Alarm data output method and device
By setting up an IP information database inside the traffic detection device, the resource consumption problem caused by external query and filtering is solved, and efficient IP address information enrichment and alarm data analysis are achieved.
Patent Information
- Application Number
- CN202510629786.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-15
- Publication Date
- 2025-07-25
AI Technical Summary
After the prior art generates alarm data in network traffic detection equipment, external database query and analysis personnel are required to screen IP address related information, resulting in excessive resource consumption.
Set up an IP information database inside the traffic detection device, only the IP address and its corresponding IP tag are configured, the priority is the network security attack and defense type, reduce external database calls, and ensure the accuracy and formatting of the IP tag through the priority and handler of the IP information source.
It reduces the number of database calls for IP address-related information query, reduces the screening workload of the analysts, and improves the analysis efficiency and accuracy of the alarm data.
Smart Images

Figure CN120378279A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technologies, and in particular, to a method for outputting alarm data, an apparatus for outputting alarm data, a computer device, a computer-readable storage medium, and a computer program product. Background Art
[0002] In a traffic detection device, a judgment rule indicating traffic anomalies is pre-configured. For traffic data transmitted in a network, the traffic detection device acquires the traffic data and then matches the traffic data with the judgment rule. If the match fails, it is determined that the traffic data is normal, and no processing is performed on the traffic data, allowing the traffic data to continue to flow. If the match is successful, it is determined that the traffic data is abnormal, and then alarm data is generated based on the traffic data and the alarm data is output.
[0003] Generally speaking, alarm data is only the result of preliminary detection. In some scenarios, the network traffic corresponding to the output alarm data may actually pose a security threat or may be normal. This requires analysts to further analyze the alarm data. To facilitate analysts to directly analyze based on the alarm data, the alarm data can be further expanded. For example: expand the source Internet Protocol (IP) address and destination IP address in the alarm data, query in various databases related to IP information in the network, and thus add the queried information related to the IP address to the alarm data and display it to the analysts together.
[0004] However, querying information related to IP addresses in the network requires invoking multiple databases, and the queried information related to IP addresses is also quite diverse and not necessarily all applicable to the analysts' analysis of the alarm data. Analysts still need to screen out the actual required information from the numerous related information, which will increase the resource consumption when further analyzing the alarm data. Summary of the Invention
[0005] The purpose of the embodiments of this application is to provide a method for outputting alarm data, an apparatus for outputting alarm data, a computer device, a computer-readable storage medium, and a computer program product to reduce the resource consumption when further analyzing the alarm data.
[0006] To solve the above technical problems, the embodiments of this application provide the following technical solutions:
[0007] The first aspect of the present application provides a method for outputting alarm data. The method is applied to a traffic detection device, which includes an Internet Protocol (IP) information database. The IP information database includes multiple IP addresses and their corresponding IP tags. The IP tags are used to indicate the manufacturers or network security attack and defense types corresponding to the IP addresses. The network security attack and defense type has a higher priority than the manufacturer as the IP tag. The method includes: obtaining the alarm data initially generated by the traffic detection device; extracting the target IP address from the alarm data; searching for the target IP tag corresponding to the target IP address in the IP information database; adding the target IP tag to the position corresponding to the target IP address in the initially generated alarm data; and outputting the alarm data after adding the target IP tag.
[0008] Compared with the prior art, in the method for outputting alarm data provided by the first aspect of the present application, the IP information database is moved inside the traffic detection device, and only one database is set up, which can reduce the number of calls to the database when querying IP address-related information and reduce resource consumption. Moreover, in the IP information database, only the IP addresses and their corresponding IP tags are configured. One IP address corresponds to only one IP tag, and based on the network security attack and defense type as the IP tag, the manufacturer is no longer configured. Only when the network security attack and defense type is not obtained, the manufacturer is configured for the IP tag. This enables only one IP tag to be queried based on the IP address in the alarm data, and only a single piece of information that is more useful for judging the IP address is displayed in the alarm data, which can reduce the workload of the judging personnel in screening various IP address-related information, and further reduce the resource consumption when further judging the alarm data.
[0009] In other embodiments provided by the present application, before obtaining the alarm data initially generated by the traffic detection device, the method further includes: obtaining the IP addresses and their corresponding IP tags from multiple IP information sources; obtaining the priority of each IP information source; and writing the IP addresses and their corresponding IP tags obtained from each IP information source into the IP information database in ascending order of priority. When the currently to-be-written IP address duplicates the already-written IP address, the currently to-be-written IP address and its corresponding IP tag overwrite the already-written IP address and its corresponding IP tag.
[0010] When constructing the IP information database, writing each of the IP addresses and their corresponding IP tags obtained from multiple IP information sources into the database in ascending order of the priority of the IP information sources and overwriting the same IP address with different IP tags can ensure that the more correct IP tag corresponding to the IP address is written into the IP information database, and improve the accuracy of the IP tag corresponding to the IP address in the IP information database.
[0011] In other embodiments provided by the present application, the multiple IP information sources include the IP range tables publicly disclosed by each manufacturer, AS autonomous systems, the IP-related database belonging to the same management system as the traffic detection device, and the third-party IP-related database obtained through public channels; obtaining the IP addresses and their corresponding IP tags from the multiple IP information sources includes: obtaining the IP addresses and their corresponding IP tags in sequence according to the IP-related database belonging to the same management system as the traffic detection device, the IP range tables publicly disclosed by each manufacturer, the AS autonomous systems, and the third-party IP-related database obtained through public channels.
[0012] The credibility of the IP tags corresponding to the IP addresses in the IP-related database belonging to the same management system as the traffic detection device, the IP range tables publicly disclosed by each manufacturer, the AS autonomous systems, and the third-party IP-related database obtained through public channels decreases in sequence. Obtaining the IP addresses and their corresponding IP tags in this order can ensure that the more accurate IP tags corresponding to the IP addresses are obtained earlier, avoiding abnormal acquisition of IP tags due to unexpected factors during the subsequent acquisition process of IP tags, and ultimately improving the accuracy of the IP tags corresponding to the IP addresses in the IP information database.
[0013] In other embodiments provided by the present application, obtaining the priority of each IP information source includes: obtaining the source address of each IP information source; determining the priority of each IP information source according to the range accuracy of the network address and the host address in the source address, where the range accuracy of the network address and the host address is positively correlated with the priority.
