Security collaboration method, device and equipment based on data sharing terminal and storage medium
By establishing a secure data transmission channel between terminals, sharing and analyzing security data in real time, and generating collaborative defense strategies and situation reports, the problem of insufficient information sharing during independent terminal operation is solved, and network security protection capabilities are improved.
Patent Information
- Application Number
- CN202510939370.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-08
- Publication Date
- 2025-10-10
AI Technical Summary
In traditional terminal security protection, each terminal operates independently and lacks information sharing and collaborative defense mechanisms, resulting in the inability to timely detect and deal with potential security threats.
Establish secure data transmission channels between terminals, share security-related data in real time, generate collaborative defense strategies through threat analysis, conduct in-depth threat identification, and integrate to generate security situation reports.
It realizes the integrated utilization of multi-terminal security data, improves the comprehensiveness and accuracy of threat analysis, can timely discover new attacks and potential threats, generate accurate collaborative defense strategies, enhance terminal security collaborative defense capabilities, and improve the overall security and reliability of the system.
Smart Images

Figure CN120768601A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and in particular to a terminal security cooperation method and device based on data sharing, equipment and a storage medium. BACKGROUND
[0002] With the rapid development of network technology, network security threats are increasingly complex and diverse, and the security protection capability of a single terminal device is limited, which is difficult to effectively respond to new and large-scale network attacks. The traditional security protection mode is often independent operation of each terminal, lacking information sharing and cooperative defense mechanism, which leads to the inability to timely discover and handle potential security threats and difficulty in guaranteeing the overall security of the network environment.
[0003] Therefore, the prior art still needs to be improved and developed. SUMMARY
[0004] The main purpose of the present application is to solve the problem that each terminal independently operates in the traditional terminal security protection, lacking information sharing and cooperative defense mechanism, leading to the inability to timely discover and handle potential security threats.
[0005] The first aspect of the present application provides a terminal security cooperation method based on data sharing, comprising: establishing a secure data transmission channel between terminals, sharing the security-related data of each terminal in real time through the secure data transmission channel to form a shared data set; performing threat analysis on the shared data set to generate a threat analysis result, and generating a terminal cooperative defense strategy based on the threat analysis result; performing deep threat identification on the shared data set to identify new attack patterns and potential threats of the shared data set, and generating a threat identification result; integrating the shared data set, the terminal cooperative defense strategy and the threat identification result to generate a security posture report containing security event information, threat intelligence information and defense measure information.
[0006] Optionally, in the first implementation manner of the first aspect of the present application, a communication key between terminals is generated by using a secure data transmission protocol; a secure data transmission channel is constructed based on the communication key, which is used for obfuscating and encrypting the security-related data to generate encrypted data; the hash values of the security-related data of each terminal are calculated by using a hash algorithm, and the hash values are compared between terminals, if the comparison is inconsistent, a difference data incremental transmission process is triggered to generate synchronization data; the encrypted data and the synchronization data jointly constitute the shared data set.
[0007] Optionally, in the second implementation form of the first aspect of the present application, the shared data set is cleaned and format-unified to generate structured data; a correlation rule mining algorithm is used to analyze the correlation relationship among the security events, vulnerability information and threat intelligence in the structured data, to generate threat correlation rules as the threat analysis result.
[0008] Optionally, in the third implementation form of the first aspect of the present application, a threat feature is extracted from the threat analysis result, the threat feature is matched with a policy template in a preset policy template library, and a matching result is generated; the matching policy template is filtered according to the matching result, and a terminal cooperative defense strategy is generated based on a predefined defense measure in the policy template.
[0009] Optionally, in the fourth implementation form of the first aspect of the present application, a key feature is extracted from the shared data set, and the key feature is normalized to generate a normalized feature vector; an initial threat recognition model is constructed, and the initial threat recognition model is trained by historical security event data of the terminal to generate a trained attack pattern recognition model; the normalized feature vector is input into the trained attack pattern recognition model, and the normalized feature vector is recognized by the trained attack pattern recognition model for new attack pattern and potential threat, to output a threat recognition result.
[0010] Optionally, in the fifth implementation form of the first aspect of the present application, threat warning information is generated based on a threatened terminal recorded in the threat recognition result; the threat warning information is synchronized to the threatened terminal, and a warning response mechanism is triggered.
[0011] Optionally, in the sixth implementation form of the first aspect of the present application, security event information is extracted from the shared data set, defense measure information is extracted from the terminal cooperative defense strategy, and threat intelligence information is extracted from the threat recognition result, to form a multi-source data element set; the multi-source data element set is structured, and the structured multi-source data element is filled into a corresponding position of a preset report template to generate a security posture report containing the security event information, the threat intelligence information and the defense measure information.
