Method and device for monitoring network security threats

Through a network security threat monitoring method based on a relational database, the problem of a large number of EDR device alarms is solved by utilizing log time grouping and anomaly judgment rules. This achieves noise reduction and filtering of monitoring logs and reduces the number of alarms, thereby improving the efficiency of network security threat monitoring.

CN120658483APending Publication Date: 2025-09-16CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510934439.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-07
Publication Date
2025-09-16

AI Technical Summary

Technical Problem

Existing terminal detection and response (EDR) devices generate a huge amount of threat monitoring alerts, and there are a large number of non-attack vulnerability events, which increases the workload of processing personnel and reduces efficiency.

Method used

Through the network security threat monitoring method based on relational database, the log time grouping and aggregation period are used to determine the characteristic indicators of basic log information. Combined with the anomaly judgment rules, abnormal logs are identified in a hierarchical manner to achieve noise reduction and filtering of monitoring logs and reduce the number of alarms.

Benefits of technology

It effectively reduces the number of alarms to be processed, improves the efficiency of network security threat monitoring, avoids alarm accumulation, and improves the work efficiency of processing personnel.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120658483A_ABST
    Figure CN120658483A_ABST
Patent Text Reader

Abstract

The invention provides a network security threat monitoring method and device, and relates to the technical field of network security. The method comprises the following steps: determining basic log information corresponding to an aggregation time period according to log time included in monitoring log information of EDR equipment; determining a first feature index of the basic log information according to the basic log information; determining first abnormal grouped log information and normal grouped log information in the basic log information according to the first feature index and a preset first abnormal judgment rule; determining sub-grouping log information corresponding to the normal grouping log information according to the normal grouping log information and the threat type; determining a second feature index of the sub-group log information according to the sub-group log information; determining second abnormal grouped log information in the normal grouped log information according to the second feature index and a preset second abnormal judgment rule; and obtaining alarm log information based on the first abnormal grouping log information and the second abnormal grouping log information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of network security technology, and in particular to a method and apparatus for monitoring network security threats. Background Art

[0002] Current endpoint detection and response (EDR) devices generate a massive amount of threat monitoring alerts, including numerous recurring vulnerability events that are not offensive in nature. These events often involve numerous hosts and users, generating tens of thousands of alerts that need to be processed every day.

[0003] EDR device alarm logs typically lack source IP addresses, only relevant information such as victim IP addresses and threat events. These logs are constantly adding more victim IP addresses to the EDR system. While existing blacklist and whitelist-based network threat monitoring solutions can reduce the volume of alerts, the volume remains high, often adding significant unnecessary workload to personnel and leading to alert fatigue. Consequently, the efficiency of network threat monitoring is low. Summary of the Invention

[0004] The present application provides a network security threat monitoring method, apparatus, and device, which can automatically discover configuration parameters for monitoring network security threats based on a relational database, thereby improving the efficiency of the network security threat monitoring process.

[0005] In a first aspect, an embodiment of the present application provides a method for monitoring network security threats, the method comprising:

[0006] Determining basic log information corresponding to an aggregation period based on a log time included in monitoring log information of an EDR device; the basic log information is obtained by grouping monitoring log information based on the aggregation period to which the log time belongs; the aggregation period is a period obtained by dividing consecutive aggregation windows within an observation window; the monitoring log information includes the log time, destination address, and threat type;

[0007] Determining a first characteristic indicator of the basic log information based on the basic log information; the first characteristic indicator represents the distribution balance of threat events with the same destination address relative to an aggregation period;

[0008] Determine first abnormal group log information and normal group log information in the basic log information according to the first characteristic indicator and a preset first abnormality judgment rule;

[0009] Determining, according to the normal group log information and the threat type, sub-group log information corresponding to the normal group log information; the sub-group log information is obtained by grouping the monitoring log of the normal group log information based on the threat type;

[0010] Determining a second characteristic indicator of the sub-group log information according to the sub-group log information; the second characteristic indicator represents a degree of dispersion of threat events of the same threat type and destination address between different aggregation time periods;

[0011] Determining second abnormal group log information in the normal group log information according to the second characteristic indicator and a preset second abnormality judgment rule;

[0012] Alarm log information is obtained based on the first abnormal group log information and the second abnormal group log information.

[0013] A second aspect of the present application provides a device for monitoring network security threats, the device comprising:

[0014] A basic grouping module is configured to determine basic log information corresponding to an aggregation period based on a log time included in monitoring log information of an EDR device; the basic log information is obtained by grouping monitoring log information based on the aggregation period to which the log time belongs; the aggregation period is a period obtained by dividing consecutive aggregation windows within an observation window; the monitoring log information includes the log time, destination address, and threat type;

[0015] An address aggregation module is configured to determine a first characteristic indicator of the basic log information based on the basic log information; the first characteristic indicator represents the distribution balance of threat events of the same destination address relative to an aggregation period;

[0016] a first noise reduction module, configured to determine first abnormal group log information and normal group log information in the basic log information according to the first characteristic indicator and a preset first abnormality judgment rule;

[0017] a secondary grouping module, configured to determine, based on the normal group log information and the threat type, sub-group log information corresponding to the normal group log information; the sub-group log information being obtained by grouping the monitoring log of the normal group log information based on the threat type;

[0018] A feature aggregation module is configured to determine a second feature index of the sub-group log information based on the sub-group log information; the second feature index represents a degree of dispersion of threat events of the same threat type and destination address between each aggregation period;

[0019] A second noise reduction module is configured to determine second abnormal group log information in the normal group log information according to the second characteristic indicator and a preset second abnormality judgment rule;

[0020] The alarm execution module is used to obtain alarm log information based on the first abnormal group log information and the second abnormal group log information.

[0021] In an optional embodiment, the device further includes a time period management module; the time period management module is configured to:

[0022] Taking a preset time interval as a time period, based on the time sequence, continuous aggregation windows are divided within the observation window according to the time interval to obtain the aggregation period; the aggregation period includes an existing aggregation period and a newly added aggregation period; the existing aggregation period is the aggregation period obtained when the continuous aggregation windows were divided within the observation window according to the time interval for the previous time.

[0023] In an optional embodiment, the address aggregation module is specifically configured to:

[0024] Based on the basic log information, parent group information corresponding to the basic log information is determined; the parent group information includes basic log sub-information, a destination address feature corresponding to the basic log sub-information, and the total number of first threat events corresponding to the basic log sub-information; the basic log sub-information is a set obtained by grouping monitoring log information in the basic log information corresponding to the aggregation period according to the destination address; the destination address feature is the destination address of the basic log sub-information of the basic log information corresponding to the aggregation period; the total number of first threat events is the number of monitoring log information contained in the basic log sub-information;

[0025] A first characteristic indicator of the basic log information is obtained according to the total number of the first threat events.

[0026] In an optional embodiment, the parent group information further includes a number of threat events of a specific type corresponding to the basic log sub-information; the number of threat events of a specific type is the number of threat events of a single type corresponding to the basic log sub-information; and the address aggregation module is specifically configured to:

[0027] For the newly added aggregation period, select the parent group information corresponding to the basic log information one by one. For each parent group information selected, based on the chronological order, sequentially obtain the parent group information with the same destination address as the currently selected parent group information from the parent group information of the basic log information corresponding to each aggregation period, and construct a parent group data point set;

[0028] According to the total number of first threat events and the number of threat events by type for each parent group information in the constructed parent group data point set, a first characteristic indicator corresponding one-to-one to each parent group information in the constructed parent group data point set is obtained.

[0029] In an optional embodiment, the first noise reduction module is specifically configured to:

[0030] Select basic log information corresponding to the newly added aggregation period one by one. For each basic log information selected, select the parent group information corresponding to the currently selected basic log information one by one. For each parent group information selected, calculate the coefficient of variation of the first characteristic indicator included in the parent group data point set of the currently selected parent group information to obtain the first coefficient of variation corresponding to the currently selected parent group information.

