Alarm behavior data generation method and device, equipment, medium and product

Through clustering analysis and sorting, the alarm timing data is generated, and the problem of low noise reduction efficiency of alarm data in the existing technology is solved, and efficient and accurate network risk analysis is achieved.

CN120474759APending Publication Date: 2025-08-12CHINA MOBILE GROUP ANHUI +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510578531.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-06
Publication Date
2025-08-12

AI Technical Summary

Technical Problem

In the prior art, the method of performing noise reduction alarm data for each traffic data based on different nodes is less efficient, resulting in less real-time network analysis and less accurate network risk determination.

Method used

By obtaining traffic reference values and alarm reference values, clustering analysis is performed based on multiple traffic data and alarm data, traffic data attribute values and target alarm data attribute values, traffic data deviation values and alarm risk values are calculated, alarm timing data is generated according to the alarm time, and target alarm data that meets the attack ranking is selected.

Benefits of technology

It improves the noise reduction efficiency of alarm data, improves the accuracy of alarm information, and can promptly predict and solve network risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120474759A_ABST
    Figure CN120474759A_ABST
Patent Text Reader

Abstract

The invention discloses an alarm behavior data generation method and device, equipment, a medium and a product, and belongs to the technical field of data processing, and the method comprises the steps: obtaining a traffic reference value, an alarm reference value, and a plurality of pieces of first traffic data and a plurality of pieces of first alarm data of a plurality of nodes in a first time window; determining a traffic data attribute value based on the plurality of first traffic data, and determining a target alarm data attribute value based on the plurality of first alarm data; determining a traffic data deviation value based on the traffic data attribute value and the traffic reference value; determining an alarm risk value based on the traffic data deviation value and the target alarm attribute value; under the condition that the alarm risk value is greater than an alarm reference value, sorting the multiple pieces of target alarm data according to alarm time to obtain alarm time sequence data; the target alarm data conforming to the attack sequence are determined in the alarm time sequence data, the alarm behavior data are obtained, noise reduction and duplicate removal are performed through the alarm data generated based on different traffic data, and the accuracy of the determined alarm information is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the field of data processing technology, and in particular relates to a method, device, equipment, medium and product for generating alarm behavior data. Background Art

[0002] In the existing technology, the denoising of alarm data is to detect alarm data based on each traffic data for different nodes, and deduplicate the alarm data to obtain the alarm behavior data of the node, thereby analyzing the security of the device based on the alarm behavior data and determining the network risk of the node.

[0003] However, the above-mentioned method of performing noise reduction alarm data for each flow data based on different nodes is inefficient, affecting the real-time performance of network analysis, thereby reducing the accuracy of the determined network risks. Summary of the Invention

[0004] The embodiments of the present application provide a method, apparatus, device, medium, and product for generating alarm behavior data, which can reduce noise and deduplicate alarm data generated based on different traffic data, thereby improving the accuracy of the determined alarm information.

[0005] In a first aspect, an embodiment of the present application provides a method for generating alarm behavior data, comprising:

[0006] Obtaining a flow reference value, an alarm reference value, a plurality of first flow data of a plurality of nodes within a first time window, and a plurality of first alarm data, wherein the flow reference value and the alarm reference value are respectively determined based on a plurality of second flow data and a plurality of second alarm data of a plurality of nodes within a second time window, the second time window being earlier than the first time window;

[0007] Determining a flow data attribute value based on the plurality of first flow data, and determining a target alarm data attribute value based on the plurality of first alarm data, wherein the target alarm attribute value represents an attribute value of a plurality of target alarm data including a same Internet Protocol IP address within a first time window;

[0008] determining a flow data deviation value based on the flow data attribute value and the flow reference value;

[0009] determining an alarm risk value based on the traffic data deviation value and the target alarm attribute value;

[0010] When the alarm risk value is greater than the alarm reference value, the plurality of target alarm data are sorted according to the alarm time to obtain alarm time series data;

[0011] Target alarm data that meets the attack ranking is determined in the alarm time series data to obtain alarm behavior data.

[0012] In a second aspect, an embodiment of the present application provides a device for generating alarm behavior data, including:

[0013] an acquisition module, configured to acquire a flow reference value, an alarm reference value, a plurality of first flow data of a plurality of nodes within a first time window, and a plurality of first alarm data, wherein the flow reference value and the alarm reference value are respectively determined based on a plurality of second flow data and a plurality of second alarm data of a plurality of nodes within a second time window, the second time window being earlier than the first time window;

[0014] a determining module, configured to determine a flow data attribute value based on the plurality of first flow data, and determine a target alarm data attribute value based on the plurality of first alarm data, wherein the target alarm attribute value represents an attribute value of a plurality of target alarm data including the same Internet Protocol IP address within a first time window;

[0015] The determination module is further configured to determine a flow data deviation value based on the flow data attribute value and the flow reference value;

[0016] The determination module is further configured to determine an alarm risk value based on the flow data deviation value and the target alarm attribute value;

[0017] a sorting module, configured to sort the plurality of target alarm data according to alarm time to obtain alarm time series data when the alarm risk value is greater than the alarm reference value;

[0018] The generating module is used to determine the target alarm data that meets the attack ranking in the alarm time series data and obtain the alarm behavior data.

[0019] In a third aspect, an embodiment of the present application provides an electronic device, the device comprising:

[0020] a processor and a memory storing computer program instructions;

[0021] When the processor executes the computer program instructions, it is used to execute the method for generating alarm behavior data of the first aspect mentioned above.

[0022] In a fourth aspect, an embodiment of the present application provides a computer storage medium having computer program instructions stored thereon, which, when executed by a processor, implements the method for generating alarm behavior data according to the first aspect.

[0023] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program, which, when processed by a processor, implements the method for generating alarm behavior data according to the first aspect.

[0024] The embodiments of the present application provide a method, apparatus, device, medium and product for generating alarm behavior data, which obtains a flow reference value, an alarm reference value, a plurality of first flow data of a plurality of nodes in a first time window and a plurality of first alarm data, determines a flow data attribute value through the plurality of first flow data, determines a target alarm data attribute value based on the plurality of first alarm data, determines a flow data deviation value through the flow data attribute value and the flow reference value, determines an alarm risk value based on the flow data deviation value and the target alarm attribute value, determines whether the alarm data needs to be denoised by comparing the alarm risk value with the alarm reference value, and generates an alarm risk value based on the target alarm attribute value. When the risk value is greater than the alarm reference value, multiple target alarm data are sorted according to the alarm time to obtain alarm time series data, and the target alarm data that meets the attack sorting is determined in the alarm time series data to obtain alarm behavior data. This can realize noise reduction of alarm data based on multiple traffic data and multiple alarm data of multiple nodes obtained, which can improve the efficiency of noise reduction of the number of alarms. In addition, obtaining alarm behavior data based on target alarm data including the same Internet Protocol address can help users analyze the network risk of nodes based on alarm behavior data, which is conducive to early prediction or timely resolution of possible network risks. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0026] Figure 1 A flowchart of a method for generating alarm behavior data provided in some embodiments of the present application.

