Data processing method and device, equipment, storage medium and product
By acquiring and analyzing the security analysis rules and parsing rule chains in SIEM products, the effectiveness of the rules is clarified, which solves the problem of difficulty in determining the effectiveness of rules in SIEM products and provides clear rule evaluation results to support rule optimization and improvement.
Patent Information
- Application Number
- CN202510630085.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-15
- Publication Date
- 2025-09-09
AI Technical Summary
The effectiveness of a large number of security analysis rules in SIEM products is difficult to determine, resulting in a lack of strong basis for rule optimization and improvement, which limits the improvement of security protection capabilities.
By obtaining the analysis rule set and the parsing rule set, it is determined whether there is a valid parsing chain for the security analysis rule, the effectiveness status of the rule is clarified, and the rule evaluation results are displayed, including the validity information of each security analysis rule.
Clearly indicate the effectiveness of security analysis rules, provide solid data support for subsequent rule improvement work, and ensure the accuracy and effectiveness of rule evaluation results.
Smart Images

Figure CN120611375A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data security technology, and in particular to a data processing method, apparatus, device, storage medium and product. Background Art
[0002] SIEM (Security Information and Event Management) products, as key tools for data security monitoring, are widely used in various systems. They deploy numerous security analysis rules to monitor and analyze massive amounts of data in real time to identify potential security threats.
[0003] However, the effectiveness of the numerous security analysis rules within SIEM products is difficult to determine. Technical personnel are unable to intuitively and clearly understand the actual effectiveness of each rule, which leaves them without a solid basis for rule optimization and improvement, significantly limiting the security protection capabilities of SIEM products.
[0004] Therefore, there is an urgent need to provide a method to clarify the effectiveness status of each rule in the SIEM product and provide solid data support for subsequent rule improvement work.
[0005] The above content is only used to assist in understanding the technical solution of this application and does not constitute an admission that the above content is prior art. Summary of the Invention
[0006] The main purpose of this application is to provide a data processing method, device, equipment, storage medium and product that can clarify the effective status of security analysis rules.
[0007] To achieve the above objectives, the present application proposes a data processing method, which includes:
[0008] In response to the rule evaluation instruction, obtaining an analysis rule set and a parsing rule set, wherein the analysis rule set includes a plurality of security analysis rules for data security detection, and the parsing rule set includes a plurality of parsing rule chains for parsing data to be detected;
[0009] For any security analysis rule, if there is a valid resolution chain corresponding to the security analysis rule in the resolution rule set, the security analysis rule is determined to be a valid rule; otherwise, the security analysis rule is determined to be an invalid rule. The valid resolution chain is a resolution rule chain that can provide data support for data security detection of the security analysis rule.
[0010] The rule evaluation result is displayed, where the rule evaluation result includes validity information of each security analysis rule in the analysis rule set, where the validity information is used to indicate whether the corresponding security analysis rule is valid.
[0011] Optionally, the method further includes:
[0012] Determine the information elements that each security analysis rule relies on for data security detection, and the information elements that each parsing rule chain parses from the data to be detected;
[0013] For any security analysis rule, query the parsing rule set for a parsing rule chain whose parsed information element covers the information element on which the security analysis rule depends;
[0014] The queried parsing rule chain is determined as a valid parsing chain corresponding to the security analysis rule.
[0015] Optionally, the rule evaluation result further includes a valid resolution chain and an invalid resolution chain corresponding to each security analysis rule; the method further includes:
[0016] For any security analysis rule, determining parsing rule chains in the parsing rule set other than the valid parsing chain corresponding to the security analysis rule;
[0017] The parsing rule chains other than the valid parsing chain in the parsing rule set are determined as invalid parsing chains corresponding to the security analysis rule.
[0018] Optionally, the rule evaluation result further includes invalid elements and invalid classifications of invalid resolution chains corresponding to each security analysis rule; the method further includes:
[0019] For any invalid parsing chain of any security analysis rule, determining, among the information elements that the security analysis rule depends on, information elements that are not parsed by the invalid parsing chain;
[0020] Determining the information element that is not resolved by the invalid resolution chain as an invalid element of the invalid resolution chain;
[0021] According to the information type to which the invalid element belongs, the invalid category to which the invalid resolution chain belongs is determined.
[0022] Optionally, the information element not resolved by the invalid resolution chain includes at least one information element selected from the group consisting of an event name, a field name, and an enumerated field value;
[0023] The step of determining the information element that is not resolved by the invalid resolution chain as an invalid element of the invalid resolution chain includes:
[0024] In a case where the information element not resolved by the invalid resolution chain includes an event name, determining the event name as the invalid element;
[0025] Alternatively, when the information element not resolved by the invalid resolution chain does not include an event name but includes a field name, the field name is determined as the invalid element;
[0026] Alternatively, when the information element not resolved by the invalid resolution chain does not include an event name and a field name but includes an enumeration field value, the enumeration field value is determined to be the invalid element.
[0027] Optionally, for any security analysis rule, among the multiple invalid resolution chains corresponding to the security analysis rule, there are multiple invalid resolution chains with the same invalid elements and invalid classifications;
[0028] Before displaying the rule evaluation result, the method further includes:
[0029] In the multiple invalid resolution chains corresponding to the security analysis rule, multiple invalid resolution chains with the same invalid elements and invalid classifications are merged into one invalid resolution chain to obtain an updated invalid resolution chain corresponding to the security analysis rule.
[0030] Optionally, for any security analysis rule, the multiple invalid resolution chains corresponding to the security analysis rule each include multiple sub-resolution steps;
[0031] The step of merging multiple invalid resolution chains corresponding to the security analysis rule, which have the same invalid elements and invalid classifications, into one invalid resolution chain to obtain an updated invalid resolution chain corresponding to the security analysis rule, includes:
[0032] Generate an invalid rule tree based on multiple invalid resolution chains corresponding to the security analysis rule, wherein the root node of the invalid rule tree represents the initial sub-resolution step common to the multiple invalid resolution chains, the leaf nodes represent the terminal sub-resolution steps of each invalid resolution chain, and the paths from the root node along the edges of the invalid rule tree to each leaf node constitute each invalid resolution chain;
[0033] Based on the invalidation rule tree, multiple invalidation resolution chains corresponding to the security analysis rule, which have the same invalid elements and invalid classifications, are merged into one invalidation resolution chain to obtain an updated invalidation resolution chain corresponding to the security analysis rule.
[0034] Optionally, based on the invalidation rule tree, merging multiple invalidation chains corresponding to the security analysis rule, which have the same invalid elements and invalid classifications, into one invalidation chain to obtain an updated invalidation chain corresponding to the security analysis rule, includes:
[0035] Performing a pruning operation on the invalid rule tree at least once until the number of nodes in the invalid rule tree remains unchanged, the pruning operation comprising: if multiple leaf nodes belong to the same intermediate node and the invalid elements and invalid categories of the invalid resolution chains corresponding to the multiple leaf nodes are the same, deleting the multiple leaf nodes so that the intermediate nodes to which the multiple leaf nodes belong become new leaf nodes;
[0036] Each invalid resolution chain formed by a path from the root node along the edge of the pruned invalid rule tree to each leaf node is determined as an updated invalid resolution chain corresponding to the security analysis rule.
[0037] Optionally, the method further includes:
[0038] In response to the rule comparison instruction, obtaining the analysis rule set and the parsing rule set before the update and the analysis rule set and the parsing rule set after the update;
[0039] Determine a rule evaluation result before the update based on the analysis rule set and the parsing rule set before the update, and determine a rule evaluation result after the update based on the analysis rule set and the parsing rule set after the update;
[0040] Generate a rule comparison result based on the rule evaluation result before and after the update, the rule comparison result including status information and validity information of each security analysis rule in the analysis rule set before and after the update, the status information indicating whether each security analysis rule exists in the analysis rule set before and after the update;
[0041] Display the rule comparison results.
[0042] Optionally, the rule comparison result further includes detection capability change information of each security analysis rule; and the method further includes at least one of the following:
[0043] Determine the detection capability change information of the security analysis rules that do not exist or are invalid in the analysis rule set before the update but exist and are valid in the analysis rule set after the update as capability improvement;
[0044] Determining detection capability change information of security analysis rules that exist and are valid in the analysis rule set before the update, but do not exist or are invalid in the analysis rule set after the update as capability degradation;
[0045] Determine the detection capability change information of the security analysis rules that are valid and exist in the analysis rule set before the update and are valid and exist in the analysis rule set after the update as the valid capability remains unchanged;
[0046] The detection capability change information of the security analysis rules that exist and are invalid in the analysis rule set before the update and exist and are invalid in the analysis rule set after the update, as well as the security analysis rules that do not exist in the analysis rule set before the update and exist and are invalid in the analysis rule set after the update, and the security analysis rules that exist and are invalid in the analysis rule set before the update and do not exist in the analysis rule set after the update are determined as invalid capabilities unchanged.
[0047] Optionally, the method further includes:
[0048] Deleting invalid rules from the analysis rule set;
[0049] Alternatively, according to the invalid elements and invalid categories of the invalid resolution chain corresponding to the invalid rule, the invalid resolution chain is modified so that the information elements resolved by the invalid resolution chain cover the information elements on which the invalid rule depends.
[0050] In addition, to achieve the above-mentioned purpose, the present application also proposes a data processing device, which includes:
[0051] an instruction response module, configured to obtain, in response to a rule evaluation instruction, an analysis rule set and a parsing rule set, wherein the analysis rule set includes a plurality of security analysis rules for data security detection, and the parsing rule set includes a plurality of parsing rule chains for parsing data to be detected;
[0052] a rule evaluation module configured to, for any security analysis rule, determine that if there is a valid resolution chain corresponding to the security analysis rule in the resolution rule set, the security analysis rule is a valid rule; otherwise, the security analysis rule is determined to be an invalid rule, wherein the valid resolution chain is a resolution rule chain that can provide data support for performing data security detection on the security analysis rule;
[0053] The result display module is used to display the rule evaluation result, wherein the rule evaluation result includes validity information of each security analysis rule in the analysis rule set, and the validity information is used to indicate whether the corresponding security analysis rule is valid.
