Multistage isolation strategy abnormity real-time detection method and system
By preprocessing access logs and mining baselines for multi-level isolation strategies, constructing an abstract baseline tree, and evaluating isolation requests in real time, the accuracy and timeliness issues of isolation failure detection in existing technologies are resolved, ensuring the security of the system.
Patent Information
- Application Number
- CN202510584503.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-07
- Publication Date
- 2025-09-16
AI Technical Summary
Existing multi-level isolation strategy detection methods are difficult to accurately and timely detect isolation failure behaviors, leading to potential lateral movement risks and information leakage, and the detection results are easily affected by system complexity and dynamic changes.
By obtaining access logs for preprocessing, mining and compressing candidate baselines, building an abstract baseline tree, evaluating isolation requests in real time, generating judgment results and comparing them with current policy decisions, isolation policy anomalies are identified.
It achieves real-time detection and incremental adjustment of isolation failures, improves the accuracy of detection results, and prevents lateral movement risks and information leakage.
Smart Images

Figure CN120658422A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of log security isolation, and in particular to a multi-level isolation strategy anomaly real-time detection method and system. Background Art
[0002] Multi-level isolation strategies are fundamental security technologies for isolating security domains within complex information systems and mitigating the risk of lateral movement. System administrators can configure isolation policies to define the boundaries of permitted interactions between modules, applications, or security domains. With the rapid development of technologies such as cloud computing, the Internet of Things, and mobile communications, fine-grained isolation policy languages have become increasingly mainstream. These policies typically specify under what circumstances and which system components or security domains are permitted to interact with each other and invoke services, thereby enabling granular isolation control. However, due to the need to balance system availability and business continuity in actual deployments, fine-grained isolation policy configurations are often more permissive than required. This permissive configuration can allow unnecessary or even dangerous interactions between security domains, leading to isolation failure risks. Furthermore, during system runtime, it can be difficult to distinguish between necessary interactions for normal business operations and non-compliant cross-domain operations caused by this permissive configuration, making it difficult to detect and identify potential isolation failures. Furthermore, with the increasing complexity of system functionality and the dynamic nature of interaction requirements, administrators often struggle to accurately describe all isolation requirements, introducing hidden isolation failure risks into the policies. If attackers or malicious programs exploit this isolation failure to move laterally, it could pose a significant security threat to the system. Therefore, it is essential to accurately and in real time detect isolation failures caused by inaccurate policy configuration. Based on the above analysis, while the flexibility of the fine-grained isolation policy language improves the flexible deployment of system functions, it can also lead to looser policy configurations, which can introduce hidden isolation failure risks. Accurately identifying isolation failure risks in configurations and detecting and responding to the resulting non-compliant cross-domain behaviors in real time has become a critical security issue that needs to be addressed. Currently, multi-level isolation policy failure detection primarily employs two approaches: one is to clearly define detection targets based on security isolation requirements and verify whether the policy meets the established isolation requirements in actual deployment; the other is to extract normal interaction patterns from system interactions or access history and use this as a security baseline to dynamically determine policy deviations.
[0003] Detecting the failure of multi-level isolation strategies requires comprehensive and accurate descriptions of isolation requirements. However, since actual isolation requirements are often complex and change with business dynamics, the accuracy and timeliness of detection results will be affected. On the one hand, system administrators may have deviations when describing isolation requirements and their corresponding detection targets, resulting in incomplete final detection results, which may miss some hidden isolation failures. On the other hand, although existing baseline determination methods do not require clear definition of detection targets, their log mining results may themselves have insufficient isolation, making it difficult to detect isolation failure anomalies in a timely manner. In addition, their offline detection mode often causes delays in detection results. Summary of the Invention
[0004] The present invention provides a real-time detection method and system for multi-level isolation strategy anomalies, which are used to ensure that the judgment of isolation failure behavior in the system is both accurate and rapid, and to promptly discover security domain isolation failures caused by inaccurate configuration or improper operation, thereby preventing potential security issues such as lateral movement risks and information leakage.
[0005] The present invention provides a multi-level isolation strategy anomaly real-time detection method, comprising: Obtain access logs for the isolation policy to be tested and preprocess them to obtain a log dataset for security baseline extraction; Derives a security baseline based on the log data set through candidate baseline mining and candidate baseline compression; Based on the security baseline, isolated log streams in the log data set are evaluated in real time to detect isolation failures, and the security baseline is encoded into an abstract baseline tree during the isolation failure detection process; Based on the abstract baseline tree, the latest isolation request in the isolation log stream is evaluated in real time, the latest isolation request is judged, and a judgment result is generated. The judgment result is compared with the current isolation policy decision to determine whether there is an isolation policy anomaly.
[0006] According to a real-time detection method for multi-level isolation policy anomalies provided by the present invention, the access logs of the isolation policy to be detected are obtained and pre-processed to obtain a log data set for security baseline extraction, specifically including: Obtain the access logs of the isolation policy to be tested. For multiple log entries describing the same isolation request, only retain the latest decision result. Discretize the multiple attribute value pairs in the isolation request and ignore the missing attribute values directly to generate a log dataset for security baseline extraction.
