Security alarm information processing method and device based on multi-agent cooperation

Through the multi-agent collaborative processing method, the honey dot management module and the agent system are used to filter false positive information and generate detailed attack analysis reports, which solves the problem of low efficiency and accuracy of security alarm information analysis, and improves the understanding and response capabilities of network attacks.

CN120378229AActive Publication Date: 2025-07-25POWERCHINA JIANGXI ELECTRIC POWER ENGINEERING CO LTD

Patent Information

Application Number
CN202510865747.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-26
Publication Date
2025-07-25
Estimated Expiration
2045-06-26

AI Technical Summary

Technical Problem

In the prior art, the analysis efficiency and accuracy of security alarm information is low, false alarm information interferes with judgment, it is difficult to deal with complex and changeable attack scenarios, and it is impossible to fully explore the full picture and potential threat of attack behavior.

Method used

The security alarm information processing method of multi-agents is adopted to obtain the original alarm flow through the honey dot management module, and the large language model of the alarm noise reduction agent is used to filter false alarm information, and the attack model agent generates attack hypothesis and analysis reports to build an attack path.

Benefits of technology

Automated preprocessing and intelligent noise reduction reduce manual screening costs, reduce false alarms, enhance network attack understanding and response capabilities, improve the efficiency and accuracy of security alarm information analysis, and provide a comprehensive attack behavior analysis report.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120378229A_ABST
    Figure CN120378229A_ABST
Patent Text Reader

Abstract

The invention discloses a security alarm information processing method and device based on multi-agent cooperation, and relates to the technical field of honey point alarms, and the method comprises the steps: obtaining an original alarm flow from a honey point management module, and carrying out the preprocessing of the original alarm flow, and obtaining an alarm set; pushing the alarm set to an alarm noise reduction agent so as to filter false alarm information through a large language model noise reducer, then transmitting the false alarm information to a priority marker to endow the alarm set with a corresponding priority mark, and storing the marked alarm set into a historical alarm database; and pushing the alarm set to an attack model agent to generate an attack hypothesis through an attack mapping large language model, transmitting the attack hypothesis to an attack path backtracking engine, querying a historical alarm database to obtain associated historical attack data, and generating a corresponding analysis report after constructing a specific attack path. According to the invention, the problem of low safety alarm information analysis efficiency and accuracy in the prior art is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of honey spot alarm technology, and in particular to a safety alarm information processing method and device based on multi-agent collaboration. Background Art

[0002] Honey spots can usually be regarded as a lightweight honeypot or network monitoring probe. They are widely used because they can monitor a large area at a relatively low cost. In practice, honey spots are deployed at various nodes in the network to collect alarm information. These alarm information contains rich but complex information, including real attack clues and a large amount of false alarm information, which brings great challenges to subsequent security analysis.

[0003] At present, security analysts directly analyze the original alarm information. However, if they rely solely on security analysts to quickly and accurately filter out real and effective attack information from massive alarm data, a large amount of false positive information will interfere with the judgment of security analysts, consuming a lot of time and energy. At the same time, it is difficult to cope with complex and changeable attack scenarios, and it is impossible to fully and deeply explore the full picture of attack behaviors and potential threats. This leads to the problem of low efficiency and accuracy in security alarm information analysis. Summary of the invention

[0004] In view of this, the purpose of the present invention is to provide a security alarm information processing method and device based on multi-agent collaboration, aiming to solve the problem of low efficiency and accuracy in security alarm information analysis in the prior art.

[0005] On the one hand, the present invention proposes a security alarm information processing method based on multi-agent collaboration, which processes the security alarm information based on a constructed honey spot alarm backtracking system, wherein the honey spot alarm backtracking system at least includes a communication-connected honey spot management module, an alarm noise reduction agent, and an attack model agent, and the method includes: Obtaining an original alarm stream from the honey spot management module and preprocessing the original alarm stream to obtain an alarm set, wherein the original alarm stream is obtained by the honey spot management module from data collected by a pre-deployed honey spot cluster; The alarm set is pushed to the alarm denoising agent to filter out false alarm information through the large language model denoiser in the alarm denoising agent, and then passed to the priority marker in the alarm denoising agent to assign the corresponding priority marker to the alarm set and store the marked alarm set in the historical alarm database; Push the alarm set to the attack model agent to generate attack hypotheses by fine-tuning the attack mapping large language model in the attack model agent, and pass the attack hypotheses to the attack path backtracking engine in the attack model agent. Query the historical alarm database through the attack path backtracking engine to obtain relevant historical attack data, and generate a corresponding analysis report after constructing a specific attack path.

