Network security operation workbench
Through the data monitoring, threat analysis and risk handling modules of the network security operation workbench, efficient identification and flexible response to network threats are achieved, improving the security and threat handling capabilities of the network platform.
Patent Information
- Application Number
- CN202510756931.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-06
- Publication Date
- 2025-09-16
AI Technical Summary
Traditional threat identification methods are unable to effectively respond to complex and changing threat attack methods and incidents, resulting in the continuous amplification of network security risks. Existing technologies are unable to efficiently identify threat information in network information and deal with it in a timely manner.
A network security operation workbench is provided, including a data monitoring module, a threat analysis module, a risk processing module and a log generation module. It improves the accuracy and flexibility of threat identification through real-time monitoring, abnormal data identification, threat type and level analysis, security management operations and log recording.
It improves the network platform's recognition accuracy and flexibility for diverse threat events, enhances the network platform's security and response capabilities, and provides data support and convenience throughout the entire process.
Smart Images

Figure CN120658442A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a network security operation workbench. Background Art
[0002] With the rise of technologies such as big data, cloud computing, the Internet of Things, and mobile Internet, the physical boundaries of data are becoming increasingly blurred. Virtualization technologies and equipment in systems are being widely adopted, and the types and numbers of various asset objects in the network are increasing day by day, making network security information processing more difficult. The risks of network security are being continuously amplified by technology. Therefore, how to efficiently identify threat information in network information and deal with it has become a problem that needs to be solved urgently.
[0003] At present, traditional threat identification methods rely heavily on manually defined rules. Although they have a high accuracy in identifying threat information that has already occurred, with the increasing number of threat events using new technologies, traditional threat identification methods have gradually become inadequate and unable to cope with complex and changing threat attack methods and events.
[0004] Therefore, the present invention provides a network security operation workbench. Summary of the Invention
[0005] The present invention provides a network security operation workbench to improve the accuracy of identifying abnormal information in network information, thereby accurately identifying hidden threat events and handling threat events in a timely manner, thereby continuously improving the security and flexibility of the network platform.
[0006] The present invention provides a network security operation workbench, characterized by comprising: The data monitoring module is used to monitor network events within the system, identify abnormal data and output abnormal information; A threat analysis module is used to perform secondary identification on the abnormal information using a preset identification algorithm, obtain the threat type and level corresponding to each abnormal event in the abnormal information, and generate threat identification information; A risk processing module is used to analyze the threat identification information, match corresponding response strategies and methods, and perform security management operations on each abnormal event based on the response strategies and methods; The log generation module is used to record the identification and analysis process of each abnormal event in the system and the security management operation process, and generate threat management logs.
[0007] Preferably, the data monitoring module includes: The data acquisition submodule is used to obtain the log data of all network events in the system and perform preprocessing to obtain the initial data; The data identification submodule is used to identify and analyze abnormal data in the initial data and output abnormal information.
[0008] Preferably, the threat analysis module includes: A first feature extraction submodule is used to extract features from the abnormal information to obtain abnormal data features; The algorithm matching submodule is used to select a corresponding preset recognition algorithm from the algorithm database based on the abnormal data characteristics.
[0009] Preferably, the threat analysis module further includes: A secondary identification submodule is used to perform secondary identification on the abnormal information using the preset identification algorithm to obtain threat type information and corresponding level information of each abnormal event; The information generation module is used to collect statistics on the threat type information and corresponding level information of all abnormal events and generate threat identification information.
[0010] Preferably, the risk processing module includes: A second feature extraction submodule is used to extract features from the threat identification information to obtain threat data features; A strategy-method matching submodule is used to match the threat data characteristics with the corresponding threat handling strategy and threat handling method in the preset strategy and method database; The security management submodule is used to perform security management operations on corresponding abnormal events in the system based on the threat handling strategy and threat handling method.
[0011] Preferably, the strategy-method matching submodule includes: A factor acquisition unit, configured to convert the threat data feature into a threat matching factor in a preset format; an information matching unit, configured to select historical threat information having a matching degree greater than a first preset degree from a historical threat database based on the threat matching factor, and output the selected information to obtain first threat information; At the same time, selecting historical threat information with a matching degree less than a first preset degree but greater than a second preset degree from the historical threat database, and outputting the second threat information; When the matching degree of the threat matching factor in the historical threat database is less than a second preset degree, converting the corresponding threat data features into an online recognition format and transmitting the format to a cloud database for recognition analysis, and outputting third threat information based on the recognition result and the manual judgment result; a historical strategy-method matching unit, configured to obtain corresponding historical threat handling strategies and historical threat handling methods from a historical threat response strategy-method database based on the first threat information and the second threat information; A strategy design unit is used to isolate the threat event and related systems when the input threat information is third threat information, combine the threat level information, design a threat response strategy through system self-matching instructions and human operation instructions, and output a customized strategy and method; A threat preprocessing unit, configured to preprocess corresponding threat events based on the historical threat processing strategies, historical threat processing methods, and custom strategies and methods, and determine the threat preprocessing effect in combination with the real-time monitoring data obtained by the data monitoring module; When the threat pre-processing effect satisfies the first preset condition, the relevant threat event processing state is marked as the first state, and the threat event in the first state is monitored for a preset duration and level by the data monitoring module; When the monitoring result satisfies the second preset condition, the first state of the threat event is released, the isolation of the relevant system is lifted, and at the same time, the corresponding threat handling strategy and threat handling method are output to the security management module; When the threat preprocessing result obtained after preprocessing the threat event corresponding to the third threat information using the custom strategy and method meets the first preset condition and the second preset condition, the custom strategy and method is updated to the historical threat response strategy-method database. At the same time, the corresponding threat event is updated to the historical threat database, and a mapping relationship between the threat event and the corresponding custom strategy and method is established.