[0007] According to a multi-level isolation policy anomaly real-time detection method provided by the present invention, the security baseline is derived based on the log data set through candidate baseline mining and candidate baseline compression, specifically comprising: Based on the log data set, the mining problem is converted into a submodular maximization problem, and by constructing an approximate optimization framework and combining it with the Pareto optimization algorithm, a candidate isolation decision rule set is iteratively mined from the log data set; Each isolation determination rule in the isolation determination rule set is traversed to construct an isolation space and to construct a security baseline through mining using an iterative mining algorithm.
[0008] According to a multi-level isolation strategy anomaly real-time detection method provided by the present invention, the mining problem is converted into a submodular maximization problem based on the log data set, and an approximate optimization framework is constructed and combined with the Pareto optimization algorithm to iteratively mine a candidate isolation decision rule set from the log data set. Specifically, the method includes: Based on the log data set, an approximate optimization framework is constructed by iteratively applying a greedy strategy to the rule set; Based on the approximate optimization framework, the Pareto optimization algorithm is used to iteratively calculate the Pareto optimal solution related to the marginal benefit function from the log data set to obtain a set of candidate isolation decision rules.
[0009] According to a multi-level isolation strategy anomaly real-time detection method provided by the present invention, traversing each isolation determination rule in the isolation determination rule set, constructing an isolation space, and mining and constructing a security baseline through an iterative mining algorithm specifically include: Traversing each isolation determination rule in the isolation determination rule set, for each rule, in combination with the covered system modules or security domain sets, constructing a corresponding isolation space based on existing isolation access log records; Based on the isolation space, an iterative mining algorithm is used to mine all candidate isolation decision rules, combine each sub-rule and merge them to build a security baseline.
[0010] According to a multi-level isolation strategy anomaly real-time detection method provided by the present invention, in the process of encoding the security baseline into an abstract baseline tree during the isolation failure detection process, the abstract baseline tree can be adjusted to generate a positive abstract baseline tree and a negative abstract baseline tree; Among them, the positive abstract baseline tree specifies the isolation requirements that must be achieved in any case, while the negative abstract baseline tree specifies the isolation behavior that must be rejected.
[0011] According to the present invention, a multi-level isolation policy anomaly real-time detection method is provided. The method evaluates the latest isolation request in the isolation log stream in real time based on the abstract baseline tree, judges the latest isolation request, generates a judgment result, and compares the judgment result with the current isolation policy decision to determine whether there is an isolation policy anomaly. Specifically, the method includes: Obtain the current real-time isolated access log stream and extract the access request to be detected from the latest log entry; Using the abstract baseline tree, the positive abstract baseline tree, and the negative abstract baseline tree as security baselines, the access request is judged and a judgment result is generated; Compare the judgment result of the baseline tree with the current isolation policy decision of the system. If the isolation policy decision is to allow cross-domain interaction and the judgment result of the baseline tree is to deny it, the current log item will be marked as suspected isolation failure and submitted to the system administrator for further confirmation.
[0012] The present invention also provides a multi-level isolation strategy anomaly real-time detection system, the system comprising: The isolation access log preprocessing module is used to obtain the access logs of the isolation policy to be detected and preprocess them to obtain the log data set for security baseline extraction; A security baseline derivation module, configured to derive a security baseline based on the log data set through candidate baseline mining and candidate baseline compression; A baseline tree encoding module is used to perform real-time evaluation on isolated log streams in the log data set based on the security baseline to detect isolation failures, and to encode the security baseline into an abstract baseline tree during the isolation failure detection process; The isolation failure judgment module is used to evaluate the latest isolation request in the isolation log stream in real time based on the abstract baseline tree, judge the latest isolation request, generate a judgment result, and compare the judgment result with the current isolation policy decision to determine whether there is an isolation policy anomaly.
[0013] The present invention also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and runnable on the processor. When the processor executes the computer program, it implements any of the above-mentioned multi-level isolation strategy anomaly real-time detection methods.
[0014] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements any of the above-described multi-level isolation strategy anomaly real-time detection methods.
[0015] The present invention provides a multi-level isolation policy anomaly real-time detection method and system, which derives a security baseline through candidate baseline mining and candidate baseline compression, reducing the risk that the baseline itself contains isolation failure conditions and improving the accuracy of isolation failure detection results; encoding the security baseline into an abstract baseline tree structure can achieve real-time detection and incremental adjustment of isolation failures, quickly discover cross-domain penetration risks caused by loose or inaccurate policy configuration, and promptly discover security domain isolation failures caused by lax configuration or improper operation, thereby preventing potential lateral movement risks and information leakage. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the technical solutions in the present invention or the prior art, a brief introduction is given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0017] Figure 1 It is a flow chart of the multi-level isolation strategy anomaly real-time detection method provided by the present invention.
[0018] Figure 2 It is a flow chart of the candidate baseline mining algorithm provided by the present invention.
[0019] Figure 3 This is a flow chart of the candidate baseline compression algorithm provided by the present invention.
[0020] Figure 4 This is a schematic diagram of the abstract baseline tree structure provided by the present invention.
