Intelligent operation method and system for network security arrangement
By clustering and integrating security operation and maintenance events during network security operations and generating a unified security orchestration script, the problem of network security operation and maintenance fragmentation is solved, and the security operation and maintenance efficiency and process standardization are improved.
Patent Information
- Application Number
- CN202510747815.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-05
- Publication Date
- 2025-09-16
AI Technical Summary
In existing technologies, network security operations and maintenance are fragmented and lack unified standards, resulting in low security operations and maintenance efficiency.
By acquiring multiple security operation and maintenance events during the security operation process, clustering and integrating security orchestration scripts, determining priorities, generating the final security orchestration script, and orchestrating it through a visual configuration interface, the security orchestration script is unified and authoritative.
It improves the efficiency of security operations and maintenance, achieves the uniformity and authority of security orchestration scripts, simplifies the security operations and maintenance process, reduces dependence on security experts, and shortens response and disposal time.
Smart Images

Figure CN120658438A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to an intelligent operation method and system for network security orchestration. Background Art
[0002] In the Internet field, the system may be subject to various types of threats during operation, resulting in various security risks, such as network attacks, remote Trojans, viruses, etc.
[0003] Typically, when addressing network security operational issues, different security teams have their own security tool sets, capabilities, common use cases, and compliance requirements. This can easily lead to fragmented security operations and a lack of unified standards. This can also require multiple security teams to collaborate with each other, resulting in low security operations efficiency. Summary of the Invention
[0004] The present invention provides an intelligent operation method and system for network security orchestration to address the defects of existing technologies such as fragmented security operation and maintenance, lack of unified standards, and low security operation and maintenance efficiency.
[0005] In one aspect, the present invention provides a method for intelligent operation of network security orchestration, comprising: Obtain multiple security operation and maintenance events during the security operation process; Clustering the multiple security operation and maintenance events to obtain multiple security operation and maintenance cases; Obtain the initial security orchestration scripts of different security personnel for any security operation and maintenance case; Merging each initial security orchestration script of any security operation and maintenance case to obtain a merged security orchestration script of any security operation and maintenance case; Reviewing the integrated security orchestration script of any of the security operations and maintenance cases to obtain a final security orchestration script for any of the security operations and maintenance cases; Traverse all security operation and maintenance cases and obtain the final security orchestration script for each security operation and maintenance case.
[0006] According to a smart operation method for network security orchestration provided by the present invention, each initial security orchestration script of any security operation and maintenance case is integrated to obtain an integrated security orchestration script of any security operation and maintenance case, including: If there is no conflict between the processes of any two initial security orchestration scripts, merge the two initial security orchestration scripts; If there is a conflict between the processes of any two initial security orchestration scripts, determining the priority of each initial security orchestration script in the any two initial security orchestration scripts; The process of the initial security orchestration script with a high priority is retained, and any two initial security orchestration scripts are merged; Traverse all initial security orchestration scripts to obtain a fusion security orchestration script for any of the security operation and maintenance cases.
[0007] According to a smart operation method for network security orchestration provided by the present invention, determining the priority of each of the two initial security orchestration scripts includes: Obtaining department information, position information, and historical arrangement information of the security personnel corresponding to each of the initial security arrangement scripts; Perform a weighted summation of each security officer's department information, position information, and historical orchestration information to obtain the basic trust value of each initial security orchestration script; The priority of each initial security orchestration script is obtained by performing a weighted summation of the basic trust of each initial security orchestration script and the verification trust value of each initial security orchestration script.
[0008] According to a smart operation method for network security orchestration provided by the present invention, each initial security orchestration script includes a verification strategy and verification steps; The process of obtaining the verification trust value of each initial security orchestration script includes: Based on the verification strategy, each initial security orchestration script is verified using the verification steps to obtain a verification trust value of each initial security orchestration script.
[0009] According to the present invention, a smart operation method for network security orchestration is provided, which further includes: Obtain operational data during security operations; The operation data is analyzed, and when the script processing conditions are met, the process of the final security orchestration script of the case corresponding to the operation data is executed.
