Network range security situation analysis method and device
By collecting, converting and preprocessing data in the network shooting range, extracting features and using machine learning models for security situation analysis, the efficient analysis and attack behavior identification problems of network shooting range data are solved, and threat detection capabilities are improved.
Patent Information
- Application Number
- CN202510568844.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-30
- Publication Date
- 2025-07-25
AI Technical Summary
The existing technology cannot conduct efficient security situation analysis on network shooting range data and cannot achieve accurate identification of attack behavior.
Security-related data is collected from various devices in the network shooting range, data conversion and preprocessing is performed through adapters or agents, target features are extracted, and security situation analysis is used using machine learning models to generate attack pattern matching results and security threat identification results.
It significantly improves the threat detection capabilities in complex and changeable network environments and provides strong network security protection support.
Smart Images

Figure CN120378176A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security, and in particular, to a method and device for analyzing the security situation of a network range. Background Art
[0002] With the development of Software Defined Network (SDN) and Network Function Virtualization (NFV) technologies, heterogeneous network ranges constructed using virtualization technologies have become important scenarios for network security research. Heterogeneous network ranges provide real and reliable technical environment support for network security attack and defense drills by simulating network attacks, and can improve the network security emergency response capabilities and technical research levels. Therefore, an analysis system constructed for heterogeneous network ranges can help security experts quickly discover abnormal behaviors, evaluate network risks, and respond to security incidents in a timely manner, which is a key link in constructing an independent and controllable network security system.
[0003] However, the following problems still exist in the network range security analysis in related technologies: it is impossible to perform efficient security situation analysis on network range data, and it is impossible to accurately identify attack behaviors.
[0004] For the above problems, no effective solutions have been proposed yet. Summary of the Invention
[0005] A method for analyzing the security situation of a network range includes: collecting security-related data from various devices in the network range; extracting target features from the security-related data; using the extracted target features to perform security situation analysis on the security-related data to obtain a security situation analysis result, where the security situation analysis result includes at least one of the following: a matching result of an attack pattern, an identification result of a security threat; and sending the security situation analysis result to a client.
[0006] Optionally, collecting security-related data from various devices in the network range includes: using an adapter or a proxy program to collect log, event, and traffic data from various devices to obtain initial data; and converting the collected initial data into a unified target format to obtain security-related data.
[0007] Optionally, before extracting target features from the security-related data, preprocessing the security-related data includes: removing duplicate data, invalid data, and noise data in the security-related data, and / or; modifying the timestamps of all security-related data to make the timestamps consistent, and / or; performing normalization processing on security-related data from different sources.
[0008] Optionally, the security-related data at least includes: logs and event records, network traffic system events. Extracting target features from the security-related data includes: extracting first target features from the logs and event records, where the first target features at least include one of the following: keywords, IP addresses, port numbers, user IDs; extracting second target features from the network traffic, where the second target features at least include one of the following: protocol types, packet sizes, transmission rates; extracting third target features from the system events, where the third target features at least include one of the following: process startup, file access, registry modification; determining at least one of the first target features, the second target features, and the third target features as the target features.
[0009] Optionally, performing a security situation analysis on the security-related data using the extracted target features, and the obtained security situation analysis result includes: for each target feature, querying for known attacks matching the target feature in a preset security rule library to obtain a matching result of the known attack pattern, where the preset security rule library contains different known attack patterns and the features matching each known attack pattern, and the matching result of the known attack pattern is: matching the known attack pattern or not matching the known attack pattern, and the known attack patterns at least include one of the following: vulnerability exploitation, malware behavior, and abnormal traffic; using the matching result of the known attack pattern as the security situation analysis result.
[0010] Optionally, performing a security situation analysis on the security-related data using the extracted target features, and the obtained security situation analysis result includes: for each target feature, inputting the target feature into a first target model to process and obtain a matching result of the composite attack pattern and a detection result of the abnormal feature, where the first target model is trained by multiple sets of training data, and each set of training data includes historical features and the preset composite attack patterns matching the historical features, as well as labels indicating whether the historical features are abnormal features; combining the matching result of the composite attack pattern and the detection result of the abnormal feature as the security situation analysis result.
[0011] Optionally, performing a security situation analysis on the security-related data using the extracted target features, and the obtained security situation analysis result includes: for multiple target features extracted using different tools or different methods, inputting the target features into a second target model to process and obtain a correlation analysis result of the multiple target features and an identification result of the composite attack pattern, where the second target model is trained by multiple sets of training data, and each set of training data includes the correlation analysis result of historical multiple features and the identification result of the historical composite attack pattern; using the identification result of the composite attack pattern as the security situation analysis result.
[0012] Optionally, perform a security situation analysis on security-related data using the extracted target features. The obtained security situation analysis results include: in the case where an attack pattern is matched using the extracted target features, obtain the traffic associated with the attack pattern from the security-related data, and determine whether there is a security threat based on the context information of the traffic. The obtained security threat identification result, where the context information of the traffic includes at least one of the following: behavior pattern, traffic source; determine the security threat identification result as the security situation analysis result.