[0021] Figure 5 This is a flow chart of the abstract baseline tree encoding algorithm provided by the present invention.
[0022] Figure 6 This is a flowchart of anomaly detection of the isolation strategy provided by the present invention.
[0023] Figure 7 This is a schematic diagram of module connections of the multi-level isolation strategy anomaly real-time detection system provided by the present invention.
[0024] Figure 8 It is a structural schematic diagram of the electronic device provided by the present invention.
[0025] Reference numerals: 110: isolation access log preprocessing module; 120: security baseline derivation module; 130: baseline tree encoding module; 140: isolation failure determination module; 810: processor; 820: communication interface; 830: memory; 840: communication bus. DETAILED DESCRIPTION
[0026] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.
[0027] The following combination Figure 1The present invention describes a multi-level isolation policy anomaly real-time detection method, including: step 100, obtaining the access log of the isolation policy to be detected and preprocessing it to obtain a log data set for security baseline extraction.
[0028] Specifically, the access logs of the isolation policy to be tested are obtained. For multiple log entries describing the same isolation request, only the latest decision result is retained. Multiple attribute value pairs in the isolation request are discretized, and missing attribute values are directly ignored to generate a log dataset for security baseline extraction.
[0029] In the present invention, each log entry contains the isolation request, policy decision, and time information. The preprocessing process includes: for multiple log entries describing the same isolation request, only the most recent decision result is retained; multiple attribute value pairs in the isolation request are discretized, and missing attribute values are directly ignored; after preprocessing, a log data set for security baseline extraction is obtained. .
[0030] Step 200: Derives a security baseline based on the log data set through candidate baseline mining and candidate baseline compression.
[0031] Specifically, based on the log data set, the mining problem is converted into a submodular maximization problem. By constructing an approximate optimization framework and combining it with the Pareto optimization algorithm, a candidate isolation decision rule set is iteratively mined from the log data set. Each isolation determination rule in the isolation determination rule set is traversed to construct an isolation space and to construct a security baseline through mining using an iterative mining algorithm.
[0032] refer to Figure 2-Figure 4 In this invention, candidate baseline mining is performed with the goal of extracting a security baseline that can cover the necessary isolation requirements as much as possible. , temporarily ignoring the isolation failure conditions that may be contained in the mining results themselves. The mined baseline is composed of multiple isolation judgment rules Each rule is a set of isolated conditions A set of conditions where each Contains attributes , expected attribute value and expected relationships It requires that the corresponding attributes in the isolation request meet the specified conditions. The candidate baseline mining process mainly considers three parts: mining target, mining framework and mining algorithm.
[0033] For the mining target, in order to ensure the consistency of the mining results with the isolated cases in the log and the simplicity of the baseline itself, the baseline mining target is defined as minimizing the empirical loss of the mining results. The empirical loss is determined by the scoring function It considers two common types of empirical losses: losses due to incorrect mining results and losses due to overly complex results, and is calculated as follows: Among them, if the mining result is given , The first item represents the false negative errors caused by the candidate baseline not covering some positive samples (i.e., real isolation failure behaviors); the second item counts the number of negative log items incorrectly covered by each rule (i.e., normal isolation behaviors are mistakenly judged as failures), which is expressed as ,Such sum calculation is necessary because each wrong rule may incorrectly describe the isolation state, leading to subsequent misconfiguration judgment errors, parameter is a preset non-negative hyperparameter; the third term represents the complexity of the rule itself, that is, the total number of all conditions in the baseline, expressed as ,parameter is another preset non-negative hyperparameter.
[0034] Based on the above definition, the goal of baseline mining is to find The optimal baseline . Furthermore, considering the minimization is equivalent to maximizing its negative value, that is, At the same time, due to is a constant, then maximize The optimization objective of can be simplified to maximize the remaining items. According to this transformation, the mining objective is redefined as a new scoring function .based on The ultimate goal of baseline mining is to find a set of scoring functions that Maximizing Isolation Decision Rules .
[0035] For the mining framework, in order to maximize the shape The objective function is to obtain accurate and stable mining results. The solution is proposed by exploiting the fact that it is a submodular function involving modular costs. This property allows the use of approximation algorithms to mine near-optimal results, thus reducing the impact of arbitrary data distributions.
[0036] First of all, The sub-model property of Can be decomposed into ,in: 、 Obviously, It indicates a positive example A non-negative function of coverage that is both monotone and submodular. Next, define , which is a non-negative modular function because it is a sum of additive terms. At the same time, is a modular function. Since is submodular and is a modular function, is a submodular function with modular cost.
[0037] Based on the above sub-model characteristics, sub-model maximization can be performed. Specifically, a mining framework based on approximate optimization is adopted: a greedy strategy is used to iteratively construct the rule set. First, starting from an empty solution set, iteratively search and insert the solution that can make the marginal benefit function Maximized isolation decision rule. In each round of iteration, the proposed method needs to select from all possible isolation decision rule spaces. Find Satisfaction rules, and then add them to the rule set Until the stopping condition is reached (such as all access records are included in the rule set where the marginal benefit is designed to be , which can ensure that the results are The following approximation guarantees are obtained: in, It is the optimal solution under ideal circumstances.