[0010] According to the present invention, a smart operation method for network security orchestration is provided, which obtains the initial security orchestration scripts of different security personnel for any security operation and maintenance case, including: Through the visual configuration interface, the initial security orchestration script of different security personnel for any security operation and maintenance case is obtained; wherein, the visual configuration interface is configured to perform visual orchestration of the script process by dragging and dropping.
[0011] According to the present invention, a smart operation method for network security orchestration is provided, which also includes: If the security orchestration script update conditions are met, update the final security orchestration script for each security operation and maintenance case; The security orchestration script update condition includes at least one of receiving an update instruction, reaching a preset update cycle, and an increment of security operation and maintenance events reaching a preset increment threshold.
[0012] On the other hand, the present invention also provides a network security orchestration intelligent operation system, which includes: The first acquisition module is used to acquire multiple security operation and maintenance events during the security operation process; A clustering module, configured to cluster the plurality of security operation and maintenance events to obtain a plurality of security operation and maintenance cases; The second acquisition module is used to obtain the initial security orchestration scripts of different security personnel for any security operation and maintenance case; A fusion module, configured to fuse the initial security orchestration scripts of each of the security operation and maintenance cases to obtain a fused security orchestration script for the security operation and maintenance case; A review module, configured to review the integrated security orchestration script of any security operation and maintenance case to obtain a final security orchestration script of any security operation and maintenance case; The traversal module is used to traverse all security operation and maintenance cases and obtain the final security orchestration script for each security operation and maintenance case.
[0013] On the other hand, the present invention also provides an electronic device, which includes a memory, a processor, and a computer program stored in the memory and runnable on the processor, wherein when the processor executes the program, it implements an intelligent operation method for network security orchestration as described in any one of the above.
[0014] On the other hand, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the intelligent operation method of network security orchestration as described in any of the above.
[0015] On the other hand, the present invention also provides a computer program product, including a computer program, which, when executed by a processor, implements the intelligent operation method of network security orchestration as described in any of the above.
[0016] The intelligent operation method and system for network security orchestration provided by the present invention obtain multiple security operation and maintenance events in the security operation process; cluster the multiple security operation and maintenance events to obtain multiple security operation and maintenance cases; obtain the initial security orchestration scripts of different security personnel for any security operation and maintenance case; fuse each initial security orchestration script of any security operation and maintenance case to obtain the fused security orchestration script of any security operation and maintenance case; review the fused security orchestration script of any security operation and maintenance case to obtain the final security orchestration script of any security operation and maintenance case; traverse all security operation and maintenance cases to obtain the final security orchestration script of each security operation and maintenance case, thereby realizing the fusion of security orchestration scripts of different security personnel, making the final security orchestration script unified and authoritative, so as to improve the security operation and maintenance efficiency in subsequent security operation and maintenance. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] In order to more clearly illustrate the technical solutions in the present invention or the prior art, a brief introduction is given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0018] Figure 1 This is a flowchart of a smart operation method for network security orchestration provided by an embodiment of the present invention; Figure 2 This is a schematic diagram of the structure of the intelligent operation system for network security orchestration provided by an embodiment of the present invention; Figure 3 It is a structural diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0019] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.
[0020] Security orchestration brings together people, processes, and technology to streamline security processes and enhance security automation to accelerate incident response by integrating multiple systems and platforms. It helps transform complex incident response processes and tasks into consistent, repeatable, measurable, and effective workflows, improving the overall efficiency of security operations teams.
[0021] Automation is a subset of orchestration that allows for the automated integration of security capabilities based on certain conditions. If it relies entirely on API implementation, it is considered automated.
[0022] Response covers the entire incident lifecycle—alert generation, verification, automated response, policy distribution, manual handling, and reporting.
[0023] The most fundamental and crucial function in security orchestration and automated response, it runs throughout the entire security incident lifecycle, helping users conduct streamlined, continuous investigation, analysis, and response tracking for a group of related incidents. Case management includes trigger conditions and response actions. Through case flow processing, different Playbooks can be assigned to different cases and their execution monitored. Once a case is opened, incidents matching that case are automatically responded to, reducing mean time to repair.
[0024] A playbook is a script that documents the security engineer's workflow. Playbooks focus on response and disposal, and can be created and saved through visual orchestration and referenced in case studies. Common playbooks include forensic analysis and collection, global blocking, host isolation, work orders, and email alerts.