[0014] Since the network address and the host address can characterize the range accuracy of the network to which the source belongs, the range of the network address is usually represented by the prefix length (i.e., subnet mask) of the IP address, and the identification of a specific host is represented by the length of the host address. Generally speaking, the shorter the prefix length of the IP address, the larger the range of the network address represented, and the longer the host address part, the more specific the host represented. Therefore, the priority of the IP information source can be quickly and accurately determined through the range accuracy of the network address and the host address of the source address of the IP information source.
[0015] In other embodiments provided by the present application, before writing the IP addresses and their corresponding IP tags obtained from each IP information source into the IP information database, the method further includes: creating an IP information data table in the IP information database, where the IP information data table at least includes an IP address field, an IP tag field, and a source address field, and multiple handlers are correspondingly configured for the IP information data table, and each handler can process the IP tag corresponding to the source address of the corresponding type into an IP tag in a standard format; writing the IP addresses and their corresponding IP tags obtained from each IP information source into the IP information database, including: writing the IP addresses and their corresponding IP tags obtained from each IP information source and the source address corresponding to the corresponding IP information source into the corresponding fields of the IP information data table; calling the corresponding handler according to the type of the written source address, and modifying the written IP tag into an IP tag in a standard format through the called handler, so as to complete the writing of the IP address and its corresponding IP tag in the IP information database.
[0016] By creating an IP information data table, and after writing the IP tag in the table, processing the written IP tag into a standard format according to the type of the written source address by calling the corresponding handler, it is ensured that the standard format conversion of the IP tag is achieved at a fixed position, and the accuracy of the IP information data table for storing the IP address and its corresponding IP tag is improved.
[0017] In other embodiments provided by the present application, before writing the IP addresses and their corresponding IP tags obtained from each IP information source and the source address corresponding to the corresponding IP information source into the corresponding fields of the IP information data table, the method further includes: backing up the existing IP addresses and their corresponding IP tags in the IP information data table, and clearing the IP information data table; modifying the written IP tag into an IP tag in a standard format through the called handler, including: if the called handler indicates that the modification fails, selecting the IP tag with the same IP address as the IP tag corresponding to the failed modification from the backed-up IP tags as the IP tag in the standard format, and writing the IP tag in the standard format to the position where the modification fails in the IP information data table.
[0018] In the case where the standard format conversion of the IP tag in the table fails, directly using the IP tag corresponding to the same IP address in the backup data before clearing, since the backed-up IP tags are also obtained from the same IP information source using the same data processing method, the rapid acquisition of the IP tag in the standard format can be achieved, thereby improving the generation efficiency of the IP information data table.
[0019] In other embodiments provided by the present application, after writing the IP addresses and their corresponding IP tags obtained from each IP information source into the IP information database, the method further includes: compressing each IP address and its corresponding IP tag in the IP information database respectively by using a preset compression method to obtain a plurality of compressed blocks; processing the plurality of compressed blocks into a data file in the MaxMindDB format; and injecting the data file into the traffic detection device in an upgraded manner.
[0020] First, each IP address and its corresponding IP tag are compressed respectively, and then they are uniformly compressed into the MaxMind DB format. That is, by using the preset block-level compression and MaxMind DB format compression, the IP addresses and their corresponding IP tags can be compressed to the greatest extent, further reducing the resource occupancy of the IP information database in the traffic detection device.
[0021] In other embodiments provided by the present application, before searching for the target IP tag corresponding to the target IP address in the IP information database, the method further includes: if the target IP address is the internal network address or asset address of itself, outputting the initially generated alarm data.
[0022] Before querying the IP tag from the IP information database based on the IP address, first filter the IP address to be queried, and no longer query the IP addresses of the internal network and the internal assets. Since the internal network addresses and the internal asset addresses do not pose any security threats to itself and are easy to be identified by the research and judgment personnel, therefore, skipping the query of such IP addresses can improve the enrichment efficiency of the alarm data while ensuring that the alarm data can be researched and judged.
[0023] The second aspect of the present application provides an output device for alarm data. The device is applied to a traffic detection device. The traffic detection device includes an Internet Protocol (IP) information database, and the IP information database includes a plurality of IP addresses and their corresponding IP tags. The IP tags are used to indicate the manufacturers or network security attack and defense types corresponding to the IP addresses, and the network security attack and defense type has a higher priority than the manufacturer as the IP tag. The device includes: an acquisition module, configured to acquire the initially generated alarm data of the traffic detection device; an extraction module, configured to extract the target IP address from the alarm data; a search module, configured to search for the target IP tag corresponding to the target IP address in the IP information database; an addition module, configured to add the target IP tag to the position corresponding to the target IP address in the initially generated alarm data; and an output module, configured to output the alarm data after adding the target IP tag.
[0024] The third aspect of the present application provides a computer device, including a memory, a processor, and a computer program stored on the memory. The processor executes the computer program to implement the steps of the method in the first aspect.
[0025] The fourth aspect of the present application provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the method in the first aspect are implemented.
[0026] The fifth aspect of the present application provides a computer program product, including a computer program, and when the computer program is executed by a processor, the steps of the method in the first aspect are implemented.
[0027] The alarm data output device provided in the second aspect of the present application, the computer device provided in the third aspect, the computer-readable storage medium provided in the fourth aspect, and the computer program product provided in the fifth aspect have the same or similar beneficial effects as the alarm data output method provided in the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] By referring to the drawings and reading the detailed description below, the above and other objects, features, and advantages of the exemplary embodiments of the present application will become readily understandable. In the drawings, several embodiments of the present application are shown in an exemplary rather than restrictive manner, and the same or corresponding reference numerals represent the same or corresponding parts, where:
[0029] Figure 1 It is a schematic diagram of the application scenario of the alarm data output method in the embodiment of the present application;
[0030] Figure 2 It is a flowchart of the alarm data output method in the embodiment of the present application Figure 1 ;
[0031] Figure 3 It is a flowchart of the alarm data output method in the embodiment of the present application Figure 2 ;
[0032] Figure 4 It is a partial example of the IP information database processed in the MaxMind DB format in the embodiment of the present application;
[0033] Figure 5 It is an example where the IP tag in the alarm data output in the embodiment of the present application is VPN;
[0034] Figure 6 It is an example where the IP tag in the alarm data output in the embodiment of the present application is scanner;
[0035] Figure 7 It is a schematic diagram of the structure of the alarm data output device in the embodiment of the present application Figure 1 ;
[0036] Figure 8 It is a schematic diagram of the structure of the alarm data output device in the embodiment of the present application Figure 2;
[0037] Figure 9 This is a schematic structural diagram of a computer device in an embodiment of the present application. Detailed implementation manners
[0038] Hereinafter, the exemplary embodiments of the present application will be described in more detail with reference to the accompanying drawings. Although the exemplary embodiments of the present application are shown in the drawings, it should be understood that the present application can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present application can be more thoroughly understood and the scope of the present application can be fully conveyed to those skilled in the art.