[0012] Preferably, the log generation module includes: The abnormal data log submodule is used to generate an abnormal data log by combining the timestamps corresponding to all the abnormal data identified; The abnormal data includes abnormal login information, abnormal access records, abnormal traffic and abnormal system events; The threat analysis log submodule is used to obtain process data during the secondary identification process of the abnormal information by the threat analysis module, and output a threat identification log based on the time series features corresponding to each identification result in the threat identification information; The risk processing log submodule is used to obtain the matching process data of strategies and methods and the process data of security management for each abnormal event, and output the risk processing log; a standardization submodule, configured to perform standardization processing on the abnormal data log, threat identification log, and risk handling log, and output a first log, a second log, and a third log respectively based on corresponding time features; an abnormal activity analysis submodule, configured to monitor the first, second, and third logs in real time using a preset log monitoring tool, identify abnormal activities in the log data, locate the abnormal activities based on location beacons pre-annotated in the log data, obtain the time of occurrence, type, and frequency of the abnormal activities, and output log abnormality data; The daily management submodule is used to analyze the abnormal log data in combination with the preset log management tool, and to process the abnormal log data in combination with the preset management measures. At the same time, it sets the access requirements corresponding to each log data, sets the corresponding storage policy and access permission level, and generates daily log management data; The security management submodule is used to encrypt sensitive log data based on the security requirements corresponding to each log data and in combination with a preset encryption method. At the same time, it generates log security management data based on the access records and modification records of the log data; The threat management log generation submodule is used to generate a threat management log based on the first log, the second log, the third log, log exception data, log daily management data and log security management data.
[0013] Preferably, the secondary identification submodule includes: A feature data set generating unit is used to extract features from the abnormal information and generate a feature data set. The feature data set includes: node log data, network traffic data, device behavior data, and user behavior data; a test data set generating unit, configured to select feature data from the feature data set using a preset selection instruction to obtain a test data set; a height determination unit, configured to divide the data set to be tested into samples and determine the outlier height of each divided data;
[0014] Among them, hi represents the outlier height of the i-th partition data; Indicates the amount of outlier data in the i-th partition data; Perform feature clustering on each sub-data in each partitioned data to obtain the cluster center and cluster radius of each clustering result, and divide the clustering result into a circular closed area to construct a cluster sequence corresponding to the clustering result ,in, represents the data density of the sub-data in the j2th circular closed area; represents the corresponding cluster radius; Indicates the corresponding unit division length; [ ] indicates the rounding down symbol; Calculate the abnormality index S of the corresponding partitioned data according to the cluster sequence and the outlier height;
[0015] in, Indicates the data ratio of the i-th partition data to all the data in the test set; Represents the average value of the discrete heights of all partitioned data; Represents the overall variance of the discrete heights of all partitioned data; Represents the average distance between the cluster center of the i-th partition data and the cluster centers of other partition data; Indicates the data density of the sub-data in the first circular closed area; Anomaly analysis unit, used to compare and analyze the anomaly index of each segmented data with a preset threshold, and determine the threat type corresponding to each segmented data in combination with a mapping rule; The threat level determination unit is configured to determine the threat level corresponding to each threat type based on the number of attacks, the attack type, and the types and corresponding quantities of the threat events corresponding to the threat type.
[0016] The present invention provides a network security operation workbench, which can realize real-time monitoring of network events and identify abnormal data therein through the data monitoring module. Then, the abnormal information can be secondary identified through the threat analysis module to obtain the threat type and level corresponding to each abnormal event, which not only improves the platform's recognition accuracy of increasingly diverse threat events, but also improves the platform's flexibility in responding to diverse threat events; then, the identified threat events are safely handled through the risk handling module, thereby improving the security of the platform; at the same time, the identification and analysis process and the security handling process of abnormal events can be recorded through the log generation module, providing data support and convenience for the subsequent identification and handling of threat events. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] In order to more clearly illustrate the technical solutions in the present invention or the prior art, a brief introduction is given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0018] Figure 1 This is a schematic diagram of a network security operation workbench provided by an embodiment of the present invention; Figure 2 This is a clustering result diagram provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0019] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.
[0020] The following combination Figure 1 A network security operations workbench of the present invention is described.
[0021] Figure 1 This is a schematic diagram of a framework of a network security operation workbench provided by an embodiment of the present invention.