[0006] Further, in the above method for processing security alarm information based on multi-agent collaboration, the step of obtaining the original alarm stream from the honeypot management module and preprocessing the original alarm stream to obtain an alarm set includes: Perform data cleaning and feature extraction on the original alarm stream in sequence, and then perform spatio-temporal aggregation analysis to aggregate alarm events that are close in time and related in spatial location in the original alarm stream to obtain an alarm set.

[0007] Further, in the above method for processing security alarm information based on multi-agent collaboration, the step of filtering false alarm information through the large language model noise reducer in the alarm noise reduction agent and then passing it to the priority marker in the alarm noise reduction agent to assign a corresponding priority marker to the alarm set includes: After the large language model noise reducer receives the alarm set, query the historical alarm database to obtain historical relevant false alarm patterns, and filter false alarm information based on the comparison of the alarm information in the current alarm set with the data of the historical relevant false alarm patterns; The filtered alarm set is passed to the priority marker to evaluate the importance of each alarm set, and corresponding priority markers are assigned according to the level of importance.

[0008] Further, in the above method for processing security alarm information based on multi-agent collaboration, the step of, after the large language model noise reducer receives the alarm set, querying the historical alarm database to obtain historical relevant false alarm patterns and filtering false alarm information based on the comparison of the alarm information in the current alarm set with the data of the historical relevant false alarm patterns includes: After the large language model noise reducer receives the alarm set, perform semantic parsing on the alarm set to convert the unstructured text in the alarm set into a structured feature vector; Perform similarity matching between the feature vector of the alarm set and the feature vector corresponding to the relevant false alarm pattern in the historical alarm database. When the similarity between the feature vector of the alarm set and the feature vector corresponding to the relevant false alarm pattern exceeds the preset threshold, determine that the alarm information in the alarm set is a false alarm and filter it.

[0009] Further, in the above method for processing security alarm information based on multi-agent collaboration, the honeypot cluster at least includes: Web honeypots, protocol honeypots, file honeypots, and account honeypots.

[0010] Further, in the above-mentioned security alert information processing method based on multi-agent collaboration, the Web honeypots at least include Web mirror honeypots, Web parasitic honeypots, and Web vulnerability honeypots. Among them, the Web mirror honeypots include disguising as real web services by replicating the interfaces and basic interaction logics of target web pages to induce attackers to access. The protocol honeypots include simulated SSH or Telnet or MySQL protocol services, isolated from real services, and exposed only to specific internal networks or honeynet areas through rule settings.

[0011] Further, in the above-mentioned security alert information processing method based on multi-agent collaboration, the file honeypots include inserting decoy files disguised as sensitive information into the user system file structure. The decoy files are deployed at path trap locations, and the path trap locations include remote shares and hidden folders under the system root directory. The account honeypots include presetting multiple false accounts without actual business functions in the system or Web platform, and registering log triggers through LDAP or Web authentication interfaces to detect brute-force cracking and password guessing behaviors.

[0012] Another object of the present invention is to provide a security alert information processing device based on multi-agent collaboration, which processes security alert information based on the constructed honeypot alert backtracking system. The honeypot alert backtracking system at least includes a honeypot management module, an alert noise reduction agent, and an attack model agent that are communicatively connected. The device includes: An alert set acquisition module, configured to obtain the original alert stream from the honeypot management module and preprocess the original alert stream to obtain an alert set. The original alert stream is obtained by the honeypot management module from the data collected from the pre-deployed honeypot cluster. A first processing module, configured to push the alert set to the alert noise reduction agent to filter false alarm information through the large language model noise reducer in the alert noise reduction agent, and then pass it to the priority marker in the alert noise reduction agent to assign corresponding priority markers to the alert set and store the marked alert set in the historical alert database. A second processing module, configured to push the alert set to the attack model agent to generate attack hypotheses by fine-tuning the attack mapping large language model in the attack model agent, and pass the attack hypotheses to the attack path backtracking engine in the attack model agent. The attack path backtracking engine queries the historical alert database to obtain relevant historical attack data, constructs a specific attack path, and generates a corresponding analysis report.

[0013] Another object of the present invention is to provide a readable storage medium, on which a computer program is stored. When the program is executed by a processor, the steps of the above-mentioned method are implemented.

[0014] Another object of the present invention is to provide an electronic device, including a memory, a processor, and a computer program stored on the memory and running on the processor. When the processor executes the program, the steps of the above method are implemented.

