Network security alarm processing method and device, storage medium and electronic equipment

By automatically processing network security alerts through a large security model, the problems of low efficiency and frequent false alarms in network security alert processing are solved, and efficient and accurate alert handling is achieved.

CN120658458APending Publication Date: 2025-09-16BEIJING HONGTENG INTELLIGENT TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510805061.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-16
Publication Date
2025-09-16

AI Technical Summary

Technical Problem

In existing technologies, network security alert processing is inefficient and false alarms are frequent, resulting in heavy workloads for security analysts and inefficient handling of key threats.

Method used

Use the big security model to match and process the alarm handling strategy. By determining the target network security alarm, call the big security model to match and handle the alarm handling strategy, and automatically process the alarm handling content.

Benefits of technology

It improves the efficiency and accuracy of network security alarm handling, and improves the efficiency and accuracy of network security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120658458A_ABST
    Figure CN120658458A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a network security alarm processing method and device, a storage medium and electronic equipment, and the method comprises the steps: determining a target network security alarm for target equipment, calling a security big model based on the target network security alarm to carry out alarm processing strategy matching processing, and obtaining a target processing strategy, and performing alarm processing on the target network security alarm based on the target processing strategy through the security big model to obtain alarm processing content, and displaying the alarm processing content. Therefore, alarm processing strategy matching is automatically carried out on the target network security alarm through the security big model, and alarm processing is automatically carried out on the target network security alarm by adopting the matched target processing strategy, so that the alarm processing efficiency can be effectively improved, the network security protection efficiency is improved, and meanwhile, the network security protection efficiency is improved. And alarm processing strategy matching and alarm processing are carried out by means of the security big model, so that the alarm processing accuracy is ensured, and the network security protection accuracy is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a method, device, storage medium, and electronic device for processing network security alarms. Background Art

[0002] With the widespread use of the internet, institutions, organizations, and enterprises are facing unprecedented cybersecurity challenges. The continuous development of network technology has led to a growing number of information systems, terminal devices, and application services, generating massive amounts of network security data and alerts. This information comes from security devices such as intrusion detection systems, firewalls, antivirus software, and vulnerability scanning tools, and covers multiple aspects, including network traffic monitoring, system logs, and user behavior analysis.

[0003] However, most enterprises, organizations, and institutions are severely deficient in their cybersecurity alert processing capabilities, facing several pressing challenges. For example, the sheer volume and complexity of alerts necessitates manual analysis by security analysts, consuming significant time and effort. Manual alert analysis is relatively inefficient, leading to critical threats being overlooked or delayed, thereby increasing the risk of system and data attacks. Furthermore, as attack techniques evolve and attackers' behavior becomes increasingly covert and sophisticated, many security tools struggle to fully identify new threats, resulting in frequent false positives. These false positives, in turn, require security analysts to expend significant resources processing irrelevant alerts, increasing their workload and reducing their efficiency in addressing alerts related to real threats.

[0004] Therefore, how to effectively improve the efficiency of alarm handling is an urgent problem to be solved in the field of network security alarm processing. Summary of the Invention

[0005] The present invention provides a method, device, computer storage medium, and electronic device for processing network security alerts. The technical solution is as follows:

[0006] In a first aspect, an embodiment of the present application provides a method for processing a network security alarm, the method comprising:

[0007] Identify target network security alerts for target devices;

[0008] Based on the target network security alarm, the security big model is called to perform alarm handling strategy matching processing to obtain a target handling strategy, and the target network security alarm is handled by the security big model based on the target handling strategy to obtain alarm handling content;

[0009] Display the alarm handling content.

[0010] In conjunction with the first aspect, in some possible implementations, the invoking a security big model based on the target network security alarm to perform alarm handling strategy matching processing to obtain a target handling strategy includes:

[0011] Based on the target network security alarm, the security big model is called to perform alarm analysis and processing to obtain alarm analysis information;

[0012] Based on the alarm analysis information, the alarm attributes and alarm analysis results of the target network security alarm are identified, and the alarm handling strategy matching processing is performed on the preset handling strategy according to the alarm analysis results and the alarm attributes through the security big model to obtain the target handling strategy.

[0013] In combination with the above embodiment, in some possible implementations, the alarm handling strategy matching process is performed on the preset handling strategy by the security big model according to the alarm analysis result and the alarm attribute to obtain the target handling strategy, including:

[0014] Obtaining priorities of preset processing strategies, and sorting the preset processing strategies according to the priorities to obtain a reference processing strategy sequence;

[0015] The security big model performs alarm handling strategy matching processing on the reference handling strategy sequence according to the alarm analysis result and the alarm attribute to obtain a target handling strategy.

[0016] In conjunction with the first aspect, in certain possible implementations, performing alarm handling on the target network security alarm based on the target handling strategy using the security big model to obtain alarm handling content includes:

[0017] The target handling decision is determined according to the target handling strategy by the security big model, and the target network security alarm is handled according to the target handling decision by the security big model to obtain alarm handling content.

[0018] In combination with the above embodiment, in some possible implementations, determining the target handling decision according to the target handling strategy using the security big model includes:

[0019] Determine a preset disposal plan corresponding to the target disposal strategy through the security big model;

[0020] The security big model determines the plan matching parameters corresponding to the target network security alarm according to the preset disposal plan, determines the plan parameter detection threshold corresponding to the preset disposal plan, and determines the target disposal decision corresponding to the plan matching parameters from the preset disposal plan according to the plan parameter detection threshold.

[0021] In conjunction with the first aspect, in some possible implementations, determining a target network security alarm for a target device includes:

[0022] determining at least one network security alert for the target device;

[0023] A preset alarm screening condition is obtained, and the network security alarm is screened based on the preset alarm screening condition to obtain a target network security alarm.

[0024] In conjunction with the first aspect, in some possible implementations, determining a target network security alarm for a target device includes:

[0025] determining at least one cybersecurity event for a target device;

[0026] Acquire a preset security event screening condition, and perform event screening processing on the network security event based on the preset security event screening condition to obtain a target network security event;

[0027] Determine the alarm sub-item included in the target network security event, and determine the alarm sub-item as a target network security alarm.

[0028] In conjunction with the first aspect, in some possible implementations, displaying the alarm handling content includes:

[0029] Determining an alarm handling process and an alarm handling result based on the alarm handling content;

[0030] On the handling display interface of the situation awareness platform, receiving an alarm handling display operation for the target network security alarm;

[0031] In response to the alarm handling display operation, the alarm handling process and the alarm handling result are displayed.

[0032] In a second aspect, an embodiment of the present application provides a device for processing network security alarms, the device comprising:

[0033] An alarm processing module is used to determine a target network security alarm for a target device;

[0034] An alarm handling module is configured to call a security big model based on the target network security alarm to perform alarm handling strategy matching processing to obtain a target handling strategy, and perform alarm handling on the target network security alarm based on the target handling strategy using the security big model to obtain alarm handling content;

[0035] The processing display module is used to display the alarm processing content.

[0036] Optional alarm handling module, including:

[0037] An alarm analysis unit is used to call a security big model to perform alarm analysis and processing based on the target network security alarm to obtain alarm analysis information;

[0038] A policy matching unit is used to identify the alarm attributes and alarm analysis results of the target network security alarm based on the alarm analysis information, and to match the preset handling strategy with the alarm analysis results and the alarm attributes through the security big model to obtain the target handling strategy.