[0039] It should be noted that unless otherwise specified, the technical terms or scientific terms used in the present application should have the ordinary meanings understood by those skilled in the art to which the present application belongs.
[0040] Currently, in order to enrich the information of IP addresses in alarm data, it is necessary to externally call various databases to query IP address-related information. The invocation of multiple databases and the screening of the complex related information queried by the research and judgment personnel both consume certain resources, thereby increasing the resource consumption when further researching and judging the alarm data.
[0041] In view of this, the embodiments of the present application provide a method for outputting alarm data, a device for outputting alarm data, a computer device, a computer-readable storage medium, and a computer program product. Instead of externally calling multiple databases to query IP address-related information, it queries through an IP information database built in a traffic detection device, which can reduce the number of database invocations and simplify the external call to an internal call. Moreover, in the IP information database, only one IP label is configured for each IP address. The IP label preferentially selects the network security attack and defense type, and secondly selects the corresponding manufacturer. In this way, only one piece of information that is most beneficial for researching and judging the IP address can be displayed in the alarm data, enabling the research and judgment personnel to further research and judge based on more IP address-related information without the need to screen the relevant information, thereby reducing the resource consumption when further researching and judging the alarm data.
[0042] It should be noted here that all components, data, and related processing methods involved in the present application are authorized by the user or fully authorized by all parties, and the collection, use, and processing of related data comply with the relevant laws, regulations, and standards of relevant countries and regions.
[0043] First, the application scenario of the method for outputting alarm data provided by the embodiments of the present application will be described.
[0044] Figure 1The following is a schematic diagram of the application scenario of the method for outputting alarm data in the embodiments of the present application. Refer to Figure 1 As shown in the figure, this scenario may include: a traffic detection device 11.
[0045] In the traffic detection device, a judgment rule and an IP information database are preset.
[0046] The judgment rule here is a relevant feature representation for detecting whether the traffic data is abnormal. For example: the judgment rule is that the password is entered incorrectly three times in a row, etc.
[0047] In the IP information database, it includes multiple IP addresses and their corresponding IP tags. The IP tag is used to indicate the manufacturer or the type of network security attack and defense corresponding to the IP address. The type of network security attack and defense has a higher priority than the manufacturer as the IP tag. That is to say, when the manufacturer and the type of network security attack and defense corresponding to the IP address are obtained, the IP tag corresponding to the IP address preferentially uses the type of network security attack and defense. In the case where the type of network security attack and defense corresponding to the IP address is not obtained, the IP tag corresponding to the IP address then uses the manufacturer.
[0048] The manufacturer here generally refers to the holder of the IP address. For example: xx enterprise. And the type of network security attack and defense can refer to various entity types related to network security attacks or defenses. For example: security-related websites, scanners, etc.
[0049] For the traffic data that needs to be security-detected in the network, the traffic detection device obtains the traffic data and matches the traffic data with the judgment rule. If the match fails, it means that the traffic data belongs to normal transmission and no special processing is required, so that the traffic data can continue to flow. If the match is successful, it means that the traffic data is abnormal. The traffic detection device needs to generate alarm data based on the traffic data and output it to the user.
[0050] Before the traffic detection device outputs the alarm data, it also needs to query the IP address in the alarm data in the IP information database. If the same IP address is found, the IP tag corresponding to the same IP address is also added to the alarm data, and then the alarm data is output. If the same IP address is not found, the alarm data can be directly output.
[0051] Next, the method for outputting alarm data provided in the embodiments of the present application will be described in detail.
[0052] Figure 2 The following is the flowchart of the method for outputting alarm data in the embodiments of the present application Figure 1 Refer to Figure 2 As shown in the figure, this method may include:
[0053] S21: Obtain the alarm data initially generated by the traffic detection device.
[0054] After the traffic detection device initially generates alarm data based on traffic data and judgment rules, it does not immediately output the alarm data. Instead, it first enriches the content in the alarm data.
[0055] When enriching the content of the alarm data, all contents in the alarm data can be enriched, or only some contents in the alarm data can be enriched. For example: Enrich the source IP address and destination IP address in the alarm data to provide information that is more helpful for the judgment personnel to further judge without seriously increasing the burden on the traffic detection device.
[0056] S22: Extract the target IP address from the alarm data.
[0057] In the alarm data, generally, it will contain the IP addresses from which the traffic data is sent and to which it is received, that is, the target IP address, which is the source IP address and the destination IP address. And the IP address is also effective information that can help the judgment personnel determine whether there is a real security threat to the traffic data corresponding to the alarm data. Therefore, it is very necessary to extract the IP address from the alarm data and enrich the information of the IP address.
[0058] Generally speaking, the position of the IP address in the alarm data is preset and relatively fixed. The IP address can be directly extracted from the preset position, which can improve the extraction efficiency of the IP address. It is also possible to perform feature recognition on the content in the alarm data, identify the content with the characteristics of the IP address, and use the identified content as the target IP address.
[0059] S23: Search for the target IP label corresponding to the target IP address in the IP information database.
[0060] In the IP information database, the corresponding relationships between various IP addresses and IP labels are stored. Search for the target IP address extracted from the alarm data in the IP information database, and then use the IP label corresponding to the same IP address found as the target IP label corresponding to the target IP address.
[0061] S24: Add the target IP label to the position corresponding to the target IP address in the initially generated alarm data.