[0022] like Figure 1 As shown, an embodiment of the present invention provides a network security operation workbench, including: The data monitoring module is used to monitor network events within the system, identify abnormal data and output abnormal information; The threat analysis module is used to perform secondary identification on abnormal information using a preset identification algorithm, obtain the threat type and level corresponding to each abnormal event in the abnormal information, and generate threat identification information; The risk processing module is used to analyze threat identification information, match corresponding response strategies and methods, and perform security management operations on each abnormal event based on the response strategies and methods; The log generation module is used to record the identification and analysis process of each abnormal event in the system and the security management operation process, and generate threat management logs.
[0023] In this embodiment, network events refer to behaviors generated by all nodes in the network, including various network devices, servers, containers, and sensors, and are usually present in some form such as logs or messages. In this embodiment, abnormal data: that is, the data corresponding to each network event is security-checked by the data monitoring module to obtain data that deviates from normal data, such as abnormal IP access, abnormal traffic, abnormal time period access, etc. In this embodiment, abnormal information: that is, information obtained based on abnormal data output, which facilitates subsequent data analysis; In this embodiment, the preset recognition algorithm is used to identify abnormal events in the abnormal information and obtain the corresponding threat type and level. The algorithm is pre-set. For example, a machine learning algorithm such as a decision tree or random forest is used to analyze a large amount of network logs and network data to identify abnormal modules and threat events. In this embodiment, abnormal events refer to abnormal events in network behavior, including non-threatening events and threatening events; In this embodiment, the threat type and level refer to the threat type and threat level corresponding to each abnormal event. Generally speaking, the more threat types an abnormal event has, the more severe the security situation the system faces, and the higher the probability of being attacked or even breached. The higher the threat level of a threat event, the greater the negative impact of the threat on the system. In this embodiment, threat identification information includes information on the threat type and level corresponding to each abnormal event in the abnormal information, providing data support for subsequent security management operations; In this embodiment, the response strategies and methods are strategies and methods for responding to various abnormal events to reduce or eliminate the negative impact that the threat events may have on the system; In this embodiment, the security management operation is an operation for handling corresponding abnormal events according to the matched response strategies and methods, such as isolation, deletion, and marking; In this embodiment, the threat management log is a log recorded according to the identification and analysis process of each abnormal event and the security management operation process, which provides data support for the subsequent identification or handling of similar or identical abnormal events.
[0024] The implementation principle and beneficial effects of this embodiment are as follows: the data monitoring module can realize real-time monitoring of network events and identify abnormal data therein. Then, the threat analysis module can perform secondary identification of abnormal information to obtain the threat type and level corresponding to each abnormal event, which not only improves the platform's identification accuracy of increasingly diverse threat events, but also improves the platform's flexibility in responding to diverse threat events; then, the risk processing module can perform security disposal on the identified threat events, thereby improving the security of the platform; at the same time, the log generation module can record the identification and analysis process and the security disposal process of abnormal events, providing data support and convenience for the subsequent identification and disposal of threat events.
[0025] An embodiment of the present invention provides a network security operation workbench and a data monitoring module, including: The data acquisition submodule is used to obtain the log data of all network events in the system and perform preprocessing to obtain the initial data; The data identification submodule is used to identify and analyze abnormal data in the initial data and output the abnormal information.
[0026] In this embodiment, log data refers to the data recorded by the system for each network event, such as network access volume, access IP, access path, etc. In this embodiment, preprocessing is an operation used to improve data validity and facilitate subsequent data processing, such as cleaning invalid data, removing or supplementing missing values in data, etc. In this embodiment, the initial data refers to the data obtained after preprocessing the log data; The implementation principle and beneficial effects of this embodiment: The present invention can not only accurately obtain the completed or ongoing log data in the system through the data acquisition submodule, but also pre-process the log data, which not only eliminates the impact of invalid data or missing data on the abnormal analysis results, but also improves the data quality and effectiveness of the log data, thereby improving the accuracy of subsequent abnormal data identification and analysis results.
[0027] An embodiment of the present invention provides a network security operation workbench and a threat analysis module, including: The first feature extraction submodule is used to extract features from abnormal information to obtain abnormal data features; The algorithm matching submodule is used to select the corresponding preset recognition algorithm from the algorithm database based on the abnormal data characteristics.
[0028] In this embodiment, feature extraction is a process of extracting data features such as abnormal values, abnormal frequencies, abnormal associations, and abnormal behaviors from abnormal information through a first feature extraction submodule; In this embodiment, abnormal data features: that is, data features obtained by extracting features from abnormal information through the first feature extraction submodule, such as abnormal IP login, abnormal traffic increase, etc.; In this embodiment, the algorithm database: contains a database of a large number of threat identification algorithms for abnormal events; In this embodiment, the preset recognition algorithm is an algorithm obtained by screening from the algorithm database and used to analyze the threat type and level of abnormal events. It is pre-set, for example, a support vector machine (SVM), a decision tree, a neural network, or the like. The implementation principle and beneficial effects of this embodiment: The present invention can extract data features in abnormal information through the first feature extraction sub-module and output abnormal data features, which not only improves the extraction efficiency and accuracy of data features, but also improves the diversity of data features. At the same time, the preset recognition algorithm obtained by screening in the algorithm database can help the system automatically monitor and identify abnormal data points, improve the accuracy and efficiency of algorithm recognition, and help the system to timely detect potential security threats or abnormal events.