[0054] Optionally, the device further comprises:
[0055] The parsing chain determination module is used to determine the information elements that each security analysis rule relies on for data security testing, as well as the information elements parsed from the data to be tested by each parsing rule chain; for any security analysis rule, query the parsing rule chain whose parsed information elements cover the information elements that the security analysis rule relies on from the parsing rule set; and determine the queried parsing rule chain as the valid parsing chain corresponding to the security analysis rule.
[0056] Optionally, the rule evaluation result further includes a valid resolution chain and an invalid resolution chain corresponding to each security analysis rule;
[0057] The resolution chain determination module is further configured to determine, for any security analysis rule, resolution rule chains in the resolution rule set other than the valid resolution chain corresponding to the security analysis rule; and determine the resolution rule chains in the resolution rule set other than the valid resolution chain as invalid resolution chains corresponding to the security analysis rule.
[0058] Optionally, the rule evaluation result further includes invalid elements and invalid classifications of invalid resolution chains corresponding to each security analysis rule; the apparatus further includes:
[0059] An information element determination module, configured to determine, for any invalid parsing chain of any security analysis rule, information elements that are not parsed by the invalid parsing chain among the information elements that the security analysis rule depends on;
[0060] an invalid element determination module, configured to determine an information element that is not resolved by the invalid resolution chain as an invalid element of the invalid resolution chain;
[0061] The invalid classification determination module is used to determine the invalid classification to which the invalid resolution chain belongs according to the information type to which the invalid element belongs.
[0062] Optionally, the information element not resolved by the invalid resolution chain includes at least one information element selected from the group consisting of an event name, a field name, and an enumerated field value;
[0063] The invalid element determination module is used to determine, when the information element unresolved by the invalid resolution chain includes an event name, the event name as the invalid element; or, when the information element unresolved by the invalid resolution chain does not include an event name but includes a field name, determine the field name as the invalid element; or, when the information element unresolved by the invalid resolution chain does not include an event name and a field name but includes an enumeration field value, determine the enumeration field value as the invalid element.
[0064] Optionally, for any security analysis rule, there are multiple invalid resolution chains with the same invalid elements and invalid classifications among the multiple invalid resolution chains corresponding to the security analysis rule; the apparatus further includes:
[0065] The parsing chain merging module is used to merge multiple invalid parsing chains corresponding to the security analysis rule, which have the same invalid elements and invalid categories, into one invalid parsing chain to obtain an updated invalid parsing chain corresponding to the security analysis rule.
[0066] Optionally, for any security analysis rule, the multiple invalid resolution chains corresponding to the security analysis rule each include multiple sub-resolution steps;
[0067] The resolution chain merging module includes:
[0068] a rule tree generation unit, configured to generate an invalid rule tree based on multiple invalid resolution chains corresponding to the security analysis rule, wherein a root node of the invalid rule tree represents an initial sub-resolution step common to the multiple invalid resolution chains, a leaf node represents a terminal sub-resolution step of each invalid resolution chain, and a path from the root node along an edge of the invalid rule tree to each leaf node constitutes each invalid resolution chain;
[0069] The parsing chain merging unit is configured to merge, based on the invalid rule tree, multiple invalid parsing chains corresponding to the security analysis rule, which have the same invalid elements and invalid classifications, into one invalid parsing chain to obtain an updated invalid parsing chain corresponding to the security analysis rule.
[0070] Optionally, the resolution chain merging unit is used to perform a pruning operation on the invalid rule tree at least once until the number of nodes of the invalid rule tree does not change, and the pruning operation includes: when multiple leaf nodes belong to the same intermediate node and the invalid elements and invalid classifications of the invalid resolution chains corresponding to the multiple leaf nodes are the same, deleting the multiple leaf nodes so that the intermediate nodes to which the multiple leaf nodes belong become new leaf nodes; and determining each invalid resolution chain formed by the path from the root node along the edge of the pruned invalid rule tree to each leaf node as the updated invalid resolution chain corresponding to the security analysis rule.
[0071] Optionally, the device further comprises:
[0072] A rule comparison module is used to obtain the analysis rule set and parsing rule set before the update and the analysis rule set and parsing rule set after the update in response to the rule comparison instruction; determine the rule evaluation result before the update based on the analysis rule set and parsing rule set before the update, and determine the rule evaluation result after the update based on the analysis rule set and parsing rule set after the update; generate a rule comparison result based on the rule evaluation result before the update and the rule evaluation result after the update, the rule comparison result including status information and validity information of each security analysis rule in the analysis rule set before the update and the analysis rule set after the update, the status information indicating whether each security analysis rule exists in the analysis rule set before the update and the analysis rule set after the update; and display the rule comparison result.
[0073] Optionally, the rule comparison result also includes detection capability change information of each security analysis rule;
[0074] The rule comparison module is further configured to perform at least one of the following:
[0075] Determine the detection capability change information of the security analysis rules that do not exist or are invalid in the analysis rule set before the update but exist and are valid in the analysis rule set after the update as capability improvement;
[0076] Determining detection capability change information of security analysis rules that exist and are valid in the analysis rule set before the update, but do not exist or are invalid in the analysis rule set after the update as capability degradation;
[0077] Determine the detection capability change information of the security analysis rules that are valid and exist in the analysis rule set before the update and are valid and exist in the analysis rule set after the update as the valid capability remains unchanged;
[0078] The detection capability change information of the security analysis rules that exist and are invalid in the analysis rule set before the update and exist and are invalid in the analysis rule set after the update, as well as the security analysis rules that do not exist in the analysis rule set before the update and exist and are invalid in the analysis rule set after the update, and the security analysis rules that exist and are invalid in the analysis rule set before the update and do not exist in the analysis rule set after the update are determined as invalid capabilities unchanged.
[0079] Optionally, the device further comprises:
[0080] A rule updating module is configured to delete invalid rules from the analysis rule set; or, based on the invalid elements and invalid categories of the invalid resolution chain corresponding to the invalid rule, modify the invalid resolution chain so that the information elements resolved by the invalid resolution chain cover the information elements on which the invalid rule depends.
[0081] In addition, to achieve the above-mentioned purpose, the present application also proposes a data processing device, which includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the data processing method described above.
[0082] In addition, to achieve the above-mentioned purpose, the present application also proposes a storage medium, which is a computer-readable storage medium. A computer program is stored on the storage medium, and when the computer program is executed by a processor, the steps of the data processing method described above are implemented.
[0083] In addition, to achieve the above-mentioned purpose, the present application also provides a computer program product, which includes a computer program, and when the computer program is executed by a processor, it implements the steps of the data processing method described above.
[0084] One or more technical solutions proposed in this application have at least the following technical effects:
[0085] The data processing solution provided by this application can clearly determine whether each security analysis rule in an analysis rule set is valid or invalid. Specifically, in response to a rule evaluation instruction, an analysis rule set and a parsing rule set are obtained. The analysis rule set includes multiple security analysis rules for data security testing, and the parsing rule set includes multiple parsing rule chains for parsing the data to be tested. For any security analysis rule, if there is a valid parsing chain corresponding to the security analysis rule in the parsing rule set, that is, a parsing rule chain that can provide data support for the security analysis rule, then the security analysis rule can exert its detection capabilities based on the data provided by the corresponding valid parsing chain when performing data security testing. If there is no corresponding valid parsing chain to provide data support for the security analysis rule, the security analysis rule cannot operate according to its detection logic and thus cannot exert its detection capabilities. Therefore, if there is a valid parsing chain corresponding to the security analysis rule in the parsing rule set, the security analysis rule is determined to be valid; otherwise, the security analysis rule is determined to be invalid, thereby ensuring the accuracy of the validity information of each determined security analysis rule. The rule evaluation results are then displayed. The rule evaluation results include the validity information of each security analysis rule in the analysis rule set to indicate whether the corresponding security analysis rule is valid. This can clearly provide technical personnel with the effectiveness of the security analysis rules and provide solid data support for subsequent rule improvement work. BRIEF DESCRIPTION OF THE DRAWINGS
[0086] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0087] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0088] Figure 1 A schematic diagram of an implementation environment of the data processing method of this application;
[0089] Figure 2 A flowchart of the first embodiment of the data processing method of this application is provided;
[0090] Figure 3 A flowchart of the second embodiment of the data processing method of this application is provided;
[0091] Figure 4A flowchart of the third embodiment of the data processing method of this application is provided;
[0092] Figure 5 This is a schematic diagram of the merged parsing chain process in the fourth embodiment of the data processing method of this application;
[0093] Figure 6 A schematic diagram of an invalid rule tree provided for this application;
[0094] Figure 7 A flowchart of the fifth embodiment of the data processing method of the present application is provided;
[0095] Figure 8 A flowchart of the sixth embodiment of the data processing method of the present application is provided;
[0096] Figure 9 A schematic diagram of the process of using a data processing unit to perform rule evaluation provided by this application;
[0097] Figure 10 A schematic diagram of the interface of the rule analysis tool provided for this application;
[0098] Figure 11 This is a schematic diagram of the module structure of the data processing device according to an embodiment of the present application;
[0099] Figure 12 Schematic diagram of the device structure of the hardware operating environment involved in the data processing method in the embodiment of the present application.
[0100] The purpose, features and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION
[0101] It should be understood that the specific embodiments described herein are merely used to explain the technical solutions of the present application and are not intended to limit the present application.
[0102] In order to better understand the technical solution of the present application, a detailed description will be given below in conjunction with the accompanying drawings and specific implementation methods.
[0103] Figure 1 This is a schematic diagram of an implementation environment provided by an embodiment of the present disclosure. Figure 1 The implementation environment includes a terminal 101 and a server 102. The terminal 101 and the server 102 are connected via a wireless or wired network. For example, the terminal 101 is installed with a target application provided by the server 102, and the terminal 101 can implement functions such as data transmission and message exchange through the target application.
[0104] Exemplarily, terminal 101 is a computer, mobile phone, tablet computer, or other terminal. Exemplarily, the target application is a target application in the operating system of terminal 101, or a target application provided by a third party. For example, the target application is a data detection application, a data analysis application, a data management application, etc. The target application can continuously monitor network traffic, system logs, and other security-related data sources to detect potential data security threats. Exemplarily, server 102 is the backend server corresponding to the target application.