[0027] Figure 2 A flowchart of another method for generating alarm behavior data provided in some embodiments of the present application.

[0028] Figure 3 A flowchart of another method for generating alarm behavior data provided in some embodiments of the present application.

[0029] Figure 4 A flowchart of another method for generating alarm behavior data provided in some embodiments of the present application.

[0030] Figure 5 A schematic diagram of a device for generating alarm behavior data provided in some embodiments of the present application.

[0031] Figure 6 A schematic diagram of the hardware structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0032] The features and exemplary embodiments of various aspects of the present application will be described in detail below. In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below in conjunction with the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain the present application, rather than to limit the present application. For those skilled in the art, the present application can be implemented without the need for some of these specific details. The following description of the embodiments is merely to provide a better understanding of the present application by illustrating the examples of the present application.

[0033] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or device comprising the element.

[0034] Before describing the technical solutions provided by the embodiments of the present application, in order to facilitate understanding of the embodiments of the present application, the present application first specifically describes the problems existing in the related art:

[0035] With the accelerated iteration of new-generation information technology, node security analysis is becoming increasingly important. Noise reduction of alarm data can filter and optimize the received alarm data to obtain alarm behavior data, thereby reducing false alarm data and improving the accuracy of large network risks analyzed by users based on alarm behavior data.

[0036] Current methods for reducing the noise of alarm data typically involve detecting the alarm data generated by different nodes on the same traffic data set, thereby removing duplicates and reducing the noise from the alarm data generated by the same traffic data set to generate alarm behavior data. However, this approach, which involves performing separate noise reduction on each individual traffic data set generated by different nodes, is inefficient. Furthermore, the generated alarm behavior data may generate a large amount of duplicate data, hindering users' ability to assess network risks based on alarm behavior data.

[0037] Based on this, an embodiment of the present application provides a method, device, equipment, medium and product for generating alarm behavior data, which can solve the above problems. The following is a detailed description of a method for generating alarm behavior data provided in an embodiment of the present application.

[0038] In some embodiments, as Figure 1 As shown, an embodiment of the present application provides a method for generating alarm behavior data, which may include the following steps S110-S160:

[0039] S110: Obtain a traffic reference value, an alarm reference value, multiple first traffic data of multiple nodes in a first time window, and multiple first alarm data. The traffic reference value and the alarm reference value are respectively determined based on multiple second traffic data and multiple second alarm data of multiple nodes in a second time window. The second time window is earlier than the first time window.

[0040] Here, multiple first traffic data and multiple first alarm data of multiple nodes within the first time window can be obtained. Here, each first traffic data can include characteristic values such as Internet Protocol (IP) address, port identifier and transmission time. The IP address can include the source IP address or the destination IP address, and the port identifier is the identifier of the port of the node that receives or sends the first traffic data.

[0041] The above-mentioned multiple first alarm data are obtained by formatting the original alarm data. Multiple original alarm data of multiple nodes within the first time window can be obtained, and information such as the source IP, destination IP, alarm time, alarm type, and attack stage included in each original alarm data can be extracted. Here, the attack stage is a step in the process of network intrusion. For example, the network intrusion steps may include reconnaissance, sending data, and retrieving data. Based on the above information extracted from the original alarm data, each first alarm data is determined. For example, the format of the first alarm data can be "source IP, destination IP, alarm type, alarm time, attack stage".

[0042] In some embodiments, the traffic reference value may include an IP traffic reference value and a port traffic reference value, and the step of determining the traffic reference value based on the second traffic data of the plurality of nodes in the second time window may include the following steps S11-S13:

[0043] S11: Clustering the multiple second traffic data according to the characteristic values included in each second traffic data to obtain multiple cluster classifications. For example, clustering can be performed based on the IP addresses included in the second traffic data, and the second traffic data including the same IP address can be classified into one category to obtain multiple IP classifications. At the same time, clustering can be performed based on the port identifiers included in the second traffic data, and the second traffic data including the same port identifier can be classified into a group to obtain multiple port classifications.

[0044] S12: Based on each IP classification, determine the number of different ports included in each IP classification Average memory usage of the second traffic data The total memory occupied by the second flow data Among them, c IP Identification of IP classification; and

[0045] Based on each port classification, determine the number of different IP addresses included in the plurality of second traffic data in each port classification Average memory usage of the second traffic data The total memory occupied by the second flow data Among them, c port Identifies the port classification.

[0046] S13: Based on the multiple IP categories, obtain the number of different port identifiers included in the multiple second traffic data in the multiple IP categories The mean and standard deviation Go and find the average memory usage of the second traffic data in multiple IP categories The mean as well as

[0047] Based on multiple port categories, find the number of different IP addresses in multiple port categories The mean and standard deviation Calculate the average memory usage of the second flow data in multiple port categories The mean

[0048] S13: Determine the IP traffic reference value based on the following expression (1):

[0049]

[0050] in, is the reference value of IP traffic, is an average value of the number of different port identifiers included in a plurality of second traffic data in a plurality of IP categories, is a standard deviation of the number of different port identifiers included in a plurality of second traffic data in a plurality of IP categories, The average memory usage of the second traffic data for each IP classification, The total memory occupied by the second traffic data of each IP classification, is a mean value of average memory usage of second flow data in multiple port categories;

[0051] At the same time, the port flow reference value is determined based on the following expression (2):

[0052]

[0053] in, is the port flow reference value, is an average value of the number of different port identifiers included in the plurality of second traffic data in the plurality of port categories, is a standard deviation of the number of different port identifiers included in the plurality of second traffic data in the plurality of port categories, The average memory usage of the second traffic data classified for each port, The total memory occupied by the second traffic data classified for each port, It is the average of the average memory usage of the second traffic data in multiple IP categories.

[0054] In some examples, in order to improve the accuracy of the determined IP traffic reference value and port traffic reference value, the above-mentioned second time window can include multiple sub-time windows, each sub-time window includes multiple sub-second traffic data, and the sub-IP traffic reference value and sub-port traffic reference value can be determined based on the multiple sub-second traffic data included in each sub-time window. The IP traffic reference value is determined by the average value of the multiple sub-IP traffic reference values, and the port traffic reference value is determined based on the average value of the multiple sub-port traffic reference values.

