Security event response method and device, computer equipment, readable storage medium and program product
By classifying and similarity calculation of the attribute information of network security events, the problem of insufficient matching of automated scripts is solved, the efficiency and accuracy of security incident response is achieved, and the efficiency and quality of network security guarantees are improved.
Patent Information
- Application Number
- CN202510501677.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-21
- Publication Date
- 2025-08-05
AI Technical Summary
The existing technology is difficult to effectively deal with complex and changeable network security threats, resulting in inefficient security incident response and insufficient matching of automated scripts, which affects the efficiency and quality of network security guarantees.
By classifying the attribute information of security events, calculating the similarity of different attribute categories, determining the target case from the event library based on the similarity, and recommending the response script, using attribute weights and structural weights for weight summing, improving case matching accuracy.
Improve the efficiency and accuracy of security incident response, ensure the reliability and persuasiveness of recommended response scripts, reduce dependence on professional security analysts, and control operational costs.
Smart Images

Figure CN120433967A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular to a security incident response method, apparatus, computer equipment, computer-readable storage medium, and computer program product. Background Art
[0002] In today's digital age, cybersecurity is crucial for major missions. Critical business systems and important data assets rely on a stable and secure network environment. Cyberattacks can lead to severe economic losses, data leaks, and business interruptions.
[0003] In order to effectively respond to complex and ever-changing network security threats, improving the efficiency of handling security incidents, lowering the threshold for security analysis, and reducing operating costs have become key issues that need to be urgently addressed in the field of network security. Summary of the Invention
[0004] Based on this, it is necessary to provide a security incident response method, apparatus, computer equipment, computer-readable storage medium and computer program product that can improve the response efficiency of network security incidents in response to the above technical problems.
[0005] In a first aspect, the present application provides a security incident response method, comprising:
[0006] Attribute splitting of event information of security events to be responded to, and obtaining attribute information corresponding to each attribute category;
[0007] For any historical case in the event library, determine the similarity of each attribute category based on the attribute information corresponding to each attribute category of the historical case and the attribute information corresponding to each attribute category of the security event to be responded to, and determine the similarity between the historical case and the security event to be responded to based on the similarity of each attribute category;
[0008] According to the similarity between each of the historical cases in the event library and the security event to be responded to, a target case is determined from the event library, and a response script of the target case is used as a recommended response script for the security event to be responded to.
[0009] In one embodiment, determining the similarity between the historical case and the security incident to be responded to based on the similarity of each attribute category includes:
[0010] Determining the event type of the security event to be responded to;
[0011] Determining the weight of each attribute category according to the event type;
[0012] The similarities of the attribute categories are weighted and summed based on the weights of the attribute categories to obtain the similarities between the historical case and the security incident to be responded to.
[0013] In one embodiment, determining the similarity of each attribute category based on the attribute information corresponding to each attribute category of the historical case and the attribute information corresponding to each attribute category of the security event to be responded to includes:
[0014] According to the attribute information corresponding to each attribute category of the historical cases and the attribute information corresponding to each attribute category of the security events to be responded to, the attribute similarity and the structural similarity of each attribute category are determined respectively.
[0015] In one embodiment, the weights of the attribute categories include attribute weights and structure weights, and the similarities of the attribute categories are weighted and summed based on the weights of the attribute categories to obtain the similarity between the historical case and the security incident to be responded to, including:
[0016] Performing a weighted summation of the attribute similarities of each attribute category based on the attribute weights of each attribute category to obtain the attribute similarity between the historical case and the security incident to be responded to, and performing a weighted summation of the structural similarities of each attribute category based on the structural weights of each attribute category to obtain the structural similarity between the historical case and the security incident to be responded to;
[0017] The similarity between the historical case and the security event to be responded to is determined based on the attribute similarity and structure similarity between the historical case and the security event to be responded to.
[0018] In one embodiment, the attribute categories include a first attribute category, a second attribute category, and a third attribute category, wherein:
[0019] The first attribute category is a category of identification attributes;
[0020] The second attribute category is a category of sortable attributes;
[0021] The third attribute category is a text attribute category.
[0022] In one embodiment, the attribute information includes attributes and attribute values corresponding to the attributes, and determining the attribute similarity of each attribute category based on the attribute information corresponding to each attribute category of the historical case and the attribute information corresponding to each attribute category of the security event to be responded to includes:
[0023] For any attribute in the first attribute category, determine a minimum common subclass of a first attribute value corresponding to the attribute in the security event to be responded to and a second attribute value corresponding to the attribute in the historical case, and determine a first similarity corresponding to the attribute based on a depth of the minimum common subclass in the hierarchy, a depth of the first attribute value in the hierarchy, and a depth of the second attribute value in the hierarchy;
[0024] The attribute similarity of the first attribute category is determined according to the first similarities corresponding to the attributes in the first attribute category.
[0025] In one embodiment, the attribute information includes attributes and attribute values corresponding to the attributes, and determining the attribute similarity of each attribute category based on the attribute information corresponding to each attribute category of the historical case and the attribute information corresponding to each attribute category of the security event to be responded to includes:
[0026] For any attribute in the second attribute category, determining a difference between an attribute value corresponding to the attribute in the security event to be responded to and an attribute value corresponding to the attribute in the historical case, and determining a second similarity corresponding to the attribute based on the difference, where the second similarity is negatively correlated with the difference;
[0027] The attribute similarity of the second attribute category is determined according to the second similarities corresponding to the attributes in the second attribute category.
[0028] In one embodiment, the attribute information includes attributes and attribute values corresponding to the attributes, and determining the attribute similarity of each attribute category based on the attribute information corresponding to each attribute category of the historical case and the attribute information corresponding to each attribute category of the security event to be responded to includes:
[0029] For any attribute in the third attribute category, determining a term frequency-inverse document frequency of an attribute value corresponding to the attribute in the security event to be responded to and an attribute value corresponding to the attribute in the historical case;
[0030] The attribute similarity of the third attribute category is determined based on the term frequency-inverse document frequency corresponding to each attribute in the third attribute category.
[0031] In one embodiment, determining the structural similarity of each attribute category based on the attribute information corresponding to each attribute category of the historical case and the attribute information corresponding to each attribute category of the security event to be responded to includes:
[0032] For any of the attribute categories, determine the intersection of the attribute value set of the security event to be responded to for the attribute category and the attribute value set of the historical case for the attribute category, and based on the intersection and the attribute value set of the security event to be responded to for the attribute category, determine the structural similarity of the attribute category.
[0033] In a second aspect, the present application further provides a security incident response device, comprising:
[0034] A splitting module is used to split the event information of the security incident to be responded to by attributes, and obtain the attribute information corresponding to each attribute category;
[0035] A first determination module is configured to determine, for any historical case in the event library, the similarity of each attribute category according to attribute information corresponding to each attribute category of the historical case and attribute information corresponding to each attribute category of the security event to be responded to, and determine the similarity between the historical case and the security event to be responded to based on the similarity of each attribute category;
[0036] The second determination module is used to determine a target case from the event library based on the similarity between each historical case in the event library and the security event to be responded to, and use the response script of the target case as the recommended response script for the security event to be responded to.