[0105] In the present application, the terminal 101 is used to send a rule evaluation instruction to the server 102 when detecting an operation instructing the user to perform rule evaluation. The server 102 is used to receive the rule evaluation instruction and, in response to the rule evaluation instruction, obtain an analysis rule set and a parsing rule set. The analysis rule set includes a plurality of security analysis rules for data security detection, and the parsing rule set includes a plurality of parsing rule chains for parsing the data to be detected. For any security analysis rule, if there is a valid parsing chain corresponding to the security analysis rule in the parsing rule set, the security analysis rule is determined to be a valid rule, otherwise the security analysis rule is determined to be an invalid rule. A valid parsing chain is a parsing rule chain that can provide data support for the security analysis rule to perform data security detection. The server 102 then sends the rule evaluation result to the terminal 101. After receiving the rule evaluation result, the terminal 101 displays the rule evaluation result. The rule evaluation result includes the validity information of each security analysis rule in the analysis rule set, and the validity information is used to indicate whether the corresponding security analysis rule is valid.
[0106] Alternatively, the above data processing process can also be completed by the terminal 101 alone. Alternatively, the terminal 101 completes it through the installed target application. This embodiment of the present application does not limit this.
[0107] Figure 2 This is a flow chart of the first embodiment of the data processing method of this application. Figure 2 Taking the execution subject as a terminal as an example, the data processing method includes the following steps S10 to S30:
[0108] Step S10 , in response to the rule evaluation instruction, obtaining an analysis rule set and a parsing rule set, wherein the analysis rule set includes a plurality of security analysis rules for data security detection, and the parsing rule set includes a plurality of parsing rule chains for parsing the data to be detected.
[0109] A rule evaluation command is a trigger action or signal that initiates the evaluation of security analysis rules. It can be a manual command from a user or a scheduled command automatically sent by the endpoint. It initiates the entire evaluation process, telling the endpoint to evaluate the effectiveness of the security analysis rules.
[0110] An analysis rule set contains multiple security analysis rules. These rules are used to perform data security checks, specifically to determine whether the data being tested contains data security threats or abnormal behavior. For example, an analysis rule set might include rules to detect abnormal network traffic, abnormal system login behavior, or risky file access behavior. These security analysis rules are crucial for ensuring terminal data security.
[0111] The parsing rule set contains multiple parsing rule chains, which are used to parse the data to be detected. Since the data to be detected may have a complex structure and multiple formats, the parsing rule chain is designed to convert the data to be detected into a format that can be understood and processed by the security analysis rules. For example, for network traffic data, the parsing rule chain can parse the original network data packet and extract key information such as the source IP (Internet Protocol) address, destination IP address, port number, protocol type, etc. The parsing rule chain is a sequence of rules that disassembles and structures the original data to be detected, providing appropriate data input for subsequent security analysis rules. The parsing rule chain contains multiple sub-parsing steps, each of which has its own specific parsing function to extract the required information elements from the original data to be detected.
[0112] Step S20: For any security analysis rule, if there is a valid resolution chain corresponding to the security analysis rule in the resolution rule set, the security analysis rule is determined to be a valid rule; otherwise, the security analysis rule is determined to be an invalid rule. A valid resolution chain is a resolution rule chain that can provide data support for data security detection of the security analysis rule.
[0113] An effective parsing chain is a parsing rule chain that can provide data support for the security analysis rule to perform data security testing. That is, an effective parsing chain can parse the original data to be tested into the information required by the security analysis rule, ensuring that the security analysis rule can perform accurate security testing based on the parsed information.
[0114] For example, for a security analysis rule that detects whether there are abnormal IP addresses in network traffic, the corresponding effective resolution chain needs to accurately extract the IP address information in the network traffic data, including the source IP address and the destination IP address, so that the security analysis rule can analyze these IP addresses and determine whether there is abnormal behavior.
[0115] Valid rules refer to security analysis rules that can properly perform data security detection functions. Invalid rules refer to security analysis rules that cannot properly perform data security detection functions.
[0116] Step S30 : Displaying the rule evaluation result. The rule evaluation result includes validity information of each security analysis rule in the analysis rule set. The validity information is used to indicate whether the corresponding security analysis rule is valid.
[0117] The rule evaluation result summarizes the evaluation of each security analysis rule in the analysis rule set. It contains the validity information for each security analysis rule, clarifying which security analysis rules are valid and which are invalid. This is the final output of the entire evaluation process. It allows technical personnel to review the validity of security analysis rules and subsequently adjust or optimize invalid rules to improve terminal security performance.
[0118] Validity information explicitly indicates whether the corresponding security analysis rule is valid. It can be a specific flag. For example, "1" indicates valid, and "0" indicates invalid. Validity information can also include more detailed information, such as the reason why a security analysis rule is invalid. For example, the invalidity of a security analysis rule could be due to an issue with the rule chain parsing or a logical issue within the security analysis rule itself. This information provides valuable reference for technical personnel to improve rules.
[0119] The data processing solution provided by this application can clearly determine whether each security analysis rule in an analysis rule set is valid or invalid. Specifically, in response to a rule evaluation instruction, an analysis rule set and a parsing rule set are obtained. The analysis rule set includes multiple security analysis rules for data security testing, and the parsing rule set includes multiple parsing rule chains for parsing the data to be tested. For any security analysis rule, if there is a valid parsing chain corresponding to the security analysis rule in the parsing rule set, that is, a parsing rule chain that can provide data support for the security analysis rule, then the security analysis rule can exert its detection capabilities based on the data provided by the corresponding valid parsing chain when performing data security testing. If there is no corresponding valid parsing chain to provide data support for the security analysis rule, the security analysis rule cannot operate according to its detection logic and thus cannot exert its detection capabilities. Therefore, if there is a valid parsing chain corresponding to the security analysis rule in the parsing rule set, the security analysis rule is determined to be valid; otherwise, the security analysis rule is determined to be invalid, thereby ensuring the accuracy of the validity information of each determined security analysis rule. The rule evaluation results are then displayed. The rule evaluation results include the validity information of each security analysis rule in the analysis rule set to indicate whether the corresponding security analysis rule is valid. This can clearly provide technical personnel with the effectiveness of the security analysis rules and provide solid data support for subsequent rule improvement work.
[0120] Based on the above first embodiment, the second embodiment of the present application is proposed. For the same or similar contents as the first embodiment, please refer to the above introduction and will not be described in detail later. Figure 3In the second embodiment, between the above steps S10 and S20, steps S401 to S403 are included:
[0121] Step S401 : determining the information elements that each security analysis rule relies on for data security detection, and the information elements that each parsing rule chain parses from the data to be detected.
[0122] Information elements are the smallest units of key information involved in data security testing. These elements can be various data attributes. For example, in system operation logs, information elements might include user ID, operation type, and operation time. They are the fundamental building blocks of data. Whether it's security testing using security analysis rules or data parsing using parsing rule chains, they all revolve around information elements.
[0123] The information elements a security analysis rule relies on are the information elements it requires to perform data security checks. Different security analysis rules require different information elements to make judgments. For example, a security analysis rule that detects abnormal network connections might rely on information elements such as the event name "Network Connection," the fields "Protocol" and "Threat Type," and the field value "Remote Control Trojan" in the "Threat Type" field. Only when these information elements are provided can the security analysis rule, based on its built-in algorithms and logic, determine whether a network connection is abnormal.
[0124] The information elements parsed by the parsing rule chain from the data to be tested represent the information elements extracted by the parsing rule chain during the parsing operation on the data to be tested. For example, when parsing a network packet, the parsing rule chain may extract information elements such as the source MAC (Media Access Control) address and the destination MAC address. These information elements are extracted and organized by the parsing rule chain from the raw, unprocessed data to be tested, and are the result of structured processing of the raw data to be tested.
[0125] Step S402: For any security analysis rule, query the parsing rule set for a parsing rule chain whose parsed information element covers the information element on which the security analysis rule depends.
[0126] The information elements parsed by the parsing rule chain cover the information elements that the security analysis rule depends on, which means that the information element set extracted by the parsing rule chain includes all the information elements required by the security analysis rule.
[0127] Exemplarily, for any security analysis rule, the terminal traverses all parsing rule chains in the parsing rule set to search for a parsing rule chain in which the parsed information element covers the information element on which the security analysis rule depends.
[0128] Step S403: Determine the found parsing rule chain as a valid parsing chain corresponding to the security analysis rule.
[0129] The parsed information elements cover the parsing rule chain of the information elements that the security analysis rule depends on, and can provide data support for the security analysis rule to perform data security detection, so it can serve as a valid parsing chain corresponding to the security analysis rule.
[0130] In the embodiments of the present application, by clearly identifying the information elements that security analysis rules rely on for data security testing and the information elements parsed by the parsing rule chain, it is possible to accurately match the security analysis rules with the parsing rule chain. Specifically, a parsing rule chain whose parsed information elements cover the information elements required by each security analysis rule is found, and the parsing rule chain whose parsed information elements cover the information elements required by each security analysis rule is then determined as the valid parsing chain corresponding to each security analysis rule. This approach ensures that an accurate valid parsing chain is found for each security analysis rule.
[0131] Based on the above second embodiment of the present application, the third embodiment of the present application is proposed. For the same or similar contents as the second embodiment, please refer to the above introduction and will not be repeated hereafter. Figure 4 In the third embodiment, steps S404 to S408 are included between step S403 and step S20, and step S30 is further refined into step S301.
[0132] Step S404: for any security analysis rule, determine the parsing rule chains in the parsing rule set except the valid parsing chain corresponding to the security analysis rule.
[0133] Step S405 : Determine the parsing rule chains in the parsing rule set other than the valid parsing chain as invalid parsing chains corresponding to the security analysis rule.
[0134] An invalid parsing chain is a parsing rule chain that cannot provide all or part of the information elements required for the security analysis rule, resulting in the security analysis rule being unable to properly perform its data security detection function.
