A network security information monitoring management method and system
By receiving and de-identifying tenant anomaly reports in a multi-tenant cloud environment, performing aggregated analysis, and generating structured threat intelligence, the technology solves the problem of balancing personalization and overall security in existing technologies. This enables early identification and response to cross-tenant threats, protects privacy, and enhances platform security.
Patent Information
- Application Number
- CN202511295827.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-11
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2045-09-11
AI Technical Summary
In a multi-tenant cloud environment, existing network security monitoring systems struggle to balance tenants’ personalized customization needs with the platform’s overall security, resulting in potential threats not being identified or responded to in a timely manner, and information sharing may infringe on tenant privacy.
By receiving abnormal event reports uploaded by terminals, the system performs anonymization and aggregation analysis to filter high-confidence platform-level security threat information, generate structured threat intelligence, and provide tenants with personalized handling suggestions while respecting their operational autonomy.
It enables early identification of attacks that spread across tenants, protects tenant privacy, improves the platform's ability to respond to threats and overall security, shortens response time, and promotes collaborative protection among tenants.
Smart Images

Figure CN120811780B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the technical field of network security, and particularly relates to a network security information monitoring management method and system. BACKGROUND
[0002] In a large multi-tenant cloud environment, a cloud service provider provides infrastructure as a service (IaaS) and platform as a service (PaaS) for a large number of independent tenants. In order to ensure the safety of the cloud environment, the cloud environment provider usually deploys a centralized network security information monitoring management system to collect and analyze information such as virtual network traffic, security device logs, and internal security events of virtual machines of each tenant. However, with the continuous expansion of the scale of tenants and the increasing diversification of business forms, this standardized monitoring management mode faces serious challenges. Different types of tenants have significant differences in the sensitivity of security events, the types of threats they are concerned about, and the acceptable alarm levels. A financial technology company may be highly vigilant about any minor abnormal access attempt directed at its core database, while an individual developer may be more concerned about whether its website is subject to a large-scale denial of service attack.
[0003] Initially, the monitoring system adopts a unified alarm threshold and analysis rule. This one-size-fits-all strategy causes the security team of a financial technology company tenant to be often plagued by a large number of low-priority alarms that are not closely related to its business scenario, thereby drowning out the high-risk threats that really need to be concerned about; at the same time, an individual developer tenant may not be sensitive enough to some low-frequency probing behaviors targeting its specific application framework due to the default policy, resulting in potential security risks that are not discovered in a timely manner.
[0004] To address this problem, the cloud environment provider upgrades the monitoring management system to allow tenants to customize their security monitoring strategies to a certain extent within the framework preset by the cloud environment provider. Tenants can adjust the alarm level of specific events, configure custom detection rules for their own business characteristics, or selectively ignore alarms generated by certain known safe behaviors. However, the flexibility of this strategy customization also introduces new management complexity and potential risks. Some tenants may incorrectly configure overly lenient security strategies due to a lack of professional security knowledge or for the purpose of reducing alarm interference. Such behavior not only puts the tenant itself at great risk, but more seriously, if the tenant's system is compromised by a malicious actor and is used as a platform to attack other tenants, this will pose a serious threat to the stability of the entire cloud platform and the security of other tenants. Therefore, the cloud environment provider must ensure that the tenant's customized strategy does not exceed a global security bottom line in order to maintain the security of the overall cloud environment.
[0005] Therefore, there is an urgent need for a mechanism to effectively balance the tenant's individual customization needs and the overall security assurance of the platform. When a tenant submits or modifies its monitoring policy, the system should first perform a check to ensure that its customized content does not conflict with the global mandatory security policy set by the cloud environment provider. If the tenant's policy configuration is identified by the system as potentially causing a serious security blind spot, the system should warn the tenant, suggest modifications, or in extreme cases, refuse to apply the configuration and enforce a policy with a minimum security standard.