[0015] The present invention obtains the original alarm stream from the honey point management module and preprocesses the original alarm stream to obtain an alarm set, and pushes the alarm set to the alarm noise reduction intelligent agent, so as to filter out false alarm information through the large language model noise reducer in the alarm noise reduction intelligent agent, automate preprocessing and intelligent noise reduction, reduce the manual screening cost, reduce false alarms, and enhance the understanding and response ability to network attacks. Then, the alarm set is passed to the priority marker in the alarm noise reduction intelligent agent to assign corresponding priority markers to the alarm set and store the marked alarm set in the historical alarm database, improving the pertinence of data analysis; the alarm set is pushed to the attack model intelligent agent to generate attack hypotheses by parameter-tuning the attack mapping large language model in the attack model intelligent agent, and the attack hypotheses are passed to the attack path backtracking engine in the attack model intelligent agent. The attack path backtracking engine queries the historical alarm database to obtain related historical attack data, constructs a specific attack path, and generates a corresponding analysis report, revealing the attacker's behavior pattern and possible next actions. The detailed analysis report generated by the engine provides a comprehensive perspective to security analysts, improving the efficiency and accuracy of subsequent security alarm information analysis. It solves the problem of low efficiency and accuracy in analyzing security alarm information in the prior art. Brief Description of the Drawings

[0016] Figure 1 It is a flowchart of the method for processing security alarm information based on multi-agent collaboration in the first embodiment of the present invention; Figure 2 It is a structural block diagram of the device for processing security alarm information based on multi-agent collaboration in the third embodiment of the present invention.

[0017] The following specific embodiments will further illustrate the present invention in conjunction with the above drawings. Specific Embodiments

[0018] To facilitate the understanding of the present invention, the present invention will be described more comprehensively below with reference to the relevant drawings. Several embodiments of the present invention are shown in the drawings. However, the present invention can be implemented in many different forms and is not limited to the embodiments described herein. On the contrary, these embodiments are provided to make the disclosure of the present invention more thorough and comprehensive.

[0019] It should be noted that when an element is referred to as being "fixed to" another element, it can be directly on the other element or there may also be an intermediate element. When an element is considered to be "connected" to another element, it can be directly connected to the other element or there may be an intermediate element at the same time. The terms "vertical", "horizontal", "left", "right" and similar expressions used herein are for illustrative purposes only.

[0020] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which this invention belongs. The terms used in the specification of this invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention. The term "and / or" used herein includes any and all combinations of one or more of the related listed items.

[0021] Embodiment 1 Please refer to Figure 1 , which shows the method for processing security alarm information based on multi-agent cooperation in the first embodiment of the present invention. The security alarm information is processed based on the constructed honeypot alarm backtracking system. The honeypot alarm backtracking system at least includes a honeypot management module, an alarm noise reduction agent, and an attack model agent that are communicatively connected. The method includes steps S10 to S12.

[0022] Step S10: Obtain the original alarm stream from the honeypot management module and preprocess the original alarm stream to obtain an alarm set. Among them, the original alarm stream is obtained by the honeypot management module from the data collected from the pre-deployed honeypot cluster.

[0023] Among them, the embodiment of the present invention processes the security alarm information based on the constructed honeypot alarm backtracking system. Specifically, the honeypot alarm backtracking system includes main components such as a honeypot management module, an alarm noise reduction agent, and an attack model agent that are communicatively connected. The honeypot management module is used to obtain alarm information. As the name implies, the alarm noise reduction agent and the attack model agent are respectively used for alarm information noise reduction and attack path construction.

[0024] Specifically, security analysts are first responsible for deploying the honeypot cluster and requesting real-time monitoring of these honeypots. The monitored data can be uploaded to the honeypot management module for management. The original alarm stream can be obtained from the honeypot management module or other monitoring systems through methods such as API interfaces or direct reading. Then, the original alarm stream is preprocessed to obtain an alarm set, providing basic data support for subsequent processing and helping analysts identify potential threats faster and take corresponding measures. In specific implementation, the original alarm stream is successively subjected to data cleaning and feature extraction, and then spatio-temporal aggregation analysis is performed to aggregate alarm events that are close in time and related in spatial location in the original alarm stream to obtain an alarm set.

[0025] In addition, the constructed HoneyPoint alarm backtracking system can be divided into a data collection layer, a data calculation layer, a data service layer, a business layer, and an application layer in terms of data processing functions. Each layer from the data collection layer to the application layer plays a crucial role, ensuring the efficient operation and function realization of the entire system.