[0031] If the currently selected parent group information satisfies the parent group normal sub-rule of the first abnormality judgment rule, the currently selected parent group information is judged to be normal, and the currently selected parent group information is used as normal group log information; the parent group normal sub-rule is that the first coefficient of variation is less than the first control threshold, or the previous neighbor feature index difference is less than or equal to the first control threshold; the previous neighbor feature index difference is the absolute value of the difference between the first feature index of the currently selected parent group information and the first feature index of the previous parent group information of the currently selected parent group information in the parent group data point set;

[0032] If the currently selected parent group information meets the parent group anomaly sub-rule of the first anomaly judgment rule, the currently selected parent group information is judged to be abnormal, and the currently selected parent group information is used as a first abnormal group log information; the parent group anomaly sub-rule is that the first coefficient of variation is greater than or equal to the first control threshold, or the difference in the previous neighbor feature index is greater than the first control threshold.

[0033] In an optional embodiment, the feature aggregation module is specifically configured to:

[0034] Based on the sub-group log information, determining sub-group information corresponding to the sub-group log information; the sub-group information includes detailed log sub-information, a combined information feature corresponding to the detailed log sub-information, and a total number of second threat events corresponding to the detailed log sub-information; the detailed log sub-information is a set obtained by grouping the monitoring log information of the parent group information included in the normal group log information corresponding to the aggregation period according to the threat type; the combined information feature is a combination of the threat type and the destination address of the detailed log sub-information of the sub-group log information corresponding to the aggregation period; the total number of the second threat events is the number of monitoring log information contained in the detailed log sub-information;

[0035] For the newly added aggregation period, sub-group information corresponding to the basic log information is selected one by one. For each sub-group information selected, based on the chronological order, sub-group information with the same destination address and threat type as the currently selected sub-group information is sequentially obtained from the sub-group information of the basic log information corresponding to each aggregation period to construct a sub-group data point set;

[0036] According to the total number of second threat events of each sub-group information in the constructed sub-group data point set, a second characteristic indicator corresponding to the currently selected sub-group information is obtained.

[0037] In an optional embodiment, the second characteristic indicator is a second coefficient of variation obtained by calculating the coefficient of variation of the total number of second threat events; and the second noise reduction module is specifically configured to:

[0038] Selecting normal group log information corresponding to the newly added aggregation period one by one, each time a normal group log information is selected, selecting sub-group information corresponding to the currently selected normal group log information one by one, and each time a sub-group information is selected, calculating the mean and standard deviation of the total number of second threat events of each sub-group information in the sub-group data point set where the currently selected sub-group information is located, and correspondingly obtaining the sub-group mean and sub-group standard deviation corresponding to the currently selected sub-group information;

[0039] If the currently selected sub-group information satisfies the sub-group normal sub-rule of the second abnormality judgment rule, then the currently selected sub-group information is judged to be normal; the sub-group normal sub-rule is: the second coefficient of variation is less than the first control threshold, and the frequency difference is less than 3 times the sub-group standard deviation; or, the second coefficient of variation is greater than or equal to the first control threshold and less than the second control threshold, and the frequency difference is less than 2 times the sub-group standard deviation; or, the second coefficient of variation is greater than or equal to the second control threshold, and the frequency difference is less than the sub-group standard deviation; the second control threshold is greater than the first control threshold; the frequency difference is the absolute value of the difference between the total number of second threat events of the currently selected sub-group information and the sub-group mean;

[0040] If the currently selected sub-group information satisfies the sub-group anomaly sub-rule of the second anomaly judgment rule, the currently selected sub-group information is judged to be abnormal, and the currently selected sub-group information is used as a second abnormal group log information in the normal group log information; the sub-group anomaly sub-rule is satisfied if any one of the following conditions is met: the second coefficient of variation is less than the first control threshold, and the frequency difference is greater than or equal to 3 times the sub-group standard deviation; the second coefficient of variation is greater than or equal to the first control threshold and less than the second control threshold, and the frequency difference is greater than or equal to 2 times the sub-group standard deviation; the second coefficient of variation is greater than or equal to the second control threshold, and the frequency difference is greater than or equal to the sub-group standard deviation.

[0041] According to a third aspect provided by an embodiment of the present application, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method described in the first aspect is implemented.

[0042] According to a fourth aspect provided by an embodiment of the present application, an electronic device is provided, comprising a processor and a memory, wherein the memory stores a computer program that can be run on the processor, and when the computer program is executed by the processor, the method described in the first aspect is implemented.

[0043] In the above embodiment of the present application, based on the log time included in the monitoring log information of the EDR device, the basic log information corresponding to the aggregation time period is determined; the basic log information is obtained by grouping the monitoring log information based on the aggregation time period to which the log time belongs; the aggregation time period is a time period obtained by dividing continuous aggregation windows within the observation window; the monitoring log information includes the log time, destination address and threat type; based on the basic log information, the first characteristic indicator of the basic log information is determined; the first characteristic indicator characterizes the distribution balance of threat events of the same destination address relative to an aggregation time period; based on the first characteristic indicator and the preset first abnormality judgment rule, the first abnormal grouping date in the basic log information is determined Log information and normal group log information; according to the normal group log information and the threat type, determine the sub-group log information corresponding to the normal group log information; the sub-group log information is obtained by grouping the monitoring log of the normal group log information based on the threat type; according to the sub-group log information, determine the second characteristic index of the sub-group log information; the second characteristic index characterizes the discrete degree of threat events of the same threat type and destination address between each aggregation time period; according to the second characteristic index and the preset second abnormality judgment rule, determine the second abnormal group log information in the normal group log information; based on the first abnormal group log information and the second abnormal group log information, obtain the alarm log information. Therefore, in this embodiment, hierarchical abnormal log identification of the monitoring process of network security threats can be performed based on the destination address and threat type, noise reduction and filtering of the monitoring log can be achieved, the number of alarms to be processed can be reduced, and the accumulation of alarms can be effectively avoided based on the aggregation time period, thereby improving the efficiency of the monitoring process of network security threats. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0045] Figure 1 A flowchart of a method for monitoring network security threats provided by an embodiment of the present application;

[0046] Figure 2 A schematic diagram of a process for determining a first characteristic indicator based on basic log information in a network security threat monitoring method provided in an embodiment of the present application;

[0047] Figure 3A schematic diagram of a process for obtaining a first characteristic indicator of basic log information according to the total number of first threat events in a network security threat monitoring method provided in an embodiment of the present application;

[0048] Figure 4 A schematic diagram of a process for determining first abnormal group log information and normal group log information in basic log information in a method for monitoring network threats provided by an embodiment of the present application;

[0049] Figure 5 A schematic diagram of a flow chart of determining a second characteristic indicator based on sub-group log information in a network security threat monitoring method provided in an embodiment of the present application;

[0050] Figure 6 A schematic diagram of a process for determining second abnormal group log information in normal group log information in a method for monitoring network threats provided by an embodiment of the present application;

[0051] Figure 7 A schematic diagram of the structure of a network security threat monitoring device provided in an embodiment of the present application;

[0052] Figure 8 A schematic diagram of the structure of another network security threat monitoring device provided in an embodiment of the present application;

[0053] Figure 9 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0054] To make the objectives, technical solutions, and advantages of this application more clear, this application will be further described in detail below with reference to the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making any creative efforts are within the scope of protection of this application.

[0055] It should be noted that the terms "including" and "having" and their variations involved in the documents of this application are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or are inherent to these processes, methods, products or devices.

