in detail the response method for security events of the present application with a specific embodiment. After receiving the alarm event information sent by the security operation platform, the instant messaging platform will forward the alarm event information to the security personnel terminal and the responsible person terminal. After receiving the alarm event information, if the security personnel determine that they are unable to handle it, they will send a personnel addition instruction to the security operation platform through the instant messaging platform. After receiving the personnel addition instruction, the security operation platform will return the newly added personnel information. The instant messaging platform will determine the newly added personnel terminal based on the newly added personnel information and re-send the alarm event information to the newly added personnel terminal to obtain the first event handling information. After receiving the alarm event information, the responsible person will determine whether the current security event is an operation by himself / herself. In the case of his / her own operation, the instant messaging platform will respond to the operation instruction of the responsible person and send the operation information of the responsible person to the security personnel terminal; in the case of not his / her own operation, the instant messaging platform will create a group to interact with the security personnel terminal and the responsible person terminal to determine the corresponding event handling information. If the responsible person does not make a judgment within the preset time, the instant messaging platform will create a group and send alarm prompt information to the security personnel terminal and the responsible person terminal respectively to prompt the relevant personnel to handle it. In the case of handling by himself / herself, the responsible person will also determine whether to apply for whitelisting. When applying for whitelisting is required, the security operation platform will obtain the whitelisting application instruction through the instant messaging platform and dispatch the office automation system to generate the corresponding whitelisting work order. The office automation system is used to execute the corresponding approval process; when security operation personnel approval is required, the office automation system will interact with the security operation platform to enable the security operation platform to send the whitelisting judgment information to the security personnel terminal through the instant messaging platform. After the security personnel terminal returns the corresponding whitelisting approval instruction through the instant messaging platform, the security operation platform will perform blocking processing or whitelisting processing based on the whitelisting approval instruction. Through the response method for security events of this embodiment, the full-cycle management of security events can be realized, so that the closed-loop of alarm notification, research and judgment, and disposal can be completed on the instant messaging platform. The operation personnel do not need to log in to each independent security system anymore, which greatly improves the convenience and efficiency of event handling. And through the office automation system, the dynamic process management of complex events is realized, including work order initiation, approval node synchronization, and status feedback. At the same time, the whitelisting operation can be automated, effectively improving the event response speed.
[0060] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.
[0061] Based on the same inventive concept, an embodiment of the present application further provides a response device for implementing the response method for the security events involved above. The solution provided by this device to solve the problem is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the response device for security events provided below can refer to the limitations on the response method for security events in the above text, and will not be repeated here.
[0062] In one embodiment, as Figure 7 shown, a response device for security events is provided, which is applied to an instant messaging platform. The response device includes:
[0063] A first alarm information sending module 211, configured to send alarm event information to a security personnel terminal in response to alarm event information sent by a security operation platform; wherein, the security personnel terminal displays a first event processing interface based on the alarm event information;
[0064] An add instruction sending module 212, configured to send an add personnel instruction to the security operation platform in response to an add personnel instruction input on the first event processing interface; wherein, the security operation platform determines new personnel information based on the add personnel instruction;
[0065] A second alarm information sending module 213, configured to determine a new personnel terminal based on the new personnel information and send the alarm event information to the new personnel terminal; wherein, the new personnel terminal displays a second event processing interface based on the alarm event information;
[0066] An event processing information sending module 214, configured to send first event processing information to the security operation platform in response to first event processing information input on the second event processing interface; wherein, the first event processing information is used for the security operation platform to process the event based on the alarm event information.
[0067] In one embodiment, the response device further includes:
[0068] The third alarm information sending module is used to send alarm event information to the responsible person's terminal; wherein, the responsible person's terminal displays an operation judgment interface based on the alarm event information;
[0069] The first operation information sending module is used to send the personal operation information to the security personnel's terminal in response to the personal operation instruction input on the operation judgment interface.
[0070] In one embodiment, the response device further includes:
[0071] The second operation information sending module is used to send the non-personal operation information to the security personnel's terminal through a group in response to the non-personal operation instruction input on the operation judgment interface; wherein, the group is used for information interaction between the security personnel's terminal and the responsible person's terminal at the same time;
[0072] The event processing information sending module 214 is further used to send the second event processing information to the security operation platform in response to the second event processing information input by the group; wherein, the second event processing information is used for the security operation platform to perform event processing based on the alarm event information.
[0073] In one embodiment, the response device further includes: an alarm prompt module, which is used to send alarm prompt information to the responsible person's terminal and the security personnel's terminal through a group in the case of not receiving a personal operation instruction or a non-personal operation instruction within a preset time; wherein, the preset time is determined by the event level of the alarm event information.
[0074] In one embodiment, the response device further includes: a whitelisting processing module, which is used to send the whitelisting application instruction to the security operation platform in response to the whitelisting application instruction input on the operation judgment interface; wherein, the security operation platform schedules the office automation system to generate a whitelisting work order based on the whitelisting application instruction; sends the whitelisting judgment information to the security personnel's terminal; wherein, the whitelisting judgment information is determined by the whitelisting work order, and the security personnel's terminal displays a whitelisting judgment interface based on the whitelisting judgment information; sends the whitelisting approval instruction to the security operation platform in response to the whitelisting approval instruction input on the whitelisting judgment interface; wherein, the security operation platform performs a blocking process or a whitelisting process based on the whitelisting approval instruction.
