Early warning method, electronic equipment, storage medium and program product
By building a mapping relationship between cloud infrastructure resources and application services, generating early warning information and automatically managing resource tags, the problem of insufficient resource and business correlation in cloud security operation and maintenance services is solved, and the response efficiency of security incidents and the accuracy of operation and maintenance decisions are improved.
Patent Information
- Application Number
- CN202410309184.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-18
- Publication Date
- 2025-09-26
AI Technical Summary
Existing cloud security operations services are unable to effectively analyze the correlation between cloud infrastructure resources and businesses, resulting in high costs for security incident impact assessments, complex daily security operations, and a lack of automated management tools.
By collecting configuration management data, building a mapping relationship between cloud infrastructure resources and application services, generating early warning information, accurately locating security incidents and assessing business impact, and using automated resource tag management to improve operation and maintenance efficiency.
It achieves accurate location of security incidents and business impact assessment, improves the overall security level of cloud services and the accuracy of operation and maintenance decisions, and enhances the work efficiency of security operation and maintenance personnel.
Smart Images

Figure CN120711005A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of cloud service technology, and in particular to a security incident-based early warning method, electronic device, computer-readable storage medium, and computer program product. Background Art
[0002] Cloud service security operations centers (SOCs) can provide capabilities such as cloud infrastructure resource management and security incident management. For example, they can collect raw data from various security incidents based on cloud computing for threat detection, incident tracing, investigation, and response. However, related technologies cannot further correlate application services based on cloud infrastructure resources, resulting in a lack of the ability to directly and quickly correlate security incidents with application services. Summary of the Invention
[0003] The embodiments of the present application provide a security event-based early warning method, electronic device, computer-readable storage medium, and computer program product to alleviate or solve one or more technical problems existing in the prior art.
[0004] In a first aspect, an embodiment of the present application provides an early warning method based on security incidents, which is applied to a server side. The early warning method includes: determining a first cloud infrastructure resource corresponding to a security incident; determining a first application service corresponding to the first cloud infrastructure resource based on a first mapping relationship between multiple cloud infrastructure resources and multiple application services, wherein the mapping relationship is constructed based on parsing resource configuration data, and the resource configuration data includes resource data of the multiple cloud infrastructure resources and service data of the multiple application services; generating early warning information for the security incident, the first cloud infrastructure resource and the first application service.
[0005] In the second aspect, an embodiment of the present application provides an early warning method based on security incidents, which is applied to a client. The early warning method includes: receiving early warning information sent by a server for a security incident, a first cloud infrastructure resource and a first application service, wherein the first cloud infrastructure resource corresponds to the security incident; the first application service corresponds to the first cloud infrastructure resource, and is determined based on a first mapping relationship between multiple cloud infrastructure resources and multiple application services, the first mapping relationship being constructed based on parsing resource configuration data, and the resource configuration data including resource data of the multiple cloud infrastructure resources and service data of the multiple application services.
[0006] On the third aspect, an embodiment of the present application provides an early warning system based on security events, including: a server, used to implement any method of the embodiment of the present application and send early warning information to the client; a client, used to receive the early warning information.
[0007] In a fourth aspect, an embodiment of the present application provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory, wherein the processor implements any method of the embodiments of the present application when executing the computer program.
[0008] In a fifth aspect, an embodiment of the present application provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, the method of any one of the embodiments of the present application is implemented.
[0009] In a sixth aspect, an embodiment of the present application provides a computer program product, including a computer program, which implements any method of the embodiments of the present application when executed by a processor.
[0010] Based on the security incident-based early warning method of the embodiment of the present application, first, by collecting configuration management data, not only the resource data of the cloud infrastructure resources can be obtained, but also the service data of the application services can be obtained. Since these application services are configured on the cloud infrastructure resources, the resource data and service data contain the mapping relationship between the cloud infrastructure resources and the application services. By parsing the resource data and service data, the mapping relationship between multiple cloud infrastructure resources and multiple application services can be obtained, thereby constructing a first associated data model. Based on the first associated data model, the cloud infrastructure resources can be associated with the business, so that security operation and maintenance personnel can have a more comprehensive and in-depth understanding of the relationship between cloud infrastructure resources and the business, and provide more accurate data support for the operation and maintenance decisions of security operation and maintenance personnel; further, based on the first associated data model, the application service associated with the cloud infrastructure resource corresponding to the security incident can be determined, thereby associating the security incident with the application service, so that security operation and maintenance personnel can accurately locate which businesses are affected by the security incident, thereby more effectively responding to security incidents, improving the overall security level of cloud services, and providing more accurate data support for the operation and maintenance decisions of security operation and maintenance personnel.
[0011] The above description is only an overview of the technical solution of this application. In order to more clearly understand the technical means of this application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of this application more obvious and easy to understand, the specific implementation methods of this application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] In the accompanying drawings, unless otherwise specified, the same reference numerals throughout the multiple drawings represent the same or similar components or elements. These drawings are not necessarily drawn to scale. It should be understood that these drawings only depict some embodiments according to the present application and should not be regarded as limiting the scope of the present application.