[0135] For any security analysis rule, there may be no valid resolution chain corresponding to the security analysis rule in the resolution rule set, or there may be one or more valid resolution chains corresponding to the security analysis rule. If there is no valid resolution chain corresponding to the security analysis rule in the resolution rule set, then all resolution rule chains in the resolution rule set are invalid resolution chains corresponding to the security analysis rule. If there is one or more valid resolution chains corresponding to the security analysis rule in the resolution rule set, then all resolution rule chains in the resolution rule set other than the one or more valid resolution chains are invalid resolution chains corresponding to the security analysis rule. Any security analysis rule may have multiple invalid resolution chains corresponding to it.
[0136] Step S406 : For any invalid resolution chain of any security analysis rule, determine, among the information elements that the security analysis rule depends on, information elements that are not resolved by the invalid resolution chain.
[0137] Among the information elements that the security analysis rule relies on, the information elements that are not resolved by the invalid resolution chain refer to: among the information elements required by the security analysis rule for data security detection, the information elements that the invalid resolution chain cannot provide.
[0138] Step S407: Determine the information element that is not resolved by the invalid resolution chain as an invalid element of the invalid resolution chain.
[0139] It is understandable that a rule parsing chain may become an invalid parsing chain corresponding to multiple security analysis rules. For multiple different security analysis rules corresponding to the invalid parsing chain, the invalid elements of the invalid parsing chain are also different.
[0140] Optionally, the information element not resolved by the invalid resolution chain includes at least one information element among an event name, a field name, and an enumerated field value. Determining the information element not resolved by the invalid resolution chain as an invalid element of the invalid resolution chain includes: in the case where the information element not resolved by the invalid resolution chain includes an event name, determining the event name as an invalid element; or, in the case where the information element not resolved by the invalid resolution chain does not include an event name and includes a field name, determining the field name as an invalid element; or, in the case where the information element not resolved by the invalid resolution chain does not include an event name and a field name and includes an enumerated field value, determining the enumerated field value as an invalid element. That is to say, when determining an invalid element, the event name has a higher priority than the field name, and the field name has a higher priority than the enumerated field value.
[0141] An event name is the name of an operation or activity that occurs in the system. It can be used to describe a specific behavior or transaction. Examples include "user login event," "file download event," "database access event," and "network connection event." These event names provide a general description of what occurred and are important information elements when analyzing security risks.
[0142] Field names are specific attribute names within the data, identifying different parts of the data. For example, a system log might contain fields such as "timestamp," "user ID," and "operation type." These fields store corresponding data and provide specific information for security analysis. During data parsing and security analysis, extracting and analyzing the contents of these fields can determine whether there are any abnormal behaviors or security threats.
[0143] Enumerated field values refer to fields with a limited number of possible values. These values are pre-set and can be enumerated. For example, for the "User Permissions" field, its enumerated field values might be "Administrator," "Regular User," "Guest," and so on. These enumerated field values are important information elements in data security testing and may affect the judgment results of security analysis rules.
[0144] Since the event name provides important information for security analysis, the event name is determined as an invalid element first, which can clarify the most important information missing issues of the invalid resolution chain. Since the field name provides more specific data attribute information for security analysis, the field name is placed second, which can clarify more detailed information missing issues of the invalid resolution chain. The information of the enumeration field value is relatively less important and has less impact. Therefore, when the information element that is not resolved by the invalid resolution chain does not include the event name and field name but includes the enumeration field value, the enumeration field value is determined as an invalid element, which can clarify further detailed information missing issues of the invalid resolution chain. By determining the invalid elements in this priority order, the determined invalid elements can point out the most important element missing issues of each invalid resolution chain. This is conducive to the subsequent adjustment of the invalid resolution chain.
[0145] Exemplarily, for any invalid resolution chain of any security analysis rule, when determining the information elements that the security analysis rule depends on, the information elements that are not resolved by the invalid resolution chain are first determined to be resolved, then whether the field is resolved, and finally whether the enumeration field value is resolved. If the event name is not resolved, the event name is directly determined as an invalid element without determining whether the field and enumeration field value are resolved. If the event name is resolved and the field is not resolved, the field is determined to be an invalid element without determining whether the enumeration field value is resolved. If both the event name and the field are resolved, then determine whether the enumeration field value is resolved. If the enumeration field value is not resolved, the enumeration field value is determined to be an invalid element. This can improve the efficiency of data processing and save terminal resources.
[0146] Step S408: Determine the invalid category to which the invalid resolution chain belongs based on the information type to which the invalid element belongs.
[0147] Invalid classifications categorize invalid parsing chains based on the information type of the invalid element. For example, if the invalid element is the event name "Network Connection," the invalid parsing chain may belong to the invalid category "Event Name." If the invalid element is the field "Protocol," the invalid parsing chain may belong to the invalid category "Field." If the invalid element is the field value "Remote Control Trojan" in the field "Threat Type," the invalid parsing chain may belong to the invalid category "Field Value." Invalid classifications categorize invalid parsing chains based on the information type of the invalid element, helping to more clearly analyze and resolve issues with parsing rule chains.
[0148] Step S301 displays the rule evaluation results, which include the validity information of each security analysis rule in the analysis rule set, the valid resolution chain and invalid resolution chain corresponding to each security analysis rule, and the invalid elements and invalid categories of the invalid resolution chain corresponding to each security analysis rule. The validity information is used to indicate whether the corresponding security analysis rule is valid.
[0149] For example, the rule evaluation results are shown in the following table 1:
[0150]
[0151] Table 1
[0152] In the embodiments of the present application, not only is the validity of each security analysis rule clearly indicated, but also the valid and invalid parsing chains corresponding to each security analysis rule, as well as the invalid elements and invalid categories of the invalid parsing chains, are clearly indicated. This provides technical personnel with comprehensive and detailed rule evaluation information, enabling them to gain a deep understanding of the operation of each rule, determining not only whether the rule is valid but also the specific reasons for its failure. This allows technical personnel to more specifically inspect and modify invalid security analysis rules or parsing rule chains, rendering invalid security analysis rules valid and optimizing data security detection performance.
[0153] It should be noted that this embodiment may not execute steps S406 to S408, and the displayed rule evaluation result does not include invalid elements and invalid categories of the invalid resolution chain.
[0154] Optionally, after displaying the rule evaluation results, the terminal can delete the invalid rule from the analysis rule set according to the user's instructions. Alternatively, based on the invalid elements and invalid categories of the invalid resolution chain corresponding to the invalid rule, the invalid resolution chain can be modified so that the information elements resolved by the invalid resolution chain overwrite the information elements on which the invalid rule depends.
[0155] For example, technicians can also supplement information such as event names, fields, and field values in the data to be detected based on the rule evaluation results, so that the security analysis rules and parsing rule chains that rely on this information can take effect.
[0156] Because invalid rules cannot provide effective security detection capabilities, they occupy system resources during operation without providing the corresponding security detection results. Therefore, deleting invalid rules from the analysis rule set can reduce the terminal's processing burden during data security detection, focusing more resources on executing effective security analysis rules, thereby improving overall data processing efficiency and performance. Modifying invalid analysis chains based on the invalid elements and invalid categories corresponding to the invalid rules can convert the originally non-functioning parts into valid rules and analysis chains, thereby improving the reliability of the entire data security detection system.
[0157] Based on the third embodiment of the present application, the fourth embodiment of the present application is proposed. For the same or similar contents as the third embodiment, please refer to the above introduction and will not be repeated hereafter. Figure 5 In the fourth embodiment, steps S409 to S410 are included between step S408 and step S20.
[0158] Step S409: Generate an invalid rule tree based on multiple invalid resolution chains corresponding to the security analysis rules. The root node of the invalid rule tree represents the initial sub-resolution step common to multiple invalid resolution chains, and the leaf nodes represent the terminal sub-resolution steps of each invalid resolution chain. The paths from the root node along the edges of the invalid rule tree to each leaf node constitute each invalid resolution chain.
[0159] The invalid rule tree is a data structure constructed from multiple invalid resolution chains corresponding to security analysis rules. It organizes invalid resolution chains in a tree-like format, with the root node representing the initial sub-resolution step shared by multiple invalid resolution chains. This initial sub-resolution step is the first step in the invalid resolution chain's parsing operation, providing a starting point for subsequent parsing. Leaf nodes represent the final sub-resolution step of each invalid resolution chain and are the final step in the parsing process. The paths from the root node along the edges of the tree to each leaf node constitute each invalid resolution chain.
[0160] For example, a security analysis rule corresponds to four invalid parsing chains: Parsing Chain 1: "AA entry parsing - KK sub-parsing - XX sub-parsing"; Parsing Chain 2: "AA entry parsing - KK sub-parsing - YY sub-parsing"; Parsing Chain 3: "AA entry parsing - KK sub-parsing - ZZ sub-parsing"; Parsing Chain 4: "AA entry parsing - PP sub-parsing - QQ sub-parsing". The invalid element for Parsing Chains 1, 2, and 3 is "field 1", and the invalid category is "field". The invalid element for Parsing Chain 4 is "field 2", and the invalid category is "field".
[0161] refer to Figure 6 , Figure 6 A schematic diagram of an invalid rule tree provided in this application. The invalid rule tree is constructed based on the above-mentioned four invalid resolution chains. Among them, "AA entry resolution" is the root node of the invalid rule tree. "XX sub-resolution", "YY sub-resolution", "ZZ sub-resolution" and "QQ sub-resolution" are leaf nodes of the invalid rule tree. "KK sub-resolution" and "PP sub-resolution" are intermediate nodes of the invalid rule tree. The lines between the nodes are the edges of the invalid rule tree. The path from the root node along the edge of the invalid rule tree to the leaf node "KK sub-resolution" constitutes resolution chain 1. The path from the root node along the edge of the invalid rule tree to the leaf node "YY sub-resolution" constitutes resolution chain 2. The path from the root node along the edge of the invalid rule tree to the leaf node "ZZ sub-resolution" constitutes resolution chain 3. The path from the root node along the edge of the invalid rule tree to the leaf node "QQ sub-resolution" constitutes resolution chain 4.
[0162] In step S410 , based on the invalidation rule tree, multiple invalidation resolution chains corresponding to the security analysis rule, which have the same invalid elements and invalidation categories, are merged into one invalidation resolution chain to obtain an updated invalidation resolution chain corresponding to the security analysis rule.