[0013] Optionally, sending the security situation analysis result to the client includes: generating a chart based on the security situation analysis result, where the chart includes at least one of the following: heat map, trend chart; generating corresponding security warning information when a potential security threat is identified in the security situation analysis result; generating a security situation analysis report based on the security warning, where the security situation analysis report includes at least one of the following: threat type, affected system, countermeasures; send the chart, security warning information, and security situation analysis report to the client.
[0014] According to another aspect of the embodiments of the present application, there is also provided a network range security situation analysis device, which includes: a data collection unit for collecting security-related data from various devices in the network range; a data processing unit for extracting target features from the security-related data; an analysis unit for performing a security situation analysis on the security-related data using the extracted target features to obtain security situation analysis results, where the security situation analysis results include at least one of the following: matching results of attack patterns, identification results of security threats; a sending unit for sending the security situation analysis results to the client.
[0015] According to another aspect of the embodiments of the present application, there is also provided an electronic device, which includes: a memory storing an executable program; a processor connected to the memory through a bus for running the program, where when the program runs, it executes the method of any one of the embodiments of the present application.
[0016] In the embodiments of the present application, security-related data is collected from various devices in a network range; target features are extracted from the security-related data; the extracted target features are used to perform security situation analysis on the security-related data to obtain a security situation analysis result, and the security situation analysis result includes at least one of the following: a matching result of an attack pattern, an identification result of a security threat; the security situation analysis result is sent to a client. This solves the problem in the related art that it is impossible to perform efficient security situation analysis on network range data and impossible to accurately identify attack behaviors. By performing feature extraction and security situation analysis on the security-related data in the network range, and obtaining a matching result of an attack pattern and an identification result of a security threat, the present application can significantly improve the threat detection ability in a complex and changeable network environment, thereby providing strong support for network security protection. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of this application. The schematic embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation to the present invention. In the drawings:
[0018] Figure 1 is a flowchart of a method for security situation analysis of a network range according to an embodiment of the present application;
[0019] Figure 2 is a schematic diagram of a security situation analysis system of a network range according to an embodiment of the present application;
[0020] Figure 3 is a schematic diagram of a security situation analysis device of a network range according to an embodiment of the present application;
[0021] Figure 4 is a block diagram of the structure of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0022] In order to enable those skilled in the art of this technology to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0023] It should be noted that the terms "first", "second", etc. in the specification, claims and above-mentioned drawings of the present invention are used to distinguish similar objects and do not necessarily have to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0024] According to an embodiment of the present application, there is provided a method for analyzing the security situation of a network range as Figure 1 shown. Figure 1 is a flowchart of a method for analyzing the security situation of a network range according to an embodiment of the present application. As Figure 1 shown, the method may include the following steps:
[0025] Step S102: Collect security-related data from various devices in the network range;
[0026] The network range is a test or evaluation platform that includes various different types of hardware, software, networks, and system environments. The network range in the embodiments of the present application may be a heterogeneous range, and the heterogeneous range can be used to simulate diverse information technology (IT) infrastructures in the real world, including but not limited to different operating systems, network devices (such as routers, switches, firewalls), servers, workstations, mobile devices, intrusion detection systems (IDS), and various applications and services. The security-related data includes but is not limited to logs, events, and traffic data. And after collecting the required data, the collected data is converted into a unified target format for subsequent processing and analysis.
[0027] Step S104: Extract target features from the security-related data;
[0028] Specifically, the extracted target features may be representative features. For example, keywords, Internet Protocol (IP) addresses, port numbers, user identification (ID) and other features are extracted from logs and event records; protocol types, packet sizes, transmission rates and other features are extracted from network traffic; and behavior features such as process startup, file access, and registry modification are extracted from system events.
[0029] Step S106: Perform a security situation analysis on security-related data using the extracted target features to obtain a security situation analysis result, where the security situation analysis result includes at least one of the following: the matching result of the attack pattern, the identification result of the security threat;
[0030] Specifically, the security situation analysis result is a data analysis result that can reflect the security status of the network range. Among them, the acquisition method of the matching result of the attack pattern can be: compare the extracted target features with the known attack pattern database to check whether there is similarity between the target features and the known attack patterns. If the system finds that some features in the security-related data match the attack patterns in the database, then it will generate a clear matching result indicating the possible attack types; or input the target features into a machine learning model, and the machine learning model outputs the matching result. The machine learning model has been trained through security situation analysis and can identify more complex attack patterns that cannot be recognized by the known attack pattern database; or, use the detection results obtained by different tools or different methods as multiple features for joint analysis.
[0031] The identification result of the security threat can be that in addition to feature-based matching, the system uses a machine learning model to identify potential security threats. For data samples that do not directly match the known attack patterns, the machine learning model identifies whether the behavior pattern of the data source conforms to the expected pattern. If the behavior pattern of the data source does not conform to the expectation, it is considered that the data is abnormal and there is a security threat.
[0032] The result obtained by the above security situation analysis method can be used as the security situation analysis result.
[0033] Step S108: Send the security situation analysis result to the client.
[0034] Specifically, after receiving the security situation analysis result, the client can display the security situation analysis result to the user in the form of a chart and generate a detailed report. The report can be exported in multiple formats, such as Portable Document Format (PDF), Comma-Separated Values (CSV), and HyperText Markup Language (HTML), which is convenient for users to further analyze and archive.