[0039] Optional policy matching unit, specifically used to:

[0040] Obtaining priorities of preset processing strategies, and sorting the preset processing strategies according to the priorities to obtain a reference processing strategy sequence;

[0041] The security big model performs alarm handling strategy matching processing on the reference handling strategy sequence according to the alarm analysis result and the alarm attribute to obtain a target handling strategy.

[0042] Optional alarm handling module, including:

[0043] The alarm handling unit is used to determine a target handling decision according to the target handling strategy through the security big model, and to perform alarm handling on the target network security alarm according to the target handling decision through the security big model to obtain alarm handling content.

[0044] Optional alarm handling unit, specifically used to:

[0045] Determine a preset disposal plan corresponding to the target disposal strategy through the security big model;

[0046] The security big model determines the plan matching parameters corresponding to the target network security alarm according to the preset disposal plan, determines the plan parameter detection threshold corresponding to the preset disposal plan, and determines the target disposal decision corresponding to the plan matching parameters from the preset disposal plan according to the plan parameter detection threshold.

[0047] Optional alarm processing module, including:

[0048] an alarm determining unit, configured to determine at least one network security alarm for a target device;

[0049] The alarm screening unit is used to obtain a preset alarm screening condition, and perform alarm screening processing on the network security alarm based on the preset alarm screening condition to obtain a target network security alarm.

[0050] Optional alarm processing module, including:

[0051] an event determination unit, configured to determine at least one network security event for a target device;

[0052] An event screening unit, configured to obtain a preset security event screening condition, and perform event screening processing on the network security event based on the preset security event screening condition to obtain a target network security event;

[0053] The event splitting unit is used to determine the alarm sub-items included in the target network security event and determine the alarm sub-items as target network security alarms.

[0054] Optionally, the alarm display module is also used to:

[0055] Determining an alarm handling process and an alarm handling result based on the alarm handling content;

[0056] On the handling display interface of the situation awareness platform, receiving an alarm handling display operation for the target network security alarm;

[0057] In response to the alarm handling display operation, the alarm handling process and the alarm handling result are displayed.

[0058] In a third aspect, an embodiment of the present application provides a computer storage medium, which has multiple instructions, and the instructions are suitable for being loaded by a processor and executing the above method.

[0059] In a fourth aspect, an embodiment of the present application provides an electronic device, which may include: a memory and a processor; wherein the memory stores a computer program, and the computer program is suitable for being loaded by the memory and executing the above method.

[0060] The beneficial effects of the technical solutions provided in the embodiments of the present application include at least:

[0061] The network security alarm processing method provided in the embodiment of the present application determines the target network security alarm for the target device, calls the security big model based on the target network security alarm to perform alarm handling strategy matching processing to obtain the target handling strategy, performs alarm handling on the target network security alarm based on the target handling strategy through the security big model to obtain the alarm handling content, and displays the alarm handling content. Thus, the target network security alarm is automatically matched with the alarm handling strategy through the security big model, and then the target network security alarm is automatically handled using the matched target handling strategy, which can effectively improve the alarm handling efficiency, thereby improving the network security protection efficiency. At the same time, the alarm handling strategy matching and alarm handling with the help of the security big model ensure the accuracy of the alarm handling, thereby improving the accuracy of the network security protection. BRIEF DESCRIPTION OF THE DRAWINGS

[0062] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without paying any creative work.

[0063] Figure 1 This is a flowchart of a method for processing network security alerts provided in an embodiment of the present application;

[0064] Figure 2 This is a flowchart of another method for processing network security alerts provided in an embodiment of the present application;

[0065] Figure 3 This is a flowchart of another method for processing network security alarms provided in an embodiment of the present application;

[0066] Figure 4 This is a schematic diagram of the structure of a network security alarm processing device provided in an embodiment of the present application;

[0067] Figure 5 This is a structural diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0068] In order to make the purpose, features, and advantages of the embodiments of the present application more obvious and easy to understand, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without making creative efforts shall fall within the scope of protection of this application.

[0069] In the description of this application, it should be understood that the terms "first", "second", etc. are used for descriptive purposes only and are not to be understood as indicating or implying relative importance. In the description of this application, it should be noted that, unless otherwise expressly specified and limited, "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units that are not listed, or may optionally include other steps or units inherent to these processes, methods, products or devices. For those of ordinary skill in the art, the specific meanings of the above terms in this application can be understood according to the specific circumstances. In addition, in the description of this application, unless otherwise specified, "multiple" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exists at the same time, and B exists alone. The character " / " generally indicates that the associated objects before and after are in an "or" relationship.

[0070] The present application is described in detail below with reference to specific embodiments.

[0071] In one embodiment, Figure 1 As shown, a method for processing network security alerts is proposed. This method can be implemented using a computer program and can be run on a network security alert processing device based on the von Neumann architecture. The computer program can be integrated into an application or run as a standalone tool application.

[0072] Specifically, the method for handling the network security alarm includes:

[0073] S101: Determine a target network security alarm for a target device.

[0074] It is understood that a target device refers to an electronic device in a secure management state. This state can be achieved by running security management software, security management tools, or a security management system. In this secure management state, the network environment of the target device can be monitored to comprehensively detect and analyze abnormal behaviors such as security incidents, threats, and vulnerabilities generated on the target device.

[0075] A targeted network security alert is a network security alert generated on a target device that meets specific conditions. A network security alert is a prompt or warning message generated by a security management system (or security management software or security management tool) upon detecting abnormal behavior or potential threats within the target device's network environment. Specifically, in different implementation scenarios, the specific conditions for determining a targeted network security alert can be set based on the specific implementation scenario. For example, the specific condition could be an emergency alert level or a severe alert level.

[0076] In some embodiments, step S101 may specifically include: filtering target network security alarms from network security alarms for the target device according to preset alarm filtering conditions; or filtering target network security events from network security events for the target device according to preset event filtering conditions, and determining the network security alarms included in the target network security events as the target network security alarms. The alarm filtering conditions and event filtering conditions may be set based on the implementation scenario.

[0077] In another embodiment, executing step S101 may include: receiving an alarm selection operation input by a user, and determining a target network security alarm for a target device according to the alarm selection operation.

[0078] In another embodiment, executing step S101 may include: receiving a security event selection operation input by a user, determining a reference network security event for a target device based on the security event selection operation, determining a reference network security alarm included in the reference network security event, and determining the reference network security alarm as a target network security alarm.

[0079] S102: Based on the target network security alarm, the security big model is called to perform alarm handling strategy matching processing to obtain the target handling strategy, and the target network security alarm is handled by the security big model based on the target handling strategy to obtain the alarm handling content.

[0080] The safety big model refers to a multimodal big model with alarm handling capabilities. The safety big model can be obtained by training the model for alarm handling scenarios based on the basic multimodal big model.

[0081] Target handling strategy refers to the strategy used to handle target network security alerts.

[0082] The alarm handling content may include the alarm handling behavior taken in response to the alarm, the executing entity of the alarm handling behavior, and the alarm handling result.

[0083] In some embodiments, executing step S102 may specifically include: inputting the target network security alarm into the security big model, obtaining a preset alarm handling strategy through the security big model, searching for a target handling strategy that matches the target network security alarm from the preset alarm handling strategies through the security big model, and then performing alarm handling on the target network security alarm based on the target handling strategy through the security big model to obtain alarm handling content.

[0084] S103, display the alarm handling content.