[0013] Figure 1 A schematic diagram of the architecture of an exemplary system provided in an embodiment of the present application;
[0014] Figure 2 A flowchart illustrating a security incident warning method according to an embodiment of the present application is shown;
[0015] Figure 3 A schematic diagram showing an application example based on a security event according to an embodiment of the present application;
[0016] Figure 4 A block diagram of an electronic device used to implement an embodiment of the present application. DETAILED DESCRIPTION
[0017] Hereinafter, only certain exemplary embodiments are briefly described. As will be appreciated by those skilled in the art, the described embodiments may be modified in various ways without departing from the spirit or scope of the present application. Therefore, the drawings and description are to be regarded as illustrative in nature and not restrictive.
[0018] To facilitate understanding of the technical solutions of the embodiments of the present application, the following describes the related technologies of the embodiments of the present application. The following related technologies can be combined with the technical solutions of the embodiments of the present application as optional solutions, and all of them fall within the scope of protection of the embodiments of the present application.
[0019] Cloud infrastructure resources are the foundation for building cloud services, including but not limited to physical servers, cloud infrastructure computing facility resources, cloud infrastructure network equipment resources, and cloud infrastructure storage equipment resources. Among them, cloud infrastructure computing facility resources, cloud infrastructure network equipment resources, and cloud infrastructure storage equipment resources can include both physical equipment resources and virtual resources (such as virtual network equipment and virtual storage resources). Cloud infrastructure resources are usually managed by cloud service providers, and businesses usually include one or more application services involved in one or more products / product lines. Therefore, the cloud security operation and maintenance services provided by cloud service providers usually focus on the security assessment of cloud infrastructure resources, but are insufficient in identifying the connection between cloud infrastructure resources and businesses, which leads to high costs for assessing the impact of security incidents on businesses, making daily security operation and maintenance, operational audits, and application troubleshooting complicated and cumbersome.
[0020] In one implementation of cloud security operations services, cloud computing is used to collect raw data from various security incidents and systems for threat detection, incident tracing, investigation, and response. Alternatively, cloud-native security is used to provide capabilities such as cloud asset management, security situation management, security information and event management, security orchestration, and automated response. However, due to the inability to perform further correlation analysis on application services (such as applications or application systems) on infrastructure resources, this type of cloud security operations service lacks the ability to directly and quickly correlate security incidents in the business dimension. In addition, in existing cloud security operations service implementations, the identification and prioritization of cloud infrastructure resources at the business level are very limited. Operations personnel need to manually identify them, and there is a lack of effective business-dimensional resource tag automation management tools. This has many limitations for security operations that require rapid response and tracking of security incidents.
[0021] Figure 1 This is a schematic diagram of an exemplary system architecture provided in an embodiment of the present application. Figure 1 As shown, the system includes a configuration management database (CMDB) and a security operation and maintenance center, wherein the security operation and maintenance center includes a security operation and maintenance center database, a security operation and maintenance center server and a client. The client can be an operation and maintenance client, a user client, or both an operation and maintenance client and a user client.
[0022] The security operation and maintenance center server can execute the resource management method and the early warning method of security incidents of the embodiment of the present application. For example, the security operation and maintenance center server can obtain not only the resource data of the cloud infrastructure resources, but also the service data of the application services by collecting the configuration management data in the configuration management database (CMDB) deployed outside the cloud service security operation and maintenance center. Since these application services are configured on the cloud infrastructure resources, the resource data and service data contain the mapping relationship between the cloud infrastructure resources and the application services. By parsing the resource data and service data, the first mapping relationship between multiple cloud infrastructure resources and multiple application services can be obtained. For example, the first mapping relationship can be stored as a first associated data model in the security operation and maintenance center database. Based on this, the cloud infrastructure resources can be associated with the business, so that the security operation and maintenance personnel can have a more comprehensive and in-depth understanding of the relationship between the cloud infrastructure resources and the business, and provide more accurate data support for the operation and maintenance decisions of the security operation and maintenance personnel.
[0023] Exemplarily, the security operation and maintenance center server acquires resource data of cloud infrastructure resources and service data of application services by collecting configuration management data from the CMDB. The service data includes application levels of application services, such as security level, continuity level, availability level, and importance level. Therefore, based on the configuration management data, a second mapping relationship between multiple application services and multiple application levels can also be obtained. Exemplarily, the second mapping relationship can be stored as a second association data model in the security operation and maintenance center database.
[0024] Furthermore, based on the first and second mapping relationships, cloud infrastructure resources can be associated with application levels, thereby configuring resource tags for cloud infrastructure resources that match their application levels. Since the resource tags of cloud infrastructure resources can represent the application level of application services, not only can resource tags be automatically configured for cloud infrastructure resources, but also resource tags with business dimensions can be configured for cloud infrastructure resources. This improves the automated tag management capabilities of cloud infrastructure resources, greatly improving the work efficiency of security operations personnel, and at the same time, effectively maintaining the identification and priority processing of cloud infrastructure resources.
[0025] For example, in the process of collecting configuration management data, the operation and maintenance client can feedback the data collection model preset by the operation and maintenance personnel to the security operation and maintenance center server. The data collection model includes the data structure and data type of the resource configuration data to be collected. The security operation and maintenance center server can collect configuration management data from the CMDB according to the data collection model.