[0025] Playbooks automate security operations and maintenance, offering advantages over manual operations such as agility, accurate judgment, and high sustainability. Automated or manual orchestration is expressed through playbooks. The workflows required for business scenarios are constructed through the serial and parallel connections between playbooks. Playbooks are triggered when conditions are met, and the response device is called to perform the response action. Playbooks are developed in Python and can be updated subsequently through the official NSFOCUS knowledge base. SOAR provides a powerful SDK, allowing Playbooks to implement complex orchestration scenarios with minimal code. Micro-scenario-specific general-purpose Playbook scripts include the following categories: Global Playbook scripts: block-IP, block-URL, IP-isolation, etc.
[0026] Playbook for removing common threats from infected hosts: kill-process, delete-file, kill-task, disable-service, clear-register, etc.
[0027] Common hardening playbooks for affected hosts: disable-service, add-NF-rule, etc.
[0028] Playbooks can be automatically generated through visual orchestration. The script is equivalent to the handling and response part of the case, but lacks the trigger condition part compared to the case.
[0029] Figure 1 This is a flow chart of the intelligent operation method for network security orchestration provided by an embodiment of the present invention.
[0030] like Figure 1 As shown, the execution subject of the intelligent operation method for network security orchestration provided by the embodiment of the present invention can be an electronic device, and the method mainly includes the following steps: 101. Obtain multiple security operation and maintenance events during the security operation process; In a specific implementation, standardized log collection protocols (such as Syslog and SNMP) and tools (such as ELK Stack and Splunk) can be used to collect multiple security operations events from logs corresponding to various devices. Alternatively, an API interface can be used to collect multiple security operations events during security operations, although this embodiment does not impose any specific limitations.
[0031] 102. Cluster the multiple security operation and maintenance events to obtain multiple security operation and maintenance cases; In a specific implementation, a preset clustering algorithm can be used to cluster the multiple security operations events to obtain multiple security operations cases. These multiple security operations cases may include, but are not limited to, intrusion, denial of service, ransomware, phishing, hotlinking, information leakage, etc. This facilitates serialized responses and executions of the same event type using a labeled approach, while also enabling security performance metrics for the responses and executions of the same event type to determine execution efficiency and accuracy, allowing for unified adjustments to execution strategies.
[0032] Each security operation and maintenance case includes at least one security operation and maintenance incident.
[0033] In a specific implementation, the clustering process can be as follows: a. Extract multiple features of each security operation and maintenance event; In a specific implementation process, basic features such as event type, occurrence time, source IP, destination IP, and attack signature code can be extracted from each operation and maintenance event. At the same time, natural language processing technology can be used to perform semantic analysis on the event description text to extract semantic features such as keywords and key phrases.
[0034] b. For any two security operation and maintenance events, obtain the similarity between them using a preset clustering calculation formula; In a specific implementation process, the clustering calculation formula can be:
[0035] in, Indicates the similarity between the first and second security operation and maintenance events in any two security operation and maintenance events. It represents the weight of the i-th feature, which is dynamically adjusted according to the historical convergence effect through machine learning algorithms (such as gradient boosting tree). In this way, the weight is optimized in real time as the characteristics of security events change, adapting to new attacks and improving the convergence accuracy. Represents the similarity function of the i-th feature. For numerical features (such as timestamps), Euclidean distance similarity can be used for similarity calculation, and for text features, cosine similarity can be used for similarity calculation.
[0036] c. When the similarity between any two security operation and maintenance events is greater than the preset similarity, the two security operation and maintenance events are clustered into the same security operation and maintenance case; d. Traverse all security operation and maintenance events to obtain multiple security operation and maintenance cases.
[0037] 103. Obtain the initial security orchestration scripts of different security personnel for any security operation and maintenance case; In a specific implementation process, a visual configuration interface can be provided so that different security personnel can create an initial security orchestration script for any security operation and maintenance case based on the visual configuration interface. The visual configuration interface is configured to visually orchestrate the script process by dragging and dropping. That is, security personnel can select the log sources, security rules, forensic tools, and response methods involved in the analysis and judgment by dragging and dropping, thereby reducing the workload of security configuration. The security orchestration process is the arrangement, coordination, and management of predetermined limited operations, operational procedures, and assets, leveraging automation across heterogeneous point solutions to accelerate the time from detection to response. Ultimately, orchestration reduces the risk exposure window and buys time for security analysts to focus on high-value tasks.