[0038] For mining algorithms, the key sub-problem of the aforementioned mining framework is how to efficiently search for the marginal benefit function The mining algorithm mainly solves the problem of the search process of maximizing the optimal isolation judgment rule. To this end, the Pareto optimization algorithm is designed, which takes the dual-objective optimization as the intermediate step of the single-objective optimization process of maximizing the marginal benefit function. Specifically, for the proposed Pareto optimization algorithm, the dual-objective optimization of the intermediate step aims to find a baseline judgment condition set , enabling it to maximize while minimizing .
[0039] The optimization idea of the rule search process based on the Pareto optimization algorithm is as follows: First, identify a temporary Pareto solution set and optimize it separately. and ; Remove the weakly dominated rules and add the remaining rules to the existing Pareto optimal set; Then, randomly select rules from the Pareto optimal set and perform mutation operations on them to generate new candidate rules. The candidate rule set is recorded as ; Each mutated rule Will undergo a dominance relationship evaluation, remove the Pareto optimal set Weakly dominated rules; after each round of iteration, only those 、 or There is at least one non-dominated rule on the indicator, which is used to update the overall Pareto set In the definition of dominance relationship, the marginal revenue function is given as , for the two rules and ,if and ,say Dominate , recorded as In addition, if and ,but weak dominance , recorded as .
[0040] Specifically, the Pareto optimization process iteratively calculates the marginal benefit function The Pareto optimal solution is related to the initialization. First, a single baseline judgment condition is searched , so that the single conditional strategy composed of Can satisfy marginal benefit maximization and add this strategy to the initial Pareto optimal set Afterwards, the Pareto optimal set is continuously updated through multiple rounds of iterations based on dual-objective optimization. In each iteration: from the Pareto optimal set Uniformly randomly select a rule ;right Perform mutation operation to generate candidate neighbor rule set ;right Each rule in Perform dominance evaluation and remove the set Middle quilt Weakly dominated rules; after the iteration, update , only keep those 、 or At least one indicator in the Pareto optimal set is not dominated. Select the one that makes The largest rule is output as the optimization result.
[0041] The goal of candidate baseline compression is to cover as many necessary isolation boundaries as possible. Therefore, the candidate baseline is a set of coarse-grained isolation decision rules. However, due to the sparsity of isolation logs, not all possible isolation requests can be recorded in the input logs. This means that some rules in the mining results may contain isolation patterns that do not appear in the logs. If the mined candidate baselines are directly applied to the baseline deviation comparison process, a large number of false positives or missed detections will be caused. Therefore, they must be compressed to eliminate potential isolation failure risks. The compression process mainly involves two operations: sub-baseline mining and baseline merging.
[0042] Among them, the purpose of the sub-rule mining operation is to remove the potential isolation failures implied by each isolation decision rule in the mining results. First, the isolation requests not recorded in the log are regarded as negative instances, and all such requests form a set In the process of sub-rule mining, the set and Isolation Log As the input data set. Specifically, the sub-rule mining algorithm is described as follows: traverse the candidate baseline Isolation determination rules in , for each isolation decision rule , the sub-rule mining algorithm will cover the entries from the input data Excavated Sub-rule set Among them, the mining process reuses the candidate security baseline mining algorithm; the set Contains collection All satisfied Other possible isolated requests that do not appear in the logs are collected Include logs All satisfied Isolation request.
[0043] For the sub-rule merging operation, the current rule Iteratively merge with the corresponding sub-rule set. , traverse its sub-rule set , take the union of the isolation condition sets in each sub-rule and add the merged result to the rule set After the traversal is completed, This constitutes the merged rule set.
[0044] Once the candidate baseline All rules in the have completed sub-rule mining and merging, and all merged rule sets can be regarded as the final derived isolation benchmark This benchmark effectively avoids the risk of isolation failure caused by overly loose isolation configuration and can serve as an important basis for subsequent detection of isolation policy configuration failure.
[0045] In the present invention, by deriving a security baseline based on an approximate optimization framework and combining the Pareto optimization algorithm, the risk of the baseline itself containing isolation failure conditions is reduced, and the accuracy of the isolation failure detection result is improved.
[0046] Step 300: Based on the security baseline, a real-time evaluation is performed on the isolated log streams in the log data set to detect isolation failures. During the isolation failure detection process, the security baseline is encoded into an abstract baseline tree.
[0047] refer to Figure 5 In this invention, when encoding a security baseline, after deriving the security baseline, it is used to perform real-time evaluation of isolated log streams to detect isolation failures. During the subsequent misconfiguration detection process, this security baseline is encoded into an abstract baseline tree structure to enable efficient real-time evaluation. The following details the key components of this process: the abstract baseline tree data structure, the baseline tree encoding algorithm, and the update algorithm.