[0029] An embodiment of the present invention provides a network security operation workbench, a threat analysis module, further comprising: The secondary identification submodule is used to perform secondary identification on abnormal information using a preset identification algorithm to obtain the threat type information and corresponding level information of each abnormal event; The information generation module is used to collect statistics on the threat type information and corresponding level information of all abnormal events and generate threat identification information.
[0030] In this embodiment, secondary identification: that is, the process of identifying the threat type and corresponding level of each abnormal event in the abnormal information by the system through a preset identification algorithm, which is different from the process and method of the first identification of abnormal data; In this embodiment, threat type information: that is, the type corresponding to each threat event, for example, software that maliciously attacks the system, such as Trojans and viruses; phishing links that obtain personal information through fake websites or fake emails; In this embodiment, the level information is the level of each threat event under the corresponding threat type. The higher the level, the greater the harm and negative impact on the system. For example, low-level threats such as interference with system operation; medium-level threats such as causing system service interruption or non-critical data leakage; high-level threats such as causing serious damage to the system or serious data leakage; In this embodiment, the threat identification information includes information on threat types and levels corresponding to all abnormal events in the abnormal information.
[0031] The implementation principle and beneficial effects of this embodiment: The present invention can use a preset recognition algorithm selected from an algorithm database to perform secondary recognition on abnormal information through a secondary recognition submodule, greatly improving the accuracy of the system's judgment results on the threat type and corresponding threat level of abnormal events in the abnormal information, and can continuously improve the system's ability to identify increasingly diversified and secretive threat events, thereby providing accurate data support for subsequent threat protection operations.
[0032] An embodiment of the present invention provides a network security operation workbench and a risk processing module, including: The second feature extraction submodule is used to extract features from the threat identification information to obtain threat data features; The strategy-method matching submodule is used to match the corresponding threat handling strategy and threat handling method in the preset strategy and method database based on the threat data characteristics; The security management submodule is used to perform security management operations on corresponding abnormal events in the system based on threat handling strategies and threat handling methods.
[0033] In this embodiment, threat data features are data features extracted from threat identification information, including type features and level features of threat events; In this embodiment, the preset strategy and method database: a database storing a large number of strategies and methods for eliminating threat events; In this embodiment, the threat handling strategy includes prevention strategy, monitoring strategy, response strategy and optimization strategy, etc., to continuously improve the efficiency of security protection operations; In this embodiment, the threat handling method includes isolating the infected system, recovering damaged data, analyzing the source of the threat, and recovering system vulnerabilities, so as to reduce or eliminate the negative impact of the threat event on the system and provide a reference for preventing future network security threat events.
[0034] The implementation principle and beneficial effects of this embodiment: The present invention can accurately extract data features in threat identification information through the second feature extraction submodule to obtain threat data features with high credibility and high information volume. Subsequently, the strategy-method matching submodule selects threat handling strategies and threat handling methods that match the threat type and level of the abnormal event from the database. Then, the security management submodule can perform security management operations on various abnormal events in the system, thereby reducing the negative impact of threat events on the system, improving the security of the system, and facilitating the prevention of subsequent identical or similar threat events.
[0035] An embodiment of the present invention provides a network security operation workbench, a strategy-method matching submodule, including: A factor acquisition unit, used to convert threat data features into threat matching factors in a preset format; an information matching unit, configured to select historical threat information having a matching degree greater than a first preset degree from a historical threat database based on a threat matching factor, and output the selected information to obtain first threat information; At the same time, selecting historical threat information with a matching degree less than a first preset degree but greater than a second preset degree from the historical threat database, and outputting the second threat information; When the matching degree of the threat matching factor in the historical threat database is less than a second preset degree, the corresponding threat data feature is converted into an online recognition format and transmitted to the cloud database for recognition analysis, and third threat information is output based on the recognition result and the manual judgment result; A historical strategy-method matching unit, configured to obtain corresponding historical threat handling strategies and historical threat handling methods from a historical threat response strategy-method database based on the first threat information and the second threat information; A strategy design unit is used to isolate the threat event and related systems when the input threat information is third threat information, combine the threat level information, design a threat response strategy through system self-matching instructions and human operation instructions, and output a customized strategy and method; The threat pre-processing unit is used to pre-process corresponding threat events based on historical threat processing strategies, historical threat processing methods, and customized strategies and methods, and to determine the threat pre-processing effect in combination with the real-time monitoring data obtained by the data monitoring module; When the threat pre-processing effect meets the first preset condition, the relevant threat event processing state is marked as the first state, and the threat event in the first state is monitored for a preset duration and level through the data monitoring module; When the monitoring result meets the second preset condition, the first state of the threat event is released, the isolation of the relevant system is lifted, and the corresponding threat handling strategy and threat handling method are output to the security management module; When the threat preprocessing result obtained after preprocessing the threat event corresponding to the third threat information through the customized strategy and method meets the first preset condition and the second preset condition, the customized strategy and method are updated to the historical threat response strategy-method database. At the same time, the corresponding threat event is updated to the historical threat database, and a mapping relationship between the threat event and the corresponding customized strategy and method is established.