[0038] Security orchestration acts as a force multiplier, streamlining analyst workflows, building immediate context for security alerts, and accelerating post-alert actions that typically require manual execution. Technology, playbooks, and dashboard integration enable rapid investigations and infrastructure linkage. Automating security processes and maintaining process consistency saves time and improves security operations efficiency. By leveraging security orchestration policy processes, security analysts can focus on high-priority threat activity analysis, threat hunting, in-depth investigations, and proactive forensics. Ultimately, enterprises can stay one step ahead of attackers in the closed loop of monitoring, analysis, forensics, and response to security threats.
[0039] In a specific implementation, the security operations incident response lifecycle can be defined as a continuous, cyclical process, encompassing security operations incident ingestion and enrichment, incident management, in-depth investigation, execution of response actions, performance measurement, and the application of lessons learned to improve future operational efficiency. Based on the security operations incident response lifecycle, different security personnel can use a visual configuration interface to complete the security orchestration of any security operations case and generate an initial security orchestration playbook. This initial security orchestration playbook can also include a complete response strategy (i.e., what to do) and complete response steps (i.e., how to do it).
[0040] 104. Merge each initial security orchestration script of any security operation and maintenance case to obtain a merged security orchestration script of any security operation and maintenance case; In a specific implementation process, after obtaining each initial security orchestration script of any security operation and maintenance case, each initial security orchestration script of any security operation and maintenance case can be integrated to unify the security operation and maintenance and obtain the integrated security orchestration script of any security operation and maintenance case.
[0041] Specifically, fusion can be achieved as follows: a1. If there is no conflict between the processes of any two initial security orchestration scripts, merge the two initial security orchestration scripts; In a specific implementation process, each of any two initial security orchestration scripts has its own multiple processes. Through semantic recognition and other technologies, it is possible to detect whether there is a conflict between the processes of any two initial security orchestration scripts, and if there is no conflict, the two initial security orchestration scripts are merged.
[0042] For example, when facing an Advanced Persistent Threat (APT) attack, a process in the first initial security orchestration playbook might include: "Immediately isolate all associated assets (100+ servers) and initiate a 72-hour full-traffic retrospective analysis to ensure that no attack paths are missed." However, a process in the second initial security orchestration playbook might include: "Isolate only the currently active attack targets (10 servers) and query IP reputation through the threat intelligence interface (completed within 1 hour) to avoid large-scale isolation and business impact." In this case, the two processes can be determined to be conflicting. If the first initial security orchestration playbook includes: "Immediately isolate all associated assets (100+ servers) and initiate a 72-hour full-traffic retrospective analysis to ensure that no attack paths are missed," while the second initial security orchestration playbook includes: "Immediately isolate all associated assets (100+ servers) and initiate a 72-hour full-traffic retrospective analysis to ensure that no attack paths are missed," then the two processes can be determined to be consistent and can be combined into: "Immediately isolate all associated assets (100+ servers) and initiate a 72-hour full-traffic retrospective analysis to ensure that no attack paths are missed."
[0043] b1. If there is a conflict between the processes of any two initial security orchestration scripts, determine the priority of each of the two initial security orchestration scripts; In a specific implementation process, if there is a conflict between the processes of any two initial security orchestration scripts, the priority of each of the any two initial security orchestration scripts is determined, so that the process of the initial security orchestration script that needs to be retained is subsequently selected according to the priority.