[0012] The second aspect of the present invention provides a terminal security collaboration device based on data sharing, including: an establishment module for establishing a secure data transmission channel between terminals, and sharing the security-related data of each terminal in real time through the secure data transmission channel to form a shared data set; an analysis module for performing threat analysis on the shared data set, generating threat analysis results, and generating a terminal collaborative defense strategy based on the threat analysis results; an identification module for performing in-depth threat identification on the shared data set, identifying new attack modes and potential threats of the shared data set, and generating threat identification results; an integration module for integrating the shared data set, terminal collaborative defense strategy and threat identification results to generate a security situation report containing security events, threat intelligence and defense measures.
[0013] Optionally, in a first implementation method of the second aspect of the present invention, the establishment module includes: a channel establishment unit, used to generate a communication key between terminals using a secure data transmission protocol; constructing a secure data transmission channel based on the communication key, and the secure data transmission channel is used to perform obfuscation encryption processing on the security-related data to generate encrypted data; a data calculation unit, used to calculate the hash value of the security-related data of each terminal through a hash algorithm, and compare the hash value between the terminals. If the comparison is inconsistent, the differential data incremental transmission process is triggered to generate synchronization data; an integration unit, used for the encrypted data and the synchronization data to jointly constitute the shared data set.
[0014] Optionally, in a second implementation of the second aspect of the present invention, the analysis module includes: a data processing unit, used to clean and unify the format of the shared data set to generate structured data; a threat analysis unit, used to use an association rule mining algorithm to analyze the correlation between security events, vulnerability information, and threat intelligence in the structured data, and generate threat association rules as the threat analysis results.
[0015] Optionally, in a third implementation of the second aspect of the present invention, the analysis module further includes: a policy matching unit, used to extract threat features from the threat analysis results, perform feature matching on the threat features with policy templates in a preset policy template library, and generate matching results; a policy generation unit, used to screen matching policy templates according to the matching results, and generate a terminal collaborative defense strategy based on the defense measures predefined in the policy templates.
[0016] Optionally, in a fourth implementation of the second aspect of the present invention, the identification module includes: a feature extraction unit, used to extract key features from the shared data set, and normalize the key features to generate a normalized feature vector; a model generation unit, used to construct an initial threat identification model, and train the initial threat identification model through the terminal's historical security event data to generate a trained attack pattern identification model; a threat identification unit, used to input the normalized feature vector into the trained attack pattern identification model, identify new attack patterns and potential threats on the normalized feature vector through the trained attack pattern identification model, and output a threat identification result.
[0017] Optionally, in the fifth implementation method of the second aspect of the present invention, the data sharing terminal security collaboration device also includes: an early warning module, which is used to generate threat warning information based on the threatened terminal recorded in the threat identification result; synchronize the threat warning information to the threatened terminal, and trigger an early warning response mechanism.
[0018] Optionally, in a sixth implementation method of the second aspect of the present invention, the integration module includes: an information extraction unit, used to extract security event information from the shared data set, extract defense measures information from the terminal collaborative defense strategy, and extract threat intelligence information from the threat identification results to form a multi-source data element set; a report generation unit, used to structure the multi-source data element set, and based on a pre-set report template, fill the structured multi-source data elements into the corresponding positions of the report template to generate a security situation report containing security event information, threat intelligence information and defense measures information.
[0019] The third aspect of the present invention provides a data sharing terminal security collaboration device, comprising: a memory and at least one processor, wherein the memory stores computer-readable instructions, and the memory and the at least one processor are interconnected through lines; the at least one processor calls the computer-readable instructions in the memory so that the data sharing terminal security collaboration device executes the various steps of the data sharing terminal security collaboration method as described above.
[0020] A fourth aspect of the present invention provides a computer-readable storage medium, which stores computer-readable instructions. When the computer-readable storage medium is run on a computer, it enables the computer to execute the various steps of the data sharing terminal security collaboration method as described above.