[0075] In one embodiment, the security operation platform is used to obtain the log information sent by multiple security devices, and the security operation platform is used to determine the alarm event information according to the multiple log information.
[0076] In one embodiment, the log information includes at least one of: data security risk log, threat intelligence risk log, dynamic decision-making and disposal log, virus killing log, compliance baseline log, and security device health monitoring log.
[0077] Each module in the above-mentioned security event response device can be implemented in whole or in part by software, hardware, or a combination thereof. Each of the above modules can be embedded in the processor of the computer device in hardware form or independent of the processor, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each of the above modules.
[0078] In one embodiment, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 8 shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals through a network connection. When the computer program is executed by the processor, it implements a method for responding to security events.
[0079] Those skilled in the art can understand that Figure 8 the structure shown in
[0080] is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have a different component layout.
[0081] In one embodiment, a computer device is provided, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, it implements the steps in each of the above method embodiments.
[0082] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., and are not limited thereto. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., and are not limited thereto.
[0083] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0084] The above-described embodiments merely represent several implementation manners of the present application. Their descriptions are relatively specific and detailed, but they should not be construed as limiting the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.
Claims
1. A method for responding to security incidents, characterized in that, Applied to an instant messaging platform, the method includes: In response to the alarm event information sent by the security operation platform, sending the alarm event information to the security personnel terminal; wherein, the security personnel terminal displays a first event processing interface based on the alarm event information; In response to the personnel addition instruction input on the first event processing interface, sending the personnel addition instruction to the security operation platform; wherein, the security operation platform determines the new personnel information based on the personnel addition instruction; Determining the new personnel terminal based on the new personnel information, and sending the alarm event information to the new personnel terminal; wherein, the new personnel terminal displays a second event processing interface based on the alarm event information; In response to the first event processing information input on the second event processing interface, sending the first event processing information to the security operation platform; wherein, the first event processing information is used for the security operation platform to process the event based on the alarm event information.
2. The response method for security events according to claim 1, wherein After the step of responding to the alarm event information sent by the security operation platform, the method further includes: Sending the alarm event information to the responsible person terminal; wherein, the responsible person terminal displays an operation judgment interface based on the alarm event information; In response to the personal operation instruction input on the operation judgment interface, sending the personal operation information to the security personnel terminal.
3. The response method for security events according to claim 2, wherein After the step of sending the alarm event information to the responsible person terminal, the method further includes: In response to the non-personal operation instruction input on the operation judgment interface, sending the non-personal operation information to the security personnel terminal through a group; wherein, the group is used for information interaction between the security personnel terminal and the responsible person terminal simultaneously; In response to the second event processing information input on the group, sending the second event processing information to the security operation platform; wherein, the second event processing information is used for the security operation platform to process the event based on the alarm event information.
4. The response method for security events according to claim 3, characterized in that, After the step of sending the alarm event information to the responsible person terminal, the method further includes: In the case where the personal operation instruction or the non-personal operation instruction is not received within a preset time, sending an alarm prompt information to the responsible person terminal and the security personnel terminal through the group; wherein, the preset time is determined by the event level of the alarm event information.
5. The response method for security incidents according to claim 2, wherein, After the step of responding to the personal operation instruction input on the operation judgment interface, the method further includes: In response to the application for whitelisting instruction input on the operation judgment interface, sending the application for whitelisting instruction to the security operation platform; wherein, the security operation platform schedules the office automation system to generate a whitelisting work order based on the application for whitelisting instruction; Sending the whitelisting judgment information to the security personnel terminal; wherein, the whitelisting judgment information is determined by the whitelisting work order, and the security personnel terminal displays a whitelisting judgment interface based on the whitelisting judgment information; In response to the whitelisting approval instruction input on the whitelisting judgment interface, send the whitelisting approval instruction to the security operation platform; wherein, the security operation platform performs blocking processing or whitelisting processing based on the whitelisting approval instruction.
6. The response method for a security event according to any one of claims 1 to 5, characterized in that, The security operation platform is used to obtain log information sent by multiple security devices, and the security operation platform is used to determine the alarm event information according to the multiple log information.
7. The response method for security events according to claim 6, wherein The log information includes at least one of: data security risk log, threat intelligence risk log, dynamic decision-making and disposal log, virus killing log, compliance baseline log, and security device health monitoring log.
8. A response device for security incidents, characterized in that, Applied to an instant messaging platform, the device includes: A first alarm information sending module, configured to send the alarm event information to a security personnel terminal in response to the alarm event information sent by the security operation platform; wherein, the security personnel terminal displays a first event processing interface based on the alarm event information. An addition instruction sending module, configured to send the personnel addition instruction to the security operation platform in response to the personnel addition instruction input on the first event processing interface; wherein, the security operation platform determines the new personnel information based on the personnel addition instruction. A second alarm information sending module, configured to determine a new personnel terminal based on the new personnel information and send the alarm event information to the new personnel terminal; wherein, the new personnel terminal displays a second event processing interface based on the alarm event information. An event processing information sending module, configured to send the first event processing information to the security operation platform in response to the first event processing information input on the second event processing interface; wherein, the first event processing information is used for the security operation platform to perform event processing based on the alarm event information.
9. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 7 are implemented.