[0056] The following are explanations of some of the words that appear in the text:

[0057] (1) EDR (Endpoint Detection and Response) device: An EDR device is a network security device that is mainly used to monitor, detect, and respond to security threats on terminal devices (such as computers, servers, mobile devices, etc.) in real time.

[0058] (2) Gini index: The Gini index is an indicator used to evaluate the classification purity of a data set, which can reflect the uniformity of the category distribution in the data set.

[0059] (3) Coefficient of variation: The coefficient of variation is the ratio of the standard deviation σ to the mean μ. The coefficient of variation is a statistical indicator used to reflect the degree of dispersion of a variable around a unit mean.

[0060] (4) Inverse Gini Index: In some embodiments of the present application, the Inverse Gini Index is an evaluation indicator obtained by modifying the Gini Index in machine learning. In some embodiments, the Inverse Gini Index is used to characterize the degree of clustering exhibited by the distribution of target objects.

[0061] Current endpoint detection and response (EDR) devices generate a massive amount of threat monitoring alerts, including numerous recurring vulnerability events that are not offensive in nature. These events often involve numerous hosts and users, generating tens of thousands of alerts that need to be processed every day.

[0062] EDR device alarm logs typically lack source IP addresses, only relevant information such as victim IP addresses and threat events. These logs are constantly adding more victim IP addresses to the EDR system. While existing blacklist and whitelist-based network threat monitoring solutions can reduce the volume of alerts, the volume remains high, often adding significant unnecessary workload to personnel and leading to alert fatigue. Consequently, the efficiency of network threat monitoring is low.

[0063] In order to solve the existing technical problems, the embodiment of the present application provides a method for monitoring network security threats, which determines the basic log information corresponding to the aggregation period according to the log time included in the monitoring log information of the EDR device; the basic log information is obtained by grouping the monitoring log information based on the aggregation period to which the log time belongs; the aggregation period is the period obtained by dividing the continuous aggregation window within the observation window; the monitoring log information includes the log time, the destination address and the threat type; according to the basic log information, the first characteristic indicator of the basic log information is determined; the first characteristic indicator represents the distribution balance of the threat events of the same destination address relative to an aggregation period; according to the first characteristic indicator and the preset first abnormality judgment rule, the first characteristic indicator is determined. Determine the first abnormal group log information and the normal group log information in the basic log information; determine the sub-group log information corresponding to the normal group log information based on the normal group log information and the threat type; the sub-group log information is obtained by grouping the monitoring log of the normal group log information based on the threat type; determine the second characteristic index of the sub-group log information based on the sub-group log information; the second characteristic index represents the degree of discreteness of threat events of the same threat type and destination address between each aggregation time period; determine the second abnormal group log information in the normal group log information based on the second characteristic index and the preset second abnormal judgment rule; obtain the alarm log information based on the first abnormal group log information and the second abnormal group log information. Therefore, in this embodiment, hierarchical abnormal log identification of the monitoring process of network security threats can be performed based on the destination address and threat type, noise reduction filtering of the monitoring log can be achieved, the number of alarms to be processed can be reduced, and alarm accumulation can be effectively avoided based on the aggregation time period, thereby improving the efficiency of the monitoring process of network security threats.

[0064] The technical solutions provided in the embodiments of the present application will be described in detail below with reference to the accompanying drawings.

[0065] The present invention provides a method for monitoring network security threats. Figure 1 As shown, the following steps are included:

[0066] Step S101: Determine basic log information corresponding to an aggregation period according to a log time included in monitoring log information of an EDR device.

[0067] Among them, the basic log information is obtained by grouping the monitoring log information based on the aggregation period to which the log time belongs; the aggregation period is the period obtained by dividing the continuous aggregation window within the observation window; the monitoring log information includes the log time, destination address and threat type.

[0068] During specific implementation, the basic log information corresponding to the aggregation period can be determined based on the log time included in the monitoring log information of the EDR device. Specifically, if the log time included in the first monitoring log information of the EDR device belongs to the target aggregation period, the first monitoring log information is determined to be a basic log information corresponding to the target aggregation period.

[0069] In an optional embodiment, before executing step S101, the method further includes: taking a preset time interval as a time period, dividing continuous aggregation windows within the observation window according to the time interval based on the chronological order, and obtaining an aggregation period; the aggregation period includes an existing aggregation period and a newly added aggregation period; the existing aggregation period is the aggregation period obtained when the continuous aggregation window was divided according to the time interval in the observation window for the previous time.

[0070] In an embodiment of the present application, the length of the preset time interval is the same as the length of the aggregation period.

[0071] In the embodiments of the present application, the newly added aggregation period may be the aggregation period added when the observation window is currently divided into consecutive aggregation windows according to the time interval. That is, the newly added aggregation period is the aggregation period obtained when the observation window is currently divided into consecutive aggregation windows according to the time interval, and is compared with the aggregation period obtained when the observation window was previously divided into consecutive aggregation windows according to the time interval.

[0072] For example, the observation window can be a day interval. For example, it can be 1 day, 2 days, 3 days, 4 days, etc.; the aggregation window can be 0.5 hours. The length of the aggregation window is smaller than the observation window. The lengths of the observation window and aggregation window are not specifically limited in the embodiments of this application.

[0073] Exemplarily, based on the log time Recor_time included in the monitoring log information Daily_Recor of the EDR device, the basic log information Basic_dr_data corresponding to the aggregation period Sort_period is determined; the basic log information Basic_dr_data is obtained by grouping the monitoring log information Daily_Recor based on the aggregation period to which the log time belongs; the aggregation period Sort_period is the period obtained by dividing continuous aggregation windows within the observation window; the monitoring log information Daily_Recor includes the log time Recor_time, the destination address Recor_Targ_IP and the threat type Recor_TYPE.

[0074] Step S102: determining a first characteristic index of the basic log information based on the basic log information; the first characteristic index represents the distribution balance of threat events with the same destination address relative to an aggregation period.

[0075] Exemplarily, according to the basic log information Basic_dr_data, a first characteristic indicator First_pro_item of the basic log information Basic_dr_data is determined; the first characteristic indicator First_pro_item represents the distribution balance of threat events of the same destination address relative to an aggregation period.

[0076] In an optional embodiment, the process of determining the first characteristic indicator of the basic log information according to the basic log information is as follows: Figure 2 As shown, this is achieved through the following steps:

[0077] Step S201: Based on the basic log information, determine the parent group information corresponding to the basic log information; the parent group information includes the basic log sub-information, the destination address feature corresponding to the basic log sub-information, and the total number of first threat events corresponding to the basic log sub-information; the basic log sub-information is a collection of monitoring log information in the basic log information corresponding to the aggregation period, grouped according to the destination address; the destination address feature is the destination address of the basic log sub-information of the basic log information corresponding to the aggregation period; the total number of first threat events is the number of monitoring log information contained in the basic log sub-information.

[0078] Exemplarily, based on the basic log information Basic_dr_data, the parent grouping information Father_sort_Info corresponding to the basic log information Basic_dr_data is determined; the parent grouping information Father_sort_Info includes the basic log sub-information Basic_dr_Subdata, the destination address feature Prop_Targ_IP corresponding to the basic log sub-information Basic_dr_Subdata, and the total number of first threat events thre_event_sum1 corresponding to the basic log sub-information Basic_dr_Subdata; the basic log sub-information Basic_dr_Subdata is a set obtained by grouping the monitoring log information in the basic log information corresponding to the aggregation period according to the destination address; the destination address feature Prop_Targ_IP is the destination address of the basic log sub-information of the basic log information corresponding to the aggregation period; the total number of first threat events thre_event_sum1 is the number of monitoring log information contained in the basic log sub-information.

[0079] Step S202: Obtain a first characteristic indicator of basic log information according to the total number of first threat events.