[0035] In an embodiment of the present application, security-related data is collected from various devices in a network range; target features are extracted from the security-related data; the extracted target features are used to perform a security situation analysis on the security-related data to obtain a security situation analysis result, where the security situation analysis result includes at least one of the following: a matching result of an attack pattern and an identification result of a security threat; and the security situation analysis result is sent to a client. This solves the problem in the related art that it is impossible to perform an efficient security situation analysis on network range data and impossible to accurately identify attack behaviors. By performing feature extraction and security situation analysis on the security-related data in the network range to obtain a matching result of an attack pattern and an identification result of a security threat, the present application can significantly improve the threat detection ability in a complex and changeable network environment, thereby providing strong support for network security protection.
[0036] To collect security-related data for subsequent processing, optionally, in the network range security situation analysis method of an embodiment of the present application, collecting security-related data from various devices in the network range includes: using an adapter or a proxy program to collect log, event, and traffic data from various devices to obtain initial data; and converting the collected initial data into a unified target format to obtain security-related data.
[0037] Specifically, in order to be able to extract security-related data from various devices (such as servers, firewalls, intrusion detection systems, etc.) in the network range, the present application deploys an adapter or a proxy program. The adapter or the proxy program can interact with different network range devices, read their log files, event records, and network traffic information, and ensure the integrity and accuracy of the data.
[0038] The data collected by the adapter or the proxy program from the device includes a log file, which records the operations and running status of the device; event records, including various behaviors in the system; and traffic data, which provides details of network communication. These data together constitute a comprehensive description of the security status of the network range.
[0039] It should be noted that the collected initial data can come from different devices and systems, so their formats and structures are different. To facilitate subsequent data processing and analysis, the present application converts all the collected initial data into a unified target format. This format is predefined, can contain all necessary information, and at the same time ensures the consistency and readability of the data.
[0040] In an embodiment of the present application, by collecting initial data and performing unified data format conversion, the standardization and normalization of the data are achieved, creating conditions for subsequent in-depth analysis and threat identification.
[0041] Optionally, in order to ensure the real-time nature and comparability of data, in the network range security situation analysis method according to the embodiments of the present application, before extracting target features from security-related data, preprocessing the security-related data includes: removing duplicate data, invalid data, and noise data from the security-related data, and / or; modifying the timestamps of all security-related data to make the timestamps consistent, and / or; performing normalization processing on security-related data from different sources.
[0042] Specifically, the data preprocessing steps according to the embodiments of the present application may include data cleaning (removing duplicate data, invalid data, and noise data): In the data collection stage, the security-related data obtained from various devices in the network range may contain a large amount of duplicate information, useless records, and various forms of noise. The primary task of data cleaning is to identify and eliminate these unnecessary data to reduce the complexity of subsequent processing and improve the accuracy and efficiency of analysis.
[0043] Timestamp calibration: In the collected data, due to the asynchronous clocks of devices or time zone differences, there may be inconsistent timestamps. In the preprocessing stage, the embodiments of the present application ensure that the time bases of all data are the same by calibrating or adjusting the timestamps. This step is crucial for time series analysis, which can avoid incorrect associations caused by time deviations and ensure the correct identification of the sequence of events and potential attack patterns.
[0044] Normalization processing: Since the data may come from multiple channels such as network traffic, log records, and event reports, the data dimensions and units of each channel may be different. Normalization processing can eliminate these dimensional differences and convert the data into a comparable form.
[0045] The embodiments of the present application improve the compatibility and analysis capabilities of the entire system through comprehensive preprocessing, provide high-quality, consistent, and comparable data for security situation analysis, and significantly enhance the threat detection capabilities and decision support effects of the system.
[0046] To select data types and extract features to ensure that potential security threats in the network range can be comprehensively captured. Optionally, in the network range security situation analysis method of the embodiment of the present application, security-related data at least includes: logs and event records, network traffic system events. Extracting target features from the security-related data includes: extracting first target features from the logs and event records, and the first target features at least include one of the following: keywords, IP addresses, port numbers, user IDs; extracting second target features from the network traffic, and the second target features at least include one of the following: protocol types, packet sizes, transmission rates; extracting third target features from the system events, and the third target features at least include one of the following: process startup, file access, registry modification; determining at least one of the first target features, the second target features, and the third target features as the target features.
[0047] The following feature extraction formula is adopted in this embodiment:
[0048] F = extract_features(D),
[0049] where F is the feature vector and D is the original data.
[0050] Feature extraction is the process of extracting useful information from the original data, which is used to simplify data processing and improve computational efficiency. The goal of feature extraction is to transform high-dimensional data into low-dimensional feature vectors while retaining as much useful information as possible. Feature extraction methods include principal component analysis, independent component analysis, and various deep learning-based methods such as autoencoders.
[0051] For example, there is an original dataset D containing network traffic data. By using principal component analysis for feature extraction, a vector F containing the main traffic features can be obtained. This can not only reduce the data dimension but also effectively remove noise and redundant information.
[0052] In the embodiment of the present application, the security-related data is used as the original data, and the target features are used as the useful information.