[0021] Beneficial effects: In the technical solution of the present invention, a secure data transmission channel is first established between terminals, and the security-related data of each terminal is shared in real time to form a shared data set; then, a threat analysis is performed on the set to generate a threat analysis result, and a terminal collaborative defense strategy is generated based on this; at the same time, a deep threat identification is performed on the set to identify new attack patterns and potential threats to generate threat identification results; finally, the shared data set, defense strategy and threat identification results are integrated to generate a security situation report containing security events, threat intelligence and defense measures information. The present invention realizes the integrated utilization of multi-terminal security data through real-time sharing and collaborative analysis of security data, improves the comprehensiveness and accuracy of threat analysis, can timely discover new attacks and potential threats, generate accurate collaborative defense strategies, and at the same time provides comprehensive decision-making support for security management through security situation reports, effectively enhancing the terminal security collaborative defense capabilities and improving the overall security and reliability of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] Figure 1 A first flow chart of a secure collaboration method based on data sharing terminals provided in an embodiment of the present invention; Figure 2 A second flow chart of the data sharing terminal security collaboration method provided in an embodiment of the present invention; Figure 3 A third flow chart of a secure collaboration method for data-sharing terminals provided in an embodiment of the present invention; Figure 4 A fourth flow chart of a secure collaboration method for data-sharing terminals provided in an embodiment of the present invention; Figure 5 A fifth flow chart of a secure collaboration method for data-sharing terminals provided in an embodiment of the present invention; Figure 6 A sixth flow chart of a secure collaboration method for data-sharing terminals provided in an embodiment of the present invention; Figure 7 A seventh flow chart of a secure collaboration method for data-sharing terminals provided in an embodiment of the present invention; Figure 8 A schematic diagram of a structure of a data sharing terminal security collaboration device provided by an embodiment of the present invention; Figure 9 Another structural diagram of a data sharing terminal security collaboration device provided by an embodiment of the present invention; Figure 10 This is a schematic diagram of the structure of a secure collaborative device based on data sharing terminals provided in an embodiment of the present invention. DETAILED DESCRIPTION
[0023] The embodiment of the present application provides a data sharing terminal security cooperation method, device, equipment and storage medium, first, a secure data transmission channel between terminals is established, and security related data of each terminal is shared in real time to form a shared data set; then, threat analysis is performed on the set to generate a threat analysis result, and a terminal cooperative defense strategy is generated accordingly; meanwhile, deep threat identification is performed on the set to identify new attack modes and potential threats to generate a threat identification result; finally, the shared data set, the defense strategy and the threat identification result are integrated to generate a security situation report containing security event, threat intelligence and defense measure information. Through multiple steps, data sharing, cooperative defense, threat analysis and response, and security policy management between terminals are realized, the overall network security protection level is effectively improved, data sharing, cooperative defense, threat analysis and security policy management between terminals are realized, the overall network security protection ability is significantly improved, various security threats are discovered and responded in time, the safe and stable operation of the network environment is ensured, cooperative protection between different network domains or regions is realized, the range and effect of security protection are expanded, and the protection ability of new threats and internal threats is improved.
[0024] The terms "first", "second", "third", "fourth" and the like in the description, claims, and drawings of the present application, and those above and below (if any) are used for distinguishing between similar objects and not necessarily for describing a particular sequential or chronological order. It is to be understood that the use of the terms so termed herein is to be interpreted to allow that combinations of the multiples so called can be technically feasible, and it is to be understood that the embodiments described herein can be practiced in locations other than those described or claimed, and that the embodiments described herein can be practiced in any suitable order, unless the context clearly indicates otherwise. Additionally, the term "comprising" or "containing" and variations thereof as used herein is to be construed in an open, inclusive sense, and is intended to cover a process, method, system, product, or apparatus that comprises or contains an element that is recited, but not necessarily limited to, those elements specifically recited, and that can include other elements not specifically recited.
[0025] For the convenience of understanding, the specific flow of the embodiment of the present application is described below, please refer to Figure 1 The first embodiment of the data sharing terminal security cooperation method in the embodiment of the present application comprises: S100, a secure data transmission channel between terminals is established, and security related data of each terminal is shared in real time through the secure data transmission channel to form a shared data set; In this embodiment, each terminal first uses the Diffie-Hellman key exchange algorithm to negotiate a communication key over an insecure channel. A secure data transmission channel is then established based on this key. The secure data transmission channel uses the Advanced Encryption Standard (AES) to obfuscate and encrypt security-related data. Specifically, the original data is divided into 128-bit blocks. Ciphertext data is generated through byte substitution (using pre-set substitution boxes for nonlinear obfuscation), row shifting (cyclically shifting data rows by different offsets), column mixing (using finite field matrix multiplication to enhance diffusibility), and round key addition (XOR operation with the round key). Simultaneously, each terminal periodically calculates the hash value of its local data using a hash algorithm and synchronously compares the hash values. If the hash values do not match, an incremental synchronization process is triggered, transmitting only the difference data to update the terminal data. Ultimately, the encrypted data and synchronized data together constitute the shared data set.
[0026] For example, terminal A collects threat intelligence "a malicious program spreads through port 445". After dividing the data into 128-bit blocks, it performs byte replacement (replaces byte 0x31 with 0x7F) and row shift (shifts the second row right by 1 bit) on the first data block, and then performs an XOR operation with the round key to generate ciphertext data; it calculates the hash value of terminal A's local data and the hash value of terminal B's local data. If the hash value of terminal B is inconsistent with that of terminal A, the data synchronization process is triggered, and only the different fields such as "port 445" and "malicious program" are synchronized to achieve real-time data sharing.