[0080] Exemplarily, according to the first threat event total thre_event_sum1, the first characteristic indicator First_pro_item of the basic log information Basic_dr_data is obtained.

[0081] In an optional embodiment, the first characteristic indicator is the inverse Gini index.

[0082] In some embodiments of the present application, the inverse Gini index is obtained based on the Gini index.

[0083] In some embodiments of the present application, the inverse Gini index and the Gini index satisfy the following formula:

[0084]

[0085] Among them, RGini represents the inverse Gini index;

[0086] Gini, which stands for Gini index.

[0087] In an optional embodiment, the parent group information further includes the number of threat events of a specific type corresponding to the basic log sub-information; the number of threat events of a specific type is the number of threat events of a single type corresponding to the basic log sub-information; the process of obtaining the first characteristic indicator of the basic log information according to the total number of the first threat events is as follows: Figure 3 As shown, this is achieved through the following steps:

[0088] Step S301: For the newly added aggregation time period, select the parent group information corresponding to the basic log information one by one. Each time a parent group information is selected, based on the chronological order, obtain the parent group information with the same destination address as the currently selected parent group information from the parent group information of the basic log information corresponding to each aggregation time period in sequence to construct a parent group data point set.

[0089] In some embodiments of the present application, the parent group information further includes the number of threat events by type corresponding to the basic log sub-information; the number of threat events by type is the number of threat events of a single threat type corresponding to the basic log sub-information.

[0090] In an optional embodiment, in step S301, the process of sequentially obtaining parent group information having the same destination address as the currently selected parent group information from the parent group information of the basic log information corresponding to each aggregation time period to construct a parent group data point set is specifically as follows: if the number of parent group information having the same destination address as the currently selected parent group information reaches a preset window control threshold, then sequentially obtaining parent group information having the same destination address as the currently selected parent group information from the parent group information of the basic log information corresponding to each aggregation time period to construct a parent group data point set.

[0091] For example, for the newly added aggregation period S_new, the parent group information Father_sort_Info corresponding to the basic log information Basic_dr_data is selected one by one. Each time a parent group information Father_sort_Info_i is selected, based on the chronological order, the parent group information with the same destination address as the currently selected parent group information Father_sort_Info_i is obtained in sequence from the parent group information Father_sort_Info of the basic log information Basic_dr_data corresponding to each aggregation period Sort_period, and the parent group data point set (S1, S2, ..., S t-1 , S t ).

[0092] Step S302 : obtaining first characteristic indicators corresponding to each parent group information in the constructed parent group data point set according to the total number of first threat events and the number of threat events by type of each parent group information in the constructed parent group data point set.

[0093] For example, according to the constructed parent grouping data point set (S1, S2, ..., S t-1 , S t ) and the number of threat events by type C_ik of each parent group information Father_sort_Info in the constructed parent group data point set, and obtain the first characteristic index First_pro_item_i corresponding to each parent group information in the constructed parent group data point set. The first characteristic index First_pro_item, can be (First_pro_item_1, First_pro_item_2, ..., First_pro_item_t-1, First_pro_item_t). For example, when the first characteristic index is the inverse Gini index, the first characteristic index First_pro_item can be (RGini1, RRGini2, ..., RGini t-1 RGini t ).

[0094] In some embodiments of the present application, the inverse Gini index of the parent group can be calculated using the following formula:

[0095]

[0096] in,

[0097] n i Representative data point S i The number of threat event types in the parent group;

[0098] k represents the kth type of threat event;

[0099] C i Represents the parent group at the i-th data point S i The number of occurrences within

[0100] c i,k represents the number of occurrences of the kth threat event of the parent group, c i,k with C i satisfy relationship.

[0101] Step S103 : determining first abnormal group log information and normal group log information in the basic log information according to the first characteristic indicator and a preset first abnormality judgment rule.

[0102] Exemplarily, according to the first characteristic indicator First_pro_item and the preset first abnormality judgment rule Rule_1, the first abnormal grouping log information Bad_sort_dr_data_1 and the normal grouping log information Norm_sort_dr_data in the basic log information Basic_dr_data are determined.

[0103] In some embodiments of the present application, according to the first characteristic indicator and the preset first abnormality judgment rule, the process of determining the first abnormal group log information and the normal group log information in the basic log information is as follows: Figure 4 As shown, this is achieved through the following steps:

[0104] Step S401, select the basic log information corresponding to the newly added aggregation period one by one, and each time a basic log information is selected, select the parent group information corresponding to the currently selected basic log information one by one, and each time a parent group information is selected, calculate the coefficient of variation of the first characteristic indicator included in the parent group data point set where the currently selected parent group information is located, and obtain the first coefficient of variation corresponding to the currently selected parent group information.

[0105] For example, the basic log information Basic_dr_data corresponding to the newly added aggregation period S_new is selected one by one. Each time a basic log information Basic_dr_data is selected, the parent group information Father_sort_Info corresponding to the currently selected basic log information Basic_dr_data_j is selected one by one. Each time a parent group information Father_sort_Info_j is selected, the parent group data point set (S1, S2, ..., S t-1 , S t) The first characteristic index First_pro_item included in the calculation of the coefficient of variation is obtained to obtain the first coefficient of variation corresponding to the currently selected parent group information.

[0106] Step S402: If the currently selected parent group information satisfies the parent group normal sub-rule of the first abnormality judgment rule, the currently selected parent group information is judged to be normal, and the currently selected parent group information is treated as a normal group log information.

[0107] Among them, the normal sub-rule of the parent group is that the first coefficient of variation is less than the first control threshold, or the difference in the previous neighbor feature index is less than or equal to the first control threshold; the previous neighbor feature index difference is the absolute value of the difference between the first feature index of the currently selected parent group information and the first feature index of the previous parent group information in the parent group data point set.

[0108] In one embodiment of the present application, the value of the first control threshold is

[0109] In one embodiment of the present application, the parent group normal sub-rule of the first abnormality judgment rule is:

[0110] or

[0111] in, Represents the first coefficient of variation, specifically the parent group data point set (S1, S2, ..., S t-1 , S t )'s inverse Gini index (RGini1,RRGini2,……,RGini t-1 RGini t )’s coefficient of variation;

[0112] RGini t , represents the parent group data point set (S1, S2, ..., S t-1 , S t ) in the parent group data point S t The inverse Gini index;

[0113] RGini t-1 , represents the parent group data point set (S1, S2, ..., S t-1 , S t ) in the parent group data point S t-1 The inverse Gini index;

[0114] |RGini t -RGini t-1 |, represents the difference in characteristic indicators of the preceding neighbors;

[0115] is the value of the first control threshold.

[0116] Step S403: If the currently selected parent group information satisfies the parent group abnormality sub-rule of the first abnormality judgment rule, the currently selected parent group information is judged to be abnormal, and the currently selected parent group information is used as a first abnormal group log information.

[0117] The parent group abnormal sub-rule is that the first coefficient of variation is greater than or equal to the first control threshold, or the difference in the previous neighbor characteristic index is greater than the first control threshold.

[0118] In one embodiment of the present application, the parent group normal sub-rule of the first abnormality judgment rule is:

[0119] or

[0120] in, Represents the first coefficient of variation, specifically the parent group data point set (S1, S2, ..., S t-1 , S t )'s inverse Gini index (RGini1,RRGini2,……,RGini t-1 RGini t )’s coefficient of variation;

[0121] RGini t , represents the parent group data point set (S1, S2, ..., S t-1 , S t ) in the parent group data point S t The inverse Gini index;

[0122] RGini t-1 , represents the parent group data point set (S1, S2, ..., S t-1 , S t ) in the parent group data point S t-1 The inverse Gini index;

[0123] |RGini t -RGini t-1 |, represents the difference in characteristic indicators of the preceding neighbors;

[0124] is the value of the first control threshold.