[0048] For the data structure of the abstract baseline tree, given an abstract baseline tree, each non-leaf node corresponds to an isolation attribute, and the following three sets of mappings are maintained: "attribute-attribute value" mapping: represents the set of all possible attribute values of the isolation attribute corresponding to the current node; "attribute value-child node" mapping: represents the expected value of the isolation attribute corresponding to the current node, and the next child node that needs to be accessed when the attribute value is satisfied; "attribute value-rule ID" mapping : Indicates the expected value of the isolation attribute corresponding to the current node, and which isolation judgment rules in the baseline can meet the expected value of the attribute. For the leaf node of the abstract baseline tree, it indicates whether all the "attribute-attribute value" mapping conditions on the path from the root node to the leaf node are met at the same time (in this case, node) or not satisfied (in this case Node). For non-leaf nodes, a security baseline is given and attributes In the attribute-attribute value mapping maintained by this node, the attribute value set only contains the attribute values that appear explicitly in the isolation judgment condition. In addition, for the attribute All attribute values not explicitly given in the security baseline are uniformly represented as a special value , which can be considered as Abstract expressions of all other implicit isolation judgment conditions. This abstract operation not only avoids the exhaustive enumeration of potentially large value domains in the construction of the abstract baseline tree, but also reduces the construction overhead while ensuring the accuracy of the detection results.
[0049] The encoding algorithm for the abstract baseline tree includes: attribute sorting, baseline tree construction, recursive construction, customized adjustment and baseline update.
[0050] Specifically, the first step of the attribute sorting construction process is to determine the hierarchical order of the isolated attributes in the abstract baseline tree structure. For each isolated attribute , by identifying all attribute values explicitly specified in all its baseline decision conditions and calculating for each value Probability , and then calculate the entropy of the attribute based on the probability: ,in Indicates the attributes that appear in the security baseline Next, the attributes are sorted in ascending order by their entropy values. Since attributes with lower entropy values have less uncertainty, they are placed at higher levels of the baseline tree, which helps reduce the complexity of the tree structure and improve evaluation efficiency.
[0051] Baseline tree construction, constructs an abstract baseline tree by iteratively inserting isolation decision rules from the security baseline. Specifically, the construction operation is performed from the root attribute downwards. For each attribute node, the construction principle (CoP) is defined as follows: If the attribute value is explicitly given in the current to-be-encoded rule The positive judgment condition of Create a key , and add the ID of the isolation decision rule to which it belongs to the list of isolation decision rule IDs corresponding to the key; if the attribute value is explicitly given in the current rule to be encoded If the negative judgment condition is The rule ID list of all keys with values other than ; if the attribute value of the attribute is not explicitly given in the current rule to be encoded, then the baseline implicitly allows all attribute values for the current attribute, so the wildcard key is used To represent all other implicitly allowed values. This process continues hierarchically until all attributes have been processed. Once the last attribute has been processed, a value marked with A leaf node indicates that any isolation request matching this path will be determined by the baseline as being isolated and valid.
[0052] Recursively construct and then repeat the above insertion process for each judgment condition in each isolation judgment rule in the security baseline, and finally determine the association between each "attribute-property value" combination and the corresponding isolation judgment rule ID and judgment result, so as to obtain the formal description of the complete security baseline by the abstract baseline tree.
[0053] Customized Adjustment: After constructing the abstract baseline tree, the system administrator can modify it to obtain a customized baseline tree that meets the isolation policy objectives. This customization can alleviate the conflict between the security baseline and the established isolation goals, thereby reducing the false positive rate; at the same time, it can focus on identifying misconfigurations that violate these isolation goals, thereby improving detection accuracy. To this end, two additional baseline trees are constructed: the forward abstract baseline tree ( ) and negative abstract baseline tree ( ). Specifies isolation requirements that must be achieved in all cases, while NBT specifies isolation behaviors that must be rejected. and Similar to the abstract baseline tree, but it does not have a "attribute value - rule ID list" mapping because and In the non-leaf nodes, the attribute value corresponds to only one binary state indicator (state symbol), whose value can be (indicates that the isolation requirements for this attribute are adjusted when obtaining a specific attribute value) or (Indicates that no additional adjustment is required for this attribute.) In the subsequent real-time misconfiguration detection process, and It is used together with the abstract baseline tree for log item evaluation.
[0054] Baseline update, since the isolation target may change over time, in order to achieve real-time and accurate misconfiguration detection, the abstract baseline tree needs to be updated. The proposed abstract baseline tree structure supports efficient incremental update operations, ensuring the correctness of the update while maintaining low performance overhead. The proposed update principle (UpP) is as follows: Given an update target (for example, adding, deleting, or modifying an isolation decision rule), the update is first represented in a rule format. Then, it is determined whether the update is of the type of forced allow or forced deny. For updates of the forced deny type, the method adds the isolation decision rule to be updated to the rule. ; For updates of the mandatory allow type, the method first checks Whether the update target is currently rejected. If not, directly add the rule to If rejected, you need to first update the isolation criteria of the rules in the target. Specifically, given the isolation judgment condition, the update process of each affected attribute value in NBT or PBT is as follows: For the positive baseline judgment condition, if the given value If the key does not exist in the node, create one; if the key already exists, select the key from the wildcard. Copy information; for negative baseline judgment conditions, except Values other than Inherit child nodes to ensure they are consistently denied or allowed.