[0053] Specifically, the security-related data at least includes logs and event records, network traffic, and system events. These data sources respectively carry security information at different levels. Logs and event records provide direct records of device operations and abnormal situations. Network traffic reveals communication patterns and potential malicious transmissions. System events track activities at the operating system level, such as process management and file system access.
[0054] When extracting the first target features from logs and event records, through natural language processing techniques such as keyword extraction and regular expression matching, information such as security-related keywords, IP addresses, port numbers, and user IDs is extracted from the logs and event records. These first target features help identify known threat patterns, such as common attack commands and access records of malicious IPs.
[0055] When extracting the second target features from network traffic, network analysis tools are used to analyze network traffic data and extract information such as protocol type, packet size, and transmission rate. The second target features are crucial for detecting abnormal traffic patterns and can reveal potential network threats such as data leakage.
[0056] When extracting the third target features from system events, system activity logs are monitored to extract information such as process startup, file access, and registry modification. The third target features help identify intrusion behaviors at the system level, such as the installation and operation of malware and unauthorized system configuration modifications.
[0057] Determine at least one of the above-extracted first target features, second target features, and third target features as the target feature, and select the most relevant feature for in-depth analysis according to specific security analysis requirements and threat types. For example, when analyzing data leakage, more emphasis can be placed on the transmission rate and packet size in the second target features, while when tracking internal threats, more attention can be paid to process startup and file access records in the third target features.
[0058] The embodiment of this application provides rich and accurate data support for security situation awareness access through feature extraction from three core data sources: logs, network traffic, and system events. Among them, awareness access refers to the operation of a security situation analysis system for data interaction and security situation judgment with various devices in a heterogeneous range.
[0059] To accurately identify known attack patterns and obtain security situation analysis results, optionally, in the network range security situation analysis method of the embodiment of this application, the extracted target features are used to perform security situation analysis on security-related data, and the obtained security situation analysis results include: for each target feature, query the known attacks matching the target feature in a preset security rule library to obtain the matching results of known attack patterns. Among them, the preset security rule library contains different known attack patterns and the features matching each known attack pattern. The matching results of known attack patterns are: matching a known attack pattern or not matching a known attack pattern. The known attack patterns include at least one of the following: vulnerability exploitation, malware behavior, and abnormal traffic; use the matching results of known attack patterns as the security situation analysis results.
[0060] This embodiment adopts the following feature matching formula:
[0061] M = match_features(F, P),
[0062] where M is the matching result and P is the feature pattern library.
[0063] Among them, feature matching is to compare the extracted feature vectors with the known feature pattern library to find similar or matching patterns. The feature pattern library P contains known malware features, abnormal behavior patterns, etc. Through feature matching, it can be determined whether the current data conforms to the known threat features.
[0064] For example, the system has extracted the feature vector F from network traffic data and has a pattern library P containing known malware features. Through the feature matching algorithm, F can be compared with the features in P to determine whether the traffic contains malicious behavior. Feature matching methods in related technologies include Euclidean distance, cosine similarity, etc.
[0065] In the embodiments of the present application, the security rule library is used as the feature pattern library.
[0066] Specifically, for each target feature extracted from security-related data (such as keywords, IP addresses, port numbers, user IDs, protocol types, packet sizes, transmission rates, process startups, file accesses, registry modifications, etc.), a query is made in the preset security rule library to find known attack patterns that match it. The purpose of this step is to use the accumulated security knowledge and the identified threat features to quickly determine whether the real-time data in the network range conforms to the known attack behaviors.
[0067] It should be noted that the preset security rule library contains a variety of known attack patterns and their feature descriptions, which are constructed based on multiple aspects of information such as industry standards, threat intelligence, and historical attack event records. For each target feature, the system will automatically search in the rule library to find whether there is a matching known attack pattern. For example, if the target feature contains an IP address related to known malware activities, the system will be able to quickly identify and mark this feature, indicating the existence of malware behavior.
[0068] Matching a known attack pattern means that the target feature coincides with one or more known attack behaviors in the rule library, which means that the network range is suffering or facing a certain clear security threat. Not matching a known attack pattern indicates that the features contained in the data have not been defined as known attack behaviors in the rule library, but it does not exclude the possibility that it belongs to an unknown threat or a more complex attack pattern. For the matched known attack pattern, the system takes it as the security situation analysis result.
[0069] In the embodiments of the present application, by using a preset security rule library for quick matching, the system can instantly detect known threat behaviors, thereby taking effective measures at the initial stage of an attack to prevent further expansion of damage.
[0070] Optionally, in order to obtain the matching results of composite attack patterns and the detection results of abnormal features, in the network range security situation analysis method of the embodiments of the present application, security situation analysis is performed on security-related data by using the extracted target features, and the obtained security situation analysis results include: for each target feature, input the target feature into a first target model, and process to obtain the matching results of composite attack patterns and the detection results of abnormal features, where the first target model is trained by multiple sets of training data, and each set of training data includes historical features, preset composite attack patterns matched by the historical features, and labels indicating whether the historical features are abnormal features; combine the matching results of composite attack patterns and the detection results of abnormal features as the security situation analysis results.