[0125] Step S104 : determining sub-group log information corresponding to the normal group log information according to the normal group log information and the threat type; the sub-group log information is obtained by grouping the monitoring logs of the normal group log information based on the threat type.

[0126] During specific implementation, the normal group log information is grouped based on the threat type to obtain sub-group log information corresponding to the normal group log information.

[0127] Exemplarily, the sub-group log information Sun_sort_Info corresponding to the normal group log information Norm_sort_dr_data is determined according to the normal group log information Norm_sort_dr_data and the threat type Recor_TYPE; the sub-group log information Sun_sort_Info is obtained by grouping the monitoring logs of the normal group log information based on the threat type.

[0128] Step S105 : determining a second characteristic index of the sub-group log information according to the sub-group log information; the second characteristic index represents the degree of dispersion of threat events of the same threat type and destination address between different aggregation time periods.

[0129] Exemplarily, the second characteristic indicator Seco_pro_item of the sub-group log information Sun_sort_Info is determined according to the sub-group log information Sun_sort_Info; the second characteristic indicator Seco_pro_item represents the degree of dispersion of threat events of the same threat type and destination address between different aggregation time periods.

[0130] In some embodiments of the present application, step S105 is a process of determining a second characteristic indicator of the sub-group log information according to the sub-group log information, such as Figure 5 As shown, this is achieved through the following steps:

[0131] Step S501: Determine the sub-group information corresponding to the sub-group log information based on the sub-group log information; the sub-group information includes subdivided log sub-information, combined information features corresponding to the subdivided log sub-information, and the total number of second threat events corresponding to the subdivided log sub-information.

[0132] Among them, the detailed log sub-information is the monitoring log information of the parent group information included in the normal group log information corresponding to the aggregation period, which is grouped according to the threat type; the combined information feature is the combination information of the threat type and destination address of the detailed log sub-information of the sub-group log information corresponding to the aggregation period; the total number of second threat events is the number of monitoring log information contained in the detailed log sub-information.

[0133] In step S502, for the newly added aggregation period, the sub-group information corresponding to the basic log information is selected one by one. Each time a sub-group information is selected, based on the chronological order, the sub-group information with the same destination address and threat type as the currently selected sub-group information is obtained in sequence from the sub-group information of the basic log information corresponding to each aggregation period to construct a sub-group data point set.

[0134] In an optional embodiment, in step S502, the process of sequentially obtaining sub-group information with the same destination address and threat type as the currently selected sub-group information from the sub-group information of the basic log information corresponding to each aggregation time period to construct a sub-group data point set is specifically as follows: if the number of sub-group information with the same destination address and threat type as the currently selected sub-group information reaches a preset window control threshold, then sequentially obtaining sub-group information with the same destination address and threat type as the currently selected sub-group information from the sub-group information of the basic log information corresponding to each aggregation time period to construct a sub-group data point set.

[0135] In some embodiments of the present application, the sub-group data point set corresponds to a sub-group information corresponding to the newly added aggregation time period; in other embodiments of the present application, the sub-group data point set may also correspond to all sub-group information corresponding to the newly added aggregation time period. In this case, the sub-group data point set may include sub-group data points corresponding to a single sub-group information corresponding to the newly added aggregation time period, the destination address and threat type of the sub-group information in each sub-group data point are the same, and the destination address and threat type of the sub-group information in different sub-group data points are different.

[0136] In an optional embodiment, sub-group information having the same destination address and threat type as the currently selected sub-group information is sequentially obtained, and the process of constructing the sub-group data point set further includes: based on the total number of second threat events, removing sub-group information corresponding to the extreme value in the total number of second threat events.

[0137] In the above embodiment, it is possible to construct a data point set after removing sub-group log information from normal group log information, thereby further improving the efficiency of the network security threat monitoring process.

[0138] Step S503: Obtain a second characteristic indicator corresponding to the currently selected sub-group information according to the total number of second threat events of each sub-group information in the constructed sub-group data point set.

[0139] In an optional embodiment, the second characteristic indicator is the inverse Gini index.

[0140] In some embodiments of the present application, the inverse Gini index is obtained based on the Gini index.

[0141] Step S106 : determining the second abnormal group log information in the normal group log information according to the second characteristic indicator and the preset second abnormality judgment rule.

[0142] In some embodiments of the present application, the second characteristic indicator is a second coefficient of variation obtained by calculating the coefficient of variation of the total number of second threat events; step S106, a process of determining the second abnormal group log information in the normal group log information according to the second characteristic indicator and the preset second abnormality judgment rule, such as Figure 6 As shown, this is achieved through the following steps:

[0143] In step S601, normal group log information corresponding to the newly added aggregation period is selected one by one. For each normal group log information selected, the sub-group information corresponding to the currently selected normal group log information is selected one by one. For each sub-group information selected, the mean and standard deviation of the total number of second threat events of each sub-group information in the sub-group data point set where the currently selected sub-group information is located are respectively calculated, and the sub-group mean and sub-group standard deviation corresponding to the currently selected sub-group information are correspondingly obtained.

[0144] For example, the second characteristic indicator Seco_pro_item is a second coefficient of variation obtained by calculating the coefficient of variation of the total number of second threat events. Assume that the subgroup data point set is (s′1, s′2, ..., s′ t-1 , s′ t ), for the newly added aggregation period S_new, the currently selected sub-group information s′ t The corresponding subgroup mean can be μ2, and the subgroup standard deviation can be σ2.

[0145] Step S602: If the currently selected sub-group information satisfies the normal sub-group sub-rule of the second abnormality judgment rule, the currently selected sub-group information is judged to be normal.

[0146] Among them, the normal sub-rule of the sub-group is: the second coefficient of variation is less than the first control threshold, and the frequency difference is less than 3 times the sub-group standard deviation; or, the second coefficient of variation is greater than or equal to the first control threshold and less than the second control threshold, and the frequency difference is less than 2 times the sub-group standard deviation; or, the second coefficient of variation is greater than or equal to the second control threshold, and the frequency difference is less than the sub-group standard deviation; the second control threshold is greater than the first control threshold; the frequency difference is the absolute value of the difference between the total number of second threat events of the currently selected sub-group information and the sub-group mean corresponding to the currently selected sub-group information.

[0147] In one embodiment of the present application, the value of the first control threshold is The value of the second control threshold is 1.

[0148] In one embodiment of the present application, the sub-group normal sub-rule of the second abnormality judgment rule is:

[0149]

[0150] in, represents a second coefficient of variation, specifically a coefficient of variation of the total number of second threat events of the sub-grouped data point set;

[0151] c t , represents the total number of second threat events of a sub-group information corresponding to the newly added aggregation period;

[0152] μ2, represents the subgroup mean;

[0153] σ2, represents the subgroup standard deviation;

[0154] is the value of the first control threshold;

[0155] 1 is the value of the second control threshold;

[0156] |c t -μ2|, indicating the frequency difference.

[0157] Step S603: If the currently selected sub-group information satisfies the sub-group abnormality sub-rule of the second abnormality judgment rule, the currently selected sub-group information is judged to be abnormal, and the currently selected sub-group information is used as a second abnormal group log information in the normal group log information.

[0158] Among them, the sub-group anomaly sub-rule is satisfied if any one of the following conditions is met: the second coefficient of variation is less than the first control threshold, and the frequency difference is greater than or equal to 3 times the sub-group standard deviation; the second coefficient of variation is greater than or equal to the first control threshold and less than the second control threshold, and the frequency difference is greater than or equal to 2 times the sub-group standard deviation; the second coefficient of variation is greater than or equal to the second control threshold, and the frequency difference is greater than or equal to the sub-group standard deviation.