[0085] In some embodiments, the alarm handling content can be displayed on the service platform. Specifically, an alarm handling display interface can be generated in the service platform, and the alarm handling content can be displayed on the alarm handling display interface.

[0086] Exemplarily, the above-mentioned service platform can be a situational awareness platform, which is a comprehensive security management system. Users can configure alarm handling through the situational awareness platform, or perform alarm handling operations through the situational awareness platform to manage security incidents, threats, vulnerabilities and abnormal behaviors in the network environment.

[0087] In the network security alarm processing method provided in the embodiment of the present application, a target network security alarm for a target device is determined, and based on the target network security alarm, a security big model is called to perform alarm handling strategy matching processing to obtain a target handling strategy. The target network security alarm is handled by the security big model based on the target handling strategy to obtain alarm handling content, and the alarm handling content is displayed. Thus, the target network security alarm is automatically matched with an alarm handling strategy through the security big model, and then the target network security alarm is automatically handled using the matched target handling strategy. This can effectively improve the efficiency of alarm handling, thereby improving the efficiency of network security protection. At the same time, the accuracy of alarm handling is ensured by using the security big model to match alarm handling strategies and handle alarms, thereby improving the accuracy of network security protection.

[0088] See Figure 2 , which is a flow chart of another embodiment of a method for processing network security alarms proposed in this application.

[0089] Specifically, the method for handling the network security alarm includes:

[0090] S201: Determine at least one network security alarm for a target device.

[0091] It is understandable that a network security alarm refers to a prompt message or warning message generated by a security management system (or security management software or security management tool) when it detects abnormal behavior or potential threats in the network environment where the target device is located.

[0092] In some embodiments, executing step S201 may specifically include: obtaining security monitoring data corresponding to the target device, and performing alarm identification processing based on the security monitoring data to obtain at least one network security alarm.

[0093] It is understood that the security monitoring data may include but is not limited to log data, traffic data, vulnerability scanning data, etc. Specifically, a probe tool may be deployed in the target device to obtain the corresponding security monitoring data of the target device through the probe tool.

[0094] Specifically, when identifying network security alerts based on security monitoring data, it is possible to identify network attacks and abnormal behavior based on the security monitoring data to generate network security alerts. For example, an attacker may intrude on a target device through phishing emails, malware, or distributed denial of service attacks, thereby generating a network security alert. Another example is the generation of abnormal behavior such as unauthorized access, abnormal login attempts, or data leakage on a target device, which can also generate a network security alert.

[0095] Optionally, when identifying network security alarms based on security monitoring data, network security alarms can be identified by performing preliminary analysis, correlation analysis, in-depth analysis, and other analytical processing on the security monitoring data.

[0096] The above preliminary analysis may include analysis processes such as keyword matching, threshold analysis, and behavioral pattern analysis. Keyword matching can be understood as filtering out log content that may be related to threats through keyword or regular expression matching; threshold analysis can be understood as detecting abnormal behavior through preset thresholds (such as the number of failed logins, the amount of data transmission, the number of port scans, etc.); behavioral pattern analysis can be understood as identifying potential threats by analyzing behavioral patterns in log data.

[0097] The aforementioned correlation analysis can include horizontal correlation analysis, vertical correlation analysis, time series analysis, and other analysis processes. Horizontal correlation analysis can be understood as correlating log data from different devices to identify cross-device attack behaviors; vertical correlation analysis can be understood as correlating multiple log data from the same device to identify complex attack behaviors; and time series analysis can be understood as sorting and analyzing log data based on timestamps to identify the complete attack process.

[0098] This in-depth analysis can include contextual analysis, threat intelligence matching, and machine learning and AI-assisted analysis. Contextual analysis can be understood as in-depth analysis of log data based on network topology, business processes, and user behavior patterns; threat intelligence matching can be understood as comparing log data with external threat intelligence to identify known threat behaviors; and machine learning and AI-assisted analysis can be understood as analyzing log data using threat identification models created based on machine learning algorithms or AI technologies to identify potential unknown threats.

[0099] S202: Acquire preset alarm screening conditions, and perform alarm screening processing on network security alarms based on the preset alarm screening conditions to obtain target network security alarms.

[0100] It is understandable that the preset alarm screening conditions refer to the search conditions for screening alarms that need to be intelligently handled by the security big model.

[0101] Specifically, the preset alarm screening condition may include at least one preset alarm level. For example, the preset alarm level may be an emergency alarm, a serious alarm, a high-risk alarm, or a medium-risk alarm.

[0102] In some embodiments, the step of obtaining the preset alarm screening condition may specifically include obtaining an alarm automatic operation configuration file, and obtaining the preset alarm screening condition from the alarm automatic operation configuration file.

[0103] Execute alarm screening processing on network security alarms based on preset alarm screening conditions to obtain target network security alarms, specifically: when the preset alarm screening conditions include a preset alarm level, the network security alarm belonging to the preset alarm level is determined as the target network security alarm; when the preset alarm screening conditions include more than two preset alarm levels that are in a parallel relationship, the network security alarm belonging to any one of these preset alarm levels is determined as the target network security alarm.

[0104] S203: Based on the target network security alarm, the security big model is called to perform alarm analysis and processing to obtain alarm analysis information.

[0105] It is understood that alarm analysis information refers to a detailed interpretation of the target network security alarm. For example, alarm analysis information may include the alarm's background, cause, process, impact, potential security threats, and evidence chain. Another example is alarm analysis information that describes the attack chain of a security incident. Another example is alarm analysis information that includes information such as the attack source, intrusion path, and intranet spread.

[0106] In some embodiments, step S203 may be executed, which may specifically include: obtaining a preset alarm handling prompt word template, generating an alarm handling prompt word based on the alarm handling prompt word template and the target network security alarm, inputting the alarm handling prompt word into the security big model, and performing alarm analysis and processing on the target network security alarm through the security big model to obtain alarm analysis information.

[0107] For example, the big security model can provide a comprehensive interpretation of the target network security alert, including the background, cause and process of the alert, the impact of the alert, the potential security threats caused by the alert, and the evidence chain of the alert. It can summarize the background, cause and process of the alert, the impact of the alert, the potential security threats caused by the alert, and the evidence chain of the alert to obtain alert analysis information.

[0108] For example, the alarm analysis information may include the following:

[0109] "Event interpretation: The event recorded in the log is a successful ransomware attack that occurred between 2024-03-18 13:52:57 and 2024-03-18 13:54:26. ​​The attack occurred on the host named "

[0110] v-wangsheng / pc" and "luohao / pc", the host IP addresses are "192.168.3.98" and "192.168.3.77" respectively. The alert shows that the attacker spread the ransomware to the target host through phishing emails and encrypted a large number of files on the target host.

[0111] Background: Ransomware is a type of malware that encrypts user files and demands payment in exchange for a decryption key. Attackers typically spread ransomware through phishing emails, malicious websites, or network attacks.

[0112] Possible cause: The alert data indicates that this incident may have originated from a phishing email. The attachment "Payslip.docx" in the phishing email may be a malicious document. When the user opened the document, the malicious code in it was executed, causing the host to be infected with the ransomware virus.

[0113] What happened: The attacker sent a phishing email to the user of the target host, which contained an attachment named "payslip.docx." This attachment used CVE-2022-30190 to embed malicious ransomware code instructions. After the user opened the attachment, the ransomware code was activated, and the attacker used PowerShell script code to encrypt a large number of documents. Taking the host 192.168.3.77 as an example, the parent process PID is 14888, and the path is "C:\Windows\System32\cmd.exe." The process PID is 12656, and the path is "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe." Its command line parameters contain an encrypted script. This encrypted script is decrypted and executed, resulting in ransomware infection.