[0006] Furthermore, when the cloud environment provider's global monitoring system discovers through its broader view that a new type of attack with high concealment and potential lateral spread ability has occurred in a tenant's environment, the tenant's own customized policy may not be able to identify or accurately assess the threat level due to the novelty of the attack, and only mark it as an ordinary abnormal behavior. However, from the perspective of the cloud environment provider's global threat intelligence and monitoring of the underlying shared infrastructure, this behavior pattern, once confirmed, may mean that the attacker has the ability to break through the isolation between tenants and pose a direct threat to other tenants on the platform.
[0007] In such a complex situation, it is absolutely unacceptable to directly use the tenant's internal detailed, possibly containing business data, raw security logs or network packet capture data for global analysis or notification to other tenants, as this would seriously infringe on the tenant's right to data privacy. Therefore, the system must have the ability to extract and share threat indicators while strictly protecting tenant privacy. By providing desensitized threat intelligence, the system can perform aggregated analysis at the cloud environment provider level to assess the likelihood and potential impact of the new attack spreading across the entire cloud platform.
[0008] When the system, based on these desensitized feature information, combines weak abnormal signals from multiple tenants, determines that the platform-level risk is significantly increasing, it generates a "high-confidence platform security event" alert specifically for the cloud environment provider's senior security operations team. This alert not only contains a description of the threat, but also may be associated with multiple seemingly isolated but actually related tenant-level abnormal events. At this point, the challenge faced by the cloud environment provider's operations team is how to effectively contain the spread of the threat without directly intervening in the tenant's internal system. Simply notifying the potentially affected tenants to investigate themselves may miss the best opportunity to control the risk due to their insufficient response speed or technical capabilities. Therefore, there is an urgent need for an effective technical solution to address the above problems. SUMMARY
[0009] The application provides a network security information monitoring management method and system, aiming to protect tenant data privacy and operation autonomy in a multi-tenant cloud environment, and improve early detection, accurate assessment and timely response capabilities for platform-level security threats.
[0010] A first object of the application is to provide a network security information monitoring management method, comprising:
[0011] Receiving and aggregating analysis of the abnormal event reports uploaded by the terminals to determine the terminal threat information contained therein;
[0012] Based on the confidence of the terminal threat information, filtering the terminal threat information higher than the preset confidence as the platform-level security threat information;
[0013] According to the platform-level security threat information, generating structured threat intelligence containing corresponding platform-level security threat information disposal suggestions;
[0014] According to the confirmation degree and influence range of the platform-level security threat information, sharing the structured threat intelligence with specific or all terminals in a hierarchical manner.
[0015] Further, receiving and aggregating analysis of the abnormal event reports uploaded by the terminals to determine the terminal threat information contained therein, comprising:
[0016] Receiving the abnormal event reports uploaded by the terminals, and extracting key data from the abnormal event reports;
[0017] Performing data processing on the key data, wherein the data processing includes data cleaning and data normalization processing;
[0018] And performing aggregation analysis on the key data after data processing to determine the terminal threat information.
[0019] Further, according to the platform-level security threat information, generating structured threat intelligence containing corresponding platform-level security threat information disposal suggestions, comprising:
[0020] Obtaining the portrait information of the terminal, the portrait information including asset profile data, technical capability evaluation data or information preference setting data for representing the terminal;
[0021] Organizing the platform-level security threat information and the corresponding disposal suggestion content into multiple independently selected information units;
[0022] According to the platform-level security threat information and the portrait information of the terminal, selecting one or more information units matched with the portrait information from the multiple information units to construct the structured threat intelligence.
[0023] Further, according to the platform-level security threat information and the portrait information of the terminal, one or more information units matched with the portrait information are selected from the plurality of information units, and structured threat intelligence is constructed, including:
[0024] Monitoring whether the portrait information or the platform-level security threat information is changed;
[0025] When it is monitored that the portrait information is changed, the updated portrait information is acquired as the portrait information on which the current selection is based; when it is monitored that the platform-level security threat information is changed, the updated platform-level security threat information is acquired as the platform-level security threat information on which the current selection is based;
[0026] According to the updated platform-level security threat information and the portrait information, one or more information units matched with the portrait information are selected from the plurality of information units, and the selected one or more information units contain descriptions of the platform-level security threat and at least one handling suggestion for the terminal to execute within the operation permission range thereof.