[0163] Optionally, this step is implemented as follows: performing a pruning operation on the invalid rule tree at least once until the number of nodes in the invalid rule tree does not change, the pruning operation including: deleting multiple leaf nodes when multiple leaf nodes belong to the same intermediate node and the invalid elements and invalid classifications of the invalid resolution chains corresponding to the multiple leaf nodes are the same, so that the intermediate nodes to which the multiple leaf nodes belong become new leaf nodes; and determining each invalid resolution chain formed by the path from the root node along the edge of the pruned invalid rule tree to each leaf node as the updated invalid resolution chain corresponding to the security analysis rule.
[0164] Continue to refer to the above Figure 6 Since the invalid elements and invalid categories of the invalid resolution chains corresponding to the leaf nodes "XX sub-resolution", "YY sub-resolution", and "ZZ sub-resolution" are the same, and these three leaf nodes belong to the same intermediate node "KK sub-resolution", deleting these three leaf nodes will result in a pruned invalid rule tree. According to the pruned invalid rule tree, the path from the root node along the edges of the pruned invalid rule tree to the new leaf node "KK sub-resolution" constitutes a new invalid resolution chain "AA entry resolution - KK sub-resolution". In addition, the updated invalid resolution chain also retains the original resolution chain 4.
[0165] It should be noted that the above solution is only one implementation method for merging invalid resolution chains. For any security analysis rule, if there are multiple invalid resolution chains with the same invalid elements and invalid classifications in the corresponding invalid resolution chains, before displaying the rule evaluation results, the multiple invalid resolution chains corresponding to the security analysis rule with the same invalid elements and invalid classifications are merged into one invalid resolution chain to obtain the updated invalid resolution chain corresponding to the security analysis rule. This can reduce information redundancy and make the rule evaluation results more concise and clear. Subsequent technicians do not need to deal with repeated invalid resolution chains, which improves information processing efficiency.
[0166] In an embodiment of the present application, by generating an invalid rule tree, multiple invalid resolution chains can be displayed in a clear structure, and the relationship between them can be visualized and structured. This facilitates merging multiple invalid resolution chains with the same invalid elements and invalid classifications into one invalid resolution chain. Moreover, by performing a pruning operation on the invalid rule tree, multiple redundant leaf nodes in the invalid rule tree that belong to the same intermediate node and have the same invalid elements and invalid classifications of the corresponding invalid resolution chains are deleted. This is equivalent to removing duplicate information in multiple invalid resolution chains, summarizing multiple invalid resolution chains with the same problem into a new invalid resolution chain, and using the new invalid resolution chain to represent the problem of this type of invalid resolution chain, providing a clearer direction for the improvement of subsequent rule resolution chains.
[0167] Based on the above embodiment, the fifth embodiment of the present application is proposed. For the same or similar contents as the above embodiment, please refer to the above introduction and will not be repeated hereafter. Figure 7 , in the fifth embodiment, steps S501 to S504 are included.
[0168] Step S501 : in response to a rule comparison instruction, obtaining the analysis rule set and parsing rule set before updating and the analysis rule set and parsing rule set after updating.
[0169] A rule comparison command is a triggering action that initiates a comparison of the rule set before and after an update. It can be a manual command issued by the user to examine changes before and after a rule update to assess the effectiveness and impact of the update. For example, in a data security monitoring system, after updating security analysis and parsing rules, such a command might be issued to verify whether the update met expectations.
[0170] The analysis rule set and parsing rule set before the update are the original analysis rule set and parsing rule set that have not been updated. The updated analysis rule set and parsing rule set are modified or updated versions of the original analysis rule set and parsing rule set, and may include newly added rules, deleted rules, or modified rules. For example, to address new security threats, the analysis rule set may add new security analysis rules. To adapt to new data formats, some parsing rule chains in the parsing rule set may be modified.
[0171] Step S502 : determining a rule evaluation result before updating based on the analysis rule set and the parsing rule set before updating, and determining a rule evaluation result after updating based on the analysis rule set and the parsing rule set after updating.
[0172] The pre-update rule evaluation results are based on the pre-update analysis rule set and parsing rule set. These results include the validity information for each security analysis rule, as well as the valid and invalid parsing chains corresponding to each security analysis rule, or the invalid elements and invalid categories of the invalid parsing chains corresponding to each security analysis rule. They reflect the pre-update rule execution status in the system.
[0173] The updated rule evaluation results are similar to those before the update, but they are based on the updated analysis and parsing rule sets. This helps determine whether the updated rules have achieved the desired effect and improved system security and performance.
[0174] Step S503: Generate rule comparison results based on the rule evaluation results before and after the update. The rule comparison results include status information and validity information of each security analysis rule in the analysis rule set before and after the update. The status information indicates whether each security analysis rule exists in the analysis rule set before and after the update.
[0175] The status information indicates whether each security analysis rule exists in the analysis rule set before and after the update, while the validity information indicates whether the security analysis rule is valid before and after the update. For example, the status information can be a specific identifier, such as "1" for existence and "0" for non-existence.
[0176] Step S504: display the rule comparison result.
[0177] In the embodiments of the present application, by comparing the rule evaluation results before and after the update and displaying the resulting rule comparison results, one can intuitively see the actual effectiveness of each security analysis rule before and after the update. For example, this can indicate whether a newly added security analysis rule is effective, whether a previously effective security analysis rule is invalid after the update, and which security analysis capabilities are lost or added after the rule update. This provides feedback for subsequent rule improvements.
[0178] Based on the above fifth embodiment, the sixth embodiment of the present application is proposed. For the same or similar contents as the sixth embodiment, please refer to the above introduction and will not be repeated hereafter. Figure 8 In the sixth embodiment, between step S502 and step S503, steps S601 to S604 are also executed. In addition, step S503 is further refined into step S5031.
[0179] In step S601 , the detection capability change information of the security analysis rules that do not exist or are invalid in the analysis rule set before the update but exist and are valid in the analysis rule set after the update is determined as capability improvement.
[0180] Detection capability change information describes the changes in security analysis rule capabilities before and after an update, reflecting the performance changes of the rules under different states. Based on the different states before and after the update, it is categorized as capability improvement, capability degradation, effective capability unchanged, and ineffective capability unchanged, facilitating the evaluation and analysis of security analysis rule performance changes.
[0181] Capability improvement refers to the change in detection capability when a security analysis rule that was nonexistent or invalid in the analysis rule set before the update becomes available and valid in the analysis rule set after the update. This indicates that the update has added or improved certain security analysis rules, making them valid or invalid, thereby improving the system's security detection capabilities. For example, before the update, the system might not be able to detect a new type of network attack, but after the update, the corresponding security analysis rule has been added and is now effective. In this case, the detection capability change information for this rule is considered capability improvement.
[0182] In step S602 , the detection capability change information of the security analysis rules that exist and are valid in the analysis rule set before the update and do not exist or are invalid in the analysis rule set after the update is determined as capability degradation.
[0183] A capability degradation occurs when a security analysis rule that existed and was effective in the analysis rule set before the update no longer exists or is invalid in the updated analysis rule set. This means that the update has caused the system to lose its original security detection capabilities, potentially adversely impacting system security. For example, a security analysis rule that was effective in detecting abnormal user login behavior before the update becomes ineffective after the update. The detection capability change information for this rule is a capability degradation.
[0184] In step S603 , the detection capability change information of the security analysis rules that are valid and exist in the analysis rule set before the update and that are valid and exist in the analysis rule set after the update is determined as the valid capability remains unchanged.
[0185] "Effective Capability Unchanged" applies to security analysis rules that were valid in the analysis rule set before the update and are also valid in the analysis rule set after the update. This indicates that the rule functions normally before and after the update, and the system's security detection capabilities for that rule have not substantially changed, remaining in a stable state. For example, a network traffic anomaly detection rule that has always existed and functioned in the system will function effectively before and after the update, and its detection capability change information is "Effective Capability Unchanged."
[0186] Step S604 determines the detection capability change information of the security analysis rules that exist and are invalid in the analysis rule set before the update and exist and are invalid in the analysis rule set after the update, as well as the security analysis rules that do not exist in the analysis rule set before the update and exist and are invalid in the analysis rule set after the update, and the security analysis rules that exist and are invalid in the analysis rule set before the update and do not exist in the analysis rule set after the update as invalid capabilities unchanged.
[0187] Invalid capabilities remain unchanged in a variety of situations: 1. A security analysis rule that existed and was invalid in the analysis rule set before the update still exists and is invalid in the analysis rule set after the update; 2. A security analysis rule that did not exist before the update but appears after the update but is invalid; 3. A security analysis rule that was invalid before the update but was deleted after the update. These situations indicate that the invalid status of the security analysis rule has not changed substantially before and after the update, and the system's security detection capabilities have not been improved or damaged due to the rule.
[0188] There is no order requirement for steps S601 to S604.
[0189] Step S5031: Generate rule comparison results based on the rule evaluation results before and after the update. The rule comparison results include status information, validity information, and detection capability change information of each security analysis rule in the analysis rule set before and after the update. The status information indicates whether each security analysis rule exists in the analysis rule set before and after the update.
[0190] Exemplarily, the rule comparison result is displayed in the form of Table 2 below, where "yes" indicates that the rule exists, and "no" indicates that the rule does not exist.
[0191]
[0192] Table 2
[0193] Exemplarily, the rule comparison results are displayed in the form of Microsoft Excel (spreadsheet) to facilitate various statistical operations. For example, for security analysis rules that were valid before the update, statistics are collected to show how many of them were deleted, how many became invalid, and how many remained valid after the update. For another example, for security analysis rules that were valid after the update, statistics are collected to show how many of them were newly added after the update, how many were invalid before the update, and how many were valid before the update. For another example, statistics are collected to show the number of security analysis rules with improved capabilities, the number of security analysis rules with reduced capabilities, the number of security analysis rules with unchanged invalid capabilities, and the number of security analysis rules with unchanged valid capabilities.
[0194] In the embodiments of the present application, by clarifying different detection capability change information, the impact of update operations on security analysis rules can be accurately assessed. Technicians can clearly understand which rules have been improved, which have been degraded, and which have remained unchanged, helping to assess whether the update operation has achieved its intended goals. Furthermore, this detection capability change information can provide guidance for subsequent system improvements. For rules with degraded capabilities, the cause of their failure can be identified and repaired; for invalid rules with unchanged capabilities, consideration can be given to converting them into valid rules; and for rules with improved capabilities, experience can be summarized to optimize the performance of the security detection system.