[0036] In this embodiment, the preset format, i.e., the data format adapted to the information matching unit, is pre-set, and the speed and efficiency of subsequent data matching can be improved by converting the data features into a format; In this embodiment, the threat matching factor is used to select a matching factor for obtaining corresponding historical threat information in the historical threat database; In this embodiment, the historical threat database: a database storing data related to past threat events, used to provide a reference for identifying and handling subsequent threat events; In this embodiment, the first preset degree is a matching degree threshold for filtering the historical threat database to obtain the first threat information; In this embodiment, the first threat information is historical threat information that is screened from the historical threat database and has a matching degree with the threat matching factor greater than a first preset degree, and is highly similar threat information. For example, if the first preset degree is 98%, then the historical threat information that has a matching degree with the threat matching factor greater than 98% is the first threat information. In this embodiment, the second preset degree is a matching degree threshold for filtering the historical threat database to obtain the second threat information; In this embodiment, the second threat information is historical threat information obtained by screening the historical threat database and having a matching degree with the threat matching factor greater than a second preset degree and less than a first preset degree, and is the reference similar threat information. For example, if the first preset degree is 98% and the second preset degree is 90%, then the historical threat information having a matching degree with the threat matching factor less than 98% and greater than 90% is the second threat information, and is used as a reference for the first threat information. In this embodiment, the online recognition format is the data format used for online recognition; In this embodiment, the cloud database stores a database with richer information on threat types and levels than the local historical threat database. When the local historical threat database is unable to identify the current threat, it is transmitted to the cloud database for identification; In this embodiment, the manual judgment result: that is, the threat judgment result made by relevant security technicians is used in combination with the identification result of the cloud database; In this embodiment, the third threat information is a threat identification result obtained by combining the identification result of the cloud database and the manual judgment result; In this embodiment, the historical threat response strategy-method database: a database storing historical threat processing strategies and historical threat processing methods for corresponding historical threat events; In this embodiment, the historical threat handling strategy refers to the system's handling strategy for each historical threat event; In this embodiment, the historical threat processing method is the method by which the system responds to each historical threat event; In this embodiment, the system self-matching instruction is a strategy design instruction that the system matches itself, which is usually obtained by the output of a model obtained through big data training; In this embodiment, the manual operation instruction is an operation instruction for manually designing a strategy; In this embodiment, custom strategies and methods are strategies and methods designed by combining system self-matching instructions and manual operation instructions to design threat response strategies. The corresponding threat events are generally new types of threats that have not yet been matched to historical response strategies and methods. In this embodiment, pre-processing refers to the operation of pre-processing the threat event to preliminarily determine the effectiveness of the strategy and method; In this embodiment, the threat preprocessing effect refers to the effect of the threat preprocessing determined; In this embodiment, the first preset condition: a determination condition for determining whether the threat event processing state is the first state, is preset; In this embodiment, the first state is a state in which the system is still in a threatened state, but the negative impact on the related systems involved has been alleviated but not completely eliminated; In this embodiment, the preset duration and level: that is, the monitoring duration and the corresponding monitoring level for continuing to monitor the threat event in the first state; In this embodiment, the second preset condition: the threshold condition for releasing the first state of the threat event and the isolation operation of the corresponding system is pre-set. The second preset condition in the present invention is that the threat event has been completely eliminated and the negative impact of the system involved has been completely eliminated.
[0037] The implementation principle and beneficial effects of this embodiment are as follows: The present invention converts threat data features into threat matching factors in a preset format, and then uses an information matching unit to quickly and accurately match and obtain corresponding historical threat information. When the historical threat database cannot filter out the adapted first threat information and second threat information, the threat data features can be identified and analyzed in conjunction with a cloud database, significantly improving the system's recognition accuracy and flexibility in threat event recognition. At the same time, the threat processing unit can process threat events with the help of historical threat processing strategies, historical threat processing methods, and customized strategies and methods, thereby improving the system's operability and flexibility in responding to threat events.