[0027] S200, performing threat analysis on the shared data set, generating a threat analysis result, and generating a terminal collaborative defense strategy based on the threat analysis result; In this embodiment, the shared data set is first cleaned, deduplicated, and formatted in a standardized manner. Specifically, duplicate records and erroneous data in the shared data set are removed, and unstructured data, such as vulnerability descriptions in text format, are converted into a unified structured format, such as by converting them into table fields to generate structured data. Subsequently, an association rule mining algorithm is used to analyze the correlation between security events and vulnerability information in the structured data. Specifically, by setting the support and confidence thresholds of the association rules, the data is scanned to generate frequent item sets, and then threat association rules are extracted. For example, "abnormal login behavior occurs at the terminal - there is a risk of data leakage within 24 hours." Finally, based on the preset policy template library, the threat association rules are matched with the characteristic conditions of the policy template library, and the predefined defense measures in the policy template library, such as firewall rules and intrusion detection policies, are called to generate a terminal collaborative defense strategy. Among them, the policy template library contains multi-dimensional policy templates such as the network layer and the host layer.
[0028] As an example, the records of "Terminal A has 3 abnormal login events at 2025-06-23 08:00" and "09:30 the data of the terminal is illegally exported" are contained in the shared data set, the correlation analysis generates the rule "if the terminal has more than or equal to 3 abnormal login events within 1 hour, trigger the data leakage warning", matches the network layer policy template, calls the defense measure "temporarily ban the IP address of the terminal for 30 minutes", and generates the cooperative defense strategy.
[0029] S300, performing deep threat identification on the shared data set to identify new attack patterns and potential threats of the shared data set, and generating a threat identification result; In this embodiment, the attack time, source IP address, target port, attack traffic characteristics and other key parameters are extracted from the shared data set, and the features are normalized to generate a normalized feature vector. An initial threat identification model is constructed by a machine learning algorithm, and the initial threat identification model is trained and verified by using historical security event data. The initial threat identification model parameters are optimized to improve the identification accuracy, and a trained threat identification model is obtained. The real-time shared feature vector is input into the trained threat identification model. If the feature vector matches the feature library of known attack patterns, or it deviates from the threshold range of normal behavior, it is determined as a new attack pattern or a potential threat, and a threat identification result containing threat type, threat level and impact range is generated.
[0030] As an example, the features of a certain attack event are extracted from the shared data: the attack time is 14:00 on the same day, which is standardized to 0.6; the source IP is 192.168.1.100, which is converted to a decimal integer; the target port is 445, which is normalized to 0.45; the traffic peak is 3 times the normal average, which is mapped to 0.9. Based on the above features, a feature vector is generated to input into the trained threat identification model. If the trained threat identification model determines that the vector matches the known ransomware attack features with a matching degree of 90%, the threat identification result "threat type: ransomware attack, threat level: high, affected terminal: server B" is output.
[0031] S400, integrating the shared data set, the terminal cooperative defense strategy and the threat identification result to generate a security posture report containing security event information, threat intelligence information and defense measure information.
[0032] In this embodiment, first, according to the data types of security events, threat intelligence, defense measures, etc., a plurality of scene report templates are predefined, such as a daily report template and an attack event special report template, and the data display structure in the template is explicitly defined, such as a time axis table, a threat heat map, and a field requirement such as event ID, threat source, and measure execution status. Detailed information of the security event is extracted from the shared data set, the measure execution record is extracted from the terminal collaborative defense strategy, and the threat intelligence data is extracted from the threat identification result, to form a multi-source data element set. The data element set is structured, such as format unification and association relationship annotation, the processed data is mapped and matched with the fields of the report template, and a report containing a comprehensive security situation is automatically filled and generated, supporting PDF, interactive chart and other format outputs.
[0033] As an example, an attack event special report template is designed, including an "event timeline" field such as recording the time nodes of attack occurrence, detection and response, a "threat source analysis" field such as threat source IP and propagation path, and a "defense measure effect" field such as measure type, execution time and terminal state. Based on the above fields, the following data is integrated: a security event "2025-06-2311:00 terminal C attacked by DDoS", a threat identification result "threat source IP: 10.0.0.5, attack duration 30 minutes", and a defense strategy "11:15 start traffic cleaning service, 11:30 attack traffic down 90%", the data is mapped to the corresponding fields of the template, a visual special report is generated, and the event overview and disposal effect are intuitively presented.
[0034] The embodiment provides a terminal security collaboration method based on data sharing, which realizes the integrated use of multi-terminal security data through real-time sharing and collaborative analysis of security data, improves the comprehensiveness and accuracy of threat analysis, can timely discover new attacks and potential threats, generate accurate collaborative defense strategies, and at the same time, through security situation reports, provide comprehensive decision support for security management, effectively enhance the terminal security collaborative defense capability, and improve the overall security and reliability of the system.