[0026] For example, the security operation and maintenance center server can determine the application service associated with the cloud infrastructure resources corresponding to the security incident based on the first mapping relationship, thereby associating the security incident with the application service, enabling security operation and maintenance personnel to accurately locate which businesses are affected by the security incident, thereby more effectively responding to security incidents, improving the overall security level of cloud services, and providing more accurate data support for the operation and maintenance decisions of security operation and maintenance personnel.
[0027] For example, in the process of configuring resource tags for cloud infrastructure resources that match their application levels, based on the fact that the user client can feedback the user-preset resource tags to the security operation and maintenance center server, the security operation and maintenance personnel can preset resource tag configuration rules, including matching rules between multiple application levels and multiple resource tags preset by users, so that the configured resource tags can not only reflect the application level, but also meet the user configuration requirements.
[0028] It should be noted that the above-mentioned application scenarios or application examples of the early warning method based on security events provided in the embodiments of the present application are for ease of understanding, and the embodiments of the present application do not specifically limit the application of the early warning method based on security events.
[0029] In addition, the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions, and provide corresponding operation entrances for users to choose or edit authorization or rejection.
[0030] The following specific embodiments are used to describe in detail the technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems. The several specific embodiments listed can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments.
[0031] An embodiment of the present application provides an early warning method based on security events, which can be applied to a cloud service security operation and maintenance center, for example, executed by a security operation and maintenance center server. Figure 2 A flowchart of a security incident warning method according to an embodiment of the present application is shown. Figure 2 As shown, the method may include step S201, step S202 and step S203.
[0032] Step S201: Determine a first cloud infrastructure resource corresponding to a security event.
[0033] In the field of information security, a security event refers to a potential threat, attack, or anomaly that affects a computer system or network. These security events may be potential security threats that endanger information security or business continuity. For example, data and information about security events can be obtained based on a Security Information and Event Management (SIEM) tool. Security event management tools can automatically collect log and event data from network devices, security devices, servers, and applications, and provide capabilities for collecting, storing, and analyzing various security log data. Security event management tools can be deployed in a security operations center.
[0034] Cloud infrastructure resources include, but are not limited to, physical servers, cloud-based computing infrastructure resources, cloud-based network equipment resources, and cloud-based storage equipment resources. These cloud-based computing infrastructure resources, cloud-based network equipment resources, and cloud-based storage equipment resources may include both physical equipment resources and virtual resources, such as virtual network equipment and virtual storage resources. In this embodiment of the present application, the first cloud infrastructure resource is the cloud infrastructure resource corresponding to a security incident, i.e., the cloud infrastructure resource affected or involved by the security incident.
[0035] Step S202: Determine a first application service corresponding to a first cloud infrastructure resource based on a first mapping relationship between multiple cloud infrastructure resources and multiple application services, wherein the first mapping relationship is constructed based on parsing resource configuration data, and the resource configuration data includes resource data of multiple cloud infrastructure resources and service data of multiple application services.
[0036] Application services include services provided by applications or application systems within one or more products or product lines. Applications or application systems are deployed on cloud infrastructure resources, meaning they provide application services based on cloud infrastructure resources. Resource configuration data includes both resource data for cloud infrastructure resources and service data for application services. For example, resource configuration data can be collected from a configuration management database (CMDB). The configuration management database, deployed outside the cloud service security operations center, stores resource configuration data for a large amount of cloud resources, including both cloud infrastructure resources and application services deployed based on them.
[0037] Exemplarily, resource data includes physical server data, cloud-based computing facility resource data, cloud-based network equipment resource data, and cloud-based storage device resource data. Service data primarily comprises business-level data, such as application data, application system data, product line data, product data, and application levels. Application levels include, but are not limited to, continuity levels, security levels, importance levels, and availability levels, and are used to characterize the business-level rating of an application service. The application level of an application service can be preset based on the actual application scenario.
[0038] Because these application services are configured on cloud infrastructure resources (i.e., services are provided based on cloud infrastructure resources), the resource data and service data contain mapping relationships between cloud infrastructure resources and application services. By parsing the resource data and service data, a first mapping relationship between multiple cloud infrastructure resources and multiple application services can be obtained, thereby constructing a first association data model. Furthermore, using the first mapping relationship, the application service that has a mapping relationship with the first cloud infrastructure resource can be determined, thereby obtaining the first application service.
[0039] Step S203: Generate warning information for the security event, the first cloud infrastructure resource, and the first application service.
[0040] Exemplarily, the warning information includes identification information, key information, or detailed information of the security event, the first cloud infrastructure resource, and the first application service. Based on steps S201 and S203, an association can be established between the security event and the first cloud infrastructure resource and the first application service. Therefore, when issuing a warning for the security event, the first cloud infrastructure resource and the first application service associated with the security event can be obtained based on the warning information, and a warning can be issued for the first cloud infrastructure resource and the first application service.