[0037] In one embodiment, determining the similarity between the historical case and the security incident to be responded to based on the similarity of each attribute category includes:
[0038] Determining the event type of the security event to be responded to;
[0039] Determining the weight of each attribute category according to the event type;
[0040] The similarities of the attribute categories are weighted and summed based on the weights of the attribute categories to obtain the similarities between the historical case and the security incident to be responded to.
[0041] In one embodiment, determining the similarity of each attribute category based on the attribute information corresponding to each attribute category of the historical case and the attribute information corresponding to each attribute category of the security event to be responded to includes:
[0042] According to the attribute information corresponding to each attribute category of the historical cases and the attribute information corresponding to each attribute category of the security events to be responded to, the attribute similarity and the structural similarity of each attribute category are determined respectively.
[0043] In one embodiment, the weights of the attribute categories include attribute weights and structure weights, and the similarities of the attribute categories are weighted and summed based on the weights of the attribute categories to obtain the similarity between the historical case and the security incident to be responded to, including:
[0044] Performing a weighted summation of the attribute similarities of each attribute category based on the attribute weights of each attribute category to obtain the attribute similarity between the historical case and the security incident to be responded to, and performing a weighted summation of the structural similarities of each attribute category based on the structural weights of each attribute category to obtain the structural similarity between the historical case and the security incident to be responded to;
[0045] The similarity between the historical case and the security event to be responded to is determined based on the attribute similarity and structure similarity between the historical case and the security event to be responded to.
[0046] In one embodiment, the attribute categories include a first attribute category, a second attribute category, and a third attribute category, wherein:
[0047] The first attribute category is a category of identification attributes;
[0048] The second attribute category is a category of sortable attributes;
[0049] The third attribute category is a text attribute category.
[0050] In one embodiment, the attribute information includes attributes and attribute values corresponding to the attributes, and determining the attribute similarity of each attribute category based on the attribute information corresponding to each attribute category of the historical case and the attribute information corresponding to each attribute category of the security event to be responded to includes:
[0051] For any attribute in the first attribute category, determine a minimum common subclass of a first attribute value corresponding to the attribute in the security event to be responded to and a second attribute value corresponding to the attribute in the historical case, and determine a first similarity corresponding to the attribute based on a depth of the minimum common subclass in the hierarchy, a depth of the first attribute value in the hierarchy, and a depth of the second attribute value in the hierarchy;
[0052] The attribute similarity of the first attribute category is determined according to the first similarities corresponding to the attributes in the first attribute category.
[0053] In one embodiment, the attribute information includes attributes and attribute values corresponding to the attributes, and determining the attribute similarity of each attribute category based on the attribute information corresponding to each attribute category of the historical case and the attribute information corresponding to each attribute category of the security event to be responded to includes:
[0054] For any attribute in the second attribute category, determining a difference between an attribute value corresponding to the attribute in the security event to be responded to and an attribute value corresponding to the attribute in the historical case, and determining a second similarity corresponding to the attribute based on the difference, where the second similarity is negatively correlated with the difference;
[0055] The attribute similarity of the second attribute category is determined according to the second similarities corresponding to the attributes in the second attribute category.
[0056] In one embodiment, the attribute information includes attributes and attribute values corresponding to the attributes, and determining the attribute similarity of each attribute category based on the attribute information corresponding to each attribute category of the historical case and the attribute information corresponding to each attribute category of the security event to be responded to includes:
[0057] For any attribute in the third attribute category, determining a term frequency-inverse document frequency of an attribute value corresponding to the attribute in the security event to be responded to and an attribute value corresponding to the attribute in the historical case;
[0058] The attribute similarity of the third attribute category is determined based on the term frequency-inverse document frequency corresponding to each attribute in the third attribute category.
[0059] In one embodiment, determining the structural similarity of each attribute category based on the attribute information corresponding to each attribute category of the historical case and the attribute information corresponding to each attribute category of the security event to be responded to includes:
[0060] For any of the attribute categories, determine the intersection of the attribute value set of the security event to be responded to for the attribute category and the attribute value set of the historical case for the attribute category, and based on the intersection and the attribute value set of the security event to be responded to for the attribute category, determine the structural similarity of the attribute category.
[0061] In a third aspect, the present application also provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements any of the above security incident response methods when executing the computer program.
[0062] In a fourth aspect, the present application also provides a computer-readable storage medium having a computer program stored thereon, which implements any of the above security incident response methods when executed by a processor.
[0063] In a fifth aspect, the present application also provides a computer program product, including a computer program, which implements any of the above security incident response methods when executed by a processor.
[0064] The above-mentioned security incident response method, apparatus, computer equipment, computer-readable storage medium and computer program product can perform attribute splitting on the event information of the security incident to be responded to, obtain the attribute information corresponding to each attribute category, and for any historical case in the event library, determine the similarity of each attribute category based on the attribute information corresponding to each attribute category of the historical case and the attribute information corresponding to each attribute category of the security incident to be responded to, and determine the similarity of the historical case and the security incident to be responded to based on the similarity of each attribute category, and then determine the target case from the event library based on the similarity of each historical case in the event library and the security incident to be responded to, and use the response script of the target case as the recommended response script for the security incident to be responded to. By using the security incident response method, apparatus, computer equipment, computer-readable storage medium, and computer program product provided in the embodiments of the present application, attribute information can be classified. Since different types of attributes have different characteristics and functions, classification can more carefully consider the impact of each attribute on similarity. This not only comprehensively captures the degree of similarity between the security incident to be responded to and historical cases, but also avoids mutual interference between different types of attributes, thereby improving the case matching accuracy, accurately matching the recommended corresponding scripts for reference from the event library, and thus improving the response efficiency of security incidents. BRIEF DESCRIPTION OF THE DRAWINGS
[0065] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following briefly introduces the drawings required for use in the embodiments of the present application or related technical descriptions. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying any creative work.
[0066] Figure 1 1 is a flow chart of a security incident response method according to an embodiment;
[0067] Figure 2 104 is a flow chart of step 104 in one embodiment;
[0068] Figure 3 206 is a flow chart of step 206 in one embodiment;
[0069] Figure 4 Schematic diagram of a process for determining attribute similarity of a first attribute category in one embodiment;
[0070] Figure 5 Schematic diagram of a process for determining attribute similarity of a second attribute category in one embodiment;
[0071] Figure 6FIG1 is a flow chart of determining attribute similarity of a third attribute category in one embodiment;
[0072] Figure 7 Schematic diagram of a security incident response method in one embodiment;
[0073] Figure 8 is a structural block diagram of a security incident response device in one embodiment;
[0074] Figure 9 FIG. 1 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION
[0075] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.