[0114] Impact: Ransomware infection can lead to the encryption of users' important files, affecting data availability and integrity. Furthermore, the infection can spread to other devices on the network, causing greater damage.

[0115] Potential security threats: Ransomware attacks can not only cause data loss or corruption, but can also lead to financial losses. Furthermore, if attackers are able to further penetrate the network through a ransomware-infected host, they could pose a greater threat to the entire network.

[0116] Analysis: Based on the alert and log information, we can conclude that the attack was successful, as the log clearly shows that multiple user file names were renamed, including financial report.xls.lockbit, employee list.xls.lockbit, etc.

[0117] For example, the big security model can find the attack entry point of the security incident, the attack continuation process of the security incident, and the potential data leakage caused by the security incident based on the target network security alarm, summarize the attack entry point of the security incident, the attack continuation process of the security incident, and the potential data leakage caused by the security incident, and obtain alarm analysis information.

[0118] Specifically, the alarm handling prompt word can be task description information used to instruct the security big model to conduct alarm analysis and alarm handling of the target network security alarm. Exemplarily, the alarm handling prompt word can include obtaining role description information, background information, alarm analysis task description information, alarm handling task description information and other information. Among them, the role description information can be the description information of the identity, responsibilities or specific character image set for the big model; the background information can refer to the relevant pre-information, environment description, relevant knowledge or historical dialogue provided for the big model to perform the task; the alarm analysis task description information is used to instruct the security big model to conduct alarm analysis and processing based on the target network security alarm to obtain alarm analysis information; the alarm handling task description information is used to instruct the security big model to perform alarm handling on the target network security alarm based on the alarm analysis information.

[0119] Specifically, the security big model can determine the target handling strategy corresponding to the target network security alarm based on the alarm handling task description information and the alarm analysis information, and use the target handling strategy to handle the target network security alarm.

[0120] Optionally, the training process of the large security model may include the following steps:

[0121] Use a multimodal large language model to create an initial large security model for alarm handling scenarios;

[0122] Obtain a sample network security alarm, and label the sample network security alarm with an alarm handling strategy label and an alarm handling content label; wherein the alarm handling content label may include an alarm handling behavior label, an alarm handling behavior execution subject label, and an alarm handling result label;

[0123] Use sample network security alerts to conduct at least one round of model training on the initial security model;

[0124] During the model forward propagation training process, the initial security big model is called based on the sample network security alarm to perform alarm handling strategy matching processing to obtain a predicted alarm handling strategy, and the initial security big model is used to perform alarm handling on the sample network security alarm based on the predicted alarm handling strategy to obtain the predicted alarm handling content;

[0125] During the model backpropagation training process, the predicted alarm handling strategy and the alarm handling strategy label are used to determine the first loss value, the predicted alarm handling content and the alarm handling content label are used to determine the second loss value, and the comprehensive model loss is determined based on the first loss value and the second loss value;

[0126] The model parameters of the initial security large model are adjusted based on the comprehensive model loss to obtain the security large model after model training.

[0127] Optionally, the first loss value and the second loss value can be calculated using any one of the hinge loss function, contrast loss function, Euclidean distance loss function or cross entropy loss function in the relevant technology.

[0128] Optionally, the execution of using a multimodal big language model to create an initial security big model for the alarm handling scenario can be: obtaining the multimodal big language model, creating an alarm handling scenario adaptation module for the alarm handling scenario and a big language generation module based on the multimodal big language model, and forming the initial security big model based on the big language generation module and the alarm handling scenario adaptation module.

[0129] Parameter adjustments are performed on the initial security model based on the comprehensive model loss to obtain a trained security model. This can include adjusting the model parameters of the initial alarm handling scenario adaptation module in the initial security model based on the comprehensive model loss, while maintaining the model parameters of the large language generation module unchanged. This continues until the model training completion conditions are met, resulting in the large language generation module and the alarm handling scenario adaptation module. This completes the model fusion of the large language generation module and the alarm handling scenario adaptation module, resulting in a trained security model.

[0130] Optionally, the model fusion of the large language generation module and the alarm handling scenario adaptation module can be: weight fusion of the model structure layer weight of the alarm handling scenario adaptation module and the large language generation module, by determining the target model structure layer corresponding to the model structure layer weight in the large language generation module, parameter fusion of the model structure layer parameters of the target model structure layer and the model structure layer weight, the model structure layer weight of the alarm handling scenario adaptation module can only partially correspond to and have model structure layer weights in all model structure layers in the multimodal large language model, by completing the parameter update of the model structure layer based on the model structure layer weight for this part of the target model structure layer, and so on, completing the reference update process of all model structure layer weights, thereby obtaining a safe large model.

[0131] Optionally, the model training termination conditions for the large security model may include, for example, the loss function value being less than or equal to a preset loss function threshold, the number of iterations reaching a preset number threshold, etc. Specific model training termination conditions can be determined based on actual conditions and are not specifically limited here.

[0132] S204, based on the alarm analysis information, the alarm attributes and the alarm analysis result of the target network security alarm are identified, and the alarm handling strategy is matched with the preset handling strategy according to the alarm analysis result and the alarm attributes through the security big model to obtain the target handling strategy.

[0133] It is understood that alarm attributes refer to alarm description information used to characterize alarm classification and / or alarm level. For example, alarm attributes may include but are not limited to alarm level, alarm type, threat type, vulnerability type, attack type, etc.

[0134] The alarm analysis result refers to the analysis result used to characterize the attack status of the alarm. For example, the alarm analysis result may include but is not limited to attack success, attack failure, and unknown attack status.

[0135] In some embodiments, the alarm attributes and alarm analysis results of the target network security alarm are identified based on the alarm analysis information. Specifically, it can be: identifying the target alarm classification and / or target alarm level of the target network security alarm according to the alarm analysis information through the security big model, generating alarm attributes according to the target alarm classification and / or target alarm level, and identifying the alarm analysis results of the target network security alarm according to the alarm analysis information through the security big model.

[0136] In some embodiments, alarm handling strategy matching processing is performed on the preset handling strategy according to the alarm analysis results and alarm attributes through the security big model to obtain the target handling strategy. Specifically, it can be: obtaining the priority of the preset handling strategy, sorting the preset handling strategy according to the priority to obtain a reference handling strategy sequence; performing alarm handling strategy matching processing on the reference handling strategy sequence according to the alarm analysis results and alarm attributes through the security big model to obtain the target handling strategy.

[0137] Specifically, the aforementioned ordering of the preset disposal strategies by priority to obtain the reference disposal strategy sequence may be performed by ordering the preset disposal strategies in descending order of priority to obtain the reference disposal strategy sequence. For example, there are preset disposal strategies 1, 2, and 3, and the priority of preset disposal strategy 2 is higher than that of preset disposal strategy 1, and the priority of preset disposal strategy 1 is higher than that of preset disposal strategy 3. Then, in the reference disposal strategy sequence, preset disposal strategy 2 is ranked first, preset disposal strategy 1 is ranked second, and preset disposal strategy 3 is ranked third.