[0041] In the embodiment of the present application, a business includes one or more application services involved in one or more products / product lines. According to the method of the embodiment of the present application, security incidents can be associated with application services, that is, security incidents can be associated with businesses, so that security operations personnel can have a more comprehensive and in-depth understanding of the relationship between cloud infrastructure resources and businesses, and can accurately locate which businesses are affected by security incidents, thereby more effectively responding to security incidents, improving the overall security level of cloud services, and providing more accurate data support for security operations personnel's operation and maintenance decisions.
[0042] In one embodiment, determining the first cloud infrastructure resource corresponding to the security event includes: parsing a destination IP address of the security event from a security event log; and using the cloud infrastructure resource corresponding to the destination IP address as the first cloud infrastructure resource.
[0043] The term "IP address" refers to an Internet Protocol address. For example, when a security event management tool collects a security event log, such as a Network Detection and Response (NDR) attack alert log, the data in the log can be standardized to obtain the destination IP address. The destination IP address can then be quickly associated with the corresponding destination cloud infrastructure resource to obtain the first cloud infrastructure resource.
[0044] Therefore, when the security operation and maintenance center collects the log of a security incident, the log can not only be mapped to specific cloud infrastructure resources (assets), but also be associated with the business context of the cloud infrastructure resources, thereby providing security operation and maintenance personnel with the attack path, impact range and potential business impact of the security incident, making the formulated response measures more accurate and targeted, ensuring rapid and effective threat disposal and risk mitigation.
[0045] As mentioned above, based on the mapping relationship between multiple cloud infrastructure resources and multiple application services, the application services corresponding to the cloud infrastructure resources under the management of the security operation and maintenance center can be obtained, and the cloud infrastructure resources can be associated with the business, so that security operation and maintenance personnel can have a more comprehensive and in-depth understanding of the relationship between cloud infrastructure resources and the business.
[0046] For example, based on the first mapping relationship, the application services corresponding to the cloud infrastructure resources managed by the security operation and maintenance center can be determined, and corresponding resource tags can be configured for the cloud infrastructure resources. That is, the resource tags of the cloud infrastructure resources match the application services corresponding to the cloud infrastructure. Based on this, business-related resource tags can be automatically added to the cloud infrastructure resources.
[0047] The configuration method for resource tags can be set according to operation and maintenance requirements, for example, according to the type of application service. In one embodiment, the configuration can be based on the application level of the application service. Specifically, the service data of the application service obtained from the configuration management database includes the application level. The configuration method for resource tags may include: determining a third mapping relationship between multiple cloud infrastructure resources and multiple application levels based on the first mapping relationship and the second mapping relationship between multiple application services and multiple application levels; and configuring a resource tag for each cloud infrastructure resource that matches its application level based on the third mapping relationship.
[0048] Application levels are used to measure and categorize the importance or performance of application services in different aspects, including but not limited to security level, continuity level, availability level, and importance level. For example, security level can be determined based on the application service's ability to protect data and systems from unauthorized access, leakage, tampering, or destruction; continuity level can be determined based on the application service's ability to continue operating and recover in the face of interruptions and disasters; availability level can be determined based on the degree to which the application service operates normally and is accessible within the expected timeframe; and importance level can be determined based on the importance of the application service to the business and the impact of service interruptions on the business.
[0049] By parsing the application level data of the application service in the resource configuration data, a second mapping relationship between multiple application services and multiple application levels can be obtained. Based on the first mapping relationship and the second mapping relationship, the cloud infrastructure resources can be associated with the application level, thereby configuring a resource tag for any cloud infrastructure resource that matches its application level.
[0050] Based on this, not only can resource tags be automatically configured for cloud infrastructure resources, but also resource tags with business dimensions can be configured for cloud infrastructure resources. This improves the automated tag management capabilities of cloud infrastructure resources, greatly improving the work efficiency of security operations personnel, and at the same time, effectively maintaining the identification and priority management of cloud infrastructure resources. In addition, because resource tag configuration relies on the service data of application services, when service data changes, the resource tags of the corresponding cloud infrastructure resources can be linked, thereby better managing cloud infrastructure resources.
[0051] In one embodiment, configuring a resource tag that matches an application level for any cloud infrastructure resource may include: taking any cloud infrastructure resource as a target cloud infrastructure resource, and based on preset resource tag configuration rules, determining a resource tag that matches the application level of the target cloud infrastructure resource as a target resource tag, wherein the resource tag configuration rules include matching rules between multiple application levels and multiple preset resource tags; and configuring the target resource tag for the target cloud infrastructure resource.
[0052] Among them, resource tag configuration rules can be preset by users and fed back to the security operation and maintenance center based on the user client, that is, the matching rules between multiple application levels and multiple preset resource tags can be preset by users; or, users preset resource tags according to actual needs, and feed back the preset resource tags to the security operation and maintenance center through the user client, and the operation and maintenance personnel preset the matching rules between application levels and user-preset resource tags. Using resource tag configuration rules, it is possible to automatically configure business-dimensional resource tags for cloud infrastructure resources according to user needs. For example, resource tags related to cloud infrastructure resources can be configured based on importance levels to identify their importance. Therefore, resource tag configuration rules not only help to automatically classify and identify cloud infrastructure resources in multiple dimensions, but also reflect their business-dimensional attributes.