[0026] First of all, in the data collection layer, this layer is mainly responsible for collecting data from different sources, especially the original alarm stream. Through methods such as API interfaces or direct reading, the system can obtain real-time or historical alarm information from the HoneyPoint management system and other monitoring systems, providing basic data support for subsequent processing; Next is the data calculation layer, which preliminarily processes and analyzes the collected data. It includes tasks such as but not limited to data cleaning, feature extraction, and pattern recognition. Specifically, there are: the spatio-temporal aggregation algorithm, which aggregates alarm events that are close in time and related in spatial location to reduce duplicate alarms; false alarm filtering by large language models, using machine learning or deep learning models to identify and filter out possible false alarms; the attack path construction algorithm, which constructs potential attack paths based on alarm data to help understand the development process of attack behaviors; Subsequently is the data service layer, whose main function is to provide reliable data access and service support for the upper layer, ensuring data consistency and availability. This layer contains three core components: the alarm database service, which is used to store the preliminarily processed alarm information for subsequent query and analysis; the historical pattern query service, which provides the function of quickly retrieving historical alarm data to compare whether the current alarm pattern has occurred before; the associated data analysis service, which analyzes the association relationships between alarms to help identify complex attack patterns; The business layer implements specific business logics and performs specific tasks according to the data and services provided by the lower layer. It involves two key agents: the alarm noise reduction agent and the attack model agent. The alarm noise reduction agent is responsible for alarm purification and associated query, as well as priority marking and distribution, while the attack model agent focuses on constructing attack hypotheses and verification, as well as attack path analysis and reporting; Finally, in the application layer, the system directly faces users and provides the final application functions and services. In this example, it mainly includes functions such as alarm management and attack response. The alarm noise reduction agent implements the priority sorting of alarms in this layer and distributes important alarms to the corresponding processing personnel or systems; at the same time, the attack model agent generates detailed analysis reports based on the constructed attack paths to assist security analysts in making decisions.

[0027] Step S11: Push the alarm set to the alarm noise reduction intelligent agent to filter out false alarm information through the large language model noise reducer in the alarm noise reduction intelligent agent, and then pass it to the priority tagger in the alarm noise reduction intelligent agent to assign corresponding priority tags to the alarm set and store the tagged alarm set in the historical alarm database.

[0028] Among them, this intelligent agent is mainly responsible for reducing the noise data in the original security alarms, collecting the alarm sets obtained after processing the alarm information from different security devices, and handing over the processed alarm sets to the large language model for false alarm filtering and priority tagging, so as to ensure that the information passed to the analyst is accurate. It mainly includes a large language model noise reduction and priority tagging module inside. Through this modular design, the output of the large language model can be made more stable and controllable.

[0029] Exemplarily, for the large language model noise reduction module: The aggregated alarm set is submitted to the large language model noise reducer, which queries the historical alarm database to obtain historical relevant false alarm patterns, compares the data of the current alarm pattern with the historical relevant false alarm patterns, and filters out false alarm information. This learning method based on historical data can effectively distinguish normal activities from potential threats; For the priority tagging module: The noise-reduced alarms will be assigned a priority label. This process takes into account factors such as the severity and urgency of the alarms. Priority tagging not only helps analysts quickly locate key problems but also provides a basis for automated response. Finally, this information will be stored in the historical alarm database for future reference and learning.

[0030] In specific implementation, after the large language model noise reducer receives the alarm set, it performs semantic parsing on the alarm set to convert the unstructured text in the alarm set into structured feature vectors; it performs similarity matching between the feature vectors of the alarm set and the feature vectors corresponding to the relevant false alarm patterns in the historical alarm database. When the similarity between the feature vectors of the alarm set and the feature vectors corresponding to the relevant false alarm patterns exceeds a preset threshold, it is determined that the alarm information in the alarm set is a false alarm and is filtered.

[0031] Among them, when receiving the alarm set, these alarm information often appears in the form of unstructured text, such as simple descriptive statements, log fragments, etc. They lack a unified format and structure and are difficult to be directly used for efficient analysis and processing.

[0032] At this time, the large language model noise reducer will utilize natural language processing techniques and deep learning algorithms to deeply understand the semantic information behind this unstructured text. Through a series of operations such as grammatical analysis, semantic understanding, and entity recognition of the text, the originally chaotic unstructured text is transformed into structured feature vectors. These feature vectors are like the "digital fingerprints" of the alarm information, capable of precisely capturing the key features and semantic connotations of the alarm information, making subsequent processing and analysis more convenient and efficient.

[0033] Next, the transformed alarm set feature vectors are interacted with the historical alarm database. The historical alarm database stores a large amount of alarm information that has occurred in the past, including many misreport patterns that have been marked and classified. Each misreport pattern has a corresponding feature vector, which is obtained through analysis and extraction based on historical misreport data and represents the typical features of misreports.