[0038] An embodiment of the present invention provides a network security operation workbench and a log generation module, including: The abnormal data log submodule is used to generate an abnormal data log by combining the timestamps corresponding to all the abnormal data identified; Among them, abnormal data includes: abnormal login information, abnormal access records, abnormal traffic and abnormal system events; The threat analysis log submodule is used to obtain the process data of the threat analysis module during the secondary identification of abnormal information, and output the threat identification log based on the time series features corresponding to each identification result in the threat identification information; The risk processing log submodule is used to obtain the matching process data of strategies and methods and the process data of security management for each abnormal event, and output the risk processing log; The standardization submodule is used to standardize the abnormal data log, threat identification log, and risk treatment log, and output the first log, second log, and third log respectively based on the corresponding time characteristics; The abnormal activity analysis submodule is used to monitor the first log, the second log, and the third log in real time using a preset log monitoring tool, identify abnormal activities in the log data, locate the abnormal activities based on the positioning beacons pre-marked in each log data, obtain the time of occurrence, type, and frequency of the abnormal activities, and output the log abnormality data; The daily management submodule is used to analyze log abnormality data in combination with the preset log management tool and handle the log abnormality data in combination with the preset management measures. At the same time, according to the access requirements corresponding to each log data, the corresponding storage policy and access permission level are set, and the daily log management data is generated; The security management submodule is used to encrypt sensitive log data based on the security requirements corresponding to each log data and in combination with a preset encryption method. At the same time, it generates log security management data based on the access records and modification records of the log data; The threat management log generation submodule is used to generate a threat management log based on the first log, the second log, the third log, the log exception data, the log daily management data and the log security management data.
[0039] In this embodiment, the timestamp is a time identifier such as the time when each abnormal data occurs, the time when it disappears, and the duration of the abnormal data, which is used to record the time when each abnormal event occurs; In this embodiment, the abnormal data log: a log containing each abnormal data and the corresponding timestamp; In this embodiment, the threat identification log includes data on the secondary identification process of abnormal information and corresponding time series features. For example, a log may contain a low-level threat event A that occurs at time 1, ends at time 3, and lasts for 2 seconds. In this embodiment, the risk processing log is a log file containing process data of security management operations performed on each abnormal event and corresponding time series characteristics. For example, a type A low-level threat occurring at time 1 is processed using a type I strategy and method, and is eliminated at time 3. In this embodiment, the time feature refers to the time node corresponding to each log data in each abnormal data log, threat identification log, and risk processing log after the normalization process; In this embodiment, the first log is the abnormal data log after standardization processing; In this embodiment, the second log is the threat identification log after standardization; In this embodiment, the third log is the risk processing log after standardization; In this embodiment, the preset log monitoring tool is a tool for monitoring abnormal activities in log data, which is pre-set, for example, Datadog, Loggly, etc. In this embodiment, abnormal activities refer to abnormal data in log data, such as code anomalies, multiple login failures, unauthorized access, intrusion attempts, and other activities; In this embodiment, the location beacon: a method for quickly locating abnormal data to promptly discover and locate the location and activities of threats and monitor them; In this embodiment, the log abnormality data is data including information such as the location, occurrence time, type, and frequency of each abnormal activity; In this embodiment, the preset log management tool is a tool used for daily management of logs, which is pre-set, for example, Graylog, Sumo logic, etc. In this embodiment, preset management measures: measures and methods for processing abnormal log data are pre-set, such as monitoring and early warning, interference filtering, aggregate analysis, etc. In this embodiment, the access requirement refers to the access requirement of each log data; In this embodiment, storage policy: a policy for storing log data, such as the storage duration of log data, the storage medium used, etc.; In this embodiment, the access permission level refers to the permission level for accessing each log data. For example, if the access permission for core system log data is level-8, then only users with a permission higher than or equal to level-8 can access the core system log data to ensure the security of confidential data. In this embodiment, the daily log management data includes data for daily log management operations such as abnormal log processing and log access; In this embodiment, security requirements include confidentiality, integrity, and availability of log data to ensure that data is not tampered with or leaked. In this embodiment, the preset encryption method: an encryption method used to encrypt log data to prevent data leakage and tampering, which is pre-set, for example, symmetric encryption, hash encryption, key encryption, etc.; In this embodiment, the log security management data includes the encryption method, access records, modification records and other data related to log security corresponding to the log data; In this embodiment, the threat management log is a log comprehensively generated based on the first log, the second log, the third log, the log exception data, the log daily management data, and the log security management data.
[0040] The implementation principle and beneficial effects of this embodiment: The present invention records abnormal data through the abnormal data log submodule, and records the threat identification and analysis process of each abnormal event contained in each abnormal information through the threat analysis log submodule. At the same time, the risk processing log submodule can record the processing process of security management operations on each abnormal data, thereby realizing the recording of data of the entire process of abnormal data identification, threat event identification and threat event processing; at the same time, the log data is monitored and analyzed in combination with the log abnormal data, log daily management data and log security management data, thereby improving the security and reliability of the log data.
[0041] An embodiment of the present invention provides a network security operation workstation, a secondary identification submodule, including: The feature data set generation unit is used to extract features from abnormal information and generate feature data sets. Among them, the feature data set includes: node log data, network traffic data, device behavior data and user behavior data; The test data set generating unit is used to select feature data from the feature data set using a preset selection instruction to obtain the test data set; A height determination unit is used to divide the test data set into samples and determine the outlier height of each divided data;
[0042] Among them, hi represents the outlier height of the i-th partition data; Indicates the amount of outlier data in the i-th partition data; Perform feature clustering on each sub-data in each partitioned data to obtain the cluster center and cluster radius of each clustering result, and divide the clustering result into a circular closed area to construct a cluster sequence corresponding to the clustering result ,in, represents the data density of the sub-data in the j2th circular closed area; represents the corresponding cluster radius; Indicates the corresponding unit division length; [ ] indicates the rounding down symbol; In this embodiment, for example, the divided data A1 has feature 1 and feature 2. The result obtained after clustering according to feature 1 includes: sub-data 01, sub-data 02, sub-data 09, and the result obtained after clustering according to feature 2 includes: sub-data 03, sub-data 04, sub-data 05.