[0138] The above-mentioned implementation method of obtaining the target handling strategy can be: using the security big model to determine whether the target network alarm matches the preset handling strategy ranked first in the reference handling strategy sequence based on the alarm analysis results and alarm attributes; if it matches, the preset handling strategy ranked first in the reference handling strategy sequence is determined as the target handling strategy, and the matching process is ended; if it does not match, using the security big model to determine whether the target network alarm matches the preset handling strategy ranked second in the reference handling strategy sequence based on the alarm analysis results and alarm attributes; if it matches, the preset handling strategy ranked second in the reference handling strategy sequence is determined as the target handling strategy, and the matching process is ended; if it does not match, and so on, the security big model is used to determine one by one whether the preset handling strategies arranged later in the reference handling strategy sequence match the target network security alarm, until a preset handling strategy matching the target network security alarm is found, and the matching process is stopped.

[0139] Specifically, each preset handling strategy may include a preset analysis result and a preset alarm attribute. The security big model compares the preset analysis result with the alarm analysis result, and compares the preset alarm attribute with the alarm attribute to determine whether the preset handling strategy is a target handling strategy that matches the target network security alarm. It is understandable that when the preset handling strategy includes a preset analysis result, and the preset handling strategy includes a preset alarm attribute, the alarm analysis result is the same as the preset analysis result, and the alarm attribute is the same as the preset alarm attribute, the preset handling strategy is determined to be the target handling strategy that matches the target network security alarm. Otherwise, the preset handling strategy is not the target handling strategy. When the preset handling strategy includes a preset analysis result, and the preset handling strategy includes multiple preset alarm attributes, the alarm analysis result is the same as the preset analysis result, and the alarm attribute also includes the same attributes as each preset alarm attribute, the preset handling strategy is determined to be the target handling strategy that matches the target network security alarm. Otherwise, the preset handling strategy is not the target handling strategy. When the preset handling strategy includes multiple preset analysis and judgment results, and the preset handling strategy includes a preset alarm attribute, and the alarm analysis and judgment result is the same as any of the preset analysis and judgment results, and the alarm attribute is the same as the preset alarm attribute, the preset handling strategy is determined to be the target handling strategy that matches the target network security alarm; otherwise, the preset handling strategy is not the target handling strategy. When the preset handling strategy includes multiple preset analysis and judgment results, and the preset handling strategy includes multiple preset alarm attributes, and the alarm analysis and judgment result is the same as any of the preset analysis and judgment results, and the alarm attribute also includes attributes that are the same as each of the preset alarm attributes, the preset handling strategy is determined to be the target handling strategy that matches the target network security alarm; otherwise, the preset handling strategy is not the target handling strategy.

[0140] S205 , determining a target handling decision according to the target handling strategy through the security big model, and performing alarm handling on the target network security alarm according to the target handling decision through the security big model to obtain alarm handling content.

[0141] In some embodiments, determining a target handling decision based on a target handling policy using a security model may include the following steps:

[0142] A1: Determine the preset response plan corresponding to the target response strategy through the security model;

[0143] A2: Determine the plan matching parameters corresponding to the target network security alarm based on the preset disposal plan through the security big model, determine the plan parameter detection threshold corresponding to the preset disposal plan, and determine the target disposal decision corresponding to the plan matching parameters from the preset disposal plan based on the plan parameter detection threshold.

[0144] In step A1, the preset handling plan refers to the alarm handling scheme set for the target handling strategy based on expert experience. Specifically, the preset handling plan corresponding to the target handling strategy is obtained from the handling strategy configuration file through the security big model.

[0145] In step A2, for each preset handling plan, it may include at least one parameter. The parameter value corresponding to each parameter is identified from the target network security alarm through the security big model, and at least one plan matching parameter can be obtained. Each plan matching parameter includes the parameter value of a parameter included in the preset handling plan, and the plan parameter detection threshold corresponding to each parameter included in the preset handling plan is determined. Each plan parameter detection threshold is used to match one alarm handling decision from two alarm handling decisions. Each plan matching parameter is compared with the plan parameter detection threshold corresponding to each plan matching parameter to determine the alarm handling decision corresponding to each plan matching parameter. The alarm handling decision corresponding to each pre-parameter matching parameter is summarized to obtain the target handling decision.

[0146] It is understood that the target handling decisions may include, but are not limited to, blocking access from malicious IP addresses, isolating infected devices, suspending access rights of related accounts, checking and removing files, blocking emails, etc. For example, for the decision to block access from malicious IP addresses, the security model may take the action of IP blocking.

[0147] It is understandable that the alarm handling content may include the alarm handling behavior taken in response to the alarm, the execution subject of the alarm handling behavior, and the alarm handling result.

[0148] S206: Determine the alarm handling process and alarm handling result based on the alarm handling content.

[0149] In some embodiments, the execution order of the alarm handling behaviors in the alarm handling content can be determined, and the alarm handling process can be obtained by summarizing the execution order of the handling behaviors and the executing subjects of the alarm behaviors. The alarm handling results can be extracted from the alarm handling content. The alarm handling results can be understood as the handling results obtained by summarizing the handling results generated by executing the alarm handling behaviors.

[0150] Exemplary alarm handling behaviors may include: intelligent extraction of phishing email features and email blocking; extraction of Indicators of Compromise (IOC) samples, intranet regression of IOC samples, file detection and removal, and intelligent host isolation; extraction of vulnerabilities and intelligent matching of host vulnerabilities; extraction of IOC attacker IPs and IP blocking.

[0151] For the alarm handling behaviors listed above, the alarm handling result can be "Account w******@abc.com was extracted based on the characteristics of phishing emails, and the email security gateway has been called to block the email. Based on the text sample 41139***************d0, it was marked as blacklisted, and sample regression was performed on the intranet. The same sample was found on 4 hosts, and a check and elimination operation was performed. Based on the CVE-2022-30190 vulnerability, a host vulnerability query was performed, 56 hosts were scanned, 3 vulnerabilities were found, and the hosts with the vulnerability were isolated."

[0152] S207: Receive an alarm handling display operation for the target network security alarm on the handling display interface of the situation awareness platform.

[0153] As you can see, a situational awareness platform is a comprehensive security management system that collects, processes, and analyzes security data from various network devices, systems, and applications in real time to comprehensively perceive, analyze, and predict security incidents, threats, vulnerabilities, and abnormal behavior within the network environment. The platform is designed to help businesses and organizations proactively detect security threats and respond to security incidents promptly, thereby protecting the security and stability of network systems.

[0154] In some embodiments, the handling display interface is a user interface for displaying alarm handling details. In the handling display interface, an alarm handling display control can be displayed, and the alarm handling display operation for the target network security alarm input by the user touching the alarm handling display control can be received.

[0155] S208 , in response to the alarm handling display operation, display the alarm handling process and the alarm handling result.

[0156] Specifically, in response to the alarm handling display operation, the alarm handling process and the alarm handling result may be displayed on the handling display interface.