[0034] Finally, a similarity match is performed between the feature vectors of the current alarm set and the feature vectors corresponding to the relevant misreport patterns in the historical alarm database. The similarity match comprehensively considers the similarity degree of the feature vectors in each dimension and gives a similarity score. When the similarity between the feature vectors of the alarm set and the feature vectors corresponding to a certain relevant misreport pattern exceeds the preset threshold, it means that the current alarm information has a high similarity with this misreport pattern and is very likely a repeatedly occurring misreport. At this time, the alarm information in the alarm set will be determined as a misreport, and the filtering operation will be automatically executed to eliminate these misreport information from the subsequent alarm processing process, avoiding them from interfering with the normal alarm analysis and response work.

[0035] Through such a processing process, the system can effectively identify and filter out repetitive misreports, greatly reducing the number of alarms that need to be processed, improving the efficiency and accuracy of alarm processing, enabling security analysts to focus more on the alarm information that really needs attention, and thus enhancing the stability and reliability of the entire system.

[0036] Step S12: Push the alarm set to the attack model agent to generate attack hypotheses by fine-tuning the attack mapping large language model in the attack model agent, and pass the attack hypotheses to the attack path backtracking engine in the attack model agent. Query the historical alarm database through the attack path backtracking engine to obtain relevant historical attack data, and generate a corresponding analysis report after constructing a specific attack path.

[0037] Among them, the attack model agent focuses on constructing an attack path and generating a detailed analysis report so that security analysts can understand the essence and scope of influence of the attack. Specifically, it receives the original alarm stream pushed by the honeypot management system. By fine-tuning the parameters of the large language model, the recognition ability of the model can be continuously optimized, and potential attack behaviors can be captured and distinguished more accurately. At this stage, the system not only processes alarm information intelligently, but also generates highly targeted attack hypotheses according to the characteristics of the honeypot. These hypotheses provide a solid foundation for subsequent threat analysis and traceability investigations. Based on the hypotheses provided by the attack mapping large language model, the attack path backtracking engine further queries the historical alarm database to obtain relevant historical attack data. Using this information, the engine can construct a specific attack path, revealing the attacker's behavior pattern and possible next actions. Finally, the engine generates a detailed analysis report, providing a comprehensive perspective to security analysts.

[0038] In summary, in the method for processing security alarm information based on multi-agent collaboration in the above embodiments of the present invention, the original alarm stream is obtained from the honeypot management module and preprocessed to obtain an alarm set, and the alarm set is pushed to the alarm noise reduction agent to filter false alarm information through the large language model noise reducer in the alarm noise reduction agent, realizing automated preprocessing and intelligent noise reduction, reducing the manual screening cost, reducing false alarms, and enhancing the understanding and response ability to network attacks. Then, the alarm set is passed to the priority marker in the alarm noise reduction agent to assign a corresponding priority marker to the alarm set and store the marked alarm set in the historical alarm database, improving the pertinence of data analysis; the alarm set is pushed to the attack model agent to generate attack hypotheses by fine-tuning the attack mapping large language model in the attack model agent, and the attack hypotheses are passed to the attack path backtracking engine in the attack model agent. The attack path backtracking engine queries the historical alarm database to obtain relevant historical attack data, constructs a specific attack path, and then generates a corresponding analysis report, revealing the attacker's behavior pattern and possible next actions. The detailed analysis report generated by the engine provides a comprehensive perspective to security analysts, improving the efficiency and accuracy of subsequent security alarm information analysis. This solves the problem of low efficiency and accuracy in analyzing security alarm information in the prior art.

[0039] Embodiment 2 This embodiment also proposes a method for processing security alarm information based on multi-agent collaboration. The difference between the method for processing security alarm information based on multi-agent collaboration in this embodiment and the method for processing security alarm information based on multi-agent collaboration in Embodiment 1 is as follows: The honey spot cluster includes at least: Web honey spots, protocol honey spots, file honey spots and account honey spots. Among them, honey spot technology, as an innovative defense means, can effectively detect and respond to attackers' illegal acquisition of system internal resources. The honey spots of the embodiment of the present invention include four types: Web honey spots, protocol honey spots, file honey spots and account honey spots, and these honey spots are managed and deployed using Docker containers. Unlike traditional honeypots, honey spots do not actively spread their existence, but are deployed on paths that regular users will not access. Once a honey spot is accessed, the system can confirm that the behavior is an abnormal access, and then trigger an alarm. For example, the system tripwire implementation technology based on parasitic honey spots can defend against attackers' acquisition of internal resources by deploying "dark functions" that will not be used by normal users in system services, or reproducing existing system services to hide real functions and system services. Even if an attacker breaks through the peripheral defense, the honey spot can still expose its behavior when it tries to steal resources, forming a deep security threat detection capability.