[0062] In the alarm data initially generated based on the judgment rule, the source IP address and the destination IP address are included. Then, the IP label corresponding to the source IP address and the IP label corresponding to the destination IP address are queried from the IP information database. Adding the IP label corresponding to the source IP address to the corresponding position of the source IP address in the alarm data and adding the IP label corresponding to the destination IP address to the corresponding position of the destination IP address in the alarm data can enrich the information of the IP addresses in the alarm data.
[0063] In practical applications, the position where the IP label is added to the alarm data can be the position for annotation information after the IP address or a hidden position. When the analyst clicks on the IP address in the alarm data, the information at this position is displayed, that is, the IP label is displayed. In this way, it can avoid displaying too much information at one time in the alarm data, which affects the analyst's search for the actual required information. Only when further research on the IP address in the alarm data is needed, after the analyst clicks on the IP address, the IP label is displayed, which can be more convenient for the analyst to analyze the alarm data and improve the analysis efficiency of the analyst for the alarm data.
[0064] S25: Output the alarm data after adding the target IP label.
[0065] After the IP label is added to the initially generated alarm data, the alarm data can be output, so that when the analyst further analyzes the alarm data, especially when analyzing based on the IP address, the IP label can be directly used, thereby improving the analysis efficiency of the analyst for the alarm data.
[0066] As can be seen from the above, the method for outputting alarm data provided by the embodiment of the present application moves the IP information database inside the traffic detection device and only sets one database, which can reduce the number of calls to the database when querying IP address-related information and reduce resource consumption. And in the IP information database, only the IP address and its corresponding IP label are configured. One IP address corresponds to only one IP label, and on the basis that the IP label is of the network security attack and defense type, the manufacturer is no longer configured. Only when the network security attack and defense type is not obtained, the manufacturer is configured for the IP label. So that only one IP label is queried based on the IP address in the alarm data, and only a single piece of information that is more useful for analyzing the IP address is displayed in the alarm data, which can reduce the workload of the analyst for screening various IP address-related information, and further reduce the resource consumption when further analyzing the alarm data.
[0067] Further, as a refinement and extension of the Figure 2 shown method, the embodiment of the present application also provides a method for outputting alarm data.
[0068] Figure 3 Flow schematic of the alarm data output method in the embodiments of this application Figure 2 , see Figure 3 As shown, the method may include two processes. The first process is the creation of the IP information database, and the second process is the enrichment of alarm data.
[0069] I. Create an IP information database.
[0070] S31: Obtain IP addresses and their corresponding IP tags from multiple IP information sources.
[0071] The IP information sources here can be any data sources that can provide IP addresses and their related information. In order to improve the accuracy and acquisition efficiency of IP tags in the IP information database, multiple IP information sources can select the publicly disclosed IP range tables of each manufacturer, as autonomous systems, IP-related databases belonging to the same management system as the traffic detection device, and third-party IP-related databases obtained through public channels.
[0072] The IP information source selects the publicly disclosed IP range tables of each manufacturer because each manufacturer is relatively clear about its own IP address range. After obtaining the publicly disclosed IP range table of the manufacturer, the IP address range can be determined, and the corresponding manufacturer is the IP tag.
[0073] The IP information source selects as autonomous systems. Since an as autonomous system is a logical unit of a group of IP networks and routing devices managed by a single organization (such as an ISP, a large enterprise, or an institution) in the Internet, it will contain the IP addresses of each manufacturer. In this way, the IP address and its corresponding IP tag, that is, the manufacturer, can also be obtained.
[0074] The IP information source selects the IP-related database belonging to the same management system as the traffic detection device because its own system will also maintain a knowledge base. In this knowledge base, it will contain IP addresses and their corresponding network security attack and defense types. Obtaining the IP addresses and their corresponding network security attack and defense types from this knowledge base can also obtain the IP addresses and their IP tags.
[0075] The IP information source selects the third-party IP-related database obtained through public channels because various IP addresses and their related information will also be included in public channels. Obtaining the IP addresses and their corresponding IP tags from the third-party IP-related database in public channels can maximize the acquisition of IP addresses and their IP tags. The third-party IP-related database here can be the summary of each IP address and its corresponding manufacturer or network security attack and defense type by a third party, or it can be relevant articles analyzed by a third party for IP addresses, so as to obtain IP tags through the articles and obtain the IP addresses and their corresponding IP tags.
[0076] Specifically, the above step S31 may include: obtaining the IP address and its corresponding IP label in sequence according to the IP-related database belonging to the same management system as the traffic detection device, the IP range tables publicly disclosed by each manufacturer, the AS (autonomous system), and the third-party IP-related database obtained from public channels.
[0077] By obtaining the IP address and its IP label in this order, since the reliability of the IP-related database belonging to the same management system as the traffic detection device, the IP range tables publicly disclosed by each manufacturer, the AS (autonomous system), and the third-party IP-related database obtained from public channels decreases in sequence, it can ensure that more reliable IP addresses and their IP labels are obtained first, avoiding the failure to obtain highly reliable IP addresses and their IP labels due to resource contention during the acquisition process, and improving the overall accuracy of obtaining the IP address and its IP label.
[0078] S32: Obtain the priority of each IP information source.
[0079] The priority of the IP information source is positively correlated with the reliability degree of the IP address and its IP label provided by the IP information source. The higher the reliability degree, the higher the priority.
[0080] In order to improve the acquisition efficiency of the IP information source priority, the priority of the IP information source can be determined according to the network address and the range accuracy of the host address of the source address of the IP information source. This is because: the name of the database used internally or the internal network address is shorter in length compared to the external database address and has higher reliability. Moreover, the calculation of the network address and the range accuracy of the host address is relatively simple and can be quickly determined.
[0081] Specifically, the above step S32 may include: obtaining the source address of each IP information source; determining the priority of each IP information source according to the network address and the range accuracy of the host address in the source address, where the network address and the range accuracy of the host address are positively correlated with the priority.