[0044] Specifically, different security operations and maintenance cases have different requirements for different security departments. Therefore, the department information of the security personnel corresponding to each initial security orchestration script can be obtained. The reliability of the initial security orchestration script obtained by the security orchestration of a certain security personnel is different due to the different positions of the security personnel. The efficiency and results of the security orchestration scripts obtained by the security personnel's previous security orchestration in resolving security incidents are different. Therefore, the department information, position information and historical orchestration information of the security personnel corresponding to each initial security orchestration script can be obtained; the department information, position information and historical orchestration information of each security personnel are weighted and summed to obtain the basic trust value of each initial security orchestration script; based on the verification strategy in the initial security orchestration script, each initial security orchestration script is verified using the verification steps in the initial security orchestration script to obtain the verification trust value of each initial security orchestration script. In this way, the basic trust of each initial security orchestration script and the verification trust value of each initial security orchestration script are weighted and summed to obtain the priority of each initial security orchestration script.
[0045] c1. Retain the process of the initial security orchestration script with a high priority, and merge any two of the initial security orchestration scripts; d1. Traverse all initial security orchestration scripts to obtain a fused security orchestration script for any of the security operation and maintenance cases.
[0046] 105. Review the integrated security orchestration script of any security operation and maintenance case to obtain a final security orchestration script of any security operation and maintenance case; In a specific implementation process, after obtaining the integrated security orchestration script of any security operation and maintenance case, the integrated security orchestration script of any security operation and maintenance case can be further reviewed so as to obtain the final security orchestration script of any security operation and maintenance case based on the review results.
[0047] Specifically, the reliability of the final security orchestration script of any security operation and maintenance case can be verified by executing the final security orchestration script of any security operation and maintenance case to determine the efficiency and accuracy of the security incident resolution. Alternatively, the final security orchestration script of any security operation and maintenance case can be reviewed by a review panel to determine the reliability of the final security orchestration script of any security operation and maintenance case. If the reliability is greater than a preset reliability, the integrated security orchestration script of any security operation and maintenance case can be used as the final security orchestration script of any security operation and maintenance case. Otherwise, the integrated security orchestration script of any security operation and maintenance case needs to be modified to obtain the final security orchestration script of any security operation and maintenance case.
[0048] 106. Traverse all security operation and maintenance cases and obtain the final security orchestration script for each security operation and maintenance case.
[0049] The intelligent operation method for network security orchestration of this embodiment obtains multiple security operation and maintenance events in the security operation process; clusters the multiple security operation and maintenance events to obtain multiple security operation and maintenance cases; obtains the initial security orchestration scripts of different security personnel for any security operation and maintenance case; integrates each initial security orchestration script of any security operation and maintenance case to obtain the integrated security orchestration script of any security operation and maintenance case; reviews the integrated security orchestration script of any security operation and maintenance case to obtain the final security orchestration script of any security operation and maintenance case; traverses all security operation and maintenance cases to obtain the final security orchestration script of each security operation and maintenance case, thereby realizing the integration of security orchestration scripts of different security personnel, making the final security orchestration script unified and authoritative, so as to improve the security operation and maintenance efficiency in subsequent security operation and maintenance.
[0050] In a specific implementation process, after obtaining the final security orchestration script for each security operation and maintenance case, the operational data during the security operation process can be obtained and analyzed. When the script processing conditions are met, the process of the final security orchestration script for the case corresponding to the operational data is executed.
[0051] In other words, the final security orchestration scripts for all or some security operations cases can be selectively activated to detect and protect against security incidents in real time. When operational data during security operations meets specific script handling conditions, the final security orchestration script for the case corresponding to the operational data can be executed. These script handling conditions can include preset keywords, set events, and the number of attacks reaching a preset number.
[0052] In a specific implementation, an online security experience knowledge base can be established and regularly updated based on the final security orchestration script for each security operation and maintenance case. Specifically, the final security orchestration script for each security operation and maintenance case is updated if the security orchestration script update conditions are met. The security orchestration script update conditions include at least one of receiving an update instruction, reaching a preset update cycle, and the increment of security operation and maintenance events reaching a preset increment threshold.
[0053] The intelligent operation method for network security orchestration in this embodiment can bring the following value to enterprise security operation management: 1. Active defense in advance: After judgment, events that meet the case and event rule relationship table can be automatically responded to and handled through the security orchestration processing flow, helping enterprises achieve proactive defense in advance.
[0054] 2. Reduce missed reports: For successfully matched alarms, Playbook can initiate the handling process after successful evidence collection to avoid situations where the effective alarms are overwhelming and cannot be handled.