[0040] Specifically, Web honey spots include at least Web mirror honey spots, Web parasitic honey spots, and Web vulnerability honey spots. Web mirror honey spots include those that are disguised as real web services by copying the interface and basic interaction logic of the target web page to induce attackers to visit; Protocol honey spots include simulated SSH, Telnet or MySQL protocol services, which are isolated from real services and exposed only to specific internal networks or honeynet areas through rule settings to avoid interference with normal users; File honey spots include inserting bait files disguised as sensitive information into the user's system file structure. The bait files are deployed in path trap locations, including remote shares and hidden folders under the system root directory. Real-time monitoring is performed through file access triggers. Once accessed, the behavior trajectory and access tool type are reported; Account honey spots include presetting multiple fake accounts with no actual business functions in the system or Web platform, and registering log triggers through LDAP or Web authentication interfaces to detect brute force cracking and password guessing behaviors.

[0041] In addition, while emphasizing concealment, honey spots must also ensure system isolation and security to prevent attackers from using honey spots as a springboard to threaten real systems. In the embodiment of the present invention, K3s is used as a lightweight container orchestration platform, which provides efficient cluster management and containerized environment deployment capabilities, and is suitable for running honey spot systems in resource-constrained edge or small environments. Falco, as a runtime security detection engine, is responsible for monitoring system calls and abnormal behaviors, capturing attacker activities in real time and generating alerts.

[0042] Among them, K3s is designed specifically for resource-constrained environments. Its small binary file and simplified architecture make it very suitable for building honeypot systems. Through K3s, honeypot services are deployed in the cluster in a containerized form, and each container simulates a specific service or vulnerability. K3s ensures that consistent honeypot instances are running on each node, thus expanding the trapping scope and increasing the probability of capturing attack behaviors.

[0043] As a cloud-native runtime security tool, Falco detects abnormal behaviors in the honeypot system in real time by monitoring the system calls of the Linux kernel. Its core function is based on a powerful rule engine that can identify potential malicious activities according to predefined rules or custom policies. Falco supports multiple drivers to ensure its compatibility in different kernel versions and environments. In the honeypot system, Falco is deployed as a DaemonSet and runs on each node of the K3s cluster to capture system call events inside the container in real time. By analyzing the parameters and context of system calls, Falco can detect the commands executed by attackers, the files modified, or the network connections attempted. When an attacker tries to create a malicious script or initiate an external connection in the honeypot container, Falco will trigger an alarm and record detailed event information. These alarms can be output through multiple backends for further analysis and response.

[0044] In summary, in the above-mentioned embodiment of the present invention, the method for processing security alarm information based on multi-agent collaboration obtains the original alarm stream from the honeypot management module and preprocesses the original alarm stream to obtain an alarm set, and pushes the alarm set to the alarm noise reduction agent to filter out false alarm information through the large language model noise reducer in the alarm noise reduction agent, realizing automated preprocessing and intelligent noise reduction, reducing the manual screening cost, reducing false alarms, and enhancing the understanding and response ability to network attacks. Then, the alarm set is passed to the priority marker in the alarm noise reduction agent to assign corresponding priority markers to the alarm set and store the marked alarm set in the historical alarm database, improving the pertinence of data analysis; the alarm set is pushed to the attack model agent to generate attack hypotheses by fine-tuning the attack mapping large language model in the attack model agent, and the attack hypotheses are passed to the attack path backtracking engine in the attack model agent. The attack path backtracking engine queries the historical alarm database to obtain relevant historical attack data, constructs a specific attack path, and generates a corresponding analysis report to reveal the attacker's behavior pattern and possible next actions. The detailed analysis report generated by the engine provides a comprehensive perspective for security analysts and improves the efficiency and accuracy of subsequent security alarm information analysis. It solves the problem of low efficiency and accuracy in analyzing security alarm information in the prior art.