[0071] Specifically, for each target feature extracted from security-related data, input it into the trained first target model. The first target model will process the input target feature based on the learned knowledge and operation mode, and output the matching results of composite attack patterns and the detection results of abnormal features. The matching results of composite attack patterns can reveal complex and collaborative attack behaviors existing in the feature data, while the detection results of abnormal features can identify those features that deviate from the normal behavior pattern and indicate new or unknown threats.
[0072] Combine the matching results of composite attack patterns and the detection results of abnormal features as the final security situation analysis results. This combination process considers both the identification of composite attack patterns and the detection of abnormal behaviors, thereby being able to provide a more comprehensive security situation result.
[0073] It should be noted that the first target model can be a machine learning model, and various machine learning algorithms (such as support vector machines, random forests, neural networks, etc.) are used for composite pattern matching and anomaly detection. Among them, the first target model is trained by multiple sets of training data. These training data include historical features (i.e., feature data that appeared in previous network range security events), preset composite attack patterns corresponding to these historical features (i.e., complex attack behavior patterns determined according to historical events), and labels indicating whether the historical features are abnormal features (i.e., whether the historical features are marked as inconsistent with known security behaviors).
[0074] Through training, the first target model can identify composite attack behaviors not recorded in the preset security rule library and detect abnormal features.
[0075] Through the intelligent analysis of the machine learning model, the embodiments of the present application can not only quickly identify composite attack behaviors, but also detect abnormal features, thus significantly improving the recognition ability of complex security threats and the early warning ability of new threats.
[0076] Optionally, in the network range security situation analysis method of the embodiments of the present application, in order to increase the possibility of discovering unknown or variant attacks through the correlation analysis between features, the target features extracted are used to perform security situation analysis on security-related data, and the obtained security situation analysis results include: for multiple target features extracted by different tools or different methods, the target features are input into a second target model, and the correlation analysis results of the multiple target features and the recognition results of the composite attack patterns are obtained through processing, where the second target model is trained by multiple sets of training data, and each set of training data includes the correlation analysis results of historical multiple features and the recognition results of historical composite attack patterns; the recognition results of the composite attack patterns are used as the security situation analysis results.
[0077] Specifically, first, multiple target features are prepared. These target features are from different data types, such as logs and event records, network traffic, system events, etc., and may also be extracted using different tools or methods. The diversity of features means that all aspects of the network range security situation can be covered.
[0078] Then, the above multiple target features are input into the second target model as a set. The importance of each feature, the interaction between features, and the security implications implied by the feature combination can be comprehensively considered. By processing these features, the model can output the correlation analysis results between them and the composite attack patterns identified based on the correlation results. Among them, the recognition results of the composite attack patterns are an important output of the second target model, which can reveal the hidden security threats in the feature set, especially those complex attack behaviors that require multiple features to cooperate to expose. Using the recognition results of the composite attack patterns as the security situation analysis results can quickly locate and respond to potential composite attacks.
[0079] It should be noted that the second target model is trained by multiple sets of training data, and the training data consists of the correlation analysis results of historical multiple features and the recognition results of historical composite attack patterns. These historical data cover various security events that have occurred in the network range, including but not limited to composite attack cases, and the true correlations between the features in the events. The second target model can record the complex relationships between features and identify composite attack patterns through the feature set.
[0080] The embodiments of the present application can identify more complex composite attack patterns by integrating target features from multiple different sources and extraction methods, and improve the recognition rate of known composite attacks.
[0081] In order to conduct in-depth security situation analysis on security-related data to obtain more accurate security situation analysis results, optionally, in the network range security situation analysis method of the embodiments of the present application, the security situation analysis of security-related data is performed using the extracted target features, and the obtained security situation analysis results include: in the case where an attack pattern is matched using the extracted target features, the traffic associated with the attack pattern is obtained from the security-related data, and it is determined whether there is a security threat based on the context information of the traffic, and the recognition result of the security threat is obtained, where the context information of the traffic includes at least one of the following: behavior pattern, traffic source; the recognition result of the security threat is determined as the security situation analysis result.
[0082] The following threat recognition formula is adopted in this embodiment:
[0083] T = identify_threats(M),
[0084] where T is the recognized threat.
[0085] Specifically, threat recognition further analyzes and determines whether there is a potential security threat based on the attack pattern matched by the target features. Among them, T represents the recognized threat. Threat recognition not only depends on the result of target feature matching, but also needs to combine the context information of the traffic and other security policies for comprehensive judgment. Among them, other security policies may include security policies at the network, software, code, etc. levels in the system.
[0086] For example, the feature matching result M shows that a certain network traffic is highly similar to the characteristics of known malware. Among them, the network traffic and the characteristics of known malware can be regarded as threat intelligence data. Through the threat recognition algorithm, combined with the threat intelligence data and the environment of the network range, information such as the behavior pattern and source IP address of the traffic can be further analyzed, and finally it is determined whether it constitutes a real threat.
[0087] It should be noted that machine learning models such as support vector machines and random forests may be used in the threat recognition process to improve the accuracy and reliability of recognition.
[0088] In the embodiments of the present application, by using the security threat recognition result as the security situation analysis result, the directness and pertinence of security protection decisions are ensured, and the security situation perception ability and response efficiency of the network range are enhanced.