[0055] 3. Shorten response and disposal time: As Playbooks accumulate, more incident handling-related actions can be automated, reducing the time required to respond to and handle security incidents.
[0056] 4. Reduce reliance on security experts: Solidify the experience of security experts into a Playbook, and then automate the entire process of analysis, assessment, and disposal, reducing dependence on security experts.
[0057] 5. Standardization of security operation processes: Every security incident is handled through a unified, standardized process for analysis, assessment, evidence collection, and handling. This reduces the likelihood of uncontrollable security operations and handling outcomes due to inconsistent levels of expertise among security personnel.
[0058] 6. Safety operation indicators can be quantified: Every action executed can be recorded; event response time, average event response time, and improved event handling efficiency can all be quantified.
[0059] Based on the same general inventive concept, the present invention also protects an intelligent operation system for network security orchestration. The intelligent operation system for network security orchestration provided by the present invention is described below. The intelligent operation system for network security orchestration described below and the intelligent operation method for network security orchestration described above can be referenced to each other.
[0060] Figure 2 This is a schematic diagram of the structure of the intelligent operation system for network security orchestration provided by an embodiment of the present invention. Figure 2 As shown, the intelligent operation system for network security orchestration of this embodiment includes a first acquisition module 21, a clustering module 22, a second acquisition module 23, a fusion module 24, a review module 25 and a traversal module 26.
[0061] The first acquisition module 21 is used to acquire multiple security operation and maintenance events during the security operation process; A clustering module 22 is configured to cluster the plurality of security operation and maintenance events to obtain a plurality of security operation and maintenance cases; The second acquisition module 23 is used to obtain the initial security orchestration script of different security personnel for any security operation and maintenance case; A fusion module 24 is configured to fuse the initial security orchestration script of each of the security operation and maintenance cases to obtain a fused security orchestration script of the security operation and maintenance case; A review module 25 is configured to review the integrated security orchestration script of any security operation and maintenance case to obtain a final security orchestration script of any security operation and maintenance case; The traversal module 26 is used to traverse all security operation and maintenance cases to obtain the final security orchestration script for each security operation and maintenance case.
[0062] Figure 3FIG3 is a schematic diagram of the structure of an electronic device provided by an embodiment of the present invention. The network security orchestration intelligent operation system may include: a processor 310, a communication interface 320, a memory 330, and a communication bus 340. The processor 310, the communication interface 320, and the memory 330 communicate with each other via the communication bus 340. The processor 310 can call the logic instructions in the memory 330 to execute the network security orchestration intelligent operation method.
[0063] Furthermore, the logic instructions in the aforementioned memory 330 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product, stored in a storage medium, includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, a mobile hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0064] On the other hand, the present invention also provides a computer program product, which includes a computer program. The computer program can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the intelligent operation method of network security orchestration provided by the above methods.
[0065] On the other hand, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the intelligent operation method for network security orchestration provided by the above-mentioned methods.
[0066] It should be noted that the relevant information that may be involved in the various embodiments of this application are all strictly in accordance with the requirements of laws and regulations, follow the principles of legality, legitimacy and necessity, and are based on the reasonable purposes of business scenarios to process information that users actively provide during the use of products / services or generated due to the use of products / services, as well as information obtained with user authorization.
[0067] The information processed by this application will vary depending on the specific product / service scenario and should be based on the specific scenario in which the user uses the product / service. This information may involve the user's account information, device information, or other related information. This application will treat the relevant information and its processing with a high degree of diligence.
[0068] This application attaches great importance to the security of relevant information and has taken reasonable and feasible security protection measures that comply with industry standards to protect relevant information and prevent unauthorized access, public disclosure, use, modification, damage or loss of relevant information.
[0069] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.
[0070] Through the above description of the embodiments, those skilled in the art will clearly understand that each embodiment can be implemented using software plus a necessary general-purpose hardware platform, or of course, hardware. Based on this understanding, the essence of the above technical solution, or the portion that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, or an optical disk, and includes a number of instructions for causing a computer device (such as a personal computer, server, or network device) to execute the methods described in each embodiment or certain portions of the embodiments.