[0195] One thing that needs to be explained is that during the upgrade or operation of local security brain products such as SIEM products, there will be update operations such as adding, deleting or modifying security analysis rules, which may cause changes in security analysis capabilities before and after the update. For example, during the operation process, some security analysis rules have not generated alarms for a long time, and technical personnel suspect that some security analysis rules are ineffective. Or, technical personnel add custom security analysis rules and want to know whether the rules are written reasonably and whether they can generate alarms. Or, after the product version is upgraded, for the custom security analysis rules, it is necessary to understand whether they are invalid. Or, after the product version is upgraded, it is necessary to understand which security analysis capabilities have been lost or added. In this case, the solution provided in this application can be used to evaluate security analysis rules.
[0196] refer to Figure 9 The rule evaluation solution provided in this application primarily involves two data processing units: an evaluation unit and an analysis unit. The evaluation unit provides data to the analysis unit. The evaluation unit is configured to generate rule evaluation results based on the analysis rule set and the parsing rule set. The analysis unit is configured to generate rule comparison results based on the pre-update rule evaluation results and the post-update rule evaluation results.
[0197] The rule evaluation scheme in this application can be completed by the target application on the terminal. The target application is a rule analysis tool that is used to analyze and evaluate security analysis rules. Figure 10 , Figure 10This is a schematic diagram of the rule analysis tool interface. The "Configure" control under "Rule Evaluation Before Update" is used to configure the analysis and parsing rule sets before the update. The "Run" control controls the generation of pre-update rule evaluation results. The "Configure" control under "Rule Evaluation After Update" is used to configure the analysis and parsing rule sets after the update. The "Run" control controls the generation of post-update rule evaluation results. The "Run" control under "Rule Comparison Analysis Before and After Update" controls the generation of rule comparison results based on the pre-update and post-update rule evaluation results. Furthermore, the "Run" control under "Single Data Access Comparison Analysis Before and After Update" controls the generation of rule comparison results based on the pre-update and post-update rule evaluation results. This allows technicians to understand the security performance of these security analysis rules for different data sources. The "Run Log Before Update" control on the left side of the interface controls the display of pre-update rule evaluation results. The "Run Log After Update" control controls the display of post-update rule evaluation results. The "Rule Comparison Analysis Log Before and After Update" control controls the display of rule comparison results. The "Single Data Access Before and After Update Comparison Analysis Log" control displays the rule comparison results for each data source. The result display area on the interface displays the rule evaluation and comparison results.
[0198] Another point that needs to be explained is that the above examples are only used to understand this application and do not constitute a limitation on the data processing method of this application. More simple transformations based on this technical concept are all within the scope of protection of this application.
[0199] This application also provides a data processing device, please refer to Figure 11 , the data processing device includes:
[0200] An instruction response module 10 is configured to obtain an analysis rule set and a parsing rule set in response to a rule evaluation instruction, wherein the analysis rule set includes a plurality of security analysis rules for data security detection, and the parsing rule set includes a plurality of parsing rule chains for parsing data to be detected;
[0201] A rule evaluation module 20 is configured to determine, for any security analysis rule, if a valid resolution chain corresponding to the security analysis rule exists in the resolution rule set, that the security analysis rule is a valid rule; otherwise, the security analysis rule is determined to be an invalid rule. A valid resolution chain is a resolution rule chain that can provide data support for data security testing of the security analysis rule.
[0202] The result display module 30 is used to display the rule evaluation result. The rule evaluation result includes validity information of each security analysis rule in the analysis rule set. The validity information is used to indicate whether the corresponding security analysis rule is valid.
[0203] Optionally, the device further comprises:
[0204] The parsing chain determination module is used to determine the information elements that each security analysis rule relies on for data security testing, as well as the information elements that each parsing rule chain parses from the data to be tested; for any security analysis rule, the parsing rule chain whose parsed information elements cover the information elements that the security analysis rule relies on is searched from the parsing rule set; the parsing rule chain found is determined as the valid parsing chain corresponding to the security analysis rule.
[0205] Optionally, the rule evaluation result also includes a valid resolution chain and an invalid resolution chain corresponding to each security analysis rule;
[0206] The parsing chain determination module is further configured to determine, for any security analysis rule, parsing rule chains in the parsing rule set other than the valid parsing chain corresponding to the security analysis rule; and determine the parsing rule chains in the parsing rule set other than the valid parsing chain as invalid parsing chains corresponding to the security analysis rule.
[0207] Optionally, the rule evaluation result further includes invalid elements and invalid classifications of invalid resolution chains corresponding to each security analysis rule; the apparatus further includes:
[0208] An information element determination module is used to determine, for any invalid parsing chain of any security analysis rule, information elements that are not parsed by the invalid parsing chain among the information elements that the security analysis rule depends on;
[0209] An invalid element determination module, configured to determine an information element that is not resolved by an invalid resolution chain as an invalid element of the invalid resolution chain;
[0210] The invalid classification determination module is used to determine the invalid classification to which the invalid resolution chain belongs according to the information type to which the invalid element belongs.
[0211] Optionally, the information element not resolved by the invalid resolution chain includes at least one information element selected from the group consisting of an event name, a field name, and an enumeration field value;
[0212] An invalid element determination module is used to determine the event name as an invalid element when the information element not resolved by the invalid resolution chain includes an event name; or to determine the field name as an invalid element when the information element not resolved by the invalid resolution chain does not include the event name but includes a field name; or to determine the enumeration field value as an invalid element when the information element not resolved by the invalid resolution chain does not include both the event name and the field name but includes an enumeration field value.
[0213] Optionally, for any security analysis rule, multiple invalid resolution chains corresponding to the security analysis rule include multiple invalid resolution chains having the same invalid elements and invalid classifications; the apparatus further includes:
[0214] The parsing chain merging module is used to merge multiple invalid parsing chains corresponding to the security analysis rules, which have the same invalid elements and invalid classifications, into one invalid parsing chain to obtain an updated invalid parsing chain corresponding to the security analysis rule.
[0215] Optionally, for any security analysis rule, the multiple invalid resolution chains corresponding to the security analysis rule include multiple sub-resolution steps;
[0216] The parsing chain merge module includes:
[0217] A rule tree generation unit is configured to generate an invalid rule tree based on multiple invalid resolution chains corresponding to the security analysis rule, wherein the root node of the invalid rule tree represents the initial sub-resolution step common to the multiple invalid resolution chains, and the leaf nodes represent the terminal sub-resolution steps of each invalid resolution chain. The paths from the root node along the edges of the invalid rule tree to each leaf node constitute each invalid resolution chain;
[0218] The parsing chain merging unit is used to merge multiple invalid parsing chains corresponding to the security analysis rule, which have the same invalid elements and invalid classifications, into one invalid parsing chain based on the invalid rule tree, to obtain an updated invalid parsing chain corresponding to the security analysis rule.
[0219] Optionally, the resolution chain merging unit is used to perform a pruning operation on the invalid rule tree at least once until the number of nodes of the invalid rule tree does not change, and the pruning operation includes: when multiple leaf nodes belong to the same intermediate node and the invalid elements and invalid classifications of the invalid resolution chains corresponding to the multiple leaf nodes are the same, deleting the multiple leaf nodes so that the intermediate nodes to which the multiple leaf nodes belong become new leaf nodes; and determining each invalid resolution chain formed by the path from the root node along the edge of the pruned invalid rule tree to each leaf node as the updated invalid resolution chain corresponding to the security analysis rule.
[0220] Optionally, the device further comprises:
[0221] A rule comparison module is used to respond to a rule comparison instruction to obtain the analysis rule set and parsing rule set before the update and the analysis rule set and parsing rule set after the update; determine the rule evaluation result before the update based on the analysis rule set and parsing rule set before the update, and determine the rule evaluation result after the update based on the analysis rule set and parsing rule set after the update; generate a rule comparison result based on the rule evaluation result before the update and the rule evaluation result after the update, the rule comparison result including status information and validity information of each security analysis rule in the analysis rule set before the update and after the update, the status information indicating whether each security analysis rule exists in the analysis rule set before the update and after the update; and display the rule comparison result.
[0222] Optionally, the rule comparison result also includes information on changes in the detection capabilities of each security analysis rule;
[0223] The rule comparison module is further configured to perform at least one of the following:
[0224] Determine the detection capability change information of the security analysis rules that do not exist or are invalid in the analysis rule set before the update but exist and are valid in the analysis rule set after the update as capability improvement;
[0225] Determining detection capability change information of security analysis rules that exist and are valid in the analysis rule set before the update, but do not exist or are invalid in the analysis rule set after the update as capability degradation;
[0226] Determine the detection capability change information of the security analysis rules that are valid and exist in the analysis rule set before the update and are valid and exist in the analysis rule set after the update as the valid capability remains unchanged;
[0227] The detection capability change information of the security analysis rules that exist and are invalid in the analysis rule set before the update and exist and are invalid in the analysis rule set after the update, as well as the security analysis rules that do not exist in the analysis rule set before the update and exist and are invalid in the analysis rule set after the update, and the security analysis rules that exist and are invalid in the analysis rule set before the update and do not exist in the analysis rule set after the update are determined as invalid capabilities unchanged.
[0228] Optionally, the device further comprises:
[0229] The rule update module is used to delete invalid rules in the analysis rule set; or, based on the invalid elements and invalid categories of the invalid resolution chain corresponding to the invalid rule, modify the invalid resolution chain so that the information elements resolved by the invalid resolution chain cover the information elements on which the invalid rule depends.
[0230] The data processing device provided in this application, utilizing the data processing method described in the aforementioned embodiments, can resolve the technical problem in related technologies of a large number of security analysis rules and the difficulty in determining their effectiveness. Compared to the prior art, the beneficial effects of the data processing device provided in this application are the same as those of the data processing method described in the aforementioned embodiments. Other technical features of the data processing device are the same as those disclosed in the aforementioned embodiments and are not further elaborated here.
[0231] The present application provides a data processing device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the data processing method in the above-mentioned embodiment 1.