[0076] In today's digital age, cybersecurity is crucial for critical missions. Critical business systems and important data assets rely on a stable and secure network environment. Cyberattacks can lead to severe economic losses, data leaks, business interruptions, and other adverse consequences. To effectively address complex and ever-changing cybersecurity threats, improving security incident handling efficiency, lowering the threshold for security analysis, and reducing operating costs are key issues that need to be addressed in the cybersecurity field.
[0077] In this context, documenting and reusing the valuable experience of security analysts in the form of automated scripts has become an increasingly effective solution. Automated scripts standardize and automate the processes, strategies, and methods used by security experts to handle different types of security incidents. This allows even non-professionals to quickly and accurately handle security incidents based on the scripts, significantly improving incident handling efficiency while reducing reliance on professional security analysts and effectively controlling operating costs.
[0078] However, cybersecurity incidents inherently possess numerous complex characteristics. Their attribute value types are complex and diverse, encompassing information across multiple dimensions, such as network protocols, attack types, and affected systems. Each dimension, in turn, contains numerous subcategories, making accurate description and analysis of security incidents extremely challenging. Furthermore, due to the randomness and unique nature of cybersecurity incidents, sample sizes are typically small, making comprehensive and in-depth analysis difficult. Furthermore, the rapidly evolving nature of cybersecurity knowledge often leads to a lack of prior knowledge regarding emerging attack methods and security threats, resulting in a lack of effective reference when addressing these incidents. Furthermore, in the actual process of collecting and recording security incident information, missing attribute values are common for various reasons, further complicating accurate analysis and judgment.
[0079] Given the characteristics of these cybersecurity incidents, when attempting to reuse scripts by searching for similar cases for newly generated security incidents, a serious problem arises: insufficient matching. This inability to accurately and comprehensively identify past cases that are highly similar to the new incident makes it difficult to directly apply existing automated scripts. This significantly reduces the effectiveness of automated scripts in practical applications, preventing them from fully realizing their intended role. This in turn impacts the efficiency and quality of cybersecurity assurance for major missions.
[0080] An embodiment of the present application provides a security incident response method, which improves case matching accuracy by classifying attribute information of security incidents and determining the similarity between security incidents and historical cases based on different classifications. When dealing with complex network security incidents, reference response scripts can be determined efficiently and accurately from historical cases, thereby improving the response efficiency of security incidents.
[0081] In one embodiment, Figure 1 As shown, a security incident response method is provided. This embodiment uses the method applied to a terminal as an example for illustration. It is understandable that the method can also be applied to a server, or to a system including a terminal and a server, and implemented through interaction between the terminal and the server. In this embodiment, the method includes the following steps 102 to 106, wherein:
[0082] Step 102 : performing attribute splitting on the event information of the security event to be responded to, and obtaining attribute information corresponding to each attribute category.
[0083] In an embodiment of the present application, event information of security incident reports to be responded to can be obtained from the network security command and dispatch platform, and attribute information corresponding to each attribute category can be further split from the event information.
[0084] Exemplarily, the attribute category may include a first attribute category, a second attribute category, and a third attribute category, wherein the first attribute category is a category of identification attributes, such as event name, IP information, and other attributes; the second attribute category is a category of sortable attributes, such as confidentiality level, hazard level, numerical attributes, and the like; the third attribute category is a category of text attributes, such as the text content of the event, and other attributes.
[0085] Step 104: For any historical case in the event library, the similarity of each attribute category is determined based on the attribute information corresponding to each attribute category of the historical case and the attribute information corresponding to each attribute category of the security event to be responded to, and the similarity between the historical case and the security event to be responded to is determined based on the similarity of each attribute category.
[0086] In this embodiment, the event library is a database that stores a large number of historical security incident cases (hereinafter referred to as historical cases). Each case includes detailed attribute information and corresponding response scripts. Its storage structure uses a relational or non-relational database to ensure efficient data storage and fast retrieval, and the data in the event library can be continuously updated and maintained.
[0087] For example, consider a historical case in the event database. For any attribute category, the similarity between the historical case and the pending security incident can be calculated based on the attribute information corresponding to that attribute category (i.e., the similarity for that attribute category). Similarly, the similarity for each attribute category can be calculated. By combining the similarities for each attribute category, the similarity between the historical case and the pending security incident can be calculated.
[0088] By analogy, the similarity between the security incident to be responded to and each historical case in the incident database can be obtained.
[0089] Step 106 , based on the similarity between each historical case in the event library and the security event to be responded to, a target case is determined from the event library, and the response script of the target case is used as a recommended response script for the security event to be responded to.
[0090] In an embodiment of the present application, after calculating the similarity between the security event to be responded to and each historical case in the event library, a preset number (for example: 3) of historical cases with the highest similarity can be used as target cases, and the response scripts of the target cases can be output as recommended response scripts for the security event to be responded to for reference by security experts.
[0091] The above-mentioned security incident response method can perform attribute splitting on the event information of the security incident to be responded to, obtain the attribute information corresponding to each attribute category, and for any historical case in the event library, determine the similarity of each attribute category based on the attribute information corresponding to each attribute category of the historical case and the attribute information corresponding to each attribute category of the security incident to be responded to, and determine the similarity between the historical case and the security incident to be responded to based on the similarity of each attribute category, and then determine the target case from the event library based on the similarity between each historical case in the event library and the security incident to be responded to, and use the response script of the target case as the recommended response script for the security incident to be responded to. The security incident response method provided by the embodiment of the present application can classify the attribute information. Since different types of attributes have different characteristics and functions, the impact of each attribute on the similarity can be considered more carefully through classification, which not only can comprehensively capture the similarity between the security incident to be responded to and the historical case, but also can avoid mutual interference between different types of attributes, thereby improving the case matching accuracy, accurately matching and obtaining a reference recommended corresponding script from the event library, thereby improving the response efficiency of the security incident.
[0092] In an exemplary embodiment, referring to Figure 2 As shown, in step 104, determining the similarity between the historical case and the security incident to be responded to based on the similarity of each attribute category may include the following steps 202 to 206, wherein:
[0093] Step 202: Determine the event type of the security event to be responded to;
[0094] Step 204: Determine the weight of each attribute category based on the event type;
[0095] Step 206 : Perform weighted sum processing on the similarities of each attribute category based on the weight of each attribute category to obtain the similarity between the historical case and the security incident to be responded to.
[0096] In an embodiment of the present application, the event attribute identifier of the security event to be responded to can be obtained from the event information, and the corresponding event type can be determined based on the event attribute identifier. For example, the event type can include but is not limited to security events, vulnerability events, threat events, security governance events, and other events. The event attribute identifiers contained in each event type can be pre-classified, and then the corresponding event type can be matched based on the event attribute identifier of the security event to be responded to.
[0097] For different event types, you can pre-set weights for each attribute category. Different event types can have different weights for each attribute category. Because different attributes often have different impacts on case similarity, by setting weights, more important attribute categories can be assigned higher weights, giving them a larger proportion in the final similarity calculation.