[0045] Embodiment 3 Please refer to Figure 2, shown is a security alert information processing device based on multi-agent collaboration proposed in the third embodiment of the present invention. The security alert information is processed based on the constructed honeypot alert backtracking system. The honeypot alert backtracking system at least includes a honeypot management module, an alert noise reduction agent, and an attack model agent that are communicatively connected. The device includes: An alert set acquisition module 100, configured to obtain an original alert stream from the honeypot management module and preprocess the original alert stream to obtain an alert set. Among them, the original alert stream is obtained by the honeypot management module from the data collected by a pre-deployed honeypot cluster; A first processing module 200, configured to push the alert set to the alert noise reduction agent, so as to filter out false alarm information through the large language model noise reducer in the alert noise reduction agent, and then pass it to the priority marker in the alert noise reduction agent to assign a corresponding priority marker to the alert set and store the marked alert set in the historical alert database; A second processing module 300, configured to push the alert set to the attack model agent, so as to generate an attack hypothesis by fine-tuning the attack mapping large language model in the attack model agent, and pass the attack hypothesis to the attack path backtracking engine in the attack model agent. The attack path backtracking engine queries the historical alert database to obtain relevant historical attack data, and constructs a specific attack path and then generates a corresponding analysis report.

[0046] The functions or operation steps implemented when the above modules are executed are substantially the same as those in the above method embodiment, and will not be elaborated here.

[0047] Embodiment Four On the other hand, the present invention also provides a readable storage medium, on which a computer program is stored. When the program is executed by a processor, the steps of the method described in any one of the above Embodiments 1 to 2 are implemented.

[0048] Embodiment Five On the other hand, the present invention also provides an electronic device. The electronic device includes a memory, a processor, and a computer program stored on the memory and running on the processor. When the processor executes the program, the steps of the method described in any one of the above Embodiments 1 to 2 are implemented.

[0049] The technical features of each of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as the combinations of these technical features do not conflict, they should all be considered as the scope described in this specification.

[0050] Those skilled in the art will understand that the logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a definite sequence list of executable instructions for implementing logical functions, and can be specifically implemented in any computer-readable storage medium for use by an instruction execution system, apparatus, or device (such as a computer-based system, a system including a processor, or other systems that can fetch and execute instructions from the instruction execution system, apparatus, or device), or used in conjunction with these instruction execution systems, apparatus, or devices. For the purposes of this specification, a "computer-readable storage medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0051] More specific examples (non-exhaustive list) of computer-readable storage media include the following: an electrical connection part (electronic device) having one or more wirings, a portable computer diskette (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disc read-only memory (CDROM). Additionally, the computer-readable storage medium can even be paper or other suitable media on which the program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other media, followed by editing, interpretation, or other suitable processing as necessary, and then stored in a computer memory.

[0052] It should be understood that various parts of the present invention can be implemented by hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, any one or a combination of the following techniques well known in the art can be used: discrete logic circuits having logic gate circuits for implementing logical functions on data signals, application specific integrated circuits having appropriate combinational logic gate circuits, programmable gate arrays (PGAs), field programmable gate arrays (FPGAs), etc.

[0053] In the description of this specification, the description with reference to terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples", etc. means that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples.

[0054] The above-described embodiments merely represent several implementation manners of the present invention. The description thereof is relatively specific and detailed, but it should not be construed as a limitation to the scope of the present invention patent. It should be noted that for those of ordinary skill in the art, several modifications and improvements can be made without departing from the concept of the present invention, and these all fall within the protection scope of the present invention. Therefore, the protection scope of the present invention patent shall be subject to the appended claims.

Claims

1. A method for processing security alert information based on multi-agent collaboration, characterized in that Processing security alert information based on the constructed HoneyPoint alert backtracking system. The HoneyPoint alert backtracking system at least includes a HoneyPoint management module, an alert noise reduction agent, and an attack model agent that are communicatively connected. The method includes: Obtaining the original alert stream from the HoneyPoint management module and preprocessing the original alert stream to obtain an alert set. Among them, the original alert stream is obtained by the HoneyPoint management module from the data collected by the pre-deployed HoneyPoint cluster; Pushing the alert set to the alert noise reduction agent to filter false alarm information through the large language model noise reducer in the alert noise reduction agent, and then passing it to the priority marker in the alert noise reduction agent to assign corresponding priority markers to the alert set and storing the marked alert set in the historical alert database; Pushing the alert set to the attack model agent to generate attack hypotheses by fine-tuning the attack mapping large language model in the attack model agent, and passing the attack hypotheses to the attack path backtracking engine in the attack model agent. Query the historical alert database through the attack path backtracking engine to obtain relevant historical attack data, and construct a specific attack path and then generate a corresponding analysis report.

2. The method for processing security warning information based on multi-agent collaboration according to claim 1, wherein The step of obtaining the original alert stream from the HoneyPoint management module and preprocessing the original alert stream to obtain an alert set includes: Successively performing data cleaning and feature extraction on the original alert stream, and then performing spatio-temporal aggregation analysis to aggregate alert events that are close in time and related in spatial location in the original alert stream to obtain an alert set.