[0232] Reference below Figure 12 , which shows a schematic diagram of the structure of a data processing device suitable for implementing the embodiments of the present application. The data processing device in the embodiments of the present application may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions), PMPs (Portable Media Players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 12 The data processing device shown is only an example and should not limit the functions and scope of use of the embodiments of the present application.
[0233] like Figure 12 As shown, the data processing device may include a processing device 1001 (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1002 or a program loaded from a storage device 1003 into a random access memory (RAM) 1004. RAM 1004 also stores various programs and data required for the operation of the data processing device. Processing device 1001, ROM 1002, and RAM 1004 are connected to each other via a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Typically, the following systems can be connected to I / O interface 1006: input device 1007 including, for example, a touch screen, touchpad, keyboard, mouse, image sensor, microphone, accelerometer, gyroscope, etc.; output device 1008 including, for example, a liquid crystal display (LCD), speaker, vibrator, etc.; storage device 1003 including, for example, a magnetic tape, hard disk, etc.; and communication device 1009. Communication device 1009 can allow the data processing device to communicate with other devices wirelessly or by wire to exchange data. Although the figure shows a data processing device with various systems, it should be understood that it is not required to implement or have all the systems shown. More or fewer systems can be implemented or provided instead.
[0234] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program comprising program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via a communication device, or installed from a storage device 1003, or installed from a ROM 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the method of the embodiment disclosed in the present application are executed.
[0235] The data processing device provided in this application, utilizing the data processing method of the aforementioned embodiment, can resolve the technical problem in related art of a large number of security analysis rules whose effectiveness is difficult to determine. Compared to the prior art, the beneficial effects of the data processing device provided in this application are the same as those of the data processing method provided in the aforementioned embodiment. Other technical features of this data processing device are the same as those disclosed in the aforementioned embodiment and are not further elaborated here.
[0236] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any one or more embodiments or examples in a suitable manner.
[0237] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
[0238] The present application provides a computer-readable storage medium having computer-readable program instructions (ie, computer program) stored thereon, wherein the computer-readable program instructions are used to execute the data processing method in the above-mentioned embodiment.
[0239] The computer-readable storage medium provided in this application may be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, systems or devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, system or device. The program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.
[0240] The computer-readable storage medium may be included in a data processing device, or may exist independently without being incorporated into a data processing device.
[0241] The above-mentioned computer-readable storage medium carries one or more programs. When the above-mentioned one or more programs are executed by a data processing device, the data processing device: responds to a rule evaluation instruction, obtains an analysis rule set and a parsing rule set, the analysis rule set includes multiple security analysis rules for data security detection, and the parsing rule set includes multiple parsing rule chains for parsing the data to be detected; for any security analysis rule, if there is a valid parsing chain corresponding to the security analysis rule in the parsing rule set, the security analysis rule is determined to be a valid rule, otherwise the security analysis rule is determined to be an invalid rule, and the valid parsing chain is a parsing rule chain that can provide data support for the security analysis rule to perform data security detection; displays the rule evaluation result, and the rule evaluation result includes the validity information of each security analysis rule in the analysis rule set, and the validity information is used to indicate whether the corresponding security analysis rule is valid.
[0242] Computer program code for performing the operations of the present application may be written in one or more programming languages, or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0243] The flow charts and block diagrams in the accompanying drawings illustrate the possible architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present application. In this regard, each box in the flow chart or block diagram can represent a module, program segment or a part of code, and the module, program segment or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flow chart, and the combination of the boxes in the block diagram and / or flow chart can be implemented by a dedicated hardware-based system that performs the specified function or operation, or can be implemented by a combination of dedicated hardware and computer instructions.
[0244] The modules described in the embodiments of the present application may be implemented in software or hardware, wherein the name of a module does not necessarily limit the unit itself.
[0245] The computer-readable storage medium provided in this application is a computer-readable storage medium storing computer-readable program instructions (i.e., a computer program) for executing the aforementioned data processing method. This computer-readable storage medium can address the technical problem in related art of the large number of security analysis rules whose effectiveness is difficult to determine. Compared to the prior art, the beneficial effects of the computer-readable storage medium provided in this application are the same as those of the data processing method provided in the aforementioned embodiments, and are not further elaborated here.
[0246] The present application also provides a computer program product, comprising a computer program, which implements the steps of the above-mentioned data processing method when executed by a processor.
[0247] The computer program product provided in this application can address the technical problem in related technologies of a large number of security analysis rules and the difficulty in determining their effectiveness. Compared with the prior art, the beneficial effects of the computer program product provided in this application are the same as those of the data processing method provided in the above-mentioned embodiments, and will not be elaborated here.
[0248] The above description is only part of the embodiments of the present application and does not limit the patent scope of the present application. All equivalent structural transformations made by using the contents of the present application specification and drawings under the technical concept of the present application, or direct / indirect application in other related technical fields are included in the patent protection scope of the present application.
[0249] The present application provides A1. a data processing method, the method comprising:
[0250] In response to the rule evaluation instruction, obtaining an analysis rule set and a parsing rule set, wherein the analysis rule set includes a plurality of security analysis rules for data security detection, and the parsing rule set includes a plurality of parsing rule chains for parsing data to be detected;
[0251] For any security analysis rule, if there is a valid resolution chain corresponding to the security analysis rule in the resolution rule set, the security analysis rule is determined to be a valid rule; otherwise, the security analysis rule is determined to be an invalid rule. The valid resolution chain is a resolution rule chain that can provide data support for data security detection of the security analysis rule.
[0252] The rule evaluation result is displayed, where the rule evaluation result includes validity information of each security analysis rule in the analysis rule set, where the validity information is used to indicate whether the corresponding security analysis rule is valid.
[0253] A2. The method of claim A1, further comprising:
[0254] Determine the information elements that each security analysis rule relies on for data security detection, and the information elements that each parsing rule chain parses from the data to be detected;
[0255] For any security analysis rule, query the parsing rule set for a parsing rule chain whose parsed information element covers the information element on which the security analysis rule depends;
[0256] The queried parsing rule chain is determined as a valid parsing chain corresponding to the security analysis rule.
[0257] A3. The method of claim A2, wherein the rule evaluation result further includes a valid resolution chain and an invalid resolution chain corresponding to each security analysis rule; the method further comprising:
[0258] For any security analysis rule, determining parsing rule chains in the parsing rule set other than the valid parsing chain corresponding to the security analysis rule;
[0259] The parsing rule chains other than the valid parsing chain in the parsing rule set are determined as invalid parsing chains corresponding to the security analysis rule.
[0260] A4. The method of claim A3, wherein the rule evaluation result further includes invalid elements and invalid classifications of invalid resolution chains corresponding to each security analysis rule; the method further comprising:
[0261] For any invalid parsing chain of any security analysis rule, determining, among the information elements that the security analysis rule depends on, information elements that are not parsed by the invalid parsing chain;
[0262] Determining the information element that is not resolved by the invalid resolution chain as an invalid element of the invalid resolution chain;
[0263] According to the information type to which the invalid element belongs, the invalid category to which the invalid resolution chain belongs is determined.
[0264] A5. The method according to claim A4, wherein the information element not resolved by the invalid resolution chain includes at least one information element selected from the group consisting of an event name, a field name, and an enumerated field value;
[0265] The step of determining the information element that is not resolved by the invalid resolution chain as an invalid element of the invalid resolution chain includes:
[0266] In a case where the information element not resolved by the invalid resolution chain includes an event name, determining the event name as the invalid element;
[0267] Alternatively, when the information element not resolved by the invalid resolution chain does not include an event name but includes a field name, the field name is determined as the invalid element;
[0268] Alternatively, when the information element not resolved by the invalid resolution chain does not include an event name and a field name but includes an enumeration field value, the enumeration field value is determined to be the invalid element.
[0269] A6. The method according to claim A4, wherein, for any security analysis rule, multiple invalid resolution chains corresponding to the security analysis rule contain multiple invalid resolution chains with the same invalid elements and invalid classifications;
[0270] Before displaying the rule evaluation result, the method further includes:
[0271] In the multiple invalid resolution chains corresponding to the security analysis rule, multiple invalid resolution chains with the same invalid elements and invalid classifications are merged into one invalid resolution chain to obtain an updated invalid resolution chain corresponding to the security analysis rule.
[0272] A7. The method of claim A6, wherein for any security analysis rule, the multiple invalid resolution chains corresponding to the security analysis rule each include multiple sub-resolution steps;
[0273] The step of merging multiple invalid resolution chains corresponding to the security analysis rule, which have the same invalid elements and invalid classifications, into one invalid resolution chain to obtain an updated invalid resolution chain corresponding to the security analysis rule, includes:
[0274] Generate an invalid rule tree based on multiple invalid resolution chains corresponding to the security analysis rule, wherein the root node of the invalid rule tree represents the initial sub-resolution step common to the multiple invalid resolution chains, the leaf nodes represent the terminal sub-resolution steps of each invalid resolution chain, and the paths from the root node along the edges of the invalid rule tree to each leaf node constitute each invalid resolution chain;
[0275] Based on the invalidation rule tree, multiple invalidation resolution chains corresponding to the security analysis rule, which have the same invalid elements and invalid classifications, are merged into one invalidation resolution chain to obtain an updated invalidation resolution chain corresponding to the security analysis rule.
[0276] A8. The method of claim A7, wherein, based on the invalidation rule tree, multiple invalidation chains corresponding to the security analysis rule, wherein the invalidation chains have the same invalid elements and invalidation categories, are merged into one invalidation chain to obtain an updated invalidation chain corresponding to the security analysis rule, comprising:
[0277] Performing a pruning operation on the invalid rule tree at least once until the number of nodes in the invalid rule tree remains unchanged, the pruning operation comprising: if multiple leaf nodes belong to the same intermediate node and the invalid elements and invalid categories of the invalid resolution chains corresponding to the multiple leaf nodes are the same, deleting the multiple leaf nodes so that the intermediate nodes to which the multiple leaf nodes belong become new leaf nodes;
[0278] Each invalid resolution chain formed by a path from the root node along the edge of the pruned invalid rule tree to each leaf node is determined as an updated invalid resolution chain corresponding to the security analysis rule.