[0159] In one embodiment of the present application, the sub-grouping exception sub-rule of the second exception judgment rule is:

[0160]

[0161] in, represents a second coefficient of variation, specifically a coefficient of variation of the total number of second threat events of the sub-grouped data point set;

[0162] c t , represents the total number of second threat events of a sub-group information corresponding to the newly added aggregation period;

[0163] μ2, represents the subgroup mean;

[0164] σ2, represents the subgroup standard deviation;

[0165] is the value of the first control threshold;

[0166] 1 is the value of the second control threshold;

[0167] |c t -μ2|, indicating the frequency difference.

[0168] In some other embodiments of the present application, the second characteristic indicator characterizes the degree of dispersion of threat events of the same threat type and destination address between each aggregation period and the average degree of occurrence of threat events; the second characteristic indicator includes the second coefficient of variation, subgroup mean, and subgroup standard deviation corresponding to the currently selected sub-group information. The second coefficient of variation is obtained by calculating the coefficient of variation of the total number of second threat events; the normal group log information corresponding to the newly added aggregation period is selected one by one, and for each normal group log information selected, the sub-group information corresponding to the currently selected normal group log information is selected one by one, and for each sub-group information selected, the total number of second threat events of each sub-group information in the sub-group data point set where the currently selected sub-group information is located is calculated as the mean and standard deviation, and the sub-group mean and sub-group standard deviation corresponding to the currently selected sub-group information are obtained accordingly.

[0169] Step S107: obtaining alarm log information based on the first abnormal group log information and the second abnormal group log information.

[0170] The network security threat monitoring method provided by the embodiment of the present application determines the basic log information corresponding to the aggregation period according to the log time included in the monitoring log information of the EDR device; the basic log information is obtained by grouping the monitoring log information based on the aggregation period to which the log time belongs; the aggregation period is the period obtained by dividing the continuous aggregation window within the observation window; the monitoring log information includes the log time, the destination address and the threat type; according to the basic log information, the first characteristic indicator of the basic log information is determined; the first characteristic indicator represents the distribution balance of the threat events of the same destination address relative to an aggregation period; according to the first characteristic indicator and the preset first abnormality judgment rule, the basic log information is determined. The first abnormal group log information and the normal group log information; according to the normal group log information and the threat type, the sub-group log information corresponding to the normal group log information is determined; the sub-group log information is obtained by grouping the monitoring log of the normal group log information based on the threat type; according to the sub-group log information, the second characteristic index of the sub-group log information is determined; the second characteristic index characterizes the discrete degree of threat events of the same threat type and destination address between each aggregation time period; according to the second characteristic index and the preset second abnormal judgment rule, the second abnormal group log information in the normal group log information is determined; based on the first abnormal group log information and the second abnormal group log information, the alarm log information is obtained. Therefore, in this embodiment, hierarchical abnormal log identification of the monitoring process of network security threats can be performed based on the destination address and threat type, noise reduction filtering of the monitoring log can be achieved, the number of alarms to be processed can be reduced, and the accumulation of alarms can be effectively avoided based on the aggregation time period, thereby improving the efficiency of the monitoring process of network security threats.

[0171] and Figure 1 The network security threat monitoring method described above is based on the same inventive concept. In the embodiments of this application, a network security threat monitoring device is also provided. Since this device corresponds to the network security threat monitoring method of this application and solves problems based on similar principles to the method, the implementation of this device can be referenced to the implementation of the aforementioned method, and any repetitions will not be repeated.

[0172] Figure 7 A schematic diagram of the structure of a network security threat monitoring device provided by an embodiment of the present application is shown. Figure 7 As shown, the network security threat monitoring device includes a basic grouping module 701, an address aggregation module 702, a first noise reduction module 703, a secondary grouping module 704, a feature aggregation module 705, a second noise reduction module 706 and an alarm execution module 707.

[0173] The basic grouping module 701 is configured to determine basic log information corresponding to an aggregation period based on the log time included in the monitoring log information of the EDR device; the basic log information is obtained by grouping the monitoring log information based on the aggregation period to which the log time belongs; the aggregation period is a period obtained by dividing consecutive aggregation windows within the observation window; the monitoring log information includes the log time, destination address, and threat type;

[0174] The address aggregation module 702 is configured to determine a first characteristic indicator of the basic log information based on the basic log information; the first characteristic indicator represents the distribution balance of threat events with the same destination address relative to an aggregation period;

[0175] A first noise reduction module 703 is configured to determine first abnormal group log information and normal group log information in the basic log information according to the first characteristic indicator and a preset first abnormality judgment rule;

[0176] Secondary grouping module 704, configured to determine sub-group log information corresponding to the normal group log information based on the normal group log information and the threat type; the sub-group log information is obtained by grouping the monitoring logs of the normal group log information based on the threat type;

[0177] The feature aggregation module 705 is configured to determine a second feature index of the sub-group log information based on the sub-group log information; the second feature index represents the degree of dispersion of threat events of the same threat type and destination address between each aggregation period;

[0178] The second noise reduction module 706 is configured to determine the second abnormal group log information in the normal group log information according to the second characteristic indicator and the preset second abnormality judgment rule;

[0179] The alarm execution module 707 is configured to obtain alarm log information based on the first abnormal group log information and the second abnormal group log information.

[0180] In an optional embodiment, as Figure 8 As shown, the device further includes a time period management module 801; the time period management module 801 is used to:

[0181] Taking the preset time interval as the time period, based on the time sequence, continuous aggregation windows are divided within the observation window according to the time interval to obtain aggregation time periods; the aggregation time periods include existing aggregation time periods and newly added aggregation time periods; the existing aggregation time periods are the aggregation time periods obtained when the continuous aggregation windows were divided within the observation window according to the time interval for the previous time.

[0182] In an optional embodiment, the address aggregation module 702 is specifically configured to:

[0183] Based on the basic log information, parent group information corresponding to the basic log information is determined; the parent group information includes basic log sub-information, a destination address feature corresponding to the basic log sub-information, and the total number of first threat events corresponding to the basic log sub-information; the basic log sub-information is a collection of monitoring log information in the basic log information corresponding to the aggregation period, grouped according to the destination address; the destination address feature is the destination address of the basic log sub-information of the basic log information corresponding to the aggregation period; the total number of first threat events is the number of monitoring log information contained in the basic log sub-information;

[0184] A first characteristic indicator of the basic log information is obtained according to the total number of the first threat events.

[0185] In an optional embodiment, the parent group information further includes the number of threat events by type corresponding to the basic log sub-information; the number of threat events by type is the number of threat events of a single type corresponding to the basic log sub-information; the address aggregation module 702 is specifically configured to:

[0186] For each newly added aggregation period, select the parent group information corresponding to the basic log information one by one. For each parent group information selected, based on the chronological order, sequentially obtain the parent group information with the same destination address as the currently selected parent group information from the parent group information of the basic log information corresponding to each aggregation period, and construct a parent group data point set;

[0187] According to the total number of first threat events and the number of threat events by type for each parent group information in the constructed parent group data point set, a first characteristic indicator corresponding one-to-one to each parent group information in the constructed parent group data point set is obtained.

[0188] In an optional embodiment, the first noise reduction module 703 is specifically configured to:

[0189] Select the basic log information corresponding to the newly added aggregation period one by one. For each basic log information selected, select the parent group information corresponding to the currently selected basic log information one by one. For each parent group information selected, calculate the coefficient of variation of the first characteristic indicator included in the parent group data point set of the currently selected parent group information to obtain the first coefficient of variation corresponding to the currently selected parent group information.