[0055] Step 400: Evaluate the latest isolation request in the isolation log stream in real time based on the abstract baseline tree, make a judgment on the latest isolation request, generate a judgment result, and compare the judgment result with the current isolation policy decision to determine whether there is an isolation policy anomaly.
[0056] Specifically, obtain the current real-time isolated access log stream and extract the access request to be detected from the latest log entry; Using the abstract baseline tree, positive abstract baseline tree, and negative abstract baseline tree as security baselines, access requests are judged and judgment results are generated. Compare the judgment result of the baseline tree with the current isolation policy decision of the system. If the isolation policy decision is to allow cross-domain interaction and the judgment result of the baseline tree is to deny it, the current log item will be marked as suspected isolation failure and submitted to the system administrator for further confirmation.
[0057] refer to Figure 6 In this invention, the encoded abstract baseline tree needs to evaluate the latest isolation request in the isolation log stream in real time to detect isolation failure issues as soon as possible. Starting from the root node of the baseline tree, the evaluation principle is as follows: retrieve the attribute value from the isolation request; check the isolation decision rule ID list corresponding to the corresponding attribute value based on the "attribute value-rule ID" mapping. If the list is empty, return ; If it is not empty, find the child node associated with the value according to the "attribute value-child node" mapping; when reaching the leaf node, return , otherwise continue evaluating the next attribute.
[0058] Integrated 、 The steps for real-time isolation failure detection with the abstract baseline tree are as follows: ① For the latest result in the isolation log stream, The isolation request of the proposed method is first If Returns true, the request violates the isolation constraint and must be rejected, and the system issues an alarm; ② If return , the proposed method checks PBT, if PBT returns , then the request satisfies the isolation constraints that must be allowed and is allowed to pass; ③ If PBT returns , the method uses the abstract baseline tree to evaluate the isolation request. If the abstract baseline tree returns , the request is allowed by the baseline; otherwise, the request is denied and an isolation failure alert is issued. When an alert is issued, the system administrator needs to further confirm whether the isolation request truly represents an isolation failure caused by a configuration error. The design of this layered baseline assessment method ensures that the assessment system always adheres to the administrator's customized mandatory denial and allow isolation requirements before making the final baseline judgment.
[0059] Based on a real-time detection method for multi-level isolation policy anomalies provided by the present invention, a security baseline is derived through candidate baseline mining and candidate baseline compression, which reduces the risk of the baseline itself containing isolation failure conditions and improves the accuracy of the isolation failure detection results; the security baseline is encoded into an abstract baseline tree structure, which can realize real-time detection and incremental adjustment of isolation failures, quickly discover cross-domain penetration risks caused by loose or inaccurate policy configuration, and promptly discover security domain isolation failures caused by inaccurate configuration or improper operation, thereby preventing potential lateral movement risks and information leakage.
[0060] refer to Figure 7 The present invention also discloses a multi-level isolation strategy anomaly real-time detection system, the system comprising: The isolation access log preprocessing module 110 is used to obtain the access log of the isolation policy to be detected and preprocess it to obtain a log data set for security baseline extraction; A security baseline derivation module 120, configured to derive a security baseline based on the log data set by mining candidate baselines and compressing candidate baselines; A baseline tree encoding module 130 is configured to perform real-time evaluation of isolated log streams in a log data set based on the security baseline to detect isolation failures, and to encode the security baseline into an abstract baseline tree during the isolation failure detection process; The isolation failure determination module 140 is used to evaluate the latest isolation request in the isolation log stream in real time based on the abstract baseline tree, determine the latest isolation request, generate a determination result, and compare the determination result with the current isolation policy decision to determine whether there is an isolation policy anomaly.
[0061] The access logs of the isolation policy to be tested are obtained and preprocessed to obtain a log dataset for security baseline extraction, which specifically includes: Obtain the access logs of the isolation policy to be tested. For multiple log entries describing the same isolation request, only retain the latest decision result. Discretize the multiple attribute value pairs in the isolation request and ignore the missing attribute values directly to generate a log dataset for security baseline extraction.
[0062] Based on the log dataset, a security baseline is derived through candidate baseline mining and candidate baseline compression, specifically including: Based on the log data set, the mining problem is converted into a submodular maximization problem, and by constructing an approximate optimization framework and combining it with the Pareto optimization algorithm, a candidate isolation decision rule set is iteratively mined from the log data set; Each isolation determination rule in the isolation determination rule set is traversed to construct an isolation space and to construct a security baseline through mining using an iterative mining algorithm.
[0063] Based on the log data set, the mining problem is converted into a submodular maximization problem. By constructing an approximate optimization framework and combining it with the Pareto optimization algorithm, a candidate isolation decision rule set is iteratively mined from the log data set. Specifically, the following steps are involved: Based on the log data set, an approximate optimization framework is constructed by iteratively applying a greedy strategy to the rule set; Based on the approximate optimization framework, the Pareto optimization algorithm is used to iteratively calculate the Pareto optimal solution related to the marginal benefit function from the log data set to obtain a set of candidate isolation decision rules.