[0027] Further, according to the updated platform-level security threat information and the portrait information, one or more information units matched with the portrait information are selected from the plurality of information units, and the selected one or more information units contain descriptions of the platform-level security threat and at least one handling suggestion for the terminal to execute within the operation permission range thereof, including:
[0028] The preset association rules between the plurality of information units are acquired, and the preset association rules are used to represent the association relationship between the information units, including a dependency relationship, a mutual exclusion relationship or an execution order relationship;
[0029] Based on the platform-level security threat information and the portrait information, one or more information units matched with the portrait information preference setting data are selected from the plurality of information units, and a candidate information unit set is formed;
[0030] When the candidate information unit set includes a plurality of information units, according to the preset association rules, the candidate information unit set is adjusted, and the conflicts between the information units in the candidate information unit set or the dependencies between the information units in the candidate information unit set are processed, so as to form a final information unit selection, and the final information unit selection contains descriptions of the platform-level security threat and at least one handling suggestion for the terminal to execute within the operation permission range thereof;
[0031] According to the execution order relationship represented in the association rules or the preset presentation logic, each information unit in the final information unit selection is sorted to determine the presentation order of each information unit in the final information unit selection in the structured threat intelligence.
[0032] Further, in the step of adjusting the candidate information unit set according to the preset association rule, processing the conflicts among the information units in the candidate information unit set or satisfying the dependencies among the information units in the candidate information unit set, when there are multiple adjustment operation sequences that make the candidate information unit set satisfy the preset association rule, comprising:
[0033] identifying multiple adjustment operation sequences as candidate adjustment operation sequences;
[0034] for each candidate adjustment operation sequence, adjusting the candidate information unit set, processing the conflicts among the information units in the candidate information unit set or satisfying the dependencies among the information units in the candidate information unit set, and generating a temporary final information unit selection corresponding to each candidate adjustment operation sequence;
[0035] for each temporary final information unit selection, calculating utility measure values in at least two preset evaluation dimensions; the types of the preset evaluation dimensions include association information completeness, terminal preference compliance, and expected treatment effect;
[0036] determining an optimal adjustment operation sequence from the multiple candidate adjustment operation sequences according to the utility measure values and a preset decision rule;
[0037] using the optimal adjustment operation sequence, adjusting the candidate information unit set according to the preset association rule, processing the conflicts among the information units in the candidate information unit set or satisfying the dependencies among the information units in the candidate information unit set, thereby forming a final information unit selection, the final information unit selection containing a description of the platform-level security threat and at least one treatment suggestion for the tenant to execute within the scope of its operation authority.
[0038] Further, for each temporary final information unit selection, calculating utility measure values in at least two preset evaluation dimensions, comprising:
[0039] determining a quantized value corresponding to the information completeness dimension according to the coverage of the key description elements of the platform-level security threat contained in the temporary final information unit selection and the completeness and operability of the description of the treatment suggestion;
[0040] determining a quantized value corresponding to the terminal preference compliance dimension according to the matching of the content expression style, technical term complexity level, and information presentation detail level of the temporary final information unit selection with the technical ability level recorded in the portrait information of the target tenant, historical information feedback, or preset information receiving preference;
[0041] determining a quantized value corresponding to the expected treatment effect dimension based on the estimation of the degree to which the treatment suggestion contained in the temporary final information unit selection can alleviate or eliminate the platform-level security threat;
[0042] The utility measure value is calculated by combining the quantified values determined for at least two of the three preset evaluation dimensions, i.e., the information integrity dimension, the terminal preference compliance dimension, and the expected handling effect dimension.
[0043] Further, the utility measure value is calculated by combining the quantified values determined for at least two of the preset evaluation dimensions, including:
[0044] The quantified values determined for the three dimensions of the preset evaluation dimensions are assigned corresponding weight parameters.