[0190] If the currently selected parent group information satisfies the parent group normal sub-rule of the first abnormality judgment rule, the currently selected parent group information is judged to be normal, and the currently selected parent group information is used as normal group log information; the parent group normal sub-rule is that the first coefficient of variation is less than the first control threshold, or the previous neighbor feature index difference is less than or equal to the first control threshold; the previous neighbor feature index difference is the absolute value of the difference between the first feature index of the currently selected parent group information and the first feature index of the previous parent group information in the parent group data point set;

[0191] If the currently selected parent group information meets the parent group anomaly sub-rule of the first anomaly judgment rule, the currently selected parent group information is judged to be abnormal, and the currently selected parent group information is used as a first abnormal group log information; the parent group anomaly sub-rule is that the first coefficient of variation is greater than or equal to the first control threshold, or the difference in the previous neighbor feature index is greater than the first control threshold.

[0192] In an optional embodiment, the feature aggregation module 705 is specifically configured to:

[0193] Based on the sub-group log information, determining the sub-group information corresponding to the sub-group log information; the sub-group information includes segmented log sub-information, a combined information feature corresponding to the segmented log sub-information, and the total number of second threat events corresponding to the segmented log sub-information; the segmented log sub-information is a collection of monitoring log information of the parent group information included in the normal group log information corresponding to the aggregation period, grouped according to threat type; the combined information feature is a combination of the threat type and the destination address of the segmented log sub-information of the sub-group log information corresponding to the aggregation period; the total number of second threat events is the number of monitoring log information contained in the segmented log sub-information;

[0194] For each newly added aggregation period, select the sub-group information corresponding to the basic log information one by one. For each sub-group information selected, based on the chronological order, sequentially obtain the sub-group information with the same destination address and threat type as the currently selected sub-group information from the sub-group information of the basic log information corresponding to each aggregation period, and construct a sub-group data point set;

[0195] According to the total number of second threat events of each sub-group information in the constructed sub-group data point set, a second characteristic indicator corresponding to the currently selected sub-group information is obtained.

[0196] In an optional embodiment, the second characteristic indicator is a second coefficient of variation obtained by calculating the coefficient of variation of the total number of second threat events; the second noise reduction module 706 is specifically configured to:

[0197] Select normal group log information corresponding to the newly added aggregation period one by one. For each normal group log information selected, select the sub-group information corresponding to the currently selected normal group log information one by one. For each sub-group information selected, calculate the mean and standard deviation of the total number of second threat events of each sub-group information in the sub-group data point set where the currently selected sub-group information is located, and correspondingly obtain the sub-group mean and sub-group standard deviation corresponding to the currently selected sub-group information.

[0198] If the currently selected sub-group information satisfies the sub-group normal sub-rule of the second abnormality judgment rule, then the currently selected sub-group information is judged to be normal; the sub-group normal sub-rule is: the second coefficient of variation is less than the first control threshold, and the frequency difference is less than 3 times the sub-group standard deviation; or, the second coefficient of variation is greater than or equal to the first control threshold and less than the second control threshold, and the frequency difference is less than 2 times the sub-group standard deviation; or, the second coefficient of variation is greater than or equal to the second control threshold, and the frequency difference is less than the sub-group standard deviation; the second control threshold is greater than the first control threshold; the frequency difference is the absolute value of the difference between the total number of second threat events of the currently selected sub-group information and the sub-group mean;

[0199] If the currently selected sub-group information meets the sub-group anomaly sub-rule of the second anomaly judgment rule, the currently selected sub-group information is judged to be abnormal, and the currently selected sub-group information is used as a second abnormal group log information in the normal group log information; the sub-group anomaly sub-rule is satisfied if any one of the following conditions is met: the second coefficient of variation is less than the first control threshold, and the frequency difference is greater than or equal to 3 times the sub-group standard deviation; the second coefficient of variation is greater than or equal to the first control threshold and less than the second control threshold, and the frequency difference is greater than or equal to 2 times the sub-group standard deviation; the second coefficient of variation is greater than or equal to the second control threshold, and the frequency difference is greater than or equal to the sub-group standard deviation.

[0200] Based on the same inventive concept as the above method embodiment, an electronic device is also provided in the embodiment of the present application. The electronic device can be used to monitor network security threats. In one embodiment, the electronic device can be a server, or a terminal device or other electronic device. In this embodiment, the structure of the electronic device can be as follows: Figure 9 As shown, it includes a memory 901 , a communication module 903 and one or more processors 902 .

[0201] Memory 901 is used to store computer programs executed by processor 902. Memory 901 may primarily include a program storage area and a data storage area. The program storage area may store an operating system and programs required for running instant messaging functions, while the data storage area may store various instant messaging messages and operating instruction sets.

[0202] Memory 901 may be a volatile memory, such as random-access memory (RAM); a non-volatile memory, such as read-only memory, flash memory, a hard disk drive (HDD), or a solid-state drive (SSD); or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but is not limited thereto. Memory 901 may be a combination of the above memories.

[0203] The processor 902 may include one or more central processing units (CPUs) or digital processing units, etc. The processor 902 is configured to implement the aforementioned network security threat monitoring method when calling the computer program stored in the memory 901 .

[0204] The communication module 903 is used to communicate with terminal devices and other servers.

[0205] The specific connection medium between the memory 901, the communication module 903 and the processor 902 is not limited in the embodiment of the present application. Figure 9 In the embodiment, the memory 901 and the processor 902 are connected via a bus 904. Figure 9 The connections between the other components are shown in bold lines, which are only for illustration and are not intended to be limiting. The bus 904 can be divided into an address bus, a data bus, a control bus, etc. For ease of illustration, Figure 9 Only one thick line is used in the diagram, but this does not mean that there is only one bus or one type of bus.

[0206] According to one aspect of the present application, a computer program product or computer program is provided, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device performs the network security threat monitoring method in the above-mentioned embodiment. The program product can use any combination of one or more readable media. The readable medium can be a readable signal medium or a readable storage medium. The readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of readable storage media (a non-exhaustive list) include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0207] The above is only a specific implementation method of the present application, but the scope of protection of the present application is not limited thereto. Any technician familiar with this technical field can easily think of changes or replacements within the technical scope disclosed in this application, which should be covered by the scope of protection of the present application.

Claims

1. A method for monitoring network security threats, characterized in that: The method comprises: Determining basic log information corresponding to an aggregation period based on a log time included in monitoring log information of an EDR device; the basic log information is obtained by grouping monitoring log information based on the aggregation period to which the log time belongs; the aggregation period is a period obtained by dividing consecutive aggregation windows within an observation window; the monitoring log information includes the log time, destination address, and threat type; Determining a first characteristic indicator of the basic log information based on the basic log information; the first characteristic indicator represents the distribution balance of threat events with the same destination address relative to an aggregation period; Determine first abnormal group log information and normal group log information in the basic log information according to the first characteristic indicator and a preset first abnormality judgment rule; Determining, according to the normal group log information and the threat type, sub-group log information corresponding to the normal group log information; the sub-group log information is obtained by grouping the monitoring log of the normal group log information based on the threat type; Determining a second characteristic indicator of the sub-group log information according to the sub-group log information; the second characteristic indicator represents a degree of dispersion of threat events of the same threat type and destination address between different aggregation time periods; Determining second abnormal group log information in the normal group log information according to the second characteristic indicator and a preset second abnormality judgment rule; Alarm log information is obtained based on the first abnormal group log information and the second abnormal group log information.

2. The method according to claim 1, characterized in that Before determining the basic log information corresponding to the aggregation period based on the log time included in the monitoring log information of the EDR device, the method further includes: Taking a preset time interval as a time period, based on the time sequence, continuous aggregation windows are divided within the observation window according to the time interval to obtain the aggregation period; the aggregation period includes an existing aggregation period and a newly added aggregation period; the existing aggregation period is the aggregation period obtained when the continuous aggregation windows were divided within the observation window according to the time interval for the previous time.