3. The method for processing security warning information based on multi-agent collaboration according to claim 1, wherein The step of filtering false alarm information through the large language model noise reducer in the alert noise reduction agent and then passing it to the priority marker in the alert noise reduction agent to assign corresponding priority markers to the alert set includes: After the large language model noise reducer receives the alert set, query the historical alert database to obtain historical relevant false alarm patterns, and filter false alarm information based on the comparison of the alert information in the current alert set with the data of the historical relevant false alarm patterns; The filtered alert set is passed to the priority marker to evaluate the importance of each alert set and assign corresponding priority markers according to the level of importance.

4. The method for processing security warning information based on multi-agent collaboration according to claim 3, wherein The step of querying the historical alert database to obtain historical relevant false alarm patterns after the large language model noise reducer receives the alert set and filtering false alarm information based on the comparison of the alert information in the current alert set with the data of the historical relevant false alarm patterns includes: After the large language model noise reducer receives the alert set, perform semantic parsing on the alert set to convert the unstructured text in the alert set into a structured feature vector; Perform similarity matching between the feature vector of the alert set and the feature vector corresponding to the relevant false alarm pattern in the historical alert database. When the similarity between the feature vector of the alert set and the feature vector corresponding to the relevant false alarm pattern exceeds the preset threshold, determine that the alert information in the alert set is a false alarm and filter it.

5. The method for processing security warning information based on multi-agent collaboration according to claim 1, wherein The HoneyPoint cluster at least includes: Web HoneyPoint, protocol HoneyPoint, file HoneyPoint, and account HoneyPoint.

6. The method for processing security warning information based on multi-agent collaboration according to claim 5, wherein The Web honeypots at least include Web mirror honeypots, Web parasitic honeypots, and Web vulnerability honeypots. Among them, the Web mirror honeypots include disguising as real web services by copying the interfaces and basic interaction logics of target web pages to induce attackers to access. The protocol honeypots include simulated SSH or Telnet or MySQL protocol services, isolated from real services, and exposed only to specific internal networks or honeynet areas through rule settings.

7. The method for processing security warning information based on multi-agent collaboration according to claim 6, wherein The file honeypots include inserting decoy files disguised as sensitive information into the user system file structure. Among them, the decoy files are deployed at path trap locations, and the path trap locations include remote shares and hidden folders under the system root directory. The account honeypots include presetting multiple false accounts without actual business functions in the system or Web platform, and registering log triggers through LDAP or Web authentication interfaces to detect brute-force cracking and password guessing behaviors.

8. A security alert information processing device based on multi-agent collaboration, characterized in that, Based on the constructed honeypot alarm backtracking system to process security alarm information, the honeypot alarm backtracking system at least includes a honeypot management module, an alarm noise reduction agent, and an attack model agent that are communicatively connected. The device includes: An alarm set acquisition module, configured to obtain the original alarm stream from the honeypot management module and preprocess the original alarm stream to obtain an alarm set. Among them, the original alarm stream is obtained by the honeypot management module from the data collected from the pre-deployed honeypot cluster. A first processing module, configured to push the alarm set to the alarm noise reduction agent to filter false alarm information through the large language model noise reducer in the alarm noise reduction agent, and then pass it to the priority marker in the alarm noise reduction agent to assign a corresponding priority marker to the alarm set and store the marked alarm set in the historical alarm database. A second processing module, configured to push the alarm set to the attack model agent to generate attack hypotheses by fine-tuning the attack mapping large language model in the attack model agent, and pass the attack hypotheses to the attack path backtracking engine in the attack model agent. Query the historical alarm database through the attack path backtracking engine to obtain related historical attack data, and construct a specific attack path and then generate a corresponding analysis report.

9. A readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the steps of the method described in any one of claims 1 to 7.

10. An electronic device, characterized in that, It includes a memory, a processor, and a computer program stored on the memory and running on the processor. When the processor executes the program, it implements the steps of the method described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Method for mining multi-step attack scene by utilizing honeypot alarm log

    CN111901137A

  • Automatic threat tracing method, system, equipment and medium

    CN115801431A

  • Threat alarm information processing method and device, computer equipment and storage medium

    CN116155519A

  • Alarm log analysis method and device

    CN117318967A

  • Automatic generation method of attack graph interaction rule for honey point deployment

    CN118101346A

Cited By

  • Attack behavior analysis method based on attack mapping and path analysis

    CN121173601A