[0055] The embodiment of the present application can determine the traffic reference value based on two dimensions respectively by determining the IP traffic reference value and the port traffic reference value respectively, which can facilitate the subsequent determination of the traffic data deviation based on the traffic data attribute value and the traffic reference value.

[0056] In some embodiments, the step of determining the alarm reference value based on the second alarm data of the plurality of nodes within the second time window t1 may include S21-S25:

[0057] S21: Clustering multiple second alarm data based on the IP address included in each second alarm data, classifying the second alarm data including the same IP address into one category, and obtaining multiple alarm categories, wherein each alarm category may include second alarm data. For example, in the multiple second alarm data included in one alarm category, the source IP is all IP1 and the destination IP is all IP2.

[0058] S22: Based on each alarm classification c alarm , determine the total number of different alarm types included in the multiple second alarm data in each alarm category and the total number of multiple second alarm data Among them, c alarm Identifies the alarm category.

[0059] S23: For any alarm category c alarm , you can identify the alarm category c in other alarm categories alarm Related multiple related alarm categories, multiple second alarm data in the related alarm categories and alarm category calarm The IP addresses of multiple second alarm data in are similar. alarm The source IP of each second alarm data is the first IP, the destination IP is the second IP, and the IP address of the second alarm data included in each relevant alarm category includes the first IP or the second IP. alarm A related alarm category includes multiple second alarm data whose source IPs are all third IPs and whose destination IPs are all first IPs; alarm A related alarm category includes multiple second alarm data whose source IPs are all the second IP and whose destination IPs are all the fourth IP.

[0060] Based on any one of the first related alarm categories, the source IP or destination IP of the plurality of second alarm data in the first related alarm category includes the first IP, and determining the total number of different alarm types included in the plurality of second alarm data in the first related alarm category. The plurality of second alarm data includes alarm classification c alarm The number of same alarm types in And the total number of multiple second alarm data Among them, c sa1 is the identifier of the first relevant alarm category;

[0061] Based on any second related alarm category, the source IP or destination IP of multiple second alarm data in the second related alarm category includes the second IP, and the total number of different alarm types included in the multiple second alarm data in the second related alarm category is determined. The plurality of second alarm data includes alarm classification c alarm The number of same alarm types in The total number of multiple second alarm data Among them, c sa2 The identifier of the second related alarm category.

[0062] S24: For any of the above alarm categories c alarm , the alarm value of each alarm category can be determined based on the following expression (3):

[0063]

[0064] in, is the alarm value, is the first similarity coefficient, if the first relevant alarm category c sa1 and alarm classification c alarm If the source IP in the class is the same, then otherwise, is the second similarity coefficient, if the second related alarm category c sa2 and alarm classification c alarm If the destination IP in the class is the same, then otherwise,

[0065] S25: For any of the above alarm categories c alarm , the alarm reference value corresponding to each alarm category can be determined based on the following expression (4):

[0066]

[0067] Among them, A alarm The alarm reference value corresponding to each alarm category.

[0068] The embodiment of the present application is based on clustering multiple second alarm data and determining the alarm reference value corresponding to each alarm category based on multiple alarm categories, which can be used as a benchmark for whether to perform noise reduction on the alarm data later, thereby improving the accuracy of determining whether to perform noise reduction.

[0069] S120: Determine a traffic data attribute value based on a plurality of first traffic data, and determine a target alarm data attribute value based on a plurality of first alarm data, wherein the target alarm attribute value represents an attribute value of a plurality of target alarm data including the same Internet Protocol IP address within a first time window.

[0070] The flow data attribute value can be determined based on multiple first flow data. For example, multiple first flow data attribute values including characteristic values can be clustered, and the first flow data including the same characteristic values can be classified into one category to obtain multiple flow data classifications, and the above-mentioned flow data attribute value can be determined based on the flow data classifications.

[0071] In some examples, the feature values may include IP addresses and port identifiers. Classifying the plurality of first traffic data based on the IP addresses may yield a plurality of IP traffic data groups. Classifying the plurality of first traffic data based on the port identifiers may yield a plurality of port traffic data groups. IP-class traffic data attribute values may be determined based on the plurality of IP traffic data classifications, and port-class traffic data attribute values may be determined based on the plurality of port traffic data classifications.

[0072] The target alarm data attribute value can be determined based on multiple first alarm data. Here, the IP addresses included in the multiple first alarm data can be clustered, and the alarm data including the same IP address can be classified into one category to obtain multiple alarm data classifications. The corresponding alarm data attribute value is determined based on each alarm data classification, and the target alarm data attribute value is determined from the multiple alarm data attribute values. In the case where the IP address includes a source IP and a destination IP, the source IPs of the multiple first alarm data included in the above-mentioned one alarm data classification are all the same and the destination IPs are all the same. For example, the source IPs of the multiple first alarm data included in one alarm data classification are all IPA, and the destination IPs are all IPB.

[0073] S130: Determine a flow data deviation value based on the flow data attribute value and the flow reference value.

[0074] The above-mentioned flow data deviation value can represent the deviation between the flow data and the flow reference value, and the flow data deviation value can be determined based on the difference between the flow data attribute value and the flow reference value.

[0075] In some embodiments, determining the flow data deviation value based on the flow data attribute value and the flow reference value may include the following steps S31-S32:

[0076] S31: Based on the multiple IP classifications within the second time window, determine the total number N1 of different port identifiers included in the multiple second flow data in the multiple IP classifications, and based on the multiple port classifications within the second time window, determine the total number N0 of different IP addresses included in the multiple second flow data in the multiple port classifications; and based on the multiple IP flow data classifications within the first time window, determine the total number n1 of different port identifiers included in the multiple first flow data in the multiple IP flow data classifications, and based on the multiple port flow data classifications within the first time window, determine the total number n0 of different IP addresses included in the multiple first flow data in the multiple port flow data classifications;

[0077] S32: The flow data deviation value may be determined based on the following expression (5):

[0078]

[0079] Among them, AC0 is the flow data deviation value, A IP is the IP reference value, A port is the port reference value, is the IP traffic data attribute value, It is the port class traffic data attribute value.

[0080] The traffic data deviation value may be determined based on the aforementioned IP traffic data attribute value, the port traffic data attribute value, the IP traffic reference value, and the port traffic reference value.