3. The method according to claim 2, characterized in that The determining, based on the basic log information, a first characteristic indicator of the basic log information includes: Based on the basic log information, parent group information corresponding to the basic log information is determined; the parent group information includes basic log sub-information, a destination address feature corresponding to the basic log sub-information, and the total number of first threat events corresponding to the basic log sub-information; the basic log sub-information is a set obtained by grouping monitoring log information in the basic log information corresponding to the aggregation period according to the destination address; the destination address feature is the destination address of the basic log sub-information of the basic log information corresponding to the aggregation period; the total number of first threat events is the number of monitoring log information contained in the basic log sub-information; A first characteristic indicator of the basic log information is obtained according to the total number of the first threat events.

4. The method according to claim 3, characterized in that The parent group information further includes the number of threat events of a specific type corresponding to the basic log sub-information; the number of threat events of a specific type is the number of threat events of a single type corresponding to the basic log sub-information; Obtaining a first characteristic indicator of the basic log information according to the total number of the first threat events includes: For the newly added aggregation period, select the parent group information corresponding to the basic log information one by one. For each parent group information selected, based on the chronological order, sequentially obtain the parent group information with the same destination address as the currently selected parent group information from the parent group information of the basic log information corresponding to each aggregation period, and construct a parent group data point set; According to the total number of first threat events and the number of threat events by type for each parent group information in the constructed parent group data point set, a first characteristic indicator corresponding one-to-one to each parent group information in the constructed parent group data point set is obtained.

5. The method according to claim 4, characterized in that The determining, according to the first characteristic indicator and a preset first abnormality judgment rule, first abnormal group log information and normal group log information in the basic log information includes: Select basic log information corresponding to the newly added aggregation period one by one. For each basic log information selected, select the parent group information corresponding to the currently selected basic log information one by one. For each parent group information selected, calculate the coefficient of variation of the first characteristic indicator included in the parent group data point set of the currently selected parent group information to obtain the first coefficient of variation corresponding to the currently selected parent group information. If the currently selected parent group information satisfies the parent group normal sub-rule of the first abnormality judgment rule, the currently selected parent group information is judged to be normal, and the currently selected parent group information is used as normal group log information; the parent group normal sub-rule is that the first coefficient of variation is less than the first control threshold, or the previous neighbor feature index difference is less than or equal to the first control threshold; the previous neighbor feature index difference is the absolute value of the difference between the first feature index of the currently selected parent group information and the first feature index of the previous parent group information of the currently selected parent group information in the parent group data point set; If the currently selected parent group information meets the parent group anomaly sub-rule of the first anomaly judgment rule, the currently selected parent group information is judged to be abnormal, and the currently selected parent group information is used as a first abnormal group log information; the parent group anomaly sub-rule is that the first coefficient of variation is greater than or equal to the first control threshold, or the difference in the previous neighbor feature index is greater than the first control threshold.

6. The method according to claim 5, characterized in that The determining, based on the sub-group log information, a second characteristic indicator of the sub-group log information includes: Based on the sub-group log information, determining sub-group information corresponding to the sub-group log information; the sub-group information includes detailed log sub-information, a combined information feature corresponding to the detailed log sub-information, and a total number of second threat events corresponding to the detailed log sub-information; the detailed log sub-information is a set obtained by grouping the monitoring log information of the parent group information included in the normal group log information corresponding to the aggregation period according to the threat type; the combined information feature is a combination of the threat type and the destination address of the detailed log sub-information of the sub-group log information corresponding to the aggregation period; the total number of the second threat events is the number of monitoring log information contained in the detailed log sub-information; For the newly added aggregation period, sub-group information corresponding to the basic log information is selected one by one. For each sub-group information selected, based on the chronological order, sub-group information with the same destination address and threat type as the currently selected sub-group information is sequentially obtained from the sub-group information of the basic log information corresponding to each aggregation period to construct a sub-group data point set; According to the total number of second threat events of each sub-group information in the constructed sub-group data point set, a second characteristic indicator corresponding to the currently selected sub-group information is obtained.

7. The method according to claim 6, characterized in that The second characteristic indicator is a second coefficient of variation obtained by calculating the coefficient of variation of the total number of second threat events; and determining the second abnormal group log information in the normal group log information based on the second characteristic indicator and a preset second abnormality judgment rule includes: Selecting normal group log information corresponding to the newly added aggregation period one by one, each time a normal group log information is selected, selecting sub-group information corresponding to the currently selected normal group log information one by one, and each time a sub-group information is selected, calculating the mean and standard deviation of the total number of second threat events of each sub-group information in the sub-group data point set where the currently selected sub-group information is located, and correspondingly obtaining the sub-group mean and sub-group standard deviation corresponding to the currently selected sub-group information; If the currently selected sub-group information satisfies the sub-group normal sub-rule of the second abnormality judgment rule, then the currently selected sub-group information is judged to be normal; the sub-group normal sub-rule is: the second coefficient of variation is less than the first control threshold, and the frequency difference is less than 3 times the sub-group standard deviation; or, the second coefficient of variation is greater than or equal to the first control threshold and less than the second control threshold, and the frequency difference is less than 2 times the sub-group standard deviation; or, the second coefficient of variation is greater than or equal to the second control threshold, and the frequency difference is less than the sub-group standard deviation; the second control threshold is greater than the first control threshold; the frequency difference is the absolute value of the difference between the total number of second threat events of the currently selected sub-group information and the sub-group mean; If the currently selected sub-group information satisfies the sub-group anomaly sub-rule of the second anomaly judgment rule, the currently selected sub-group information is judged to be abnormal, and the currently selected sub-group information is used as a second abnormal group log information in the normal group log information; the sub-group anomaly sub-rule is satisfied if any one of the following conditions is met: the second coefficient of variation is less than the first control threshold, and the frequency difference is greater than or equal to 3 times the sub-group standard deviation; the second coefficient of variation is greater than or equal to the first control threshold and less than the second control threshold, and the frequency difference is greater than or equal to 2 times the sub-group standard deviation; the second coefficient of variation is greater than or equal to the second control threshold, and the frequency difference is greater than or equal to the sub-group standard deviation.

8. A network security threat monitoring device, characterized in that: The device comprises: A basic grouping module, configured to determine basic log information corresponding to an aggregation period based on a log time included in monitoring log information of a terminal detection and response (EDR) device; the basic log information is obtained by grouping monitoring log information based on the aggregation period to which the log time belongs; the aggregation period is a period obtained by dividing consecutive aggregation windows within an observation window; the monitoring log information includes the log time, destination address, and threat type; An address aggregation module is configured to determine a first characteristic indicator of the basic log information based on the basic log information; the first characteristic indicator represents the distribution balance of threat events of the same destination address relative to an aggregation period; a first noise reduction module, configured to determine first abnormal group log information and normal group log information in the basic log information according to the first characteristic indicator and a preset first abnormality judgment rule; a secondary grouping module, configured to determine, based on the normal group log information and the threat type, sub-group log information corresponding to the normal group log information; the sub-group log information being obtained by grouping the monitoring log of the normal group log information based on the threat type; A feature aggregation module is configured to determine a second feature index of the sub-group log information based on the sub-group log information; the second feature index represents a degree of dispersion of threat events of the same threat type and destination address between each aggregation period; A second noise reduction module is configured to determine second abnormal group log information in the normal group log information according to the second characteristic indicator and a preset second abnormality judgment rule; The alarm execution module is used to obtain alarm log information based on the first abnormal group log information and the second abnormal group log information.

9. A computer-readable storage medium storing a computer program, wherein: When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.

10. An electronic device, characterized in that: The method comprises a memory and a processor, wherein the memory stores a computer program that can be run on the processor, and when the computer program is executed by the processor, the method according to any one of claims 1 to 7 is implemented.