[0089] To provide intuitive, timely, and detailed security intelligence, optionally, in the network range security situation analysis method of the embodiments of the present application, sending the security situation analysis result to the client includes: generating a chart based on the security situation analysis result, where the chart includes at least one of the following: heat map, trend chart; when a potential security threat is identified in the security situation analysis result, generating corresponding security warning information; based on the security warning, generating a security situation analysis report, where the security situation analysis report includes at least one of the following: threat type, affected system, countermeasure; sending the chart, security warning information, and security situation analysis report to the client.
[0090] Specifically, the chart includes at least a heat map and a trend chart. The heat map can clearly show the density of security events for each system or node in the network range, and the depth of color represents the severity or frequency of the events; the trend chart is used to show the change trend of specific security indicators over time, such as the frequency of malware activities, the magnitude of abnormal traffic, etc. The generation of the chart aims to enable the client user to quickly grasp the overall security situation in a visual way and timely discover security hotspots and trend changes.
[0091] When a potential security threat is identified, the generated security warning information will describe in detail the nature of the threat, the possible scope of influence, and the urgency. And the security situation analysis report generated based on the security warning information includes at least the threat type, the affected system, and the recommended countermeasures. The threat type describes which specific type of attack behavior the identified threat belongs to, and the affected system lists which systems or resources in the network range may be affected by the threat; the countermeasure part provides specific defense suggestions for the identified threat. The security situation analysis report can provide the client with a comprehensive overview of the security situation and specific threat response strategies to help it conduct effective security management and decision-making.
[0092] The embodiments of the present application construct an efficient and intuitive security situation feedback mechanism through chart display, security threat warning, and the compilation and sending of the situation analysis report. It can not only present the security situation of the network range in real time but also actively identify potential threats and provide response strategies, significantly enhancing the client's perception ability and response speed to the security status of the network range.
[0093] According to another aspect of the embodiments of the present application, a network range security situation analysis system is also provided. Figure 2 It is a schematic diagram of a network range security situation analysis system according to the embodiments of the present application, as Figure 2As shown in the figure, the system includes: a data acquisition module 202 for acquiring security-related data from various devices in the network range; a data preprocessing module 204 for extracting target features from the security-related data; an analysis module 206 for performing a security situation analysis on the security-related data by using the extracted target features to obtain a security situation analysis result, where the security situation analysis result includes at least one of the following: a matching result of an attack pattern, an identification result of a security threat; a report generation module 208 for generating a security situation analysis report based on the security situation analysis result, and a visualization module 210 for sending the security situation analysis report to a client, and the client displays the security situation analysis result.
[0094] In an embodiment of the present application, the data acquisition module acquires security-related data from various devices in the network range; the data preprocessing module extracts target features from the security-related data; the analysis module performs a security situation analysis on the security-related data by using the extracted target features to obtain a security situation analysis result, where the security situation analysis result includes at least one of the following: a matching result of an attack pattern, an identification result of a security threat; the report generation module generates a security situation analysis report based on the security situation analysis result; the visualization module sends the security situation analysis report to a client, and the client displays the security situation analysis result. This solves the problem in the related art that it is impossible to perform an efficient security situation analysis on network range data and impossible to accurately identify attack behaviors. By performing feature extraction and security situation analysis on the security-related data in the network range to obtain the matching result of the attack pattern and the identification result of the security threat, the present application can significantly improve the threat detection ability in a complex and changeable network environment, thereby providing strong support for network security protection.
[0095] According to another aspect of the embodiment of the present application, a network range security situation analysis device is further provided. Figure 3 It is a schematic diagram of a network range security situation analysis device according to an embodiment of the present application. As Figure 3 shown in the figure, the device includes: a data acquisition unit 302 for acquiring security-related data from various devices in the network range; a data processing unit 304 for extracting target features from the security-related data; an analysis unit 306 for performing a security situation analysis on the security-related data by using the extracted target features to obtain a security situation analysis result, where the security situation analysis result includes at least one of the following: a matching result of an attack pattern, an identification result of a security threat; a sending unit 308 for sending the security situation analysis result to a client.
[0096] In an embodiment of the present application, the data collection unit 302 collects security-related data from various devices in the network range; the data processing unit 304 extracts target features from the security-related data; the analysis unit 306 performs a security situation analysis on the security-related data by using the extracted target features to obtain a security situation analysis result, and the security situation analysis result includes at least one of the following: a matching result of an attack pattern, an identification result of a security threat; the sending unit 308 sends the security situation analysis result to the client. The problem in the related art that the security situation of network range data cannot be efficiently analyzed and the accurate identification of attack behaviors cannot be achieved is solved. By performing feature extraction and security situation analysis on the security-related data in the network range, obtaining the matching result of the attack pattern and the identification result of the security threat, the present application can significantly improve the threat detection ability in a complex and changeable network environment, thereby providing strong support for network security protection.
[0097] Optionally, the data collection unit 302 includes: a collection module, configured to collect log, event, and traffic data from various devices by using an adapter or a proxy program to obtain initial data; a conversion module, configured to convert the collected initial data into a unified target format to obtain security-related data.