[0081] It can be imagined that determining the traffic data deviation value based on the two dimensions of IP address and port identifier respectively can analyze the deviation of traffic data based on the two dimensions, thereby improving the accuracy of determining the traffic data deviation value.

[0082] S140: Determine an alarm risk value based on the traffic data deviation value and the target alarm attribute value.

[0083] The above-mentioned alarm risk value represents the network security risk of the node. The risk deviation coefficient can be determined based on the sum of the traffic data attribute value and the preset risk coefficient, and then the alarm risk value can be determined based on the product of the risk deviation coefficient and the traffic reference value.

[0084] S150: When the alarm risk value is greater than the alarm reference value, multiple target alarm data are sorted according to the alarm time to obtain alarm time series data.

[0085] When multiple alarm risk values are greater than the alarm reference value, it indicates that the network security risk of the node is high. Multiple target alarm data can be sorted by time to obtain alarm time series data.

[0086] Here, the target alarm attribute value is determined based on multiple first alarm data including the same IP address, and the alarm reference value obtained may include multiple, each alarm reference value is determined based on multiple second alarm data in an alarm category. When comparing the alarm risk value with the alarm reference value, it may include:

[0087] Determine the target alarm category of the second alarm data that includes the same IP address as the above-mentioned target alarm data among multiple alarm categories, for example, determine the target alarm category of the second alarm data that has the same IP source and destination IP as the target alarm data source, and determine the alarm reference value corresponding to the target alarm category based on the above-mentioned target alarm category, and compare the alarm risk value with the alarm reference value corresponding to the above-mentioned target alarm category.

[0088] In some examples, if the target alarm category does not exist in multiple alarm categories, there is no need to compare the alarm risk value with the alarm reference value. The multiple target alarm data can be directly sorted according to the alarm time to obtain the alarm time series data.

[0089] In some embodiments, when the first alarm data is classified based on the IP address to obtain multiple alarm data classifications, and the multiple target alarm data included in the target alarm data classification are sorted according to the alarm time to obtain alarm time series data, the relevant alarm data classification related to the target alarm data classification can be determined based on the source IP address and the destination IP address included in the multiple target alarm data, and the multiple first alarm data in the relevant alarm data classification and the multiple target alarm data in the above data can be sorted according to the alarm time to obtain the above alarm time series data. Here, the IP addresses of the multiple first alarm data included in the relevant alarm data classification are similar to the IP addresses of the target alarm data, for example, the source IP of the target alarm data is all IPA, the destination IP is all IPB, the source IP or destination IP of the multiple first alarm data in the relevant alarm data classification is all IPA, or the source IP or destination IP of the multiple first alarm data in the relevant alarm data classification is all IPB.

[0090] S160: Determine target alarm data that matches the attack ranking in the alarm time series data, and obtain alarm behavior data.

[0091] Target alarm data that conforms to the attack ranking can be determined in the alarm time series data to obtain alarm behavior data. Here, target alarm data that conforms to the attack ranking can be determined based on the attack stages included in the individual target alarm data in the alarm time series data, so that the attack stage ranking of the multiple target alarm data included in the generated alarm behavior data conforms to the steps in the above-mentioned network intrusion process.

[0092] The embodiment of the present application obtains a traffic reference value, an alarm reference value, multiple first traffic data of multiple nodes within a first time window, and multiple first alarm data, determines a traffic data attribute value based on the multiple first traffic data, determines a target alarm data attribute value based on the multiple first alarm data, and determines a traffic data deviation value based on the traffic data attribute value and the traffic reference value. This allows determining the deviation of the traffic data from the traffic reference value, which is beneficial for determining network risk. An alarm risk value is then determined based on the traffic data deviation value and the target alarm attribute value. Whether the alarm data requires noise reduction is determined by comparing the alarm risk value with the alarm reference value. When the alarm risk value is greater than the alarm reference value, the multiple target alarm data are sorted according to alarm time to obtain alarm time series data. Target alarm data that meets the attack sorting is then determined in the alarm time series data to obtain alarm behavior data. This allows noise reduction of the alarm data based on the obtained multiple traffic data and multiple alarm data of multiple nodes, thereby improving the efficiency of noise reduction of the alarm number and facilitating early prediction or timely resolution of potential network risks.

[0093] In some embodiments, determining the traffic data attribute value based on the plurality of first traffic data includes:

[0094] Based on the characteristic values included in each first traffic data, multiple first traffic data are clustered, and the first traffic data including the same characteristic values are classified into one category to obtain multiple traffic data classifications, wherein each traffic data classification includes multiple first traffic data; for each traffic data classification, the traffic data attribute value is determined based on the number of multiple different characteristic values in the traffic data classification and the occupied memory value of the first traffic data in the traffic data classification.

[0095] Here, when the first traffic data including the same characteristic value is classified into one category, the above-mentioned first traffic data can be classified based on different characteristic values, for example, the first traffic data including the same IP address is classified into one category, the first traffic data including the same port identifier is classified into one category, or the first traffic data based on the same transmission time is classified into one category, and so on.

[0096] Taking the IP address as an example of a characteristic value, the first traffic data including the same IP address is classified into one category to obtain multiple IP traffic data categories. Based on each IP traffic data category, the traffic data attribute value can be determined based on the number of other characteristic values in the traffic data category, the number of multiple different port identifiers or the number of transmission times, and the occupied memory value of the first traffic data in the traffic data category.

[0097] In an embodiment of the present application, when determining flow data attribute values based on multiple first flow data, multiple first flow data are clustered according to characteristic values, and first flow data including the same characteristic values are classified into one category to obtain multiple flow data classifications. The flow data attribute values are determined based on the number of characteristic values in each flow data classification and the occupied memory of the first flow data. The average change of the first flow data can be determined in a timely manner, which is conducive to determining whether to reduce noise on the alarm data later.

[0098] In some embodiments, the feature value includes an IP address and a port identifier, the traffic data classification includes an IP traffic data classification and a port traffic data classification, and the traffic data attribute value includes an IP class traffic data attribute value and a port class traffic data attribute value;

[0099] like Figure 2 As shown, a plurality of first traffic data are clustered based on the characteristic value included in each first traffic data to obtain a plurality of traffic data classifications, including:

[0100] S210: Cluster the IP addresses and port identifiers included in the multiple first traffic data respectively, classify the multiple first traffic data including the same IP address into one category to obtain multiple IP traffic data categories, and classify the multiple first traffic data including the same port identifier into one category to obtain multiple port traffic data categories.