[0279] A9. The method of claim A4, further comprising:
[0280] In response to the rule comparison instruction, obtaining the analysis rule set and the parsing rule set before the update and the analysis rule set and the parsing rule set after the update;
[0281] Determine a rule evaluation result before the update based on the analysis rule set and the parsing rule set before the update, and determine a rule evaluation result after the update based on the analysis rule set and the parsing rule set after the update;
[0282] Generate a rule comparison result based on the rule evaluation result before and after the update, the rule comparison result including status information and validity information of each security analysis rule in the analysis rule set before and after the update, the status information indicating whether each security analysis rule exists in the analysis rule set before and after the update;
[0283] Display the rule comparison results.
[0284] A10. The method of claim A9, wherein the rule comparison result further includes information on changes in detection capabilities of each security analysis rule; the method further includes at least one of the following:
[0285] Determine the detection capability change information of the security analysis rules that do not exist or are invalid in the analysis rule set before the update but exist and are valid in the analysis rule set after the update as capability improvement;
[0286] Determining detection capability change information of security analysis rules that exist and are valid in the analysis rule set before the update, but do not exist or are invalid in the analysis rule set after the update as capability degradation;
[0287] Determine the detection capability change information of the security analysis rules that are valid and exist in the analysis rule set before the update and are valid and exist in the analysis rule set after the update as the valid capability remains unchanged;
[0288] The detection capability change information of the security analysis rules that exist and are invalid in the analysis rule set before the update and exist and are invalid in the analysis rule set after the update, as well as the security analysis rules that do not exist in the analysis rule set before the update and exist and are invalid in the analysis rule set after the update, and the security analysis rules that exist and are invalid in the analysis rule set before the update and do not exist in the analysis rule set after the update are determined as invalid capabilities unchanged.
[0289] A11. The method of claim A4, further comprising:
[0290] Deleting invalid rules from the analysis rule set;
[0291] Alternatively, according to the invalid elements and invalid categories of the invalid resolution chain corresponding to the invalid rule, the invalid resolution chain is modified so that the information elements resolved by the invalid resolution chain cover the information elements on which the invalid rule depends.
[0292] The present application also provides B12. a data processing device, comprising:
[0293] an instruction response module, configured to obtain, in response to a rule evaluation instruction, an analysis rule set and a parsing rule set, wherein the analysis rule set includes a plurality of security analysis rules for data security detection, and the parsing rule set includes a plurality of parsing rule chains for parsing data to be detected;
[0294] a rule evaluation module configured to, for any security analysis rule, determine that if there is a valid resolution chain corresponding to the security analysis rule in the resolution rule set, the security analysis rule is a valid rule; otherwise, the security analysis rule is determined to be an invalid rule, wherein the valid resolution chain is a resolution rule chain that can provide data support for performing data security detection on the security analysis rule;
[0295] The result display module is used to display the rule evaluation result, wherein the rule evaluation result includes validity information of each security analysis rule in the analysis rule set, and the validity information is used to indicate whether the corresponding security analysis rule is valid.
[0296] B13. The apparatus of claim B12, further comprising:
[0297] The parsing chain determination module is used to determine the information elements that each security analysis rule relies on for data security testing, as well as the information elements parsed from the data to be tested by each parsing rule chain; for any security analysis rule, query the parsing rule chain whose parsed information elements cover the information elements that the security analysis rule relies on from the parsing rule set; and determine the queried parsing rule chain as the valid parsing chain corresponding to the security analysis rule.
[0298] B14. The apparatus according to claim B13, wherein the rule evaluation result further includes a valid resolution chain and an invalid resolution chain corresponding to each security analysis rule;
[0299] The resolution chain determination module is further configured to determine, for any security analysis rule, resolution rule chains in the resolution rule set other than the valid resolution chain corresponding to the security analysis rule; and determine the resolution rule chains in the resolution rule set other than the valid resolution chain as invalid resolution chains corresponding to the security analysis rule.
[0300] B15. The apparatus of claim B14, wherein the rule evaluation result further includes invalid elements and invalid classifications of invalid resolution chains corresponding to each security analysis rule; the apparatus further comprising:
[0301] An information element determination module, configured to determine, for any invalid parsing chain of any security analysis rule, information elements that are not parsed by the invalid parsing chain among the information elements that the security analysis rule depends on;
[0302] an invalid element determination module, configured to determine an information element that is not resolved by the invalid resolution chain as an invalid element of the invalid resolution chain;
[0303] The invalid classification determination module is used to determine the invalid classification to which the invalid resolution chain belongs according to the information type to which the invalid element belongs.
[0304] B16. The apparatus according to claim B15, wherein the information element not resolved by the invalid resolution chain comprises at least one information element selected from the group consisting of an event name, a field name, and an enumerated field value;
[0305] The invalid element determination module is used to determine, when the information element unresolved by the invalid resolution chain includes an event name, the event name as the invalid element; or, when the information element unresolved by the invalid resolution chain does not include an event name but includes a field name, determine the field name as the invalid element; or, when the information element unresolved by the invalid resolution chain does not include an event name and a field name but includes an enumeration field value, determine the enumeration field value as the invalid element.
[0306] B17. The apparatus of claim B15, wherein, for any security analysis rule, multiple invalid resolution chains corresponding to the security analysis rule include multiple invalid resolution chains having the same invalid elements and invalid classifications; the apparatus further comprising:
[0307] The parsing chain merging module is used to merge multiple invalid parsing chains corresponding to the security analysis rule, which have the same invalid elements and invalid categories, into one invalid parsing chain to obtain an updated invalid parsing chain corresponding to the security analysis rule.
[0308] The present application also provides C18. A data processing device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the data processing method described above.
[0309] The present application also provides D19. A storage medium, which is a computer-readable storage medium and stores a computer program. When the computer program is executed by a processor, the steps of the data processing method described above are implemented.
[0310] The present application also provides E20. A computer program product, comprising a computer program, which implements the steps of the data processing method described above when executed by a processor.
Claims
1. A data processing method, characterized in that: The method comprises: In response to the rule evaluation instruction, obtaining an analysis rule set and a parsing rule set, wherein the analysis rule set includes a plurality of security analysis rules for data security detection, and the parsing rule set includes a plurality of parsing rule chains for parsing data to be detected; For any security analysis rule, if there is a valid resolution chain corresponding to the security analysis rule in the resolution rule set, the security analysis rule is determined to be a valid rule; otherwise, the security analysis rule is determined to be an invalid rule. The valid resolution chain is a resolution rule chain that can provide data support for data security detection of the security analysis rule. The rule evaluation result is displayed, where the rule evaluation result includes validity information of each security analysis rule in the analysis rule set, where the validity information is used to indicate whether the corresponding security analysis rule is valid.
2. The method according to claim 1, wherein The method further comprises: Determine the information elements that each security analysis rule relies on for data security detection, and the information elements that each parsing rule chain parses from the data to be detected; For any security analysis rule, query the parsing rule set for a parsing rule chain whose parsed information element covers the information element on which the security analysis rule depends; The queried parsing rule chain is determined as a valid parsing chain corresponding to the security analysis rule.
3. The method according to claim 2, wherein The rule evaluation result also includes a valid resolution chain and an invalid resolution chain corresponding to each security analysis rule; the method further includes: For any security analysis rule, determining parsing rule chains in the parsing rule set other than the valid parsing chain corresponding to the security analysis rule; The parsing rule chains other than the valid parsing chain in the parsing rule set are determined as invalid parsing chains corresponding to the security analysis rule.
4. The method according to claim 3, wherein The rule evaluation result also includes invalid elements and invalid classifications of invalid resolution chains corresponding to each security analysis rule; the method further includes: For any invalid parsing chain of any security analysis rule, determining, among the information elements that the security analysis rule depends on, information elements that are not parsed by the invalid parsing chain; Determining the information element that is not resolved by the invalid resolution chain as an invalid element of the invalid resolution chain; According to the information type to which the invalid element belongs, the invalid category to which the invalid resolution chain belongs is determined.
5. The method according to claim 4, wherein The information element not resolved by the invalid resolution chain includes at least one information element selected from the group consisting of an event name, a field name, and an enumeration field value; The step of determining the information element that is not resolved by the invalid resolution chain as an invalid element of the invalid resolution chain includes: In a case where the information element not resolved by the invalid resolution chain includes an event name, determining the event name as the invalid element; Alternatively, when the information element not resolved by the invalid resolution chain does not include an event name but includes a field name, the field name is determined as the invalid element; Alternatively, when the information element not resolved by the invalid resolution chain does not include an event name and a field name but includes an enumeration field value, the enumeration field value is determined to be the invalid element.
6. The method according to claim 4, wherein For any security analysis rule, there are multiple invalid resolution chains with the same invalid elements and invalid classifications among the multiple invalid resolution chains corresponding to the security analysis rule; Before displaying the rule evaluation result, the method further includes: In the multiple invalid resolution chains corresponding to the security analysis rule, multiple invalid resolution chains with the same invalid elements and invalid classifications are merged into one invalid resolution chain to obtain an updated invalid resolution chain corresponding to the security analysis rule.
7. A data processing device, characterized in that: The device comprises: an instruction response module, configured to obtain, in response to a rule evaluation instruction, an analysis rule set and a parsing rule set, wherein the analysis rule set includes a plurality of security analysis rules for data security detection, and the parsing rule set includes a plurality of parsing rule chains for parsing data to be detected; a rule evaluation module configured to, for any security analysis rule, determine that if there is a valid resolution chain corresponding to the security analysis rule in the resolution rule set, the security analysis rule is a valid rule; otherwise, the security analysis rule is determined to be an invalid rule, wherein the valid resolution chain is a resolution rule chain that can provide data support for performing data security detection on the security analysis rule; The result display module is used to display the rule evaluation result, wherein the rule evaluation result includes validity information of each security analysis rule in the analysis rule set, and the validity information is used to indicate whether the corresponding security analysis rule is valid.
8. A data processing device, characterized in that: The device comprises: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the data processing method according to any one of claims 1 to 6.
9. A storage medium, characterized in that: The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the data processing method according to any one of claims 1 to 6 are implemented.
10. A computer program product, characterized in that The computer program product comprises a computer program, and when the computer program is executed by a processor, the steps of the data processing method according to any one of claims 1 to 6 are implemented.