[0053] In one embodiment, the warning information may include a resource tag for the first cloud infrastructure resource, where the resource tag matches the first application service. Therefore, when a security incident is detected, the resource tag of the corresponding cloud infrastructure resource can be automatically identified, its business-related attributes can be obtained, and the impact on the business can be determined, thereby determining the priority of the response to the security incident.
[0054] In one embodiment, the method of the embodiment of the present application may also include: determining the second cloud infrastructure resource corresponding to the query request; determining the second application service corresponding to the second cloud infrastructure resource based on the first mapping relationship; and displaying the service data of the second application service and / or event data of historical security events.
[0055] Among them, the second cloud infrastructure resource is the cloud infrastructure resource corresponding to the query request, that is, the cloud infrastructure resource to be queried, and the second application service is the application service with which the second cloud infrastructure resource has a mapping relationship, thereby displaying the service data of the second application service. As mentioned above, according to the method of the embodiment of the present application, each security event can be associated with the corresponding application service. Therefore, the application service can be associated with one or more historical security events, and then the corresponding historical security events can be queried and the event data of the historical security event can be displayed. Exemplarily, the event data may include one or more of an identifier, a summary, or a log.
[0056] For example, based on an operation and maintenance client, security operation and maintenance personnel can initiate a query request to the system, or based on a user client, a user can initiate a query request to the system. The security operation and maintenance center server responds to the query request and provides data analysis capabilities in different scenarios based on the first associated data model and / or the second associated data model, such as associating cloud infrastructure resources with application services or historical security events, associating application services with cloud infrastructure resources or historical security events, associating security events with cloud infrastructure resources or application services, and querying resource tags of cloud infrastructure resources. The first associated data model and the second associated data model may only provide the unique identifier and corresponding name of each associated data. More detailed information can be displayed through a query, that is, detailed information of the query results can be displayed through a query, such as information about the release platform of the application or application system, information about the relevant department and responsible personnel; information such as application level rules and descriptions; and information such as the tree path and description of the product line.
[0057] In one embodiment, the method of the embodiment of the present application may also include: collecting resource configuration data from a configuration management database based on a preset data collection model, wherein the data collection model includes the data structure and data type of the resource configuration data to be collected; parsing the resource configuration data to determine a first mapping relationship between multiple cloud infrastructure resources and multiple application services.
[0058] For example, during the process of collecting configuration management data, the operation and maintenance client can provide feedback to the security operation and maintenance center server based on a data collection model preset by the operation and maintenance personnel. The data collection model includes the data structure and data type of the resource configuration data to be collected. The security operation and maintenance center server can then collect configuration management data from the CMDB according to the data collection model. For example, after the operation and maintenance personnel obtain an inventory of cloud infrastructure resources maintained by the security operation and maintenance center, they can construct a data collection model based on the inventory, such as the data structure and data type of the resource data to be collected, and the data structure and data type of the service data to be collected. The security operation and maintenance center server can then collect the corresponding data from the CMDB according to the data collection model.
[0059] Based on this, the system efficiency and data consistency can be improved, and a clear and standardized framework can be provided for data organization and processing, thereby simplifying the development process, reducing errors and inconsistencies, accelerating data integration and analysis, and improving the maintainability and scalability of the system, while laying the foundation for rapid access to subsequent product data expansion.
[0060] An embodiment of the present application provides a security event-based early warning method, which can be applied to a cloud service security operation and maintenance center, for example, executed by a client. The early warning method includes: receiving early warning information sent by a server for a security event, a first cloud infrastructure resource, and a first application service, wherein the first cloud infrastructure resource corresponds to the security event; the first application service corresponds to the first cloud infrastructure resource, and is determined based on a first mapping relationship between multiple cloud infrastructure resources and multiple application services, the first mapping relationship being constructed based on parsing resource configuration data, the resource configuration data including resource data of the multiple cloud infrastructure resources and service data of the multiple application services.
[0061] For example, the client may be an operation and maintenance client, that is, the warning information may be sent to the operation and maintenance client. Figure 2 and Figure 3 An application example of the embodiment of the present application is introduced. Figure 2 and Figure 3 As shown, the security operation and maintenance center database may include a resource database, a model database, and an operation and maintenance configuration database.
[0062] Among them, the resource data of the cloud infrastructure resources managed by the security operation and maintenance center is stored in the resource database. The task allocation tool based on the security operation and maintenance center server can predefine the data types and data structures that need to be collected from the CMDB according to the cloud infrastructure resources managed by the security operation and maintenance center, that is, predefine the data collection model. Scheduled tasks can collect resource configuration data from the CMDB according to the data collection model, including service data of application services and resource data of cloud infrastructure resources. Among them, service data can include data of applications or application systems, such as identification data, resource usage data, etc., and can also include application-level data. The period of the scheduled task can be set by user-defined decisions. For example, it can be set to ensure that the system data has the minimum delay on the basis of achieving eventual consistency, or it can be set to achieve the minimum load on the system on the basis of achieving eventual consistency.