[0101] The IP addresses included in the multiple first traffic data are clustered, and the first traffic data including the same IP address are classified into one category to obtain multiple IP traffic data groups. At the same time, the port identifiers included in the multiple first traffic data are clustered, and the first traffic data including the same port identifier are classified into one category to obtain multiple port traffic data groups.

[0102] Determining a flow data attribute value based on the number of multiple different characteristic values in the flow data classification and the occupied memory value of the first flow data in the flow data classification includes:

[0103] S220: Determine the IP class traffic data attribute value based on the number of multiple different port identifiers in each IP traffic data classification and the occupied memory value of the first traffic data; and determine the port class traffic data attribute value based on the number of multiple different IP addresses in each port traffic data classification and the occupied memory value of the first traffic data.

[0104] Here, determining the IP class flow data attribute value based on the number of multiple different port identifiers in each IP flow data classification and the occupied memory value of the first flow data, and determining the port class flow data attribute value based on the number of multiple different IP addresses in each port flow data classification and the occupied memory value of the first flow data may include the following steps S41-S43:

[0105] S41: Based on each IP traffic data packet, the number of different port identifiers included in the plurality of first traffic data in each IP traffic data packet can be determined. Average memory usage of multiple first flow data The total memory occupied by multiple first flow data Among them, c IP0 An identification of the IP address in each IP traffic data packet; and

[0106] Based on each port traffic data packet, the number of different IP addresses included in the plurality of first traffic data in each port traffic data packet can be determined. Average memory usage of multiple first flow data The total memory occupied by multiple first flow data Among them, c port0 The port identifier in each port traffic data packet.

[0107] S42: Calculate the number of different port identifiers included in the plurality of first flow data in the plurality of IP flow data packets The mean and standard deviation And calculate the average memory occupied by multiple IP traffic data packets The mean as well as

[0108] Calculate the number of different IP addresses included in the plurality of first flow data in the plurality of port flow data packets The mean and standard deviation And calculate the average memory occupied by multiple port traffic data packets The mean

[0109] S43: Determine the IP class traffic data attribute value based on the following expression (6):

[0110]

[0111] in, is the IP traffic data attribute value, is an average value of the number of different port identifiers included in a plurality of first flow data in a plurality of IP flow data categories, a standard deviation of the number of different port identifiers included in the plurality of first flow data in the plurality of IP flow data categories, The average memory occupied by the first flow data of each IP flow data classification, The total memory occupied by the first flow data of each IP flow data classification, is the average value of the memory occupied by the traffic data packets of multiple ports; and

[0112] The port class traffic data attribute value is determined based on the following expression (7):

[0113]

[0114] in, is the port class traffic data attribute value, is an average value of the number of different port identifiers included in the plurality of first flow data in the plurality of port flow data categories, a standard deviation of the number of different port identifiers included in the plurality of first flow data in the plurality of port flow data categories, The average memory occupied by the first flow data of each port flow data classification, The total memory occupied by the first flow data of each port flow data classification, It is the average memory usage of multiple IP traffic data packets.

[0115] The embodiment of the present application clusters multiple first traffic data based on IP addresses and port identifiers to obtain multiple IP traffic data groups and port traffic data groups, and then determines the IP type traffic data attribute values and the port type traffic data attribute values respectively, so as to facilitate the subsequent determination of the traffic data deviation value based on the two dimensions of IP address and port identifier, thereby making the determined traffic data deviation value more accurate.

[0116] In some embodiments, as Figure 3 As shown, determining the target alarm data attribute value based on multiple first alarm data includes:

[0117] S310: Clustering the plurality of first alarm data, classifying the first alarm data including the same IP address into one category, and obtaining a plurality of alarm data categories.

[0118] Multiple first alarm data can be clustered. For example, first alarm data with the same source IP address and destination IP address can be grouped into one category to obtain multiple alarm data categories. The multiple first alarm data included in one alarm data category all have the same source IP address and the same destination IP address. For example, the multiple first alarm data included in one alarm data category all have the same source IP address and the same destination IP address.

[0119] S320: Based on each alarm data category, determine the total number of different alarm types included in the plurality of first alarm data in each alarm category and the total number of the plurality of first alarm data.

[0120] Here, each first alarm data includes an alarm type, and the total number of different alarm types included in multiple first alarm data in each alarm data molecule can be counted. And the total number of multiple first alarm data in each alarm data category

[0121] S330: Determine an alarm data attribute value corresponding to each alarm classification based on the total number of different alarm types included in each alarm data classification and the total number of the plurality of first alarm data.

[0122] Here, for any alarm data category c alarm0 , you can determine the alarm data category c in other alarm data categories alarm0 Related multiple related alarm data categories, multiple first alarm data in the related alarm data categories and alarm data category c alarm0 The IP addresses of the multiple first alarm data are similar. alarm0The source IP of each first alarm data in the alarm data is the first target IP, the destination IP is the second target IP, and the IP address of the first alarm data included in each relevant alarm data classification includes the first target IP or the second target IP. alarm0 A related alarm data classification includes multiple first alarm data whose source IPs are all third target IPs and whose destination IPs are all first target IPs; and the above alarm data classification c alarm0 Another related alarm data classification includes multiple first alarm data, the source IPs of which are all the second target IP, and the destination IPs of which are all the fourth target IP.

[0123] Based on any one of the first relevant alarm data categories, the source IPs or destination IPs of the plurality of first alarm data in the first relevant alarm data category include the first target IP, and determining the total number of different alarm types included in the plurality of first alarm data in the first relevant alarm data category. The plurality of first alarm data include alarm data classification c alarm0 The number of same alarm types in And the total number of multiple first alarm data Among them, c sa10 is the identifier of the first relevant alarm data classification; and

[0124] Based on any second related alarm data classification, the source IP or destination IP of multiple first alarm data in the above second related alarm data classification includes the above second target IP, and determining the total number of different alarm types included in the multiple first alarm data in the second related alarm data classification The plurality of first alarm data include alarm data classification c alarm0 The number of same alarm types in The total number of multiple first alarm data Among them, c sa20 The identifier of the second relevant alarm data category.

[0125] For any of the above alarm data categories c alarm0 , the alarm abnormality value of each alarm data classification can be determined based on the following expression (8):

[0126]

[0127] in, To warn of abnormal values, is the first similarity coefficient, if the first relevant alarm data classification c sa10 Classification of alarm data alarm0 If the source IP in the class is the same, then otherwise, is the second similarity coefficient, if the second relevant alarm data classification c sa20 Classification of alarm data alarm0 If the destination IP in the class is the same, then otherwise,

[0128] For any of the above alarm data categories c alarm0 , the alarm attribute value corresponding to each alarm data category can be determined based on the following expression (9):

[0129]

[0130] Among them, A is the alarm attribute value corresponding to each alarm data classification, Classify alarms for each alarm data c alarm0 The alarm abnormal value.