[0157] In the network security alarm processing method provided in the embodiment of the present application, at least one network security alarm for the target device is determined, preset alarm screening conditions are obtained, and the network security alarm is screened based on the preset alarm screening conditions to obtain the target network security alarm. In this way, the target network security alarm is screened by the preset alarm screening conditions, so that the alarms that generate key threats can be handled with priority; thereafter, the security big model is called to perform alarm analysis and processing based on the target network security alarm to obtain alarm analysis information, and the alarm attributes and alarm analysis results of the target network security alarm are identified based on the alarm analysis information. The alarm processing strategy is matched with the preset processing strategy according to the alarm analysis results and alarm attributes by the security big model to obtain the target processing strategy. In this way, with the help of the powerful event analysis and semantic understanding capabilities of the security big model, the attack behavior can be accurately identified and interpreted, and specialized information can be obtained. Professional and accurate attack interpretation information is obtained, and accurate alarm handling strategies can be matched through professional and accurate attack interpretation information; then, the target handling decision is determined according to the target handling strategy through the security big model, and the target network security alarm is handled according to the target handling decision through the security big model to obtain the alarm handling content. In this way, accurate handling decisions are determined through accurate alarm handling strategies, which can ensure accurate handling of alarms; then, the alarm handling process and alarm handling results are determined based on the alarm handling content, and the alarm handling display operation for the target network security alarm is received on the handling display interface of the situation awareness platform. In response to the alarm handling display operation, the alarm handling process and alarm handling results are displayed. In this way, by displaying detailed information on the alarm handling, security personnel can be assisted to quickly and comprehensively understand the threat process of the alarm, which is convenient for assisting security personnel to quickly improve network security protection.

[0158] See Figure 3 , which is a flow chart of another embodiment of a method for processing network security alarms proposed in this application.

[0159] S301: Determine at least one network security event for a target device.

[0160] It can be understood that a network security incident refers to an event that has an impact or threat to the network, device, system or data, which is obtained through correlation analysis and context evaluation of multiple related network security alerts in network security management.

[0161] In some embodiments, executing step S301 may specifically include: obtaining security monitoring data corresponding to the target device, performing alarm identification processing based on the security monitoring data to obtain at least one network security alarm, performing correlation analysis and context evaluation on the at least one network security alarm, and obtaining at least one network security event.

[0162] It is understood that the security monitoring data may include but is not limited to log data, traffic data, vulnerability scanning data, etc. Specifically, a probe tool may be deployed in the target device to obtain the corresponding security monitoring data of the target device through the probe tool.

[0163] Specifically, when identifying network security alerts based on security monitoring data, it is possible to identify network attacks and abnormal behavior based on the security monitoring data to generate network security alerts. For example, an attacker may intrude on a target device through phishing emails, malware, or distributed denial of service attacks, thereby generating a network security alert. Another example is the generation of abnormal behavior such as unauthorized access, abnormal login attempts, or data leakage on a target device, which can also generate a network security alert.

[0164] Specifically, when performing correlation analysis and context evaluation on at least one network security alarm to obtain at least one network security event, the correlation analysis may include time correlation analysis, IP address correlation analysis, device correlation analysis, and behavior pattern correlation analysis, and the context evaluation may include business context evaluation, user context evaluation, network topology context evaluation, and threat intelligence context evaluation.

[0165] The aforementioned time correlation analysis can be understood as analyzing the chronological order of alarm occurrences to identify whether an attack path exists. The aforementioned IP address correlation analysis can be understood as analyzing the IP addresses involved in the alarms to identify whether there is an association with the attack source. The aforementioned device correlation analysis can be understood as analyzing the devices involved in the alarms to identify whether there is an association with the attack target. The aforementioned behavior pattern correlation can be understood as analyzing the behavior patterns involved in the alarms to identify whether there is an association with the attack method.

[0166] The business context assessment mentioned above can be understood as evaluating whether the associated alerts are relevant to business processes. The user context assessment mentioned above can be understood as evaluating whether the associated alerts are relevant to user behavior. The network topology context assessment mentioned above can be understood as evaluating whether the associated alerts are relevant to the network topology. The threat intelligence context assessment mentioned above can be understood as evaluating whether the associated alerts are relevant to known threat intelligence.

[0167] S302: Obtain preset security event screening conditions, and perform event screening processing on network security events based on the preset security event screening conditions to obtain target network security events.

[0168] It is understandable that the preset security event screening condition may include a preset event level. For example, the preset event level may be an event level greater than or equal to a warning level.

[0169] In some embodiments, the step of obtaining the preset security event screening condition may specifically include obtaining a security event automatic operation configuration file, and obtaining the preset security event screening condition from the security event automatic operation configuration file.

[0170] Performing event screening processing on network security events based on preset security event screening conditions to obtain target network security events can specifically include: screening network security events whose event levels match the preset event levels as target network security events.

[0171] S303: Determine the alarm sub-item included in the target network security event, and determine the alarm sub-item as the target network security alarm.

[0172] Specifically, the alarm sub-item refers to the network security alarm that constitutes the target network security event, and the alarm sub-item (ie, the network security alarm that constitutes the target network security event) is determined as the target network security alarm.

[0173] S304: Based on the target network security alarm, the security big model is called to perform alarm analysis and processing to obtain alarm analysis information.

[0174] S305, based on the alarm analysis information, the alarm attributes and the alarm analysis result of the target network security alarm are identified, and the alarm handling strategy is matched with the preset handling strategy according to the alarm analysis result and the alarm attributes through the security big model to obtain the target handling strategy.

[0175] S306, determining a target handling decision according to the target handling strategy through the security big model, and performing alarm handling on the target network security alarm according to the target handling decision through the security big model to obtain alarm handling content.

[0176] S307: Determine the alarm handling process and alarm handling result based on the alarm handling content.

[0177] S308: Receive an alarm handling display operation for the target network security alarm on the handling display interface of the situation awareness platform.

[0178] S309 , in response to the alarm handling display operation, display the alarm handling process and the alarm handling result.

[0179] Specifically, the implementation of steps S304-S309 can be found in Figure 2 The description of the relevant steps in the illustrated embodiment will not be repeated in detail here.

[0180] In the method for processing network security alarms provided in the embodiment of the present application, at least one network security event for a target device is determined, preset security event screening conditions are obtained, and event screening processing is performed on the network security event based on the preset security event screening conditions to obtain a target network security event, and the alarm sub-items included in the target network security event are determined, and the alarm sub-items are determined as target network security alarms. In this way, by screening key network security events through the preset security event screening conditions, it can be ensured that alarms in key network security events can be handled with priority; thereafter, based on the target network security alarm, the security big model is called to perform alarm analysis and processing to obtain alarm analysis information, and based on the alarm analysis information, the alarm attributes and alarm analysis results of the target network security alarm are identified, and the alarm processing strategy is matched with the preset processing strategy according to the alarm analysis result and alarm attributes through the security big model to obtain the target processing strategy. In this way, with the help of the powerful event analysis and semantics of the security big model, The ability to understand and accurately identify and interpret attack behaviors can be used to obtain professional and accurate attack interpretation information, and the professional and accurate attack interpretation information can be used to match accurate alarm handling strategies. Afterwards, the target handling decision is determined according to the target handling strategy through the security big model, and the target network security alarm is handled according to the target handling decision through the security big model to obtain the alarm handling content. In this way, accurate handling decisions are determined through accurate alarm handling strategies, which can ensure accurate handling of alarms. Then, based on the alarm handling content, the alarm handling process and alarm handling results are determined, and the alarm handling display operation for the target network security alarm is received on the handling display interface of the situation awareness platform. In response to the alarm handling display operation, the alarm handling process and alarm handling results are displayed. In this way, by displaying detailed information on the alarm handling, security personnel can be assisted to quickly and comprehensively understand the threat process of the alarm, which is convenient for assisting security personnel to quickly improve network security protection.