[0063] For example, when collecting resource configuration data through a custom scheduled task, complex queries and data relationship processing are involved. To ensure the quality and consistency of data collection, the collected resource configuration data can be pre-processed through data cleaning, data relationship processing, and business logic processing. The primary purpose of cleaning is to remove data that does not meet the requirements of the security operation and maintenance center or contains abnormal values. Data relationship processing further ensures data accuracy while building a solid data infrastructure for data association. Business logic processing ensures that data association, resource labeling, or data analysis meet business requirements.
[0064] By parsing the resource configuration data, the mapping relationship between multiple application services and multiple application levels can be obtained, thereby constructing a second associated data model, and storing the second associated data model in the model database of the security operation and maintenance center; by parsing the resource configuration data, the mapping relationship between multiple cloud infrastructure resources and multiple application services can also be obtained, thereby constructing a first associated data model, and storing the first associated data model in the model database.
[0065] In one example, the analysis engine on the security operation and maintenance center server side can analyze and determine the cloud infrastructure resources corresponding to the security events collected by the security event management (SIEM) tool, and determine the associated application services based on the first correlation data model, thereby issuing early warnings for the cloud infrastructure resources and application services. Based on the SIEM's security log import and outbound capabilities, the analysis engine can be quickly associated with the security log. As the SIEM data is outbound, the association results of the security events with business information such as cloud infrastructure resources and application services are sent to downstream products in the cloud ecosystem. Downstream products can obtain relevant early warning information by consuming security log data.
[0066] For example, to ensure that business-related information can be quickly and easily associated in different scenarios, a second associated data model centered on application services and associated with application levels such as security, availability, importance, and continuity is established, along with a first associated data model that associates different infrastructure resources with application services. The analytical capabilities of the overall analysis engine are built based on these two models. A multi-model design based on the first and second associated data models provides the analysis engine with data output capabilities, enabling reuse across different scenarios and improving efficiency and consistency. Through the analysis engine, different application services can better collaborate, share data and services, and optimize business processes. For example, in externally associated analysis of security incidents and asset management, the analysis engine first activates the first associated data model to analyze the relevant business information, and then uses the second associated data model to further analyze the business's security, availability, importance, and continuity. While complex associated scenarios require multiple data models to collaborate and provide analytical capabilities, simple scenarios can be intelligently matched based on the business situation, selecting the appropriate model for analysis, ensuring accurate analysis while minimizing computing resource consumption.
[0067] In another example, in view of the fact that there may be a large number of assets (resources) or complex business, the cost of manual labeling of resource tags is high. According to the technical solution of the embodiment of the present application, the user can feedback the user-preset resource tags to the security operation and maintenance center server based on the user client, and store them in the operation and maintenance configuration database; the security operation and maintenance personnel can use the task allocation tool of the security operation and maintenance center server to preset resource tag configuration rules, including matching rules between multiple application levels and multiple user-preset resource tags, so that the configured resource tags can not only reflect the application level, but also meet the user configuration requirements, and further obtain the mapping relationship between cloud infrastructure resources and application services from the analysis engine, and configure resource tags for cloud infrastructure resources according to the resource tag configuration rules. For example, the analysis engine is called, and the appropriate data model is selected for analysis through intelligent model matching, and the obtained application services and their application levels are labeled with the corresponding cloud infrastructure resources according to the resource tag configuration rules, thereby realizing the automated management of resource tags.
[0068] For example, when querying cloud infrastructure resources managed by the Security Operations Center, information about resource tags, such as importance and type, is obtained from the CMDB linkage. This allows the Security Operations Center to identify cloud infrastructure resources based on business dimensions such as application and application level, and then assess the criticality and priority of cloud infrastructure resources based on these tags. Therefore, security incidents and warnings can be sorted according to the business importance of cloud infrastructure resources, ensuring that the security team prioritizes those incidents with the greatest impact on business operations. Furthermore, this identification method provides a structured and standardized approach for asset management, risk assessment, and compliance monitoring, significantly improving the efficiency and effectiveness of security operations.
[0069] For example, when querying information about a cloud infrastructure resource, the analysis engine can retrieve all business information associated with the resource, including the applications, application systems, product lines, and application levels supported by the resource. Furthermore, the analysis engine can provide historical security incidents related to the cloud infrastructure resource and their correlation with application services. This comprehensive view not only enhances understanding of the current state of cloud infrastructure resources but also helps predict and prevent future security threats. Through this in-depth business-related analysis, the security operations center can develop more effective security policies and optimize resource allocation to protect the organization's critical assets from attacks and ensure business continuity.
[0070] Corresponding to the application scenario and the security event-based warning method provided in the embodiments of the present application, the embodiments of the present application also provide a security event-based warning device. The device may include: a first cloud infrastructure resource determination module, configured to determine a first cloud infrastructure resource corresponding to a security event; a first application service determination module, configured to determine a first application service corresponding to the first cloud infrastructure resource based on a first mapping relationship between multiple cloud infrastructure resources and multiple application services, wherein the first mapping relationship is constructed based on parsing resource configuration data, the resource configuration data including resource data of the multiple cloud infrastructure resources and service data of the multiple application services; and a warning information generation module, configured to generate warning information for the security event, the first cloud infrastructure resource, and the first application service.
[0071] In one embodiment, the first cloud infrastructure resource determination module is specifically configured to: parse the destination IP address of the security event from the log of the security event; and use the cloud infrastructure resource corresponding to the destination IP address as the first cloud infrastructure resource.