[0082] Multiple IP information sources can be sorted in descending order according to the range precision of the network address and host address in the source address, and then priorities from high to low are assigned to each IP information source according to the sorting. When specifically sorting, multiple IP information sources can be sorted according to the range precision of the network address, and then multiple IP information sources can be sorted according to the range precision of the host address. Finally, by integrating the two sets of sorting, a set of sorting for multiple IP information sources is obtained. It is also possible to perform a single sorting on multiple IP information sources by integrating the precision range of the network address and the precision range of the host address. In addition, corresponding priorities can be pre-configured for different range precision intervals of the network address and host address, and then the range precision of the network address and host address of the source address of each IP information source is matched in each range precision interval of the network address and host address, and the priority corresponding to the successfully matched range precision interval of the network address and host address is used as the priority of the corresponding IP information source. This can reduce the sorting process of IP information sources and thus improve the determination efficiency of the priorities of IP information sources.
[0083] In practical applications, corresponding priorities can also be configured for each IP information source according to the actual situation. For example: The IP-related database that belongs to the same management system as the traffic detection device, since it is a database held by itself, has the highest credibility and is configured with the highest priority. The IP range tables publicly disclosed by each manufacturer, since the manufacturer itself is more aware of its IP range, can be configured with the second highest priority. AS autonomous systems, generally databases purchased by itself, are also relatively credible, and the priority can be configured as average. Third-party IP-related databases obtained from public channels, due to the unstable credibility of public information, can be configured with the lowest priority.
[0084] Specific values for the priorities at each level are not specifically limited here.
[0085] In practical applications, for the convenience of managing IP information sources, it can be implemented through a data table.
[0086] Table 1 IP Information Source Management Table
[0087]
[0088] When collecting IP addresses and their corresponding IP tags from different IP information sources, it is necessary to write the name and address into the corresponding fields in Table 1, configure priorities for the corresponding IP information sources, and record the time (i.e., update time) when the corresponding IP information source outputs the IP address and its IP tag and the result of whether the output is successful (i.e., update status).
[0089] After collecting IP addresses and their IP tags from multiple IP information sources, it is necessary to store the collected IP addresses and their IP tags as a whole in the IP information database.
[0090] S33: Write the IP addresses obtained from each IP information source and their corresponding IP tags into the IP information database in ascending order of priority. When the currently to-be-written IP address duplicates an already-written IP address, overwrite the already-written IP address and its corresponding IP tag with the currently to-be-written IP address and its corresponding IP tag.
[0091] When specifically writing the IP addresses and their IP tags into the IP information database, it is necessary to start from the IP addresses and their IP tags corresponding to the IP information source with the lowest priority according to the priority of the IP information source. First, write the IP addresses obtained from the IP information source with the lowest priority and their corresponding IP tags in turn according to the character order of the IP addresses and the principle of descending address range. For example: first write the IP address 1.0.0.0 / 8 and its IP tag, then write the IP address 1.0.0.0 / 24 and its IP tag, and then write the IP address 1.1.1.1 / 8 and its IP tag.
[0092] Then, write the IP addresses obtained from the IP information source with the second lowest priority and their corresponding IP tags. When specifically writing, it is also according to the character order of the IP addresses and the principle of descending address range. Just before actual writing, first check whether the currently to-be-written IP address exists among the already-written IP addresses. If it exists, overwrite the already-written IP address and its IP tag with the currently to-be-written IP address and its IP tag. If it does not exist, write the currently to-be-written IP address and its IP tag into the currently already-written IP addresses according to the IP address sorting and range size. For the next to-be-written IP address and its IP tag, it can start searching backward after the position of the previously found IP address. This can reduce the search volume of IP addresses, improve the search efficiency, and thus improve the writing efficiency of IP addresses and their IP tags. The specific search and writing process is the same as that of the previous IP address and its IP tag, and will not be elaborated here.
[0093] To facilitate the writing of IP addresses and their IP tags and subsequent data management, data tables can be used to store IP address segments and their IP tags, and the data in the table is automatically formatted and standardized.
[0094] Specifically, before the above step S33, the method further includes: creating an IP information data table in the IP information database. The IP information data table includes at least an IP address field, an IP tag field, and a source address field. The IP information data table is correspondingly configured with multiple processing programs, and each processing program can process the IP tags corresponding to the source addresses of the corresponding types into standard format IP tags.
[0095] Specifically, the above step S33 may include: writing the IP address obtained from each IP information source, its corresponding IP label, and the source address corresponding to the corresponding IP information source into the corresponding fields of the IP information data table; calling the corresponding processing program according to the type of the written source address, and modifying the written IP label to a standard format IP label through the called processing program, so as to complete the writing of the IP address and its corresponding IP label in the IP information database.
[0096] That is to say, in the IP information database, not only the IP information data table is configured, but also the processing program is configured. In the IP information data table, there are IP address fields, IP label fields, and source address fields. After obtaining the IP address and its IP label, the IP address and its IP label can be written into the IP information data table together with the address of the IP information source that obtained the IP address and its IP label. In this way, in response to the writing of the IP address, etc., the type of the IP information source can be determined according to the address of the IP information source, so that the IP label can be sent to the processing program corresponding to the type, and then the IP label can be processed into a standard format by the processing program and the original IP label in the table can be overwritten.
[0097] In the process of determining the type of the IP information source according to the address of the IP information source, it is possible to query based on the address to determine the subject of the address, and then determine the type corresponding to the subject through manual or artificial intelligence, so as to determine the type of the IP information source. It is also possible to directly determine the type of the IP information source according to the characteristics of the address. For example: if the address contains http, it is determined that the IP information source is a website. Another example: if the address contains self-owned information such as tiangang and baize, it is determined that the IP information source is a self-owned database.
[0098] After determining the type of the IP information source, the corresponding processing program can be called to process the corresponding IP label into a standard format that meets the current requirements. The corresponding relationship between each processing program and the type of the IP information source can be pre-designed and stored in a preset location for subsequent query and use. For the processing program, it can be designed by itself or an existing format conversion tool can be selected.
[0099] In practical applications, in order to improve the utilization rate of the IP information data table, the content in the IP information data table can be enriched.
[0100] Table 2 IP Information Data Table
[0101] id hid etime ip_value ip_sub rule_desc rule_desc_en ip_type confidence manuacturer service scope
[0102] Among them, id is the number, each IP address corresponds to an id, and the id increases sequentially.
[0103] The hid is the hash MD5 value of the ip_value + ip_sub fields, and duplicate entries are removed and stored in the database in descending order of priority. If there are identical data with high and low priorities, only the one with the highest priority is retained.