[0035] Please refer to Figure 2 The second embodiment of the terminal security collaboration method based on data sharing in the embodiment of the application comprises: S110, generating a communication key between terminals by using a security data transmission protocol; S120, constructing a security data transmission channel based on the communication key, the security data transmission channel being used for obfuscating and encrypting the security-related data to generate encrypted data; S130, calculating the hash value of each terminal security-related data by using a hash algorithm, comparing the hash values between terminals, and if the comparison is inconsistent, triggering a difference data incremental transmission process to generate synchronization data; S140. The encrypted data and the synchronization data together constitute the shared data set.
[0036] In this embodiment, each terminal first uses the Diffie-Hellman key exchange algorithm to negotiate a session key within an insecure network, which serves as the communication key. Based on this communication key, the Advanced Encryption Standard (AES) is used to establish a secure data transmission channel. The original security data, such as vulnerability information and attack logs, is divided into 128-bit blocks. This data is then sequentially processed through byte substitution (e.g., obfuscating data using a preset substitution table), row shifting (e.g., cyclically shifting data rows by a fixed offset), column mixing (e.g., spreading data through matrix multiplication), and round key addition (e.g., XORing the data with the session key) to generate encrypted data in ciphertext form. Simultaneously, each terminal calculates a hash value for its local security data using a secure hash algorithm (e.g., SHA-256) and synchronizes it with other terminals. If a terminal's hash value differs from the shared hash value, an incremental transmission process is triggered, transmitting only the differences between the local and shared data, such as newly added attack event fields or modified vulnerability levels, to generate synchronized data. Ultimately, the encrypted and synchronized data are stored together on a blockchain node or centralized server, forming a shared data set.
[0037] See also Figure 3 The third embodiment of the data sharing terminal security collaboration method in the embodiment of the present invention includes: S210: Clean and format the shared data set to generate structured data; S220: Analyze the association relationship among security events, vulnerability information, and threat intelligence in the structured data using an association rule mining algorithm, and generate threat association rules as the threat analysis result.
[0038] In this embodiment, the shared data set is first cleaned: duplicate security event records are eliminated, such as the repeated reporting of the same attack event by multiple terminals; unstructured data, such as the text description of "terminal anomaly", is converted into a unified structured format, such as the field "anomaly type: failed login, number of times: 5 times". Structured data is generated based on the above fields. Subsequently, an association rule mining algorithm, such as the Apriori algorithm, is used to analyze the association relationship of the structured data. Specifically, a minimum support of 20% is set, indicating that the rule covers at least 20% of the data set, and a minimum confidence of 80% is set, indicating that the prediction accuracy of the rule is not less than 80%. The data is scanned to generate frequent item sets, such as the item set where "the number of abnormal logins is greater than or equal to 5 times" and "data leakage" appear at the same time, and then threat association rules are extracted, such as "if the terminal has more than or equal to 5 abnormal logins within 1 hour, there is a risk of data leakage within 24 hours". The extracted threat association rules are used as threat analysis results.
[0039] Referring to Figure 4 The fourth embodiment of the method for terminal security cooperation based on data sharing in the embodiments of the present application comprises: S230, extracting threat features from the threat analysis result, performing feature matching on the threat features and a strategy template in a preset strategy template library, and generating a matching result; S240, screening the matched strategy template according to the matching result, and generating a terminal cooperative defense strategy based on a predefined defense measure in the strategy template.
[0040] In this embodiment, a preset strategy template library is called, wherein the preset strategy template library contains a network layer template, a host layer template, and an application layer template, each type of template having a corresponding predefined defense measure. Based on the preset strategy template library, threat features such as attack type, target port, threat level, and the like are extracted from the threat analysis result (i.e., threat correlation rule), and the extracted threat features are matched with trigger conditions of templates in the preset strategy template library. For example, the "data leakage risk" is matched with the "block abnormal IP" condition of the network layer template, and a predefined defense measure such as "ban IP address for 30 minutes" in the template is called to generate a terminal cooperative defense strategy.
[0041] Referring to Figure 5 The fifth embodiment of the method for terminal security cooperation based on data sharing in the embodiments of the present application comprises: S310, extracting key features from the shared data set, and performing normalization processing on the key features to generate a normalized feature vector; S320, constructing an initial threat identification model, and training the initial threat identification model through historical security event data of the terminal to generate a trained attack pattern identification model; S330, inputting the normalized feature vector into the trained attack pattern identification model, identifying a new attack pattern and potential threats through the trained attack pattern identification model on the normalized feature vector, and outputting a threat identification result.