[0072] In one embodiment, the warning information includes a resource tag of the first cloud infrastructure resource, and the resource tag of the first cloud infrastructure resource matches the first application service.
[0073] In one embodiment, the service data includes application levels, and the device also includes: a resource tag configuration module, used to determine a third mapping relationship between the multiple cloud infrastructure resources and the multiple application levels based on the first mapping relationship and the second mapping relationship between the multiple application services and the multiple application levels; and according to the third mapping relationship, configure a resource tag for any cloud infrastructure resource that matches its application level.
[0074] In one embodiment, the resource tag configuration module is further used to: take any of the cloud infrastructure resources as the target cloud infrastructure resource, and based on a preset resource tag configuration rule, determine a resource tag that matches the application level of the target cloud infrastructure resource as the target resource tag, wherein the resource tag configuration rule includes a matching rule between the multiple application levels and multiple preset resource tags; and configure the target resource tag for the target cloud infrastructure resource.
[0075] In one embodiment, the device also includes a query display module for determining the second cloud infrastructure resource corresponding to the query request; determining the second application service corresponding to the second cloud infrastructure resource based on the first mapping relationship; and displaying the service data of the second application service and / or the event data of historical security events.
[0076] In one embodiment, the device also includes a model building module for collecting the resource configuration data from the configuration management database based on a preset data collection model, wherein the data collection model includes the data structure and data type of the resource configuration data to be collected; parsing the resource configuration data to determine a first mapping relationship between the multiple cloud infrastructure resources and the multiple application services.
[0077] The functions of each module in each device in the embodiments of the present application can be found in the corresponding description in the above method, and have corresponding beneficial effects, which will not be repeated here.
[0078] Corresponding to the application scenario and the warning method based on security events provided in the embodiments of the present application, the embodiments of the present application also provide a warning device based on security events. The device may include: a receiving module for receiving warning information sent by a server for a security event, a first cloud infrastructure resource, and a first application service, wherein the first cloud infrastructure resource corresponds to the security event; the first application service corresponds to the first cloud infrastructure resource, and is determined based on a first mapping relationship between multiple cloud infrastructure resources and multiple application services, the first mapping relationship being constructed based on parsing resource configuration data, the resource configuration data including resource data of the multiple cloud infrastructure resources and service data of the multiple application services. Figure 4 FIG. 1 is a block diagram of an electronic device for implementing an embodiment of the present application. Figure 4 As shown, the electronic device includes: a memory 401 and a processor 402. The memory 401 stores a computer program that can be run on the processor 402. When the processor 402 executes the computer program, the method in the above embodiment is implemented. The number of the memory 401 and the processor 402 can be one or more.
[0079] The electronic device further includes a communication interface 403 for communicating with external devices and performing data exchange transmission.
[0080] If the memory 401, processor 402, and communication interface 403 are implemented independently, the memory 401, processor 402, and communication interface 403 can be connected to each other via a bus and communicate with each other. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 4 Only one thick line is used in the diagram, but this does not mean that there is only one bus or one type of bus.
[0081] Optionally, in a specific implementation, if the memory 401, the processor 402 and the communication interface 403 are integrated on a chip, the memory 401, the processor 402 and the communication interface 403 can communicate with each other through an internal interface.
[0082] An embodiment of the present application provides a computer-readable storage medium storing a computer program, which implements the method provided in the embodiment of the present application when the program is executed by a processor.
[0083] An embodiment of the present application also provides a chip, which includes a processor for calling and executing instructions stored in the memory from the memory, so that a communication device equipped with the chip executes the method provided in the embodiment of the present application.
[0084] An embodiment of the present application also provides a chip, including: an input interface, an output interface, a processor and a memory. The input interface, the output interface, the processor and the memory are connected through an internal connection path. The processor is used to execute the code in the memory. When the code is executed, the processor is used to execute the method provided in the embodiment of the application.
[0085] It should be understood that the processor may be a CPU, or other general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), an FPGA or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc. It is worth noting that the processor may be a processor that supports the Advanced RISC Machines (ARM) architecture.
[0086] Furthermore, optionally, the above-mentioned memory may include a read-only memory and a random access memory. The memory may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may include a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may include a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available. For example, static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link DRAM (SLDRAM) and direct memory bus random access memory (DR RAM).
[0087] In the above embodiments, all or part of the embodiments may be implemented using software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments may be implemented in the form of a computer program product. A computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions according to the present application are generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another.
[0088] In the description of this specification, the reference terms "one embodiment," "some embodiments," "example," "specific example," or "some examples" mean that the specific features, structures, materials, or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present application. Moreover, the specific features, structures, materials, or characteristics described may be combined in any appropriate manner in any one or more embodiments or examples. In addition, those skilled in the art may combine and integrate different embodiments or examples described in this specification, as well as features of different embodiments or examples, unless they are mutually inconsistent.
[0089] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features being referred to. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one such feature. Throughout the description of this application, "plurality" means two or more, unless otherwise specifically defined.