[0098] For example, let's consider the vulnerability event type, where the attribute categories include the first, second, and third attribute categories. For vulnerability events, the second attribute category (also known as the sorting attribute), such as the hazard level, is more important, while the first attribute category (identification attribute) and the third attribute category (text attribute) are less important. Therefore, when pre-setting the attribute category weights for the vulnerability event type, the second attribute category can be given a relatively large weight, while the first and third attribute categories can be given relatively small weights. This more accurately reflects the true similarity between cases and prevents irrelevant attributes from significantly interfering with the results.
[0099] After determining the weight of each attribute category based on the event type of the security event to be responded to, the similarity of each attribute category can be weighted and summed based on the weight of each attribute category to obtain the similarity between the historical case and the security event to be responded to.
[0100] For example, when attribute categories include identification, sortability, and textual attributes, weighting can comprehensively consider the information from each attribute category. For example, identification attributes can help quickly locate and distinguish different cases, sortability attributes can reflect differences in certain quantitative indicators, and textual attributes provide more detailed descriptive information. By assigning appropriate weights to these three attribute categories, we can combine their strengths to comprehensively measure the similarity between cases, making the calculation results more reliable and convincing.
[0101] In an exemplary embodiment, determining the similarity of each attribute category based on attribute information corresponding to each attribute category of historical cases and attribute information corresponding to each attribute category of security events to be responded to may include the following steps:
[0102] According to the attribute information corresponding to each attribute category of the historical cases and the attribute information corresponding to each attribute category of the security incident to be responded to, the attribute similarity and structural similarity of each attribute category are determined respectively.
[0103] In the embodiment of the present application, similarity can include attribute similarity and structural similarity, where attribute similarity is used to describe the similarity of the characteristics of attribute information, while structural similarity is used to describe the similarity between the overall internal structure of attribute information. That is, in the embodiment of the present application, the attribute similarity of each attribute category can be determined based on the attribute information corresponding to each attribute category of historical cases and the attribute information corresponding to each attribute category of the security incident to be responded to, and the structural similarity of each attribute category can be determined based on the attribute information corresponding to each attribute category of historical cases and the attribute information corresponding to each attribute category of the security incident to be responded to.
[0104] In an exemplary embodiment, the weight of the attribute category includes attribute weight and structure weight. Figure 3 In step 206, the similarities of each attribute category are weighted and summed based on the weights of each attribute category to obtain the similarity between the historical case and the security incident to be responded to. The steps 302 to 304 may be included, wherein:
[0105] Step 302: Based on the attribute weights of each attribute category, the attribute similarities of each attribute category are weighted and summed to obtain the attribute similarities between the historical case and the security incident to be responded to. Furthermore, based on the structural weights of each attribute category, the structural similarities of each attribute category are weighted and summed to obtain the structural similarities between the historical case and the security incident to be responded to.
[0106] Step 304 : Determine the similarity between the historical case and the security event to be responded to based on the attribute similarity and structure similarity between the historical case and the security event to be responded to.
[0107] In the embodiment of the present application, when determining the weight of the attribute category of the security event to be responded to based on the event attribute identifier, the attribute weight and structure weight corresponding to each attribute category can be obtained.
[0108] After determining the attribute similarity of each attribute category based on the attribute information corresponding to each attribute category of the historical case and the attribute information corresponding to each attribute category of the security incident to be responded to, the attribute similarity of each attribute category can be weighted and summed based on the attribute weight of each attribute category to obtain the attribute similarity of the historical case and the security incident to be responded to.
[0109] For example, still taking the example of attribute categories including the first attribute category, the second attribute category and the third attribute category, assuming that the attribute weight of the first attribute category is w1, the attribute weight of the second attribute category is w2, the attribute weight of the third attribute category is w3, and the attribute similarity of the first attribute category is calculated to be sim1 (S c , S i ), the attribute similarity of the second attribute category is sim2 (S c , S i), the attribute similarity of the third attribute category is sim3 (S c , S i ), where S c Indicates a security incident to be responded to, S i Represents a historical case. The calculation process of the attribute similarity n1 between the historical case and the security incident to be responded can refer to the following formula (1):
[0110]
[0111] Formula (1)
[0112] Similarly, after determining the attribute similarity of each attribute category based on the attribute information corresponding to each attribute category of historical cases and the attribute information corresponding to each attribute category of the security incident to be responded to, the attribute similarity of each attribute category can be weighted and summed based on the attribute weight of each attribute category to obtain the attribute similarity of the historical case and the security incident to be responded to.
[0113] For example, still taking the attribute category including the first attribute category, the second attribute category and the third attribute category as an example, assuming that the structural weight of the first attribute category is w4, the structural weight of the second attribute category is w5, and the structural weight of the third attribute category is w6, and the structural similarity of the first attribute category is calculated to be sim str1 (S c , S i ), the structural similarity of the second attribute category is sim str2 (S c , S i ), the structural similarity of the third attribute category is sim str3 (S c , S i ), where S c Indicates a security incident to be responded to, S i Represents a historical case. The calculation process of the structural similarity n2 between the historical case and the security incident to be responded can refer to the following formula (II):
[0114]
[0115] Formula (2)
[0116] After obtaining the attribute similarity and structural similarity between the historical case and the security incident to be responded to, the similarity between the historical case and the security incident to be responded to can be determined based on the attribute similarity and structural similarity. For example, the sum or product of the attribute similarity and structural similarity can be used as the similarity between the historical case and the security incident to be responded to. Alternatively, weights for the attribute similarity and structural similarity can be pre-set, and the weighted sum of the two can be used as the similarity between the historical case and the security incident to be responded to.
[0117] In the embodiment of the present application, the attribute information includes the attribute and the attribute value corresponding to the attribute. The following will describe the calculation process of the attribute similarity and structure similarity of each attribute category.
[0118] In an exemplary embodiment, referring to Figure 4 As shown, determining the attribute similarity of each attribute category based on the attribute information corresponding to each attribute category of the historical case and the attribute information corresponding to each attribute category of the security incident to be responded to may include the following steps 402 to 404, wherein:
[0119] Step 402: For any attribute in the first attribute category, determine the least common subclass of a first attribute value corresponding to the attribute in the security incident to be responded to and a second attribute value corresponding to the attribute in the historical case, and determine a first similarity corresponding to the attribute based on the depth of the least common subclass in the hierarchy, the depth of the first attribute value in the hierarchy, and the depth of the second attribute value in the hierarchy;
[0120] Step 404: Determine the attribute similarity of the first attribute category based on the first similarities corresponding to the attributes in the first attribute category.