[0042] In this embodiment, the attack time such as "2025-06-2314:30", the source address such as "10.0.0.5", the target address such as "192.168.1.100", the attack type such as "DDoS", and other key features are extracted from the shared data set. Specifically, the timestamp is converted to a standardized value in the 0-1 interval, such as 14:30 corresponding to 0.6; the source address and target address are converted to 32-bit integers, such as "10.0.0.5" corresponding to 167772165; and the attack type is converted to a binary vector through one-hot encoding, such as "DDoS" corresponding to [1, 0, 0]. The normalized feature vector is generated based on the above processed data. An initial threat identification model is constructed, the historical security event data of the terminal containing the feature vector and label of the known attack mode are called, and the historical security event data of the terminal is divided into a training set and a test set. In this embodiment, the training set is set to 80%, and the test set is set to 20%. The initial threat identification model is trained by adjusting the kernel function such as the radial basis function and the penalty factor such as C=1.0. After verifying the accuracy of the initial threat identification model, a trained threat identification model is generated. The real-time shared normalized feature vector is input into the trained threat identification model. If the classification result output by the trained threat identification model matches the label of the known attack mode, such as "DDoS attack", or exceeds the normal behavior threshold, such as the traffic anomaly multiple being greater than or equal to 5, it is determined to be a new attack mode or a potential threat, and a threat identification result containing the threat type such as "distributed denial of service attack", the threat level such as "high level", and the involved terminal such as "server A" is generated.
[0043] Please refer to Figure 6 The sixth embodiment of the data sharing terminal security cooperation method in the embodiment of the application comprises: S500, generating threat warning information based on the threatened terminal recorded in the threat identification result; S600, synchronizing the threat warning information to the threatened terminal and triggering a warning response mechanism.
[0044] In this embodiment, based on the threatened terminal recorded in the threat identification result, such as the target IP or terminal identifier involved in the threat, threat warning information containing the threat type, level, and affected terminal list is generated, such as system pop-up information and SMS notification information. The generated threat warning information is synchronized to the threatened terminal and the security management platform, and a warning response mechanism is triggered, such as automatically blocking the threat source IP and isolating the infected terminal.
[0045] As an example, if the threat identification result is "terminal C is attacked by ransomware, source IP: 10.0.0.5", the warning information "high-risk threat: ransomware attack, affected terminal: C" is generated, synchronized to terminal C, and triggers the firewall to block the network connection of source IP 10.0.0.5.
[0046] Please refer to Figure 7 The seventh embodiment of the data sharing terminal security cooperation method in the embodiment of the application comprises: S410, extracting security event information from the shared data set, extracting defense measure information from the terminal cooperative defense strategy, and extracting threat intelligence information from the threat identification result to form a multi-source data element set; S420, structuring the multi-source data element set, and based on the pre-set report template, filling the structured multi-source data element into the corresponding position of the report template to generate a security posture report containing security event information, threat intelligence information and defense measure information.
[0047] In this embodiment, multiple types of report templates are designed, such as daily report templates and major event special templates, and pre-defined data display formats such as timeline tables, threat heat maps, and field requirements. Extract security event information from the shared data set, extract defense measure information from the terminal cooperative defense strategy, and extract threat intelligence information from the threat identification result to form a multi-source data element set based on security event information, defense measure information and threat intelligence information. After structured processing of the data, such as format normalization and association annotation processing, the data is mapped to the fields of the report template and automatically filled to generate a report, which supports PDF, visual chart and other formats.
[0048] As an example, an attack event special report template is designed, which includes "event timeline" fields such as recording the time nodes of attack occurrence, detection and response, "threat trace analysis" fields such as threat source IP and propagation path, and "defense measure effect" fields such as measure type, execution time and terminal state. Based on the above fields, the following data is integrated: security event "2025-06-23 11:00 terminal C is attacked by DDoS", threat identification result "threat source IP: 10.0.0.5, attack duration 30 minutes", defense strategy "11:15 start traffic cleaning service, 11:30 attack traffic down 90%", and the data is mapped to the corresponding fields of the template to generate a visual special report, which intuitively presents the whole picture of the event and the disposal effect.
[0049] The above describes the data sharing terminal security cooperation method in the embodiment of the application, and the following describes the data sharing terminal security cooperation device in the embodiment of the application. Please refer to Figure 8In one embodiment of the present invention, a data sharing terminal security collaboration device includes: An establishing module 10 is used to establish a secure data transmission channel between terminals, and to share security-related data of each terminal in real time through the secure data transmission channel to form a shared data set; An analysis module 20 is configured to perform threat analysis on the shared data set, generate threat analysis results, and generate a terminal collaborative defense strategy based on the threat analysis results; an identification module 30 for performing in-depth threat identification on the shared data set, identifying new attack patterns and potential threats in the shared data set, and generating a threat identification result; The integration module 40 is used to integrate the shared data set, terminal collaborative defense strategy and threat identification results to generate a security situation report including security events, threat intelligence and defense measures.