[0131] S340: Determine a target alarm data attribute value among the multiple alarm data attribute values, wherein the target alarm data attribute value is any one of the multiple alarm data attribute values.

[0132] Among multiple alarm attribute values, any one can be selected as the target alarm attribute value. Then, based on the target alarm attribute value and the traffic data deviation value, an alarm risk value is determined. Here, the alarm risk value is the alarm risk value corresponding to each alarm data category. This value can be compared with the alarm reference value to determine whether noise reduction is necessary for the target alarm data. Here, the alarm reference value is the reference value corresponding to the target alarm attribute value.

[0133] The embodiment of the present application clusters multiple first alarm data based on IP addresses to obtain multiple alarm data classifications, and determines corresponding alarm data attribute values based on the multiple alarm data classifications. This can facilitate analysis of network risks of nodes corresponding to IP addresses based on different alarm data attribute values, thereby determining whether to perform noise reduction on target alarm data, and is conducive to screening target alarm data that needs noise reduction, thereby improving the efficiency of noise reduction on alarm data.

[0134] In some embodiments, the IP address includes a source IP address and a destination IP address; clustering the plurality of first alarm data to obtain a plurality of alarm data classifications includes:

[0135] Clustering is performed on the plurality of first alarm data, and the alarm data including the same source IP address and destination IP address are classified into one category, thereby obtaining a plurality of alarm data categories.

[0136] Here, the first alarm data including the same source IP address and destination IP address can be classified into one category to obtain multiple alarm data categories. For example, in one alarm data category, the source IP address of multiple first alarm data is all IPA, and the destination IP address is all IPB.

[0137] The embodiment of the present application classifies multiple first alarm data including the same source IP address and destination IP address into one category, which can help users classify and analyze alarm risks based on the classified multiple alarm data.

[0138] In some embodiments, as Figure 4 As shown, step S140: determining the alarm risk value based on the traffic data deviation value and the target alarm attribute value may include the following steps S410-S420:

[0139] S410: Determine a risk deviation coefficient based on the sum of the flow data deviation value and a preset risk coefficient, where the risk coefficient is a constant.

[0140] Here, the risk coefficient may be manually set, for example, may be set to 1. When the flow data deviation value is AC0, the risk deviation coefficient may be (1+AC0).

[0141] S420: Determine an alarm risk value based on the product of the risk offset coefficient and the target alarm attribute value.

[0142] Here, the alarm risk value can be determined based on the following expression (10):

[0143] A alarm0 (0) = A(1 + AC0) (10)

[0144] AC0 is the traffic data deviation value, and A is the target alarm attribute value.

[0145] The embodiment of the present application determines the risk deviation coefficient by multiplying the traffic data deviation value and the risk coefficient, and determines the alarm risk value based on the product of the above risk deviation coefficient and the target alarm data value. The above alarm risk value can characterize the network security risk of the node. The alarm risk value determined by combining the traffic data deviation value and the target alarm attribute value can truly express the security risk of the node.

[0146] Based on the same inventive concept, an embodiment of the present application also provides a device for generating alarm behavior data.

[0147] In some embodiments, as Figure 5 As shown, an embodiment of the present application provides a device for generating alarm behavior data, which may include:

[0148] an acquisition module 501, configured to acquire a flow reference value, an alarm reference value, a plurality of first flow data of a plurality of nodes within a first time window, and a plurality of first alarm data, wherein the flow reference value and the alarm reference value are respectively determined based on a plurality of second flow data and a plurality of second alarm data of a plurality of nodes within a second time window, the second time window being earlier than the first time window;

[0149] a determination module 502 configured to determine a flow data attribute value based on the plurality of first flow data, and to determine a target alarm data attribute value based on the plurality of first alarm data, wherein the target alarm attribute value represents an attribute value of a plurality of target alarm data including the same Internet Protocol (IP) address within a first time window;

[0150] The determination module 502 is further configured to determine a flow data deviation value based on the flow data attribute value and the flow reference value;

[0151] The determination module 502 is further configured to determine an alarm risk value based on the traffic data deviation value and the target alarm attribute value;

[0152] The sorting module 503 is configured to sort the plurality of target alarm data according to the alarm time to obtain alarm time series data when the alarm risk value is greater than the alarm reference value;

[0153] The generating module 504 is used to determine target alarm data that meets the attack ranking in the alarm time series data, and obtain alarm behavior data.

[0154] The embodiment of the present application obtains a flow reference value, an alarm reference value, multiple first flow data of multiple nodes in a first time window, and multiple first alarm data through an acquisition module, determines a flow data attribute value based on the multiple first flow data through a determination module, determines a target alarm data attribute value based on the multiple first alarm data, determines a flow data deviation value based on the flow data attribute value and the flow reference value, determines an alarm risk value based on the flow data deviation value and the target alarm attribute value, compares the alarm risk value with the alarm reference value to determine whether the alarm data needs to be denoised, and uses a sorting module to sort the multiple target alarm data according to the alarm time to obtain alarm time series data when the alarm risk value is greater than the alarm reference value, and uses a generation module to determine the target alarm data that meets the attack sorting in the alarm time series data to obtain alarm behavior data. This can achieve denoising of the alarm data based on the multiple flow data and multiple alarm data of the acquired multiple nodes, thereby improving the efficiency of denoising the alarm number.

[0155] In some embodiments, the determination module may be specifically configured to:

[0156] Clustering the plurality of first flow data based on a characteristic value included in each first flow data, classifying the first flow data including the same characteristic value into one category, thereby obtaining a plurality of flow data categories, wherein each flow data category includes a plurality of first flow data;

[0157] For each traffic data classification, a traffic data attribute value is determined based on the number of the plurality of different characteristic values in the traffic data classification and the occupied memory value of the first traffic data in the traffic data classification.

[0158] In some embodiments, the feature value includes an IP address and a port identifier, the traffic data classification includes an IP traffic data classification and a port traffic data classification, and the traffic data attribute value includes an IP class traffic data attribute value and a port class traffic data attribute value;

[0159] Determine the module, which can be used for:

[0160] Clustering the IP addresses and port identifiers included in the plurality of first flow data respectively, grouping the plurality of first flow data including the same IP address into one category to obtain a plurality of IP flow data categories, and grouping the plurality of first flow data including the same port identifier into one category to obtain a plurality of port flow data categories;

[0161] Determine the module, which can be used for:

[0162] The IP class traffic data attribute value is determined based on the number of multiple different port identifiers in each IP traffic data classification and the occupied memory value of the first traffic data; and the port class traffic data attribute value is determined based on the number of multiple different IP addresses in each port traffic data classification and the occupied memory value of the first traffic data.