[0045] The utility measure value is calculated by a preset aggregation calculation method based on the quantified values determined for the three dimensions of the preset evaluation dimensions and the corresponding weight parameters.
[0046] Further, the portrait information of the target tenant is obtained, including:
[0047] The portrait information of the terminal is obtained from a data source reflecting the current state of the terminal.
[0048] The change of the data source is monitored.
[0049] When the change of the data source is monitored, the portrait information of the terminal is updated according to the change.
[0050] The updated portrait information of the terminal is used.
[0051] A second object of the present application is to provide a network security information monitoring management system, including:
[0052] An aggregation analysis module is configured to receive and aggregate analyze the abnormal event reports uploaded by the terminals, and determine the terminal threat information contained therein.
[0053] A screening module is configured to screen the terminal threat information higher than a preset confidence level based on the confidence level of the terminal threat information, as platform-level security threat information.
[0054] A structured threat intelligence module is configured to generate structured threat intelligence containing handling suggestions for the corresponding platform-level security threat information according to the platform-level security threat information.
[0055] An output module is configured to share the structured threat intelligence to specific or all terminals in a hierarchical manner according to the confirmation degree and the influence range of the platform-level security threat information.
[0056] Compared with the prior art, the present application has the following advantages:
[0057] The network security information monitoring management method provided by the application can identify new attack activities with cross-tenant propagation risks earlier and more accurately by aggregating desensitized security event information from multiple tenants, overcome the information limitation of single-tenant perspective, ensure that sensitive business data and internal details of tenants are not leaked during information sharing and analysis, and respect the operation autonomy of tenants by mainly relying on information sharing and collaborative guidance instead of direct intervention. Structured threat intelligence and explicit disposal recommendations can be delivered to potentially affected tenants in a timely manner, enabling them to quickly understand risks and take effective protection or mitigation measures to shorten the overall response time. The method can provide professional threat analysis results and action guidelines for tenants with relatively weak security capabilities to deal with complex threats that they cannot identify and handle, improve the overall security short board of the cloud platform, encourage tenants to participate in the co-construction of platform security, form positive feedback through information sharing, and improve the security resilience of the entire cloud environment. While allowing tenants to customize security policies to meet individual needs, the method provides strong support for cloud environment providers to maintain global security baselines through independent threat information aggregation and analysis channels. BRIEF DESCRIPTION OF DRAWINGS
[0058] Figure 1 A flowchart of a network security information monitoring management method provided by the application is provided.
[0059] Figure 2 A structural diagram of a network security information monitoring management system provided by the application. DETAILED DESCRIPTION
[0060] To more clearly illustrate the technical solutions in the embodiments of the application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are only some embodiments of the application, and other drawings can be obtained by those skilled in the art without creative effort on the basis of these drawings.
[0061] As shown in Figure 1 The application provides a network security information monitoring management method, which includes:
[0062] S110: receiving and aggregating analysis of abnormal event reports uploaded by terminals to determine terminal threat information contained therein.
[0063] Embodiments of the present application relate to the monitoring of network security information of all tenants renting the cloud environment services of a cloud service provider in a multi-tenant cloud environment. The terminals mentioned in step S110 are the multiple tenants in the tenant cloud environment, and the network security information monitoring and management system that monitors and manages the network security information of the tenants is the server of the cloud environment provider. Among them, the types of tenants include multiple categories, which can be enterprise tenants, individual tenants or e-commerce platform tenants.
[0064] In a multi-tenant cloud environment, when the network security information monitoring and management system allows tenants to customize security policies to meet their individual needs, while the cloud environment provider needs to maintain a global security baseline policy to ensure the overall security of the platform, how to design a mechanism that can unintentionally reduce the detection capability of new attacks with cross-tenant propagation risks when tenants customize policies, while the global monitoring system of the cloud environment provider identifies such platform-level risks through comprehensive analysis of information collected from multiple tenants and after desensitization processing, in