[0064] Traversing each isolation determination rule in the isolation determination rule set, constructing an isolation space, and mining and constructing a security baseline through an iterative mining algorithm, specifically including: Traversing each isolation determination rule in the isolation determination rule set, for each rule, in combination with the covered system modules or security domain sets, constructing a corresponding isolation space based on existing isolation access log records; Based on the isolation space, an iterative mining algorithm is used to mine all candidate isolation decision rules, combine each sub-rule and merge them to build a security baseline.
[0065] In the process of encoding the security baseline into an abstract baseline tree during the isolation failure detection process, the abstract baseline tree can be adjusted to generate a positive abstract baseline tree and a negative abstract baseline tree; Among them, the positive abstract baseline tree specifies the isolation requirements that must be achieved in any case, while the negative abstract baseline tree specifies the isolation behavior that must be rejected.
[0066] Based on the abstract baseline tree, the latest isolation request in the isolation log stream is evaluated in real time. The latest isolation request is judged and a judgment result is generated. The judgment result is compared with the current isolation policy decision to determine whether there is an isolation policy anomaly. Specifically, the following steps are performed: Obtain the current real-time isolated access log stream and extract the access request to be detected from the latest log entry; Use the abstract baseline tree, positive abstract baseline tree, and negative abstract baseline tree as security baselines to judge access requests and generate judgment results Compare the judgment result of the baseline tree with the current isolation policy decision of the system. If the isolation policy decision is to allow cross-domain interaction and the judgment result of the baseline tree is to deny it, the current log item will be marked as suspected isolation failure and submitted to the system administrator for further confirmation.
[0067] A multi-level isolation policy anomaly real-time detection system provided by the present invention derives a security baseline through candidate baseline mining and candidate baseline compression, reducing the risk that the baseline itself contains isolation failure conditions and improving the accuracy of isolation failure detection results; encoding the security baseline into an abstract baseline tree structure can achieve real-time detection and incremental adjustment of isolation failures, quickly discover cross-domain penetration risks caused by loose or inaccurate policy configuration, and promptly discover security domain isolation failures caused by inaccurate configuration or improper operation, thereby preventing potential lateral movement risks and information leakage.
[0068] Figure 8 An example of a physical structure diagram of an electronic device is shown below. Figure 8 As shown, the electronic device may include: a processor 810, a communications interface 820, a memory 830, and a communications bus 840, wherein the processor 810, the communications interface 820, and the memory 830 communicate with each other via the communications bus 840. The processor 810 may call logic instructions in the memory 830 to execute a multi-level isolation policy anomaly real-time detection method, which includes: obtaining access logs for the isolation policy to be detected and preprocessing them to obtain a log data set for security baseline extraction; deriving a security baseline based on the log data set through candidate baseline mining and candidate baseline compression; performing real-time evaluation of isolation log streams in the log data set based on the security baseline to detect isolation failures, encoding the security baseline into an abstract baseline tree during the isolation failure detection process; and evaluating the latest isolation request in the isolation log stream in real-time based on the abstract baseline tree, determining the latest isolation request, generating a determination result, and comparing the determination result with the current isolation policy decision to determine whether there is an isolation policy anomaly.
[0069] Furthermore, the logic instructions in the aforementioned memory 830 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product, stored in a storage medium, includes instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, mobile hard drives, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical disks.
[0070] On the other hand, the present invention also provides a computer program product, which includes a computer program, which can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute a multi-level isolation policy anomaly real-time detection method provided by the above methods, the method including: obtaining the access log of the isolation policy to be detected and preprocessing it to obtain a log data set for security baseline extraction; deriving a security baseline based on the log data set through candidate baseline mining and candidate baseline compression; based on the security baseline, performing real-time evaluation of the isolation log stream in the log data set to detect isolation failure, and encoding the security baseline into an abstract baseline tree in the process of detecting isolation failure; based on the abstract baseline tree, evaluating the latest isolation request in the isolation log stream in real time, judging the latest isolation request, generating a judgment result, and comparing the judgment result with the current isolation policy decision to determine whether there is an isolation policy anomaly.
[0071] On the other hand, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements a multi-level isolation policy anomaly real-time detection method provided by the above-mentioned methods, the method comprising: obtaining the access log of the isolation policy to be detected and preprocessing it to obtain a log data set for security baseline extraction; deriving a security baseline based on the log data set through candidate baseline mining and candidate baseline compression; performing real-time evaluation of the isolation log stream in the log data set based on the security baseline to detect isolation failure, and encoding the security baseline into an abstract baseline tree during the isolation failure detection process; evaluating the latest isolation request in the isolation log stream in real time based on the abstract baseline tree, judging the latest isolation request, generating a judgment result, and comparing the judgment result with the current isolation policy decision to determine whether there is an isolation policy anomaly.
[0072] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.
[0073] Through the above description of the embodiments, those skilled in the art will clearly understand that each embodiment can be implemented using software plus a necessary general-purpose hardware platform, or of course, hardware. Based on this understanding, the essence of the above technical solution, or the portion that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, or an optical disk, and includes a number of instructions for causing a computer device (such as a personal computer, server, or network device) to execute the methods described in each embodiment or certain portions of the embodiments.