[0104] The etime is the generation time.
[0105] The ip_value is the IP address.
[0106] The ip_sub is the subnet mask.
[0107] The rule_desc is the IP label description.
[0108] The rule_desc_en is the Chinese description of the IP label.
[0109] The ip_type is the IP type, namely ipv4 or ipv6.
[0110] The confidence is the certainty, namely the priority.
[0111] The manuacturer is the source manufacturer.
[0112] The service is the service provider.
[0113] The scope is the geographical scope.
[0114] In some cases, when converting the IP labels written into the IP information data table to the standard format through the handler, the conversion may fail. In order to obtain the correct standard format IP labels more quickly, the IP labels with the same IP address in the previous IP information data table can be written.
[0115] Specifically, before the above step S33, the method may further include: backing up the existing IP addresses and their corresponding IP labels in the IP information data table, and clearing the IP information data table.
[0116] That is to say, each time the IP information data table is updated, the original IP addresses and their IP labels are deleted, and then all the newly collected IP addresses and their labels are written.
[0117] When deleting the IP addresses and their IP labels in the IP information data table, the deleted IP addresses and their IP labels are backed up. Specifically, when backing up, the IP addresses and their IP labels can be stored locally in the traffic detection device or in the cloud to reduce the occupancy of the storage space in the traffic detection device.
[0118] Specifically, the above step S33 may include: if the called handler indicates that the modification fails, select an IP tag with the same IP address as the IP tag for which the modification fails from the backed-up IP tags as the IP tag in standard format, and write the IP tag in standard format to the position where the modification fails in the IP information data table.
[0119] After the IP address and its IP tag are written into the IP information data table, the corresponding handler performs standard format conversion on the IP tag. If the handler conversion is completed, the converted IP tag overwrites the previous IP tag. If the handler conversion fails, obtain the IP tag corresponding to the same IP address from the backup, and overwrite the IP tag for which the conversion fails in the table with the obtained IP tag.
[0120] Directly performing format conversion on the IP tag by the handler can avoid the process of searching for the same IP address during incremental updates and the comparison process of changes in the IP tags of the same IP address, improving the update efficiency of the IP tag. Moreover, after the handler format conversion fails, instead of performing format conversion again, directly use the IP tag of the same IP address in the backup data, which can avoid the situation of conversion failure again and ensure the quick acquisition of the IP tag in standard format.
[0121] It should be noted here that if the IP address corresponding to the IP tag for which the format conversion fails does not exist in the backup data, then re-enter the handler and perform format conversion again. If the conversion still fails after multiple attempts, output a prompt message to input the IP tag in standard format manually, so as to standardize the format of the IP tag in the IP information data table.
[0122] At this time, multiple IP addresses, their corresponding IP tags, and other information related to the IP addresses are sorted out in the IP information data table to obtain the initial IP information database.
[0123] In practical applications, the IP tag corresponding to the IP address may include the identifiers of each manufacturer and the types of network security attacks and defenses. The types of network security attacks and defenses may include but are not limited to: Content Delivery Network (CDN), security-related websites, scanners, botnets, security products, security manufacturers, Command and Control (C2) addresses, cyberspace mapping, short link platforms, blockchain, Virtual Private Network (VPN), etc.
[0124] In order to further reduce the storage space occupied by the IP information database in the traffic detection device, the IP information database can be compressed.
[0125] S34: Process the data in the IP information database into the MaxMind DB format.
[0126] On the one hand, the IP addresses and their IP tags in the IP information database can be directly processed into the MaxMind DB format, or the IP tags in the IP information database can be processed into the MaxMind DB format. On the other hand, each IP address and its corresponding IP tag can be compressed first, and then the compressed information can be processed into the MaxMind DB format.
[0127] Specifically, the above step S34 may include: compressing each IP address and its corresponding IP tag in the IP information database respectively using a preset compression method to obtain a plurality of compressed blocks; processing the plurality of compressed blocks into a data file in the MaxMind DB format; injecting the data file into the traffic detection device in an upgraded manner.
[0128] For each pair of IP address and IP tag in the IP information database, first compress them using a compression method. Here, the compression method can be, but is not limited to, existing methods that can compress quickly. For each compressed data, then process them as a whole into the MaxMind DB format. Figure 4 This is a partial example of the IP information database processed into the MaxMind DB format in the embodiments of the present application.
[0129] After testing, when about 1 million IP data and corresponding description information are packaged into MaxMind DB data, the actual size is about 50MB. It has the characteristics of a large amount of data, rich content, and small hard disk space occupation, meeting the original intention of providing as much information as possible to the alarm analysis personnel with little or no additional burden on the traffic detection device.
[0130] Next, send the IP information database to the traffic detection device through the upgrade channel. Specifically, put the IP information database into the rule upgrade package of the traffic detection device, and download the IP information database into the traffic detection device through the rule upgrade channel reserved by the traffic detection device. In this way, it will not occupy more upgrade resources of the traffic detection device. As the rules in the traffic detection device are upgraded, it means that there are new changes in the output of alarm data. At this time, update the IP information database together to optimize the output content of the alarm data in a timely manner with the rules.
[0131] During the upgrade process, if there is a historical IP information database in the traffic detection device, use the new IP information database to overwrite the original IP information database. If there is no historical IP information database in the traffic detection device, directly put the new IP information database in the specified path.
[0132] After that, after the traffic detection device generates alarm data, it can enrich the IP addresses in the alarm data based on the IP information database.
[0133] II. Enrich alarm data.
[0134] S35: Obtain the alarm data initially generated by the traffic detection device.
[0135] S36: Extract the target IP address from the alarm data.
[0136] S37: Determine whether the target IP address is the internal network address or asset address of itself. If so, execute S38; if not, execute S39.
[0137] Here, the internal network address and asset address can refer to the addresses configured in the internal network by the holder of the traffic detection device or the target party that needs to detect traffic data, as well as the addresses of related objects belonging to its assets. These addresses are generally well-known to the analysts and will not initiate any security attacks on themselves. Even in some cases where the assets configured by users are for public network private use, it may cause inaccurate IP label configuration. Therefore, when enriching the information of the IP addresses in the alarm data, skip the enrichment of these addresses to reduce the amount of IP address information enrichment and achieve accurate and efficient enrichment of the IP address information in the alarm data.