[0121] In the embodiment of the present application, the first attribute category is the category of identification attributes. For any identification attribute, the attribute value of the identification attribute in the security event to be responded to is used as the first attribute value, and the attribute value of the identification attribute in the historical case is used as the second attribute value. First, the minimum common subclass of the first attribute value and the second attribute value can be determined. In a class hierarchy, the minimum common subclass refers to the most special (i.e., most specific) class that can simultaneously serve as a subclass of multiple given classes. It is a common ancestor of these classes in the inheritance relationship and has no other more specific common ancestor classes.
[0122] For example, assume that the security event S to be responded to c The identification attributes include: ATT&CK number: T1566.002; its hierarchy is as follows:
[0123] Enterprise
[0124] → Initial Access
[0125] → Phishing
[0126] → Spearphishing Link
[0127] Case S i The identification attributes include: ATT&CK number: T1046, and its hierarchy is as follows:
[0128] Enterprise
[0129] → Discovery
[0130] → Network Service Scanning
[0131] It can be determined that the smallest common subclass of the two is Enterprise (enterprise level).
[0132] After determining the minimum common subclass, the depth of the minimum common subclass in the hierarchy, the depth of the first attribute value in the hierarchy, and the depth of the second attribute value in the hierarchy can be determined respectively. Still taking the above example, the depth of the minimum common subclass in the hierarchy is 1, the depth of the first attribute value in the hierarchy is 4, and the depth of the second attribute value in the hierarchy is 3. Furthermore, based on the depth of the minimum common subclass in the hierarchy, the depth of the first attribute value in the hierarchy, and the depth of the second attribute value in the hierarchy, a first similarity corresponding to the attribute can be determined, wherein the first similarity is positively correlated with the depth of the minimum common subclass in the hierarchy, and negatively correlated with the depth of both the first attribute value and the second attribute value in the hierarchy.
[0133] For example, for any identification attribute k, the calculation process of the corresponding first similarity is shown in the following formula (3):
[0134] Formula (3)
[0135] in, represents the first similarity of the identification attribute k, Represents the first attribute value, Represents the second attribute value, Represents the smallest common subclass of the first attribute value and the second attribute value, represents the depth of the least common subclass in the hierarchy, Indicates the depth of the first attribute value in the hierarchy, Indicates the depth of the second attribute value in the hierarchy.
[0136] By analogy, the first similarity of each identification attribute can be obtained, and the first similarities of each identification attribute can be accumulated and summed to obtain the attribute similarity of the first attribute category; alternatively, the weight of each identification attribute can be set in advance, and then the first similarities of each identification attribute can be weighted and summed based on the weight of each identification attribute to obtain the attribute similarity of the first attribute category.
[0137] In an exemplary embodiment, referring to Figure 5As shown, determining the attribute similarity of each attribute category based on the attribute information corresponding to each attribute category of the historical case and the attribute information corresponding to each attribute category of the security incident to be responded to may include the following steps 502 to 504, wherein:
[0138] Step 502: for any attribute in the second attribute category, determine a difference between an attribute value corresponding to the attribute in the security event to be responded to and an attribute value corresponding to the attribute in the historical case, and determine a second similarity corresponding to the attribute based on the difference, where the second similarity is negatively correlated with the difference.
[0139] Step 504: Determine the attribute similarity of the second attribute category according to the second similarity corresponding to each attribute in the second attribute category.
[0140] In the embodiment of the present application, the second attribute category is the category of sortable attributes. For any sortable attribute, the difference between the attribute value of the sortable attribute in the security event to be responded to and the attribute value of the sortable attribute in the historical case can be calculated, and based on the difference, the second similarity corresponding to the sortable attribute is determined, and the second similarity is negatively correlated with the difference. For example, for any sortable attribute m, the calculation process of its corresponding second similarity is shown in the following formula (IV):
[0141] Formula (4)
[0142] in, represents the second similarity of the sortable attribute m, Indicates the attribute value of the sortable attribute m in the security event to be responded to, represents the attribute value of the sortable attribute m in the historical case, Indicates the difference between the attribute value of the sortable attribute m in the security event to be responded to and the attribute value of the sortable attribute m in the historical case.
[0143] By analogy, the second similarity of each sortable attribute can be obtained, and the second similarities of each sortable attribute can be accumulated and summed to obtain the attribute similarity of the second attribute category; alternatively, the weight of each sortable attribute can be set in advance, and then the second similarities of each sortable attribute can be weighted and summed based on the weight of each sortable attribute to obtain the attribute similarity of the second attribute category.
[0144] In an exemplary embodiment, referring to Figure 6 As shown, determining the attribute similarity of each attribute category based on the attribute information corresponding to each attribute category of the historical case and the attribute information corresponding to each attribute category of the security incident to be responded to may include the following steps 602 to 604, wherein:
[0145] Step 602: for any attribute in the third attribute category, determine the term frequency-inverse document frequency of the attribute value corresponding to the attribute in the security event to be responded to and the attribute value corresponding to the attribute in the historical case;
[0146] Step 604 : Determine the attribute similarity of the third attribute category based on the term frequency-inverse document frequency corresponding to each attribute in the third attribute category.
[0147] In the embodiment of the present application, the third attribute category is the category of text attributes. For any text attribute, the term frequency-inverse document frequency of the attribute value of the text attribute in the security event to be responded to and the attribute value corresponding to the text attribute in the historical case can be determined.
[0148] For example, the attribute values of text attributes in the security response event and the attribute values in historical cases can be preprocessed, including removing stop words (such as "through", "then", "and" and other common words that have no practical meaning), converting all words to lowercase, and other operations.
[0149] For the attribute value of the text attribute in the security incident to be responded, take the word "malware" as an example. Assuming that the total number of words in the preprocessed text attribute is N1=30, and the number of times "malware" appears is n1=2, then the word frequency TF1 of "malware" in the security incident to be responded is TF1=n1 / N1=2 / 30≈0.067.
[0150] For the text attributes of historical cases, assuming that the total number of words is N2=25 and the number of times “malware” appears is n2=1, then the word frequency TF2 of “malware” in the text attributes of historical cases is n2 / N2=1 / 25=0.04.
[0151] Assume that there are M=100 historical cases in the event database, and the number of historical cases containing the word "malware" is m=30, then the inverse document frequency IDF is malware =log(M / m)=log(100 / 30)≈1.204.
[0152] The term frequency-inverse document frequency value of "malware" in the security incident to be responded is TF-IDF1=TF1×IDF malware =0.067×1.204≈0.081; while the term frequency-inverse document frequency value of “malware” in the historical case is TF−IDF2=TF2×IDF malware =0.04×1.204=0.048.
[0153] According to the above method, the word frequency-inverse document frequency value is calculated for each word in the attribute value of the text attribute, and the text attribute is regarded as a vector, where each dimension of the vector corresponds to the word frequency-inverse document frequency value of a word.
[0154] For example, the calculation process of term frequency-inverse document frequency corresponding to the document attribute z can refer to the following formula (6):
[0155] Formula (6)
[0156] Where w is a word in the attribute value of the text attribute, n is the total number of words, is the word frequency-inverse document frequency value of word w, Represents the term frequency - inverse document frequency corresponding to the document attribute z.