[0071] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A smart operation method for network security orchestration, characterized by: include: Obtain multiple security operation and maintenance events during the security operation process; Clustering the multiple security operation and maintenance events to obtain multiple security operation and maintenance cases; Obtain the initial security orchestration scripts of different security personnel for any security operation and maintenance case; Merging each initial security orchestration script of any security operation and maintenance case to obtain a merged security orchestration script of any security operation and maintenance case; Reviewing the integrated security orchestration script of any of the security operations and maintenance cases to obtain a final security orchestration script for any of the security operations and maintenance cases; Traverse all security operation and maintenance cases and obtain the final security orchestration script for each security operation and maintenance case.
2. The intelligent operation method for network security orchestration according to claim 1, characterized in that: Each initial security orchestration script of any security operation and maintenance case is integrated to obtain an integrated security orchestration script of any security operation and maintenance case, including: If there is no conflict between the processes of any two initial security orchestration scripts, merge the two initial security orchestration scripts; If there is a conflict between the processes of any two initial security orchestration scripts, determining the priority of each initial security orchestration script in the any two initial security orchestration scripts; The process of the initial security orchestration script with a high priority is retained, and any two initial security orchestration scripts are merged; Traverse all initial security orchestration scripts to obtain a fusion security orchestration script for any of the security operation and maintenance cases.
3. The intelligent operation method for network security orchestration according to claim 2, characterized in that: Determining the priority of each of the two initial security orchestration scripts, including: Obtaining department information, position information, and historical arrangement information of the security personnel corresponding to each of the initial security arrangement scripts; Perform a weighted summation of each security officer's department information, position information, and historical orchestration information to obtain the basic trust value of each initial security orchestration script; The priority of each initial security orchestration script is obtained by performing a weighted summation of the basic trust of each initial security orchestration script and the verification trust value of each initial security orchestration script.
4. The intelligent operation method for network security orchestration according to claim 3 is characterized in that: Each initial security orchestration playbook includes a validation strategy and validation steps; The process of obtaining the verification trust value of each initial security orchestration script includes: Based on the verification strategy, each initial security orchestration script is verified using the verification steps to obtain a verification trust value of each initial security orchestration script.
5. The intelligent operation method for network security orchestration according to claim 1, characterized in that: Also includes: Obtain operational data during security operations; The operation data is analyzed, and when the script processing conditions are met, the process of the final security orchestration script of the case corresponding to the operation data is executed.
6. The intelligent operation method for network security orchestration according to claim 1, characterized in that: Obtain the initial security orchestration scripts from different security personnel for any security operations case, including: Through the visual configuration interface, the initial security orchestration script of different security personnel for any security operation and maintenance case is obtained; wherein, the visual configuration interface is configured to perform visual orchestration of the script process by dragging and dropping.
7. The intelligent operation method for network security orchestration according to any one of claims 1 to 6, characterized in that: Also includes: If the security orchestration script update conditions are met, update the final security orchestration script for each security operation and maintenance case; The security orchestration script update condition includes at least one of receiving an update instruction, reaching a preset update cycle, and an increment of security operation and maintenance events reaching a preset increment threshold.
8. A network security orchestration intelligent operation system, characterized by: include: The first acquisition module is used to acquire multiple security operation and maintenance events during the security operation process; A clustering module, configured to cluster the plurality of security operation and maintenance events to obtain a plurality of security operation and maintenance cases; The second acquisition module is used to obtain the initial security orchestration scripts of different security personnel for any security operation and maintenance case; A fusion module, configured to fuse the initial security orchestration scripts of each of the security operation and maintenance cases to obtain a fused security orchestration script for the security operation and maintenance case; A review module, configured to review the integrated security orchestration script of any security operation and maintenance case to obtain a final security orchestration script of any security operation and maintenance case; The traversal module is used to traverse all security operation and maintenance cases and obtain the final security orchestration script for each security operation and maintenance case.
9. An electronic device, characterized in that: The invention comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the intelligent operation method for network security orchestration as described in any one of claims 1 to 7 is implemented.
10. A non-transitory computer-readable storage medium, characterized in that A computer program is stored thereon, which, when executed by a processor, implements the intelligent operation method for network security orchestration as described in any one of claims 1 to 7.