[0043] In this embodiment, the clustering result for feature 1 is as follows: Figure 2 As shown, for example, sub-data 01 is the cluster center, the distribution of sub-data 02 and sub-data 03 is specifically shown in the figure, and the cluster radius is a1, and the circumferential closed areas are b1, b2 and b3.
[0044] According to the cluster sequence and outlier height, calculate the abnormal index S of the corresponding partitioned data;
[0045] in, Indicates the data ratio of the i-th partition data to all the data in the test set; Represents the average value of the discrete heights of all partitioned data; Represents the overall variance of the discrete heights of all partitioned data; Represents the average distance between the cluster center of the i-th partition data and the cluster centers of other partition data; Indicates the data density of the sub-data in the first circular closed area; Anomaly analysis unit, used to compare and analyze the anomaly index of each segmented data with a preset threshold, and determine the threat type corresponding to each segmented data in combination with a mapping rule; The threat level determination unit is configured to determine the threat level corresponding to each threat type based on the number of attacks, the attack type, and the types and corresponding quantities of the threat events corresponding to the threat type.
[0046] In this embodiment, the feature data set is a data set composed of features obtained by extracting features from abnormal information; In this embodiment, the node log data includes alarms, operation logs, audit logs and other data generated by each node; In this embodiment, network traffic data: refers to the network traffic incoming and outgoing from all network events; In this embodiment, device behavior data includes data on known and new connections, location, and network interactions of the device; In this embodiment, user behavior data refers to the user's behavior data in the network environment, such as frequent access by the same IP user, multiple failed remote logins of an account, etc. In this embodiment, the preset selection instruction: an instruction for selecting data features in the feature data set is preset; In this embodiment, the data set to be tested is a data set composed of a plurality of selected feature data; In this embodiment, feature clustering: a method of clustering data features, helps to discover potential structures and patterns in abnormal feature data, so as to timely discover potential threats; In this embodiment, the preset threshold value: the threshold value used for comparative analysis with the abnormality index of each divided data is pre-set; In this embodiment, the mapping rule refers to the mapping relationship between the data features of each divided data and the anomaly index and the threat type.
[0047] The implementation principle and beneficial effects of this embodiment: The present invention can extract the feature data in the abnormal information through the feature data set generation unit, and output a feature data set containing diversified data; then, the selected test data set is subjected to an abnormality analysis through a preset outlier algorithm, and based on the obtained analysis results and combined with the mapping rules, the threat type and threat level of each divided data in the test data set are obtained, thereby greatly improving the accuracy and efficiency of threat identification.
[0048] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A network security operation workbench, characterized in that: include: The data monitoring module is used to monitor network events within the system, identify abnormal data and output abnormal information; A threat analysis module is used to perform secondary identification on the abnormal information using a preset identification algorithm, obtain the threat type and level corresponding to each abnormal event in the abnormal information, and generate threat identification information; A risk processing module is used to analyze the threat identification information, match corresponding response strategies and methods, and perform security management operations on each abnormal event based on the response strategies and methods; The log generation module is used to record the identification and analysis process of each abnormal event in the system and the security management operation process, and generate threat management logs.
2. A network security operation workbench according to claim 1, characterized in that: The data monitoring module includes: The data acquisition submodule is used to obtain the log data of all network events in the system and perform preprocessing to obtain the initial data; The data identification submodule is used to identify and analyze abnormal data in the initial data and output abnormal information.
3. A network security operation workbench according to claim 1, characterized in that: The threat analysis module includes: A first feature extraction submodule is used to extract features from the abnormal information to obtain abnormal data features; The algorithm matching submodule is used to select a corresponding preset recognition algorithm from the algorithm database based on the abnormal data characteristics.
4. A network security operation workbench according to claim 3, characterized in that: The threat analysis module further includes: A secondary identification submodule is used to perform secondary identification on the abnormal information using the preset identification algorithm to obtain threat type information and corresponding level information of each abnormal event; The information generation module is used to collect statistics on the threat type information and corresponding level information of all abnormal events and generate threat identification information.
5. A network security operation workbench according to claim 1, characterized in that: The risk processing module includes: A second feature extraction submodule is used to extract features from the threat identification information to obtain threat data features; A strategy-method matching submodule is used to match the threat data characteristics with the corresponding threat handling strategy and threat handling method in the preset strategy and method database; The security management submodule is used to perform security management operations on corresponding abnormal events in the system based on the threat handling strategy and threat handling method.