[0098] Optionally, the data processing unit 304 includes: a data screening module, configured to remove duplicate data, invalid data, and noise data from the security-related data, and / or; a timestamp modification module, configured to modify the timestamps of all the security-related data to make the timestamps consistent, and / or; a normalization module, configured to perform normalization processing on the security-related data from different sources.
[0099] Optionally, the data processing unit 304 includes: a first target feature extraction module, configured to extract a first target feature from logs and event records, and the first target feature includes at least one of the following: keywords, IP addresses, port numbers, user IDs; a second target feature extraction module, configured to extract a second target feature from network traffic, and the second target feature includes at least one of the following: protocol types, packet sizes, transmission rates; a third target feature extraction module, configured to extract a third target feature from system events, and the third target feature includes at least one of the following: process startup, file access, registry modification; a target feature determination module, configured to determine at least one of the first target feature, the second target feature, and the third target feature as the target feature.
[0100] Optionally, the analysis unit 306 includes: a rule library analysis module, which is used to query known attacks matching the target feature in a preset security rule library for each target feature to obtain the matching result of the known attack pattern. The preset security rule library contains different known attack patterns and the features matching each known attack pattern. The matching result of the known attack pattern is: matching the known attack pattern or not matching the known attack pattern. The known attack pattern includes at least one of the following: vulnerability exploitation, malware behavior, and abnormal traffic; the matching result of the known attack pattern is used as the security situation analysis result.
[0101] The analysis unit 306 further includes: a first target model analysis module, which is used to input the target feature into the first target model for each target feature, and process to obtain the matching result of the composite attack pattern and the detection result of the abnormal feature. The first target model is trained by multiple sets of training data, and each set of training data includes historical features, preset composite attack patterns matching the historical features, and labels indicating whether the historical features are abnormal features; the matching result of the composite attack pattern and the detection result of the abnormal feature are combined as the security situation analysis result.
[0102] The analysis unit 306 further includes: a second target model analysis module, which is used to input the target features extracted by different tools or different methods into the second target model for multiple target features, and process to obtain the correlation analysis result of the multiple target features and the recognition result of the composite attack pattern. The second target model is trained by multiple sets of training data, and each set of training data includes the correlation analysis result of historical multiple features and the recognition result of the historical composite attack pattern; the recognition result of the composite attack pattern is used as the security situation analysis result.
[0103] The analysis unit 306 further includes: a security threat recognition module, which is used to obtain the traffic associated with the attack pattern from the security-related data when the attack pattern is matched by using the extracted target features, and judge whether there is a security threat according to the context information of the traffic to obtain the recognition result of the security threat. The context information of the traffic includes at least one of the following: behavior pattern, traffic source; the recognition result of the security threat is determined as the security situation analysis result.
[0104] Optionally, the sending unit 308 includes: a chart sending module, configured to generate a chart according to the security situation analysis result, where the chart includes at least one of the following: a heat map, a trend chart; an alarm module, configured to generate corresponding security alarm information when a potential security threat is identified in the security situation analysis result; a report generation module, configured to generate a security situation analysis report based on the security alarm, where the security situation analysis report includes at least one of the following: threat type, affected system, countermeasures; and a sending sub-module, configured to send the chart, the security alarm information, and the security situation analysis report to the client.
[0105] Embodiments of the present application may provide an electronic device. Figure 4 It is a structural block diagram of an electronic device according to an embodiment of the present application. As Figure 4 shown, the electronic device may include: one or more ( Figure 4 only one is shown in the figure) processors 402, a memory 404, a storage controller, and a peripheral interface, where the peripheral interface is connected to a radio frequency module, an audio module, and a display.
[0106] Among them, the memory may be used to store software programs and modules, such as program instructions / modules corresponding to the methods and devices in the embodiments of the present application. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, that is, implements the methods in the above embodiments. The memory may include a high-speed random access memory, and may further include a non-volatile memory, such as one or more magnetic storage devices, a flash memory, or other non-volatile solid-state memories. In some instances, the memory may further include a memory remotely disposed relative to the processor, and these remote memories may be connected to the terminal through a network. Examples of the above network include but are not limited to the Internet, an enterprise internal network, a local area network, a mobile communication network, and combinations thereof.
[0107] The processor may call the executable program stored in the memory through a transmission device to execute the method described in any one of the above embodiments.
[0108] Those of ordinary skill in the art can understand that the structure shown in the figure is only schematic, and the computing device may also be a terminal device such as a smart phone, a tablet computer, a palm computer, and a Mobile Internet Devices (MID), a PAD, etc. The figure does not limit the structure of the above computing device. For example, the computing device 100 may further include more or fewer components (such as a network interface, a display device, etc.) than those shown in the figure, or have a different configuration from that shown in the figure.
[0109] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing the relevant hardware of the terminal device through a program. This program can be stored in a computer-readable storage medium, and the storage medium can include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disc, etc.
[0110] Obviously, those skilled in the art should understand that the various modules or steps of the present invention described above can be implemented by a general-purpose computing device. They can be concentrated on a single computing device or distributed on a network composed of multiple computing devices. They can be implemented by program codes executable by the computing device. Thus, they can be stored in a storage device and executed by the computing device. And in some cases, the steps shown or described can be executed in a different order from here, or they can be separately fabricated into individual integrated circuit modules, or multiple modules or steps among them can be fabricated into a single integrated circuit module to implement. In this way, the present invention is not limited to any specific combination of hardware and software.