[0074] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A multi-level isolation strategy anomaly real-time detection method, characterized in that: include: Obtain access logs for the isolation policy to be tested and preprocess them to obtain a log dataset for security baseline extraction; Derives a security baseline based on the log data set through candidate baseline mining and candidate baseline compression; Based on the security baseline, isolated log streams in the log data set are evaluated in real time to detect isolation failures, and the security baseline is encoded into an abstract baseline tree during the isolation failure detection process; Based on the abstract baseline tree, the latest isolation request in the isolation log stream is evaluated in real time, the latest isolation request is judged, and a judgment result is generated. The judgment result is compared with the current isolation policy decision to determine whether there is an isolation policy anomaly.
2. The multi-level isolation strategy anomaly real-time detection method according to claim 1 is characterized in that: The access logs of the isolation policy to be detected are obtained and preprocessed to obtain a log data set for security baseline extraction, specifically including: Obtain the access logs of the isolation policy to be tested. For multiple log entries describing the same isolation request, only retain the latest decision result. Discretize the multiple attribute value pairs in the isolation request and ignore the missing attribute values directly to generate a log dataset for security baseline extraction.
3. The multi-level isolation strategy anomaly real-time detection method according to claim 1 is characterized in that: The derivation of a security baseline based on the log data set through candidate baseline mining and candidate baseline compression specifically includes: Based on the log data set, the mining problem is converted into a submodular maximization problem, and by constructing an approximate optimization framework and combining it with the Pareto optimization algorithm, a candidate isolation decision rule set is iteratively mined from the log data set; Each isolation determination rule in the isolation determination rule set is traversed to construct an isolation space and to construct a security baseline through mining using an iterative mining algorithm.
4. The multi-level isolation strategy anomaly real-time detection method according to claim 3 is characterized in that: The mining problem is converted into a submodular maximization problem based on the log data set, and an approximate optimization framework is constructed and combined with the Pareto optimization algorithm to iteratively mine a candidate isolation decision rule set from the log data set, specifically including: Based on the log data set, an approximate optimization framework is constructed by iteratively applying a greedy strategy to the rule set; Based on the approximate optimization framework, the Pareto optimization algorithm is used to iteratively calculate the Pareto optimal solution related to the marginal benefit function from the log data set to obtain a set of candidate isolation decision rules.
5. The multi-level isolation strategy anomaly real-time detection method according to claim 3 is characterized in that: Traversing each isolation determination rule in the isolation determination rule set, constructing an isolation space, and mining and constructing a security baseline through an iterative mining algorithm specifically include: Traversing each isolation determination rule in the isolation determination rule set, for each rule, in combination with the covered system modules or security domain sets, constructing a corresponding isolation space based on existing isolation access log records; Based on the isolation space, an iterative mining algorithm is used to mine all candidate isolation decision rules, combine each sub-rule and merge them to build a security baseline.
6. The multi-level isolation strategy anomaly real-time detection method according to claim 1 is characterized in that: In the process of encoding the security baseline into an abstract baseline tree during the isolation failure detection process, the abstract baseline tree can be adjusted to generate a positive abstract baseline tree and a negative abstract baseline tree; Among them, the positive abstract baseline tree specifies the isolation requirements that must be achieved in any case, while the negative abstract baseline tree specifies the isolation behavior that must be rejected.
7. The multi-level isolation strategy anomaly real-time detection method according to claim 1 is characterized in that: The method of evaluating the latest isolation request in the isolation log stream in real time based on the abstract baseline tree, determining the latest isolation request, generating a determination result, and comparing the determination result with the current isolation policy decision to determine whether there is an isolation policy anomaly specifically includes: Obtain the current real-time isolated access log stream and extract the access request to be detected from the latest log entry; Using the abstract baseline tree, positive abstract baseline tree, and negative abstract baseline tree as security baselines, access requests are judged and judgment results are generated. Compare the judgment result of the baseline tree with the current isolation policy decision of the system. If the isolation policy decision is to allow cross-domain interaction and the judgment result of the baseline tree is to deny it, the current log item will be marked as suspected isolation failure and submitted to the system administrator for further confirmation.
8. A multi-level isolation strategy anomaly real-time detection system, characterized in that: The system comprises: The isolation access log preprocessing module is used to obtain the access logs of the isolation policy to be detected and preprocess them to obtain the log data set for security baseline extraction; A security baseline derivation module, configured to derive a security baseline based on the log data set through candidate baseline mining and candidate baseline compression; A baseline tree encoding module is used to perform real-time evaluation on isolated log streams in the log data set based on the security baseline to detect isolation failures, and to encode the security baseline into an abstract baseline tree during the isolation failure detection process; The isolation failure judgment module is used to evaluate the latest isolation request in the isolation log stream in real time based on the abstract baseline tree, judge the latest isolation request, generate a judgment result, and compare the judgment result with the current isolation policy decision to determine whether there is an isolation policy anomaly.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that: When the processor executes the computer program, the multi-level isolation strategy anomaly real-time detection method as described in any one of claims 1 to 7 is implemented.
10. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method for real-time detection of multi-level isolation strategy anomalies as described in any one of claims 1 to 7 is implemented.