[0050] See also Figure 9 In this embodiment, the establishment module includes: A channel establishing unit 11 is configured to generate a communication key between terminals using a secure data transmission protocol; establish a secure data transmission channel based on the communication key, and perform obfuscation encryption processing on the security-related data to generate encrypted data; The data calculation unit 12 is used to calculate the hash value of each terminal security-related data through a hash algorithm, compare the hash values between the terminals, and trigger the incremental transmission process of the difference data if the comparison is inconsistent to generate synchronized data; The integration unit 13 is configured to combine the encrypted data and the synchronization data to form the shared data set.
[0051] See also Figure 9 In this embodiment, the analysis module includes: The data processing unit 21 is used to clean and format the shared data set to generate structured data; The threat analysis unit 22 is configured to use an association rule mining algorithm to analyze the association relationship among security events, vulnerability information, and threat intelligence in the structured data, and generate threat association rules as the threat analysis results.
[0052] See also Figure 9 In this embodiment, the analysis module further includes: A policy matching unit 23 is configured to extract threat features from the threat analysis results, perform feature matching on the threat features with policy templates in a preset policy template library, and generate a matching result; The policy generating unit 24 is configured to filter the matching policy templates according to the matching results, and generate a terminal cooperative defense policy based on the defense measures predefined in the policy templates.
[0053] See also Figure 9 In this embodiment, the identification module includes: A feature extraction unit 31 is configured to extract key features from the shared data set and perform normalization processing on the key features to generate a normalized feature vector; A model generation unit 32 is configured to construct an initial threat identification model and train the initial threat identification model using historical security event data of the terminal to generate a trained attack pattern recognition model; The threat identification unit 33 is configured to input the normalized feature vector into the trained attack pattern identification model, identify new attack patterns and potential threats on the normalized feature vector through the trained attack pattern identification model, and output a threat identification result.
[0054] See also Figure 9 In this embodiment, the data sharing terminal security collaboration device further includes: The warning module 50 is configured to generate threat warning information based on the threatened terminals recorded in the threat identification result; synchronize the threat warning information to the threatened terminals, and trigger a warning response mechanism.
[0055] See also Figure 9 In this embodiment, the integration module includes: An information extraction unit 41 is configured to extract security event information from the shared data set, defense measure information from the terminal collaborative defense strategy, and threat intelligence information from the threat identification result to form a multi-source data element set; The report generation unit 42 is used to structure the multi-source data element set, and based on a pre-set report template, fill the structured multi-source data elements into the corresponding positions of the report template to generate a security situation report containing security event information, threat intelligence information and defense measures information.
[0056] above Figure 8 and Figure 9 The secure collaboration device based on data sharing terminals in the embodiment of the present invention is described in detail from the perspective of modular functional entities. The secure collaboration device based on data sharing terminals in the embodiment of the present invention is described in detail from the perspective of hardware processing.
[0057] Figure 10is a structural schematic diagram of a data sharing terminal security collaboration device provided by an embodiment of the present application. The data sharing terminal security collaboration device 1000 can have great differences due to different configurations or performances, and can include one or more central processing units (CPUs) 1100 (for example, one or more processors) and a memory 1200, one or more storage media 1300 (for example, one or more mass storage devices) storing application programs 1310 or data 1320. The memory 1200 and the storage media 1300 can be temporary storage or persistent storage. The programs stored in the storage media 1300 can include one or more modules (not shown in the figure), and each module can include a series of instruction operations in the data sharing terminal security collaboration device 1000. Furthermore, the processor 1100 can be configured to communicate with the storage media 1300 and execute the series of instruction operations in the storage media 1300 on the data sharing terminal security collaboration device 1000.
[0058] The data sharing terminal security collaboration device 1000 can also include one or more power supplies 1400, one or more wired or wireless network interfaces 1500, one or more input / output interfaces 1600, and / or one or more operating systems 1330 such as Windows Serve, Mac OS X, Unix, Linux, FreeBSD, etc. Those skilled in the art can understand that the data sharing terminal security collaboration device 1000 can include more or fewer components than those shown, or some components can be combined, or different components can be arranged. Figure 10 The device structure shown does not constitute a limitation on the data sharing terminal security collaboration device 1000, and can include more or fewer components than those shown, or some components can be combined, or different components can be arranged.
[0059] The present application also provides a computer readable storage medium, which can be a non-volatile computer readable storage medium or a volatile computer readable storage medium. The computer readable storage medium stores instructions, and when the instructions are run on a computer, the computer executes the steps of the data sharing terminal security collaboration method.
[0060] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the above-described system or device, unit can refer to the corresponding process in the foregoing method embodiments, which will not be described here.
[0061] The integrated unit, if implemented in the form of a software function unit and sold or used as an independent product, can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application or the entire or part of the technical solutions that essentially contribute to the prior art can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in the various embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media that can store program codes.