[0157] Furthermore, the cosine similarity algorithm can be used to calculate the similarity of the two vectors to obtain the attribute similarity of the third attribute category.
[0158] In an exemplary embodiment, determining the structural similarity of each attribute category based on attribute information corresponding to each attribute category of historical cases and attribute information corresponding to each attribute category of security events to be responded to may include the following steps:
[0159] For any attribute category, determine the intersection of the attribute value set of the security incident to be responded to for the attribute category and the attribute value set of the historical case for the attribute category, and determine the structural similarity of the attribute category based on the intersection and the attribute value set of the security incident to be responded to for the attribute category.
[0160] In the embodiment of the present application, the calculation method of the structural similarity of each attribute category is the same. Taking an attribute category as an example, the first set and the second set can be determined first, wherein the elements in the first set include the attribute values of each attribute under the attribute category in the security incident to be responded to, and the elements in the second set include the attribute values of each attribute in the attribute category in the historical cases. The intersection of the first set and the second set can be determined, and the proportion of the attribute values in the intersection in the first set can be determined, and the proportion can be used as the structural similarity of the attribute category. Exemplarily, the calculation process of the structural similarity of the attribute category can refer to the following formula (seven):
[0161] Formula (7)
[0162] in, Indicates a security incident to be responded to. Represents historical cases, Represents the structural similarity of attribute categories, represents the first set, Represents the second set.
[0163] In this way, the structural similarity of each attribute category can be calculated, and the structural similarity of each attribute category can be obtained by weighted summing up the structural similarities of each attribute category to obtain the structural similarity between the security incident to be responded to and the historical cases.
[0164] In the embodiments of this application, different similarity calculation methods can be used for different types of attributes. For example, numerical calculation methods can be used for sortable attributes, while natural language processing techniques can be used for text attributes. This can fully leverage the advantages of various calculation methods, improve computational efficiency, and further enhance the accuracy of similarity, thereby improving the precision and efficiency of case matching.
[0165] In order to enable those skilled in the art to better understand the embodiments of the present application, the embodiments of the present application are described below with reference to specific examples.
[0166] In response to new network security incidents, the present embodiment proposes an efficient and accurate response method. First, the event attributes of different security incidents are split in the pre-processing method library and divided into three core areas: identification attributes, sortable attributes, and text attributes; combined with the event library constructed by the network security command and dispatch system, historical cases are compared one by one to calculate attribute similarity and structural similarity; to improve matching accuracy, the attributes and structure characteristics of the events are comprehensively considered, and the two similarities and three areas are weighted according to different event types to obtain the overall similarity; finally, historical cases are sorted according to the overall similarity, and the top three are selected as references to provide script response and disposal suggestions.
[0167] The security incident response method provided by the embodiments of this application significantly improves the matching efficiency and accuracy of network security incident response, saves labor costs, and provides strong support for network security protection. By accurately matching historical cases, it can quickly and effectively respond to emerging network security incidents and ensure the smooth progress of network security work.
[0168] The execution process of the embodiment of this application refers to Figure 7 As shown, the following steps are included:
[0169] S1: Split security event attributes: Input the event information of the security event to be responded to, and split the event attribute information, such as event name, confidentiality level, hazard level, affected asset category, IP information, text details, etc.
[0170] S2: Attribute domain division: Based on the split attributes and their attribute values, different attribute information is divided into identification attributes, sortable attributes, and text attributes; based on the event attributes of the security incident to be responded to, it is classified into one of the following categories: security incidents, vulnerability incidents, threat incidents, security governance incidents, and other incidents.
[0171] S3: Attribute similarity calculation: For any case in the event library, perform the following calculations:
[0172] Calculate the attribute similarity of the identification attribute, the attribute similarity of the sortable attribute, and the attribute similarity of the text attribute respectively. The calculation process can refer to the relevant description of the aforementioned embodiment, and will not be repeated in the embodiments of this application. According to the event type to which the input security event to be responded belongs, obtain the identification attribute weight w1, sortable attribute weight w2, and text attribute weight w3 corresponding to the event, and perform weighted summation of the attribute similarity of the identification attribute, the attribute similarity of the sortable attribute, and the attribute similarity of the text attribute based on the identification attribute weight w1, the sortable attribute weight w2, and the text attribute weight w3 to obtain the overall attribute similarity value of the security event to be responded and the historical case.
[0173] S4: Structural similarity calculation: Continue with the structural similarity calculation with the above historical cases:
[0174] The structural similarity of the identification attribute, the structural similarity of the sortable attribute, and the structural similarity of the text attribute are calculated respectively. The calculation process can be referred to the relevant description of the previous embodiment, and will not be repeated in the embodiment of this application. According to the event type to which the input security event to be responded belongs, the identification attribute structure weight w4, the sortable attribute structure weight w5, and the text attribute structure weight w6 corresponding to the security event to be responded are obtained, and the overall structural similarity between the security event to be responded and the historical case is obtained.
[0175] S5: Calculate the overall similarity based on the structural similarity and attribute similarity.
[0176] S6: Filter out matching response methods: According to the above method, complete the matching with all cases in the event library, sort them in descending order according to the calculated similarity, filter out the top three cases in similarity, and recommend the response plans corresponding to the top three cases as recommended response plans to security experts.
[0177] The embodiment of the present application uses a nearest neighbor algorithm and a composite similarity matching method to script network security incident response solutions to store different types of security incident pre-processing methods. When a new security incident occurs in the system, the method provided by the embodiment of the present application can be quickly started, and the nearest neighbor algorithm combined with the composite similarity matching method is used to perform efficient and accurate matching searches in the pre-processing method library. This process not only takes into account the basic characteristics of the security incident, but also deeply analyzes the contextual information of the incident and the potential threat pattern, thereby ensuring the accuracy and reliability of the matching results. After the matching is completed, the system will automatically recommend the closest and most appropriate pre-processing solution for the handler to choose based on the results obtained. The handler can quickly determine the best response strategy based on the actual situation and system recommendations, realizing a highly automated process from incident detection to response and disposal.
[0178] The security incident response method provided by the embodiment of the present application is applicable to various major security protection activities and application scenarios such as daily network security protection. Combining the nearest neighbor algorithm with the composite similarity technology to respond to scripted network security incidents can more accurately analyze the complexity and diversity of security incidents, thereby realizing the intelligent matching and retention of security incident handling experience. And through the nearest neighbor algorithm and composite similarity technology, the embodiment of the present application can automatically find and match the most similar cases from the historical case library when a new security incident occurs. This precise matching capability not only improves the recognition of case similarity, but also significantly improves the accuracy of matching, ensuring the pertinence and effectiveness of the processing solution. It should be noted that the security incident response method provided by the embodiment of the present application is also scalable and flexible. With the continuous evolution of security threats and the development of new technologies, the pre-processing method library can be continuously updated and improved to ensure the continuous optimization and improvement of the network security protection system. This dynamic update capability enables the method to maintain efficient and accurate response capabilities for a long time.