[0181] The following will be combined Figure 4 , the network security alarm processing device provided by the embodiment of the present application is introduced in detail. It should be noted that, Figure 4 The network security warning processing device shown is used to execute the application Figures 1 to 3 For the convenience of explanation, only the part related to the embodiment of the present application is shown. For the specific technical details not disclosed, please refer to the present application. Figures 1 to 3 The embodiment shown.

[0182] See Figure 4, which shows a schematic diagram of the structure of a network security alarm processing device according to an embodiment of the present application. The network security alarm processing device 1 can be implemented as all or part of the device through software, hardware, or a combination of both. According to some embodiments, the network security alarm processing device 1 includes an alarm processing module 11, an alarm handling module 12, and a handling display module 13, which are specifically used to:

[0183] An alarm processing module 11 is used to determine a target network security alarm for a target device;

[0184] An alarm handling module 12 is configured to call a security big model based on the target network security alarm to perform alarm handling strategy matching processing to obtain a target handling strategy, and perform alarm handling on the target network security alarm based on the target handling strategy using the security big model to obtain alarm handling content;

[0185] The handling display module 13 is used to display the alarm handling content.

[0186] Optionally, the alarm handling module 12 includes:

[0187] An alarm analysis unit is used to call a security big model to perform alarm analysis and processing based on the target network security alarm to obtain alarm analysis information;

[0188] A policy matching unit is used to identify the alarm attributes and alarm analysis results of the target network security alarm based on the alarm analysis information, and to match the preset handling strategy with the alarm analysis results and the alarm attributes through the security big model to obtain the target handling strategy.

[0189] Optional policy matching unit, specifically used to:

[0190] Obtaining priorities of preset processing strategies, and sorting the preset processing strategies according to the priorities to obtain a reference processing strategy sequence;

[0191] The security big model performs alarm handling strategy matching processing on the reference handling strategy sequence according to the alarm analysis result and the alarm attribute to obtain a target handling strategy.

[0192] Optionally, the alarm handling module 12 includes:

[0193] The alarm handling unit is used to determine a target handling decision according to the target handling strategy through the security big model, and to perform alarm handling on the target network security alarm according to the target handling decision through the security big model to obtain alarm handling content.

[0194] Optional alarm handling unit, specifically used to:

[0195] Determine a preset disposal plan corresponding to the target disposal strategy through the security big model;

[0196] The security big model determines the plan matching parameters corresponding to the target network security alarm according to the preset disposal plan, determines the plan parameter detection threshold corresponding to the preset disposal plan, and determines the target disposal decision corresponding to the plan matching parameters from the preset disposal plan according to the plan parameter detection threshold.

[0197] Optionally, the alarm processing module 11 includes:

[0198] an alarm determining unit, configured to determine at least one network security alarm for a target device;

[0199] The alarm screening unit is used to obtain a preset alarm screening condition, and perform alarm screening processing on the network security alarm based on the preset alarm screening condition to obtain a target network security alarm.

[0200] Optionally, the alarm processing module 11 includes:

[0201] an event determination unit, configured to determine at least one network security event for a target device;

[0202] An event screening unit, configured to obtain a preset security event screening condition, and perform event screening processing on the network security event based on the preset security event screening condition to obtain a target network security event;

[0203] The event splitting unit is used to determine the alarm sub-items included in the target network security event and determine the alarm sub-items as target network security alarms.

[0204] Optionally, the alarm display module 13 is further configured to:

[0205] Determining an alarm handling process and an alarm handling result based on the alarm handling content;

[0206] On the handling display interface of the situation awareness platform, receiving an alarm handling display operation for the target network security alarm;

[0207] In response to the alarm handling display operation, the alarm handling process and the alarm handling result are displayed.

[0208] The network security alarm processing device provided in the embodiment of the present application determines a target network security alarm for a target device, calls a security big model based on the target network security alarm to perform alarm handling strategy matching processing to obtain a target handling strategy, performs alarm handling processing on the target network security alarm based on the target handling strategy through the security big model to obtain alarm handling content, and displays the alarm handling content. Thus, the target network security alarm is automatically matched with an alarm handling strategy through the security big model, and then the target network security alarm is automatically handled using the matched target handling strategy, which can effectively improve the efficiency of alarm handling, thereby improving the efficiency of network security protection. At the same time, the accuracy of alarm handling is guaranteed by matching alarm handling strategies and handling alarms with the security big model, thereby improving the accuracy of network security protection.

[0209] Please refer to Figure 5 , Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. The electronic device may include one or more of the following components: a processor 110, a memory 120, an input device 130, an output device 140, and a bus 150. The processor 110, the memory 120, the input device 130, and the output device 140 may be connected via the bus 150.

[0210] The processor 110 may include one or more processing cores. The processor 110 utilizes various interfaces and circuits to connect various components within the electronic device. It executes instructions, programs, code sets, or instruction sets stored in the memory 120, as well as accesses data stored in the memory 120, to perform various functions of the electronic device and process data. Optionally, the processor 110 may be implemented using at least one of the following hardware forms: a digital signal processing (DSP), a field-programmable gate array (FPGA), or a programmable logic array (PLA). The processor 110 may integrate one or a combination of a central processing unit (CPU), a graphics processing unit (GPU), and a modem. The CPU primarily handles the operating system, user interface, and application programs; the GPU is responsible for rendering and drawing display content; and the modem handles wireless communications. It is understood that the modem may not be integrated into the processor 110 and may be implemented separately via a communications chip.

[0211] The memory 120 may include a random access memory (RAM) or a read-only memory (ROM). Optionally, the memory 120 includes a non-transitory computer-readable storage medium. The memory 120 may be used to store instructions, programs, codes, code sets, or instruction sets. The memory 120 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for implementing at least one function (such as a touch function, a sound playback function, an image playback function, etc.), instructions for implementing the following various method embodiments, etc. The operating system may be an Android system, including a system deeply developed based on the Android system, an iOS system developed by Apple, including a system deeply developed based on the iOS system, or other systems.

[0212] In order for the operating system to distinguish the specific application scenarios of third-party applications, it is necessary to open up data communication between third-party applications and the operating system so that the operating system can obtain the current scenario information of third-party applications at any time, and then perform targeted system resource adaptation based on the current scenario.

[0213] The input device 130 is used to receive input commands or data and includes, but is not limited to, a keyboard, a mouse, a camera, a microphone, or a touch-sensitive device. The output device 140 is used to output commands or data and includes, but is not limited to, a display device and a speaker. In one example, the input device 130 and the output device 140 may be combined, and the input device 130 and the output device 140 may be a touch-sensitive display.

[0214] The touch display screen can be designed as a full screen, a curved screen or a special-shaped screen. The touch display screen can also be designed as a combination of a full screen and a curved screen, or a combination of a special-shaped screen and a curved screen, which is not limited in the embodiments of the present application.

[0215] In addition, those skilled in the art will understand that the structures of the electronic devices shown in the above figures do not limit the electronic devices. The electronic devices may include more or fewer components than shown, or may combine certain components, or arrange the components differently. For example, the electronic devices may also include radio frequency circuits, input units, sensors, audio circuits, wireless fidelity (WiFi) modules, power supplies, Bluetooth modules, and other components, which will not be described in detail here.

[0216] In some embodiments, Figure 5In the electronic device shown, the processor 110 may be configured to call a program for a method for processing a network security alarm stored in the memory 120 and specifically perform the following operations:

[0217] Identify target network security alerts for target devices;

[0218] Based on the target network security alarm, the security big model is called to perform alarm handling strategy matching processing to obtain a target handling strategy, and the target network security alarm is handled by the security big model based on the target handling strategy to obtain alarm handling content;

[0219] Display the alarm handling content.