[0163] In some embodiments, the determination module may be specifically configured to:

[0164] Determine the risk deviation coefficient based on the sum of the flow data deviation value and the preset risk coefficient, where the risk coefficient is a constant;

[0165] The alarm risk value is determined based on the product of the risk deviation coefficient and the target alarm attribute value.

[0166] In some embodiments, the determination module may be specifically configured to:

[0167] Clustering the plurality of first alarm data, classifying the first alarm data including the same IP address into one category, and obtaining a plurality of alarm data categories;

[0168] Based on each alarm data category, determining a total number of different alarm types included in the plurality of first alarm data in each alarm category and a total number of the plurality of first alarm data;

[0169] Determining an alarm data attribute value corresponding to each alarm classification based on the total number of different alarm types included in each alarm data classification and the total number of the plurality of first alarm data;

[0170] A target alarm data attribute value is determined among the multiple alarm data attribute values, wherein the target alarm data attribute value is any one of the multiple alarm data attribute values.

[0171] In some embodiments, the IP address includes a source IP address and a destination IP address; the determination module may be specifically configured to:

[0172] Clustering is performed on a plurality of first alarm data, and first alarm data including the same source IP address and destination IP address are classified into one category, thereby obtaining a plurality of alarm data categories.

[0173] The apparatus of the above embodiment is used to implement the corresponding method for generating alarm behavior data in any of the above embodiments, and has the beneficial effects of the corresponding method embodiment, which will not be described in detail here.

[0174] Figure 6 A schematic diagram of the hardware structure of an electronic device provided in an embodiment of the application.

[0175] The electronic device 600 may include a processor 601 and a memory 602 storing computer program instructions.

[0176] Specifically, the processor 601 may include a central processing unit (CPU) or an application specific integrated circuit (ASIC), or may be configured to implement one or more integrated circuits of the embodiments of the present application.

[0177] The memory 602 may include a large capacity memory for data or instructions. By way of example and not limitation, the memory 602 may include a hard disk drive (HDD), a floppy disk drive, a flash memory, an optical disk, a magneto-optical disk, a magnetic tape, or a universal serial bus (USB) drive, or a combination of two or more of these. Where appropriate, the memory 602 may include removable or non-removable (or fixed) media. Where appropriate, the memory 602 may be inside or outside the integrated gateway disaster recovery device. In a specific embodiment, the memory 602 is a non-volatile solid-state memory.

[0178] In certain embodiments, memory 602 includes read-only memory (ROM). Where appropriate, the ROM may be mask-programmable ROM, programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), electrically alterable ROM (EAROM), flash memory, or a combination of two or more of these.

[0179] The memory may include a read-only memory (ROM), a random access memory (RAM), a magnetic disk storage medium device, an optical storage medium device, a flash memory device, an electrical, optical or other physical / tangible memory storage device. Thus, generally, the memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., a memory device) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the method according to the first aspect of the present application.

[0180] The processor 601 reads and executes computer program instructions stored in the memory 602 to implement any one of the methods for generating alarm behavior data in the above embodiments.

[0181] In one example, the electronic device may further include a communication interface 603 and a bus 604. Figure 6 The processor 601, the memory 602, and the communication interface 603 are connected via a bus 604 and communicate with each other.

[0182] The communication interface 603 is mainly used to implement communication between various modules, devices, units and / or equipment in the embodiments of the present application.

[0183] The bus 604 includes hardware, software, or both, and couples the components of the online data traffic metering device to each other. By way of example, and not limitation, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an InfiniBand interconnect, a Low Pin Count (LPC) bus, a memory bus, a Micro Channel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronic Standard Association (VLB) bus, or other suitable buses, or a combination of two or more of these. Where appropriate, the bus 604 may include one or more buses. Although embodiments herein describe and illustrate a particular bus, this application contemplates any suitable bus or interconnect.

[0184] The electronic device of the above embodiment is used to implement the corresponding method for generating alarm behavior data in any of the above embodiments, and has the beneficial effects of the corresponding method embodiment, which will not be described in detail here.

[0185] In addition, in conjunction with the method for generating alarm behavior data in the above embodiments, embodiments of the present application may provide a computer storage medium for implementation. The computer storage medium stores computer program instructions; when the computer program instructions are executed by a processor, any of the methods for generating alarm behavior data in the above embodiments is implemented.

[0186] In addition, in combination with the method for generating alarm behavior data in the above embodiments, the present application embodiment can provide a computer program product for implementation. When the computer program product instructions are executed by a processor of an electronic device, any of the methods for generating alarm behavior data in the above embodiments is implemented.

[0187] Those skilled in the art should understand that the discussion of any of the above embodiments is merely illustrative and is not intended to imply that the scope of the present application (including the claims) is limited to these examples. Within the scope of the present application, the technical features in the above embodiments or different embodiments may be combined, the steps may be implemented in any order, and there are many other variations of the different aspects of the embodiments of the present application as described above, which are not provided in detail for the sake of simplicity.

[0188] The functional blocks shown in the above-described block diagram can be implemented as hardware, software, firmware or a combination thereof. When implemented in hardware, it can be, for example, an electronic circuit, an application specific integrated circuit (ASIC), appropriate firmware, a plug-in, a function card, etc. When implemented in software, the elements of the present application are programs or code segments that are used to perform the required tasks. The program or code segment can be stored in a machine-readable medium, or transmitted on a transmission medium or a communication link via a data signal carried in a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (Erasable ROM, EROM), floppy disks, CD-ROMs, optical disks, hard disks, optical fiber media, radio frequency (RF) links, etc. The code segment can be downloaded via a computer network such as the Internet, an intranet, etc.

[0189] It should also be noted that the exemplary embodiments mentioned in this application describe some methods or devices based on a series of steps or devices. However, this application is not limited to the order of the above steps. In other words, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.

[0190] The present invention has been described above with reference to the flowchart and / or block diagram of the method, device (device) and computer program product according to the embodiments of the present application.It should be understood that each box in the flowchart and / or block diagram and the combination of each box in the flowchart and / or block diagram can be realized by computer program instructions.These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer or other programmable data processing device to produce a machine so that these instructions executed via the processor of the computer or other programmable data processing device enable the realization of the function / action specified in one or more boxes of the flowchart and / or block diagram.Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor or a field programmable logic circuit.It is also understood that each box in the block diagram and / or the flowchart and the combination of the boxes in the block diagram and / or the flowchart can also be realized by the dedicated hardware that performs the specified function or action, or can be realized by the combination of dedicated hardware and computer instructions.