[0179] In other words, the security incident response method provided by the embodiments of this application can efficiently and accurately match and retain current security incidents with previously accumulated handling experience. By utilizing the nearest neighbor algorithm and composite similarity technology, it significantly improves case similarity recognition and matching accuracy, optimizing retrieval and matching efficiency. Furthermore, the system can automatically recommend a handling solution based on the matching results, achieving a handling effect comparable to that of a senior security engineer, significantly improving the efficiency of security incident handling and providing a new solution for intelligent and automated response to network security incidents.
[0180] It should be understood that, although the various steps in the flowcharts involved in the various embodiments described above are displayed in sequence according to the instructions of the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowcharts involved in the various embodiments described above can include multiple steps or multiple stages, and these steps or stages are not necessarily executed and completed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of steps or stages in other steps.
[0181] Based on the same inventive concept, the embodiments of the present application also provide a security incident response device for implementing the security incident response method involved above. The implementation solution provided by the device is similar to the implementation solution described in the above method. Therefore, the specific limitations of one or more security incident response device embodiments provided below can be referred to the limitations of the security incident response method above and will not be repeated here.
[0182] In an exemplary embodiment, Figure 8 As shown, a security incident response device 800 is provided, comprising: a splitting module 802, a first determining module 804 and a second determining module 806, wherein:
[0183] A splitting module 802 is used to split the event information of the security event to be responded to by attributes to obtain attribute information corresponding to each attribute category;
[0184] A first determining module 804 is configured to determine, for any historical case in the event library, the similarity of each attribute category based on attribute information corresponding to each attribute category of the historical case and attribute information corresponding to each attribute category of the security event to be responded to, and determine the similarity between the historical case and the security event to be responded to based on the similarity of each attribute category;
[0185] The second determination module 806 is used to determine a target case from the event library based on the similarity between each historical case in the event library and the security event to be responded to, and use the response script of the target case as the recommended response script for the security event to be responded to.
[0186] The security incident response device provided in the embodiment of the present application can classify attribute information. Since different types of attributes have different characteristics and functions, classification can more carefully consider the impact of each attribute on similarity. It can not only comprehensively capture the similarity between the security incident to be responded to and the historical case, but also avoid mutual interference between different types of attributes, thereby improving the case matching accuracy, and accurately matching the recommended corresponding scripts for reference from the event library, thereby improving the response efficiency of security incidents.
[0187] In one embodiment, determining the similarity between the historical case and the security incident to be responded to based on the similarity of each attribute category includes:
[0188] Determining the event type of the security event to be responded to;
[0189] Determining the weight of each attribute category according to the event type;
[0190] The similarities of the attribute categories are weighted and summed based on the weights of the attribute categories to obtain the similarities between the historical case and the security incident to be responded to.
[0191] In one embodiment, determining the similarity of each attribute category based on the attribute information corresponding to each attribute category of the historical case and the attribute information corresponding to each attribute category of the security event to be responded to includes:
[0192] According to the attribute information corresponding to each attribute category of the historical cases and the attribute information corresponding to each attribute category of the security events to be responded to, the attribute similarity and the structural similarity of each attribute category are determined respectively.
[0193] In one embodiment, the weights of the attribute categories include attribute weights and structure weights, and the similarities of the attribute categories are weighted and summed based on the weights of the attribute categories to obtain the similarity between the historical case and the security incident to be responded to, including:
[0194] Performing a weighted summation of the attribute similarities of each attribute category based on the attribute weights of each attribute category to obtain the attribute similarity between the historical case and the security incident to be responded to, and performing a weighted summation of the structural similarities of each attribute category based on the structural weights of each attribute category to obtain the structural similarity between the historical case and the security incident to be responded to;
[0195] The similarity between the historical case and the security event to be responded to is determined based on the attribute similarity and structure similarity between the historical case and the security event to be responded to.
[0196] In one embodiment, the attribute categories include a first attribute category, a second attribute category, and a third attribute category, wherein:
[0197] The first attribute category is a category of identification attributes;
[0198] The second attribute category is a category of sortable attributes;
[0199] The third attribute category is a text attribute category.
[0200] In one embodiment, the attribute information includes attributes and attribute values corresponding to the attributes, and determining the attribute similarity of each attribute category based on the attribute information corresponding to each attribute category of the historical case and the attribute information corresponding to each attribute category of the security event to be responded to includes:
[0201] For any attribute in the first attribute category, determine a minimum common subclass of a first attribute value corresponding to the attribute in the security event to be responded to and a second attribute value corresponding to the attribute in the historical case, and determine a first similarity corresponding to the attribute based on a depth of the minimum common subclass in the hierarchy, a depth of the first attribute value in the hierarchy, and a depth of the second attribute value in the hierarchy;
[0202] The attribute similarity of the first attribute category is determined according to the first similarities corresponding to the attributes in the first attribute category.
[0203] In one embodiment, the attribute information includes attributes and attribute values corresponding to the attributes, and determining the attribute similarity of each attribute category based on the attribute information corresponding to each attribute category of the historical case and the attribute information corresponding to each attribute category of the security event to be responded to includes:
[0204] For any attribute in the second attribute category, determining a difference between an attribute value corresponding to the attribute in the security event to be responded to and an attribute value corresponding to the attribute in the historical case, and determining a second similarity corresponding to the attribute based on the difference, where the second similarity is negatively correlated with the difference;
[0205] The attribute similarity of the second attribute category is determined according to the second similarities corresponding to the attributes in the second attribute category.
[0206] In one embodiment, the attribute information includes attributes and attribute values corresponding to the attributes, and determining the attribute similarity of each attribute category based on the attribute information corresponding to each attribute category of the historical case and the attribute information corresponding to each attribute category of the security event to be responded to includes:
[0207] For any attribute in the third attribute category, determining a term frequency-inverse document frequency of an attribute value corresponding to the attribute in the security event to be responded to and an attribute value corresponding to the attribute in the historical case;
[0208] The attribute similarity of the third attribute category is determined based on the term frequency-inverse document frequency corresponding to each attribute in the third attribute category.
[0209] In one embodiment, determining the structural similarity of each attribute category based on the attribute information corresponding to each attribute category of the historical case and the attribute information corresponding to each attribute category of the security event to be responded to includes:
[0210] For any of the attribute categories, determine the intersection of the attribute value set of the security event to be responded to for the attribute category and the attribute value set of the historical case for the attribute category, and based on the intersection and the attribute value set of the security event to be responded to for the attribute category, determine the structural similarity of the attribute category.
[0211] Each module in the security incident response device described above may be implemented in whole or in part through software, hardware, or a combination thereof. Each module may be embedded in or independent of a processor in a computer device in hardware form, or may be stored in a memory in a computer device in software form, so that the processor can call and execute the corresponding operations of each module.