[0138] S38: Output the initially generated alarm data.
[0139] S39: Search for the target IP label corresponding to the target IP address in the IP information database.
[0140] S310: Add the target IP label to the position corresponding to the target IP address in the initially generated alarm data.
[0141] S311: Output the alarm data after adding the target IP label.
[0142] It should be noted here that the above steps S35, S36, S39, S310, and S311 are the same as the specific implementation manners of steps S21 - S25 in the foregoing embodiments. For relevant descriptions, reference can be made to the relevant descriptions in the foregoing embodiments, and details are not repeated here.
[0143] Figure 5 This is an example where the IP label in the alarm data output in the embodiment of the present application is VPN. Figure 6 This is an example where the IP label in the alarm data output in the embodiment of the present application is scanner.
[0144] The analyst further analyzes the alarm data and enters the details page of the alarm data. Figure 5Among them, it can be directly known that the destination IP is the VPN. In Figure 6 Among them, it can be directly known that the source IP is the scanner. Thus, the analyst can quickly and accurately make corresponding decisions based on the IP tags.
[0145] So far, the method for outputting alarm data provided by the embodiments of this application has been fully described.
[0146] Based on the same inventive concept, the embodiments of this application also provide an apparatus for outputting alarm data.
[0147] The apparatus for outputting alarm data is applied to a traffic detection device. The traffic detection device includes an Internet Protocol (IP) information database. The IP information database includes multiple IP addresses and their corresponding IP tags. The IP tags are used to indicate the manufacturers or network security attack and defense types corresponding to the IP addresses. The network security attack and defense type has a higher priority than the manufacturer as the IP tag.
[0148] Figure 7 For the structural schematic diagram of the apparatus for outputting alarm data in the embodiments of this application Figure 1 , see Figure 7 As shown, the apparatus may include:
[0149] An obtaining module 71, configured to obtain the alarm data initially generated by the traffic detection device;
[0150] An extracting module 72, configured to extract the target IP address from the alarm data;
[0151] A searching module 73, configured to search for the target IP tag corresponding to the target IP address in the IP information database;
[0152] An adding module 74, configured to add the target IP tag to the position corresponding to the target IP address in the initially generated alarm data;
[0153] An output module 75, configured to output the alarm data after adding the target IP tag.
[0154] Further, as Figure 7 a refinement and extension of the device shown, the embodiments of this application also provide an apparatus for outputting alarm data.
[0155] Figure 8 For the structural schematic diagram of the apparatus for outputting alarm data in the embodiments of this application Figure 2 , see Figure 8 As shown, the apparatus may include:
[0156] A creation module 81 is used to obtain IP addresses and their corresponding IP tags from multiple IP information sources; obtain the priority of each IP information source; write the IP addresses and their corresponding IP tags obtained from each IP information source into the IP information database in ascending order of priority. When the currently to-be-written IP address duplicates an already-written IP address, overwrite the already-written IP address and its corresponding IP tag with the currently to-be-written IP address and its corresponding IP tag.
[0157] When the multiple IP information sources include the IP range tables publicly disclosed by each manufacturer, AS (autonomous system), the IP-related database belonging to the same management system as the traffic detection device, and the third-party IP-related database obtained through public channels, the creation module 81 is specifically configured to sequentially obtain IP addresses and their corresponding IP tags in the order of the IP-related database belonging to the same management system as the traffic detection device, the IP range tables publicly disclosed by each manufacturer, AS (autonomous system), and the third-party IP-related database obtained through public channels.
[0158] The creation module 81 is specifically configured to obtain the source address of each IP information source; determine the priority of each IP information source according to the range precision of the network address and host address in the source address, where the range precision of the network address and host address is positively correlated with the priority.
[0159] The creation module 81 is further used to create an IP information data table in the IP information database. The IP information data table includes at least an IP address field, an IP tag field, and a source address field. Multiple processing programs are correspondingly configured for the IP information data table, and each processing program can process the IP tags corresponding to the source addresses of the corresponding types into standard-format IP tags.
[0160] The creation module 81 is specifically configured to write the IP addresses and their corresponding IP tags obtained from each IP information source and the source addresses corresponding to the corresponding IP information sources into the corresponding fields of the IP information data table; call the corresponding processing program according to the type of the written source address, and modify the written IP tags into standard-format IP tags through the called processing program to complete the writing of the IP addresses and their corresponding IP tags in the IP information database.
[0161] The creation module 81 is further used to back up the existing IP addresses and their corresponding IP tags in the IP information data table and empty the IP information data table.
[0162] The creation module 81 is specifically configured to, if the called processing program indicates that the modification fails, select an IP tag that is the same as the IP address corresponding to the IP tag with the modification failure from the backed-up IP tags as the standard-format IP tag, and write the standard-format IP tag to the position where the modification fails in the IP information data table.
[0163] The creation module 81 is further configured to compress each IP address in the IP information database and its corresponding IP label respectively by using a preset compression method to obtain a plurality of compressed blocks; process the plurality of compressed blocks into a data file in the MaxMind DB format; and inject the data file into the traffic detection device in an upgraded manner.
[0164] The acquisition module 82 is configured to acquire the alarm data initially generated by the traffic detection device.
[0165] The extraction module 83 is configured to extract the target IP address from the alarm data.
[0166] The first output module 84 is configured to output the initially generated alarm data if the target IP address is the internal network address or the asset address of itself.
[0167] The search module 85 is configured to search for the target IP label corresponding to the target IP address in the IP information database.
[0168] The addition module 86 is configured to add the target IP label to the position corresponding to the target IP address in the initially generated alarm data.
[0169] The second output module 87 is configured to output the alarm data after adding the target IP label.
[0170] It should be noted here that the description of the above device embodiments is similar to the description of the above method embodiments and has similar beneficial effects to the method embodiments. For the technical details not disclosed in the device embodiments of the present application, please refer to the description of the method embodiments of the present application for understanding.
[0171] Based on the same inventive concept, the embodiments of the present application further provide a computer device.
[0172] Figure 9 For the structural schematic diagram of the computer device in the embodiments of the present application, see Figure 9 As shown, the computer device may include: a memory 91, a processor 92, and a computer program stored on the memory 91. The processor 92 executes the computer program to implement the method in the foregoing embodiments.