6. A network security operation workbench according to claim 5, characterized in that: The strategy-method matching submodule includes: A factor acquisition unit, configured to convert the threat data feature into a threat matching factor in a preset format; an information matching unit, configured to select historical threat information having a matching degree greater than a first preset degree from a historical threat database based on the threat matching factor, and output the selected information to obtain first threat information; At the same time, selecting historical threat information with a matching degree less than a first preset degree but greater than a second preset degree from the historical threat database, and outputting the second threat information; When the matching degree of the threat matching factor in the historical threat database is less than a second preset degree, converting the corresponding threat data features into an online recognition format and transmitting the format to a cloud database for recognition analysis, and outputting third threat information based on the recognition result and the manual judgment result; a historical strategy-method matching unit, configured to obtain corresponding historical threat handling strategies and historical threat handling methods from a historical threat response strategy-method database based on the first threat information and the second threat information; A strategy design unit is used to isolate the threat event and related systems when the input threat information is third threat information, combine the threat level information, design a threat response strategy through system self-matching instructions and human operation instructions, and output a customized strategy and method; A threat preprocessing unit, configured to preprocess corresponding threat events based on the historical threat processing strategies, historical threat processing methods, and custom strategies and methods, and determine the threat preprocessing effect in combination with the real-time monitoring data obtained by the data monitoring module; When the threat pre-processing effect satisfies the first preset condition, the relevant threat event processing state is marked as the first state, and the threat event in the first state is monitored for a preset duration and level by the data monitoring module; When the monitoring result satisfies the second preset condition, the first state of the threat event is released, the isolation of the relevant system is lifted, and at the same time, the corresponding threat handling strategy and threat handling method are output to the security management module; When the threat preprocessing result obtained after preprocessing the threat event corresponding to the third threat information using the custom strategy and method meets the first preset condition and the second preset condition, the custom strategy and method is updated to the historical threat response strategy-method database. At the same time, the corresponding threat event is updated to the historical threat database, and a mapping relationship between the threat event and the corresponding custom strategy and method is established.
7. A network security operation workbench according to claim 1, characterized in that: The log generation module includes: The abnormal data log submodule is used to generate an abnormal data log by combining the timestamps corresponding to all the abnormal data identified; The abnormal data includes abnormal login information, abnormal access records, abnormal traffic and abnormal system events; The threat analysis log submodule is used to obtain process data during the secondary identification process of the abnormal information by the threat analysis module, and output a threat identification log based on the time series features corresponding to each identification result in the threat identification information; The risk processing log submodule is used to obtain the matching process data of strategies and methods and the process data of security management for each abnormal event, and output the risk processing log; a standardization submodule, configured to perform standardization processing on the abnormal data log, threat identification log, and risk handling log, and output a first log, a second log, and a third log respectively based on corresponding time features; an abnormal activity analysis submodule, configured to monitor the first, second, and third logs in real time using a preset log monitoring tool, identify abnormal activities in the log data, locate the abnormal activities based on location beacons pre-annotated in the log data, obtain the time of occurrence, type, and frequency of the abnormal activities, and output log abnormality data; The daily management submodule is used to analyze the abnormal log data in combination with the preset log management tool, and to process the abnormal log data in combination with the preset management measures. At the same time, according to the access requirements corresponding to each log data, the corresponding storage policy and access permission level are set, and the daily log management data is generated; The security management submodule is used to encrypt sensitive log data based on the security requirements corresponding to each log data and in combination with a preset encryption method. At the same time, it generates log security management data based on the access records and modification records of the log data; The threat management log generation submodule is used to generate a threat management log based on the first log, the second log, the third log, log exception data, log daily management data and log security management data.
8. A network security operation workbench according to claim 4, characterized in that: The secondary identification submodule includes: A feature data set generating unit is used to extract features from the abnormal information and generate a feature data set. The feature data set includes: node log data, network traffic data, device behavior data, and user behavior data; a test data set generating unit, configured to select feature data from the feature data set using a preset selection instruction to obtain a test data set; a height determination unit, configured to divide the data set to be tested into samples and determine the outlier height of each divided data; Among them, hi represents the outlier height of the i-th partition data; Indicates the amount of outlier data in the i-th partition data; Perform feature clustering on each sub-data in each partitioned data to obtain the cluster center and cluster radius of each clustering result, and divide the clustering result into a circular closed area to construct a cluster sequence corresponding to the clustering result ,in, represents the data density of the sub-data in the j2th circular closed area; represents the corresponding cluster radius; Indicates the corresponding unit division length; [ ] indicates the rounding down symbol; Calculate the abnormality index S of the corresponding partitioned data according to the cluster sequence and the outlier height; in, Indicates the data ratio of the i-th partition data to all the data in the test set; Represents the average value of the discrete heights of all partitioned data; Represents the overall variance of the discrete heights of all partitioned data; Represents the average distance between the cluster center of the i-th partition data and the cluster centers of other partition data; Indicates the data density of the sub-data in the first circular closed area; Anomaly analysis unit, used to compare and analyze the anomaly index of each segmented data with a preset threshold, and determine the threat type corresponding to each segmented data in combination with a mapping rule; The threat level determination unit is configured to determine the threat level corresponding to each threat type based on the number of attacks, the attack type, and the types and corresponding quantities of the threat events corresponding to the threat type.