[0212] In an exemplary embodiment, a computer device is provided. The computer device may be a terminal, and its internal structure diagram may be as shown in FIG. Figure 9As shown. The computer device includes a processor, memory, an input / output interface, a communication interface, a display unit, and an input device. The processor, memory, and input / output interface are connected via a system bus, and the communication interface, display unit, and input device are connected to the system bus via the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals via wired or wireless means, and the wireless means may be implemented via Wi-Fi, a mobile cellular network, near-field communication (NFC), or other technologies. When executed by the processor, the computer program implements a security incident response method. The display unit of the computer device is used to form a visually visible image, and may be a display screen, a projection device, or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covering the display screen, or a button, trackball or touchpad set on the computer device casing, or an external keyboard, touchpad or mouse.
[0213] Those skilled in the art will understand that Figure 9 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.
[0214] In one embodiment, a computer device is further provided, including a memory and a processor. The memory stores a computer program, and the processor implements the steps in the above method embodiments when executing the computer program.
[0215] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.
[0216] In one embodiment, a computer program product is provided, including a computer program, which implements the steps in the above method embodiments when executed by a processor.
[0217] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant regulations.
[0218] Those skilled in the art will understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. In particular, any reference to memory, database, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The databases involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the various embodiments provided herein may be, but are not limited to, general-purpose processors, central processing units (CPUs), graphics processing units (GPUs), digital signal processors (DSPs), programmable logic devices (PLDs), quantum computing-based data processing logic devices, artificial intelligence (AI) processors, and the like.
[0219] The technical features of the above embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.
[0220] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.
Claims
1. A security incident response method, characterized in that: The method comprises: Attribute splitting of event information of security events to be responded to, and obtaining attribute information corresponding to each attribute category; For any historical case in the event library, determine the similarity of each attribute category based on the attribute information corresponding to each attribute category of the historical case and the attribute information corresponding to each attribute category of the security event to be responded to, and determine the similarity between the historical case and the security event to be responded to based on the similarity of each attribute category; According to the similarity between each of the historical cases in the event library and the security event to be responded to, a target case is determined from the event library, and a response script of the target case is used as a recommended response script for the security event to be responded to.
2. The method according to claim 1, characterized in that Determining the similarity between the historical case and the security incident to be responded to based on the similarity of each attribute category includes: Determining the event type of the security event to be responded to; Determining the weight of each attribute category according to the event type; The similarities of the attribute categories are weighted and summed based on the weights of the attribute categories to obtain the similarities between the historical case and the security incident to be responded to.
3. The method according to claim 2, characterized in that Determining the similarity of each attribute category based on the attribute information corresponding to each attribute category of the historical case and the attribute information corresponding to each attribute category of the security event to be responded to, including: According to the attribute information corresponding to each attribute category of the historical cases and the attribute information corresponding to each attribute category of the security events to be responded to, the attribute similarity and the structural similarity of each attribute category are determined respectively.
4. The method according to claim 3, characterized in that The weights of the attribute categories include attribute weights and structure weights. The similarities of the attribute categories are weighted and summed based on the weights of the attribute categories to obtain the similarity between the historical case and the security incident to be responded to, including: Performing a weighted summation of the attribute similarities of each attribute category based on the attribute weights of each attribute category to obtain the attribute similarity between the historical case and the security incident to be responded to, and performing a weighted summation of the structural similarities of each attribute category based on the structural weights of each attribute category to obtain the structural similarity between the historical case and the security incident to be responded to; The similarity between the historical case and the security event to be responded to is determined based on the attribute similarity and structure similarity between the historical case and the security event to be responded to.
5. The method according to claim 3 or 4, characterized in that The attribute categories include a first attribute category, a second attribute category and a third attribute category, wherein: The first attribute category is a category of identification attributes; The second attribute category is a category of sortable attributes; The third attribute category is a text attribute category.
6. The method according to claim 5, characterized in that The attribute information includes attributes and attribute values corresponding to the attributes, and determining the attribute similarity of each attribute category based on the attribute information corresponding to each attribute category of the historical case and the attribute information corresponding to each attribute category of the security event to be responded to includes: For any attribute in the first attribute category, determine a minimum common subclass of a first attribute value corresponding to the attribute in the security event to be responded to and a second attribute value corresponding to the attribute in the historical case, and determine a first similarity corresponding to the attribute based on a depth of the minimum common subclass in the hierarchy, a depth of the first attribute value in the hierarchy, and a depth of the second attribute value in the hierarchy; The attribute similarity of the first attribute category is determined according to the first similarities corresponding to the attributes in the first attribute category.
7. The method according to claim 5, characterized in that The attribute information includes attributes and attribute values corresponding to the attributes, and determining the attribute similarity of each attribute category based on the attribute information corresponding to each attribute category of the historical case and the attribute information corresponding to each attribute category of the security event to be responded to includes: For any attribute in the second attribute category, determining a difference between an attribute value corresponding to the attribute in the security event to be responded to and an attribute value corresponding to the attribute in the historical case, and determining a second similarity corresponding to the attribute based on the difference, where the second similarity is negatively correlated with the difference; The attribute similarity of the second attribute category is determined according to the second similarities corresponding to the attributes in the second attribute category.
8. The method according to claim 5, characterized in that The attribute information includes attributes and attribute values corresponding to the attributes, and determining the attribute similarity of each attribute category based on the attribute information corresponding to each attribute category of the historical case and the attribute information corresponding to each attribute category of the security event to be responded to includes: For any attribute in the third attribute category, determining a term frequency-inverse document frequency of an attribute value corresponding to the attribute in the security event to be responded to and an attribute value corresponding to the attribute in the historical case; The attribute similarity of the third attribute category is determined based on the term frequency-inverse document frequency corresponding to each attribute in the third attribute category.
9. The method according to claim 5, characterized in that Determining the structural similarity of each attribute category based on the attribute information corresponding to each attribute category of the historical case and the attribute information corresponding to each attribute category of the security event to be responded to includes: For any of the attribute categories, determine the intersection of the attribute value set of the security event to be responded to for the attribute category and the attribute value set of the historical case for the attribute category, and based on the intersection and the attribute value set of the security event to be responded to for the attribute category, determine the structural similarity of the attribute category.
10. A security incident response device, characterized in that: The device comprises: A splitting module is used to split the event information of the security incident to be responded to by attributes, and obtain the attribute information corresponding to each attribute category; A first determination module is configured to determine, for any historical case in the event library, the similarity of each attribute category according to attribute information corresponding to each attribute category of the historical case and attribute information corresponding to each attribute category of the security event to be responded to, and determine the similarity between the historical case and the security event to be responded to based on the similarity of each attribute category; The second determination module is used to determine a target case from the event library based on the similarity between each historical case in the event library and the security event to be responded to, and use the response script of the target case as the recommended response script for the security event to be responded to.
11. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 9 are implemented.
12. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 9 are implemented.
13. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 9 are implemented.