[0062] The above description and the above embodiments are only used to illustrate the technical solutions of the present application, but not to limit them. Although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacements for some technical features. These modifications or replacements do not make the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A data sharing terminal security collaboration method, characterized in that: The data sharing terminal security collaboration method includes: Establishing a secure data transmission channel between terminals, sharing security-related data of each terminal in real time through the secure data transmission channel to form a shared data set; Performing threat analysis on the shared data set to generate a threat analysis result, and generating a terminal collaborative defense strategy based on the threat analysis result; Performing in-depth threat identification on the shared data set, identifying new attack patterns and potential threats in the shared data set, and generating threat identification results; Integrate the shared data set, terminal collaborative defense strategy and threat identification results to generate a security situation report containing security event information, threat intelligence information and defense measures information.
2. The data sharing terminal security collaboration method according to claim 1 is characterized in that: The step of establishing a secure data transmission channel between terminals and sharing security-related data of each terminal in real time through the secure data transmission channel to form a shared data set includes: Use secure data transmission protocols to generate communication keys between terminals; Building a secure data transmission channel based on the communication key, wherein the secure data transmission channel is used to perform obfuscation encryption processing on the security-related data to generate encrypted data; Calculate the hash value of each terminal's security-related data through a hash algorithm, compare the hash values between the terminals, and trigger the incremental transmission process of the difference data if the comparison is inconsistent to generate synchronized data; The encrypted data and the synchronization data together constitute the shared data set.
3. The data sharing terminal security collaboration method according to claim 1 is characterized in that: The step of performing threat analysis on the shared data set and generating threat analysis results includes: Cleaning and formatting the shared data set to generate structured data; An association rule mining algorithm is used to analyze the association relationship between security events, vulnerability information, and threat intelligence in the structured data, and generate threat association rules as the threat analysis result.
4. The data sharing terminal security collaboration method according to claim 1 is characterized in that: The step of generating a terminal collaborative defense strategy based on the threat analysis result includes: Extracting threat features from the threat analysis results, performing feature matching on the threat features with policy templates in a preset policy template library, and generating a matching result; The matching policy templates are screened according to the matching results, and a terminal collaborative defense policy is generated based on the defense measures predefined in the policy templates.
5. The data sharing terminal security collaboration method according to claim 1 is characterized in that: The step of performing deep threat identification on the shared data set, identifying new attack patterns and potential threats of the shared data, and generating a threat identification result includes: Extracting key features from the shared data set, and normalizing the key features to generate a normalized feature vector; Constructing an initial threat identification model and training the initial threat identification model using historical security event data of the terminal to generate a trained attack pattern recognition model; The normalized feature vector is input into the trained attack pattern recognition model, and the trained attack pattern recognition model is used to identify new attack patterns and potential threats on the normalized feature vector, and a threat recognition result is output.
6. The data sharing terminal security collaboration method according to claim 1 is characterized in that: After the step of generating a threat identification result, the method further includes: Generating threat warning information based on the threatened terminals recorded in the threat identification results; The threat warning information is synchronized to the threatened terminal, and a warning response mechanism is triggered.
7. The data sharing terminal security collaboration method according to claim 1 is characterized in that: The step of integrating the shared data set, the terminal collaborative defense strategy, and the threat identification results to generate a security situation report containing security event information, threat intelligence information, and defense measure information includes: Extracting security event information from the shared data set, extracting defense measure information from the terminal collaborative defense strategy, and extracting threat intelligence information from the threat identification results to form a multi-source data element set; The multi-source data element set is structured, and based on a pre-set report template, the structured multi-source data elements are filled into the corresponding positions of the report template to generate a security situation report containing security event information, threat intelligence information and defense measures information.
8. A data sharing terminal security collaboration device, characterized in that: include: An establishment module is used to establish a secure data transmission channel between terminals, and to share the security-related data of each terminal in real time through the secure data transmission channel to form a shared data set; An analysis module, configured to perform threat analysis on the shared data set, generate threat analysis results, and generate a terminal collaborative defense strategy based on the threat analysis results; an identification module, configured to perform in-depth threat identification on the shared data set, identify new attack patterns and potential threats in the shared data set, and generate a threat identification result; The integration module is used to integrate the shared data set, terminal collaborative defense strategy and threat identification results to generate a security situation report containing security events, threat intelligence and defense measures.
9. A data sharing terminal security collaboration device, characterized in that: comprising a memory and at least one processor, wherein the memory has computer-readable instructions stored therein; The at least one processor calls the computer-readable instructions in the memory to execute the various steps of the data sharing terminal security collaboration method according to any one of claims 1 to 7.
10. A computer-readable storage medium having computer-readable instructions stored thereon, characterized in that: When the computer-readable instructions are executed by a processor, the steps of the data sharing terminal security collaboration method according to any one of claims 1 to 7 are implemented.