[0191] The above description is only a specific embodiment of the present application. Those skilled in the art will clearly understand that for the convenience and brevity of description, the specific working processes of the devices, modules and units described above can refer to the corresponding processes in the aforementioned method embodiments, and will not be repeated here. It should be understood that the scope of protection of the present application is not limited thereto. Any person skilled in the art can easily think of various equivalent modifications or replacements within the technical scope disclosed in the present application, and these modifications or replacements should be included in the scope of protection of the present application.

Claims

1. A method for generating alarm behavior data, characterized in that: include: Obtaining a flow reference value, an alarm reference value, a plurality of first flow data of a plurality of nodes within a first time window, and a plurality of first alarm data, wherein the flow reference value and the alarm reference value are respectively determined based on a plurality of second flow data and a plurality of second alarm data of a plurality of nodes within a second time window, the second time window being earlier than the first time window; Determining a flow data attribute value based on the plurality of first flow data, and determining a target alarm data attribute value based on the plurality of first alarm data, wherein the target alarm attribute value represents an attribute value of a plurality of target alarm data including a same Internet Protocol IP address within a first time window; determining a flow data deviation value based on the flow data attribute value and the flow reference value; determining an alarm risk value based on the traffic data deviation value and the target alarm attribute value; When the alarm risk value is greater than the alarm reference value, the plurality of target alarm data are sorted according to the alarm time to obtain alarm time series data; Target alarm data that meets the attack ranking is determined in the alarm time series data to obtain alarm behavior data.

2. The method for generating alarm behavior data according to claim 1, characterized in that: The determining of the flow data attribute value based on the plurality of first flow data includes: Clustering the plurality of first flow data based on a feature value included in each first flow data, classifying the first flow data including the same feature value into one category, to obtain a plurality of flow data categories, wherein each flow data category includes a plurality of first flow data; For each traffic data classification, the traffic data attribute value is determined based on the number of multiple different feature values in the traffic data classification and the occupied memory value of the first traffic data in the traffic data classification.

3. The method for generating alarm behavior data according to claim 2, characterized in that: The characteristic value includes an IP address and a port identifier, the traffic data classification includes an IP traffic data classification and a port traffic data classification, and the traffic data attribute value includes an IP traffic data attribute value and a port traffic data attribute value; The clustering of the plurality of first flow data based on the feature value included in each first flow data to obtain a plurality of flow data classifications includes: Clustering the IP addresses and port identifiers included in the plurality of first flow data respectively, grouping the plurality of first flow data including the same IP address into one category to obtain a plurality of IP flow data categories, and grouping the plurality of first flow data including the same port identifier into one category to obtain a plurality of port flow data categories; Determining a flow data attribute value based on the number of the plurality of different characteristic values in the flow data classification and the occupied memory value of the first flow data in the flow data classification includes: The IP class traffic data attribute value is determined based on the number of multiple different port identifiers in each of the IP traffic data classifications and the occupied memory value of the first traffic data; and the port class traffic data attribute value is determined based on the number of multiple different IP addresses in each of the port traffic data classifications and the occupied memory value of the first traffic data.

4. The method for generating alarm behavior data according to claim 1, characterized in that: The determining of the alarm risk value based on the traffic data deviation value and the target alarm attribute value includes: Determining a risk deviation coefficient based on the sum of the flow data deviation value and a preset risk coefficient, wherein the risk coefficient is a constant; The alarm risk value is determined based on a product of the risk offset coefficient and the target alarm attribute value.

5. The method for generating alarm behavior data according to claim 1, characterized in that: The determining the target alarm data attribute value based on the plurality of first alarm data includes: Clustering the plurality of first alarm data, classifying the first alarm data including the same IP address into one category, and obtaining a plurality of alarm data categories; Based on each alarm data category, determining a total number of different alarm types included in the plurality of first alarm data in each alarm category and a total number of the plurality of first alarm data; Determining an alarm data attribute value corresponding to each alarm classification based on the total number of different alarm types included in each alarm data classification and the total number of the plurality of first alarm data; A target alarm data attribute value is determined among a plurality of alarm data attribute values, wherein the target alarm data attribute value is any one of the plurality of alarm data attribute values.

6. The method for generating alarm behavior data according to claim 5, characterized in that: The IP address includes a source IP address and a destination IP address; clustering the plurality of first alarm data, classifying the first alarm data including the same IP address into one category, and obtaining a plurality of alarm data categories, including: Clustering is performed on the plurality of first alarm data, and the first alarm data including the same source IP address and destination IP address are classified into one category, thereby obtaining a plurality of the alarm data categories.

7. A device for generating alarm behavior data, characterized in that: include: an acquisition module, configured to acquire a flow reference value, an alarm reference value, a plurality of first flow data of a plurality of nodes within a first time window, and a plurality of first alarm data, wherein the flow reference value and the alarm reference value are respectively determined based on a plurality of second flow data and a plurality of second alarm data of a plurality of nodes within a second time window, the second time window being earlier than the first time window; a determining module, configured to determine a flow data attribute value based on the plurality of first flow data, and determine a target alarm data attribute value based on the plurality of first alarm data, wherein the target alarm attribute value represents an attribute value of a plurality of target alarm data including the same Internet Protocol IP address within a first time window; The determination module is further configured to determine a flow data deviation value based on the flow data attribute value and the flow reference value; The determination module is further configured to determine an alarm risk value based on the flow data deviation value and the target alarm attribute value; a sorting module, configured to sort the plurality of target alarm data according to alarm time to obtain alarm time series data when the alarm risk value is greater than the alarm reference value; The generating module is used to determine the target alarm data that meets the attack ranking in the alarm time series data and obtain the alarm behavior data.

8. An electronic device, characterized in that: The device includes: a processor, and a memory storing computer program instructions; The processor reads and executes the computer program instructions to implement the method for generating alarm behavior data according to any one of claims 1 to 6.

9. A readable storage medium, characterized in that: The readable storage medium stores computer program instructions, and when the computer program instructions are executed by a processor, the method for generating alarm behavior data according to any one of claims 1 to 6 is implemented.

10. A computer program product comprising a computer program, characterized in that When the computer program is processed by a processor, the method for generating alarm behavior data according to any one of claims 1 to 6 is implemented.