[0111] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modifications, equivalent replacements, improvements, etc. made within the principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method for analyzing the security situation of a network range, characterized in that including: collecting security-related data from various devices in the network range; extracting target features from the security-related data; performing security situation analysis on the security-related data by using the extracted target features to obtain a security situation analysis result, where the security situation analysis result includes at least one of the following: a matching result of an attack pattern, an identification result of a security threat; sending the security situation analysis result to a client.
2. The network range security situation analysis method according to claim 1, wherein Collecting security-related data from various devices in the network range includes: using an adapter or a proxy program to collect log, event, and traffic data from the various devices to obtain initial data; converting the collected initial data into a unified target format to obtain the security-related data.
3. The network range security situation analysis method according to claim 1, characterized in that Before extracting target features from the security-related data, preprocessing the security-related data includes: removing duplicate data, invalid data, and noise data from the security-related data, and / or; modifying the timestamps of all the security-related data to make the timestamps consistent, and / or; performing normalization processing on the security-related data from different sources.
4. The network range security situation analysis method according to claim 1, characterized in that The security-related data includes at least: log and event records, network traffic system events, and extracting target features from the security-related data includes: extracting first target features from the log and event records, where the first target features include at least one of the following: keywords, IP addresses, port numbers, user IDs; extracting second target features from the network traffic, where the second target features include at least one of the following: protocol types, packet sizes, transmission rates; extracting third target features from the system events, where the third target features include at least one of the following: process startup, file access, registry modification; determining at least one of the first target features, the second target features, and the third target features as the target features.
5. The network range security situation analysis method according to claim 1, characterized in that Performing security situation analysis on the security-related data by using the extracted target features to obtain the security situation analysis result includes: for each target feature, querying for known attacks matching the target feature in a preset security rule library to obtain a matching result of a known attack pattern, where the preset security rule library contains different known attack patterns and features matching each known attack pattern, and the matching result of the known attack pattern is: matching a known attack pattern or not matching a known attack pattern, and the known attack pattern includes at least one of the following: vulnerability exploitation, malware behavior, and abnormal traffic; using the matching result of the known attack pattern as the security situation analysis result.
6. The network range security situation analysis method according to claim 1, characterized in that Performing security situation analysis on the security-related data by using the extracted target features to obtain the security situation analysis result includes: For each target feature, input the target feature into a first target model to process and obtain a matching result of a composite attack pattern and a detection result of an abnormal feature, where the first target model is trained by multiple sets of training data, and each set of training data includes historical features, a preset composite attack pattern matched by the historical features, and a label indicating whether the historical features are abnormal features; Combine the matching result of the composite attack pattern and the detection result of the abnormal feature as the security situation analysis result.
7. The network range security situation analysis method according to claim 1, wherein Performing security situation analysis on the security-related data by using the extracted target features, the obtained security situation analysis result includes: For multiple target features extracted by using different tools or different methods, input the target features into a second target model to process and obtain an association analysis result of the multiple target features and an identification result of a composite attack pattern, where the second target model is trained by multiple sets of training data, and each set of training data includes an association analysis result of historical multiple features and an identification result of a historical composite attack pattern; Use the identification result of the composite attack pattern as the security situation analysis result.
8. The network range security situation analysis method according to claim 1, characterized in that Performing security situation analysis on the security-related data by using the extracted target features, the obtained security situation analysis result includes: When an attack pattern is matched by using the extracted target feature, obtain the traffic associated with the attack pattern from the security-related data, and determine whether there is a security threat according to the context information of the traffic, where the context information of the traffic includes at least one of the following: behavior pattern, traffic source; Determine the identification result of the security threat as the security situation analysis result.
9. The network range security situation analysis method according to claim 1, characterized in that Sending the security situation analysis result to the client includes: Generate a chart according to the security situation analysis result, where the chart includes at least one of the following: heat map, trend chart; When a potential security threat is identified in the security situation analysis result, generate a corresponding security warning message; Based on the security warning, generate a security situation analysis report, where the security situation analysis report includes at least one of the following: threat type, affected system, countermeasure; Send the chart, the security warning message, and the security situation analysis report to the client.
10. A network range security situation analysis device, characterized in that Includes: A data collection unit for collecting security-related data from various devices in the network range; A data processing unit for extracting target features from the security-related data; An analysis unit for performing security situation analysis on the security-related data by using the extracted target features to obtain a security situation analysis result, where the security situation analysis result includes at least one of the following: a matching result of an attack pattern, an identification result of a security threat; A sending unit for sending the security situation analysis result to the client.
Citation Information
Patent Citations
Data acquisition method and data acquisition system in network target range system
CN110351255A
Network target range data management method, device and equipment and readable storage medium
CN116136877A
Multi-source data fusion network security situation awareness method and device
CN117240541A
Network target range flow data analysis method and device, equipment and storage medium
CN118432859A
Network security situation awareness system and method
CN118509259A