[0173] It should be noted here that the description of the above computer device embodiments is similar to the description of the above method embodiments and has similar beneficial effects to the method embodiments. For the technical details not disclosed in the computer device embodiments of the present application, please refer to the description of the method embodiments of the present application for understanding.
[0174] Based on the same inventive concept, an embodiment of the present application also provides a computer-readable storage medium. A computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, the method in the foregoing embodiment is implemented.
[0175] It should be noted here that the description of the above computer-readable storage medium embodiment is similar to the description of the above method embodiment, and has beneficial effects similar to those of the method embodiment. For the technical details not disclosed in the computer-readable storage medium embodiment of the present application, please refer to the description of the method embodiment of the present application for understanding.
[0176] Based on the same inventive concept, an embodiment of the present application also provides a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, the method in the foregoing embodiment is implemented.
[0177] It should be noted here that the description of the above computer program product embodiment is similar to the description of the above method embodiment, and has beneficial effects similar to those of the method embodiment. For the technical details not disclosed in the computer program product embodiment of the present application, please refer to the description of the method embodiment of the present application for understanding.
[0178] As described above, the above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed by the present application, and all of them should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A method for outputting alarm data, characterized in that, The method is applied to a traffic detection device, which includes an Internet Protocol (IP) information database. The IP information database includes multiple IP addresses and their corresponding IP tags. The IP tags are used to indicate the manufacturers or network security attack and defense types corresponding to the IP addresses. The network security attack and defense type has a higher priority than the manufacturer as an IP tag. The method includes: Obtain the alarm data initially generated by the traffic detection device; Extract the target IP address from the alarm data; Search for the target IP tag corresponding to the target IP address in the IP information database; Add the target IP tag to the position corresponding to the target IP address in the initially generated alarm data; Output the alarm data after adding the target IP tag.
2. The method according to claim 1, wherein Before obtaining the alarm data initially generated by the traffic detection device, the method further includes: Obtain IP addresses and their corresponding IP tags from multiple IP information sources; Obtain the priority of each IP information source; Write the IP addresses and their corresponding IP tags obtained from each IP information source into the IP information database in ascending order of priority. When the currently to-be-written IP address duplicates an already-written IP address, overwrite the already-written IP address and its corresponding IP tag with the currently to-be-written IP address and its corresponding IP tag.
3. The method according to claim 2, wherein The multiple IP information sources include IP range tables publicly disclosed by each manufacturer, autonomous systems (AS), IP-related databases belonging to the same management system as the traffic detection device, and third-party IP-related databases obtained from public channels; The obtaining of IP addresses and their corresponding IP tags from multiple IP information sources includes: Obtain IP addresses and their corresponding IP tags in sequence according to the order of the IP-related database belonging to the same management system as the traffic detection device, IP range tables publicly disclosed by each manufacturer, autonomous systems (AS), and third-party IP-related databases obtained from public channels.
4. The method according to claim 2, wherein The obtaining of the priority of each IP information source includes: Obtain the source address of each IP information source; Determine the priority of each IP information source according to the range precision of the network address and host address in the source address, where the range precision of the network address and host address is positively correlated with the priority.
5. The method according to claim 2, wherein Before writing the IP addresses and their corresponding IP tags obtained from each IP information source into the IP information database, the method further includes: Create an IP information data table in the IP information database. The IP information data table includes at least an IP address field, an IP tag field, and a source address field. Multiple processing programs are correspondingly configured for the IP information data table, and each processing program can process the IP tags corresponding to the source addresses of the corresponding types into standard-format IP tags; The writing of the IP addresses and their corresponding IP tags obtained from each IP information source into the IP information database includes: Write the IP addresses and their corresponding IP tags obtained from each IP information source and the source addresses corresponding to the respective IP information sources into the corresponding fields of the IP information data table. Call a corresponding handler according to the type of the written source address, and modify the written IP label to a standard format IP label through the called handler, so as to complete the writing of the IP address and its corresponding IP label in the IP information database.
6. The method according to claim 5, wherein Before writing the IP address and its corresponding IP label obtained from each IP information source and the source address corresponding to the corresponding IP information source into the corresponding fields of the IP information data table, the method further includes: Back up the existing IP addresses and their corresponding IP labels in the IP information data table, and clear the IP information data table; The modifying the written IP label to a standard format IP label through the called handler includes: If the called handler indicates that the modification fails, select an IP label that has the same IP address as the IP label for which the modification fails from the backed-up IP labels as the standard format IP label, and write the standard format IP label to the position where the modification fails in the IP information data table.
7. The method according to claim 2, characterized in that, After writing the IP addresses and their corresponding IP labels obtained from each IP information source into the IP information database, the method further includes: Compress each IP address and its corresponding IP label in the IP information database respectively by using a preset compression method to obtain a plurality of compressed blocks; Process the plurality of compressed blocks into a data file in MaxMind DB format; Inject the data file into the traffic detection device in an upgraded manner.
8. The method according to any one of claims 1 to 7, characterized in that, Before searching for the target IP label corresponding to the target IP address in the IP information database, the method further includes: If the target IP address is the internal network address or asset address of itself, output the initially generated alarm data.
9. An alarm data output device, characterized in that, The device is applied to a traffic detection device, the traffic detection device includes an Internet Protocol (IP) information database, the IP information database includes a plurality of IP addresses and their corresponding IP labels, the IP label is used to indicate the manufacturer or the type of network security attack and defense corresponding to the IP address, and the type of network security attack and defense has a higher priority than the manufacturer as the IP label. The device includes: An acquisition module, configured to acquire the alarm data initially generated by the traffic detection device; An extraction module, configured to extract a target IP address from the alarm data; A search module, configured to search for the target IP label corresponding to the target IP address in the IP information database; An addition module, configured to add the target IP label to the position corresponding to the target IP address in the initially generated alarm data; An output module, configured to output the alarm data after adding the target IP label.
10. A computer device, comprising a memory, a processor, and a computer program stored on the memory, characterized in that, The processor executes the computer program to implement the steps of the method according to any one of claims 1 to 8.
11. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the method according to any one of claims 1 to 8.
12. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the steps of the method according to any one of claims 1 to 8.