[0090] Any process or method described in the flowchart or otherwise described herein can be understood to represent a module, segment or portion of code comprising one or more executable instructions for implementing the steps of a specific logical function or process. The scope of the preferred embodiments of the present application includes other implementations in which the functions may be performed in a different order than shown or discussed, including performing the functions substantially simultaneously or in reverse order depending on the functions involved.
[0091] The logic and / or steps described in the flowchart or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by an instruction execution system, apparatus or device (such as a computer-based system, a system including a processor or other system that can fetch instructions from an instruction execution system, apparatus or device and execute instructions), or used in combination with such instruction execution systems, apparatuses or devices.
[0092] It should be understood that various parts of the present application can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. All or part of the steps of the above embodiment method can be completed by instructing the relevant hardware through a program, which can be stored in a computer-readable storage medium. When the program is executed, it includes one or a combination of the steps of the method embodiment.
[0093] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing module, or each unit may exist physically separately, or two or more units may be integrated into a single module. The aforementioned integrated modules may be implemented in the form of hardware or in the form of software functional modules. If the aforementioned integrated modules are implemented in the form of software functional modules and sold or used as independent products, they may also be stored in a computer-readable storage medium. The storage medium may be a read-only memory, a magnetic disk, or an optical disk, etc.
[0094] The above is merely an exemplary embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any person skilled in the art can easily conceive of various modifications or substitutions within the technical scope described in this application, and such modifications or substitutions should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.
Claims
1. A security event-based early warning method, applied to a server, comprising: Determining a first cloud infrastructure resource corresponding to the security incident; determining, based on a first mapping relationship between a plurality of cloud infrastructure resources and a plurality of application services, a first application service corresponding to the first cloud infrastructure resource, wherein the first mapping relationship is constructed based on parsing resource configuration data, the resource configuration data including resource data of the plurality of cloud infrastructure resources and service data of the plurality of application services; Generate early warning information for the security event, the first cloud infrastructure resource, and the first application service.
2. The method according to claim 1, wherein Identify the first cloud infrastructure resource corresponding to the security incident, including: Parsing the destination IP address of the security event from the log of the security event; The cloud infrastructure resource corresponding to the destination IP address is used as the first cloud infrastructure resource.
3. The method according to claim 1, wherein The warning information includes a resource tag of the first cloud infrastructure resource, and the resource tag of the first cloud infrastructure resource matches the first application service.
4. The method according to claim 3, wherein: The service data includes an application level, and the method further includes: determining, based on the first mapping relationship and the second mapping relationship between the plurality of application services and the plurality of application levels, a third mapping relationship between the plurality of cloud infrastructure resources and the plurality of application levels; A resource tag that matches the application level of any cloud infrastructure resource is configured according to the third mapping relationship.
5. The method according to claim 4, wherein Configure resource tags for any cloud infrastructure resource that match its application level, including: Taking any of the cloud infrastructure resources as a target cloud infrastructure resource, and determining, based on a preset resource tag configuration rule, a resource tag that matches the application level of the target cloud infrastructure resource as a target resource tag, wherein the resource tag configuration rule includes a matching rule between the multiple application levels and multiple preset resource tags; The target resource tag is configured for the target cloud infrastructure resource.
6. The method according to any one of claims 1 to 5, further comprising: Determining a second cloud infrastructure resource corresponding to the query request; Determine, according to the first mapping relationship, a second application service corresponding to the second cloud infrastructure resource; The service data of the second application service and / or the event data of the historical security events are sent to the client.
7. The method according to any one of claims 1 to 5, further comprising: Based on a preset data collection model, the resource configuration data is collected from a configuration management database, wherein the data collection model includes a data structure and a data type of the resource configuration data to be collected; The resource configuration data is parsed to determine a first mapping relationship between the plurality of cloud infrastructure resources and the plurality of application services.
8. A security event-based early warning method, applied to a client, comprising: Receive warning information sent by a server for a security event, a first cloud infrastructure resource, and a first application service, wherein the first cloud infrastructure resource corresponds to the security event; the first application service corresponds to the first cloud infrastructure resource and is determined based on a first mapping relationship between multiple cloud infrastructure resources and multiple application services, the first mapping relationship being constructed based on parsing resource configuration data, the resource configuration data including resource data of the multiple cloud infrastructure resources and service data of the multiple application services.
9. An early warning system based on security incidents, comprising: A server, configured to implement the method according to any one of claims 1 to 7 and send warning information to the client; The client is used to receive the warning information.
10. An electronic device comprising a memory, a processor, and a computer program stored in the memory, wherein the processor implements the method according to any one of claims 1 to 8 when executing the computer program.
11. A computer-readable storage medium, wherein a computer program is stored in the computer-readable storage medium, and when the computer program is executed by a processor, the method according to any one of claims 1 to 8 is implemented.
12. A computer program product comprising a computer program, which, when executed by a processor, implements the method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Infrastructure service method and device based on block chain
CN110855701A
Monitoring data association method and device, computer equipment and storage medium
CN114780335A
Operation and maintenance method and system for service continuity of data center and related equipment
CN115567362A
Data processing method and device, server and storage medium
CN116594735A
Application system portrait generation method and device, processor and electronic equipment
CN116643789A