[0220] In one embodiment, when executing the step of invoking the security big model based on the target network security alarm to perform alarm handling policy matching processing to obtain the target handling policy, the processor 110 specifically performs the following operations:

[0221] Based on the target network security alarm, the security big model is called to perform alarm analysis and processing to obtain alarm analysis information;

[0222] Based on the alarm analysis information, the alarm attributes and alarm analysis results of the target network security alarm are identified, and the alarm handling strategy matching processing is performed on the preset handling strategy according to the alarm analysis results and the alarm attributes through the security big model to obtain the target handling strategy.

[0223] In one embodiment, when executing the step of matching the preset handling strategies with the security big model according to the alarm analysis result and the alarm attribute to obtain the target handling strategy, the processor 110 specifically performs the following operations:

[0224] Obtaining priorities of preset processing strategies, and sorting the preset processing strategies according to the priorities to obtain a reference processing strategy sequence;

[0225] The security big model performs alarm handling strategy matching processing on the reference handling strategy sequence according to the alarm analysis result and the alarm attribute to obtain a target handling strategy.

[0226] In one embodiment, when executing the step of performing alarm handling on the target network security alarm based on the target handling policy using the security big model to obtain alarm handling content, the processor 110 specifically performs the following operations:

[0227] The target handling decision is determined according to the target handling strategy by the security big model, and the target network security alarm is handled according to the target handling decision by the security big model to obtain alarm handling content.

[0228] In one embodiment, when executing the step of determining a target handling decision according to the target handling policy using the security model, the processor 110 specifically performs the following operations:

[0229] Determine a preset disposal plan corresponding to the target disposal strategy through the security big model;

[0230] The security big model determines the plan matching parameters corresponding to the target network security alarm according to the preset disposal plan, determines the plan parameter detection threshold corresponding to the preset disposal plan, and determines the target disposal decision corresponding to the plan matching parameters from the preset disposal plan according to the plan parameter detection threshold.

[0231] In one embodiment, when executing the step of determining a target network security alarm for a target device, the processor 110 specifically performs the following operations:

[0232] determining at least one network security alert for the target device;

[0233] A preset alarm screening condition is obtained, and the network security alarm is screened based on the preset alarm screening condition to obtain a target network security alarm.

[0234] In one embodiment, when executing the step of determining a target network security alarm for a target device, the processor 110 specifically performs the following operations:

[0235] determining at least one cybersecurity event for a target device;

[0236] Acquire a preset security event screening condition, and perform event screening processing on the network security event based on the preset security event screening condition to obtain a target network security event;

[0237] Determine the alarm sub-item included in the target network security event, and determine the alarm sub-item as a target network security alarm.

[0238] In one embodiment, when executing the step of displaying the alarm handling content, the processor 110 specifically performs the following operations:

[0239] Determining an alarm handling process and an alarm handling result based on the alarm handling content;

[0240] On the handling display interface of the situation awareness platform, receiving an alarm handling display operation for the target network security alarm;

[0241] In response to the alarm handling display operation, the alarm handling process and the alarm handling result are displayed.

[0242] An embodiment of the present application further provides a computer-readable storage medium storing at least one instruction, wherein the at least one instruction is used to be executed by a processor to implement the method for processing network security alarms as described in the above embodiments.

[0243] An embodiment of the present application further provides a computer program product, which stores at least one instruction, and the at least one instruction is loaded and executed by the processor to implement the network security alarm processing method described in the above embodiments.

[0244] Those skilled in the art will appreciate that in one or more of the above examples, the functions described in the embodiments of the present application can be implemented using hardware, software, firmware, or any combination thereof. When implemented using software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. Computer-readable media include computer storage media and communication media, wherein communication media include any media that facilitates the transmission of computer programs from one place to another. The storage medium can be any available medium that can be accessed by a general-purpose or special-purpose computer.

[0245] The above description is merely an optional embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application shall be included in the scope of protection of the present application.

Claims

1. A method for processing network security alarms, characterized in that: The method comprises: Identify target network security alerts for target devices; Based on the target network security alarm, the security big model is called to perform alarm handling strategy matching processing to obtain a target handling strategy, and the target network security alarm is handled by the security big model based on the target handling strategy to obtain alarm handling content; Display the alarm handling content.

2. The method according to claim 1, characterized in that The step of calling the security big model based on the target network security alarm to perform alarm handling strategy matching processing to obtain the target handling strategy includes: Based on the target network security alarm, the security big model is called to perform alarm analysis and processing to obtain alarm analysis information; Based on the alarm analysis information, the alarm attributes and alarm analysis results of the target network security alarm are identified, and the alarm handling strategy matching processing is performed on the preset handling strategy according to the alarm analysis results and the alarm attributes through the security big model to obtain the target handling strategy.

3. The method according to claim 2, characterized in that The method of performing alarm handling strategy matching processing on a preset handling strategy according to the alarm analysis result and the alarm attribute by the security big model to obtain a target handling strategy includes: Obtaining priorities of preset processing strategies, and sorting the preset processing strategies according to the priorities to obtain a reference processing strategy sequence; The security big model performs alarm handling strategy matching processing on the reference handling strategy sequence according to the alarm analysis result and the alarm attribute to obtain a target handling strategy.

4. The method according to claim 1, wherein The step of performing alarm handling on the target network security alarm based on the target handling strategy by the security big model to obtain alarm handling content includes: The target handling decision is determined according to the target handling strategy by the security big model, and the target network security alarm is handled according to the target handling decision by the security big model to obtain alarm handling content.

5. The method according to claim 4, characterized in that Determining a target handling decision according to the target handling strategy using the security big model includes: Determine a preset disposal plan corresponding to the target disposal strategy through the security big model; The security big model determines the plan matching parameters corresponding to the target network security alarm according to the preset disposal plan, determines the plan parameter detection threshold corresponding to the preset disposal plan, and determines the target disposal decision corresponding to the plan matching parameters from the preset disposal plan according to the plan parameter detection threshold.

6. The method according to claim 1, characterized in that Determining a target network security alarm for a target device includes: determining at least one network security alert for the target device; A preset alarm screening condition is obtained, and the network security alarm is screened based on the preset alarm screening condition to obtain a target network security alarm.

7. The method according to claim 1, characterized in that Determining a target network security alarm for a target device includes: determining at least one cybersecurity event for a target device; Acquire a preset security event screening condition, and perform event screening processing on the network security event based on the preset security event screening condition to obtain a target network security event; Determine the alarm sub-item included in the target network security event, and determine the alarm sub-item as a target network security alarm.

8. A network security alarm processing device, characterized in that: The device comprises: An alarm processing module is used to determine a target network security alarm for a target device; An alarm handling module is configured to call a security big model based on the target network security alarm to perform alarm handling strategy matching processing to obtain a target handling strategy, and perform alarm handling on the target network security alarm based on the target handling strategy using the security big model to obtain alarm handling content; The processing display module is used to display the alarm processing content.

9. A computer storage medium, characterized in that The computer storage medium stores a plurality of instructions, and the instructions are suitable for being loaded by a processor and executing the method according to any one of claims 1 to 7.

10. An electronic device, characterized in that: include: A processor and a memory; wherein the memory stores a computer program, and the computer program is suitable for being loaded by the processor and executing the method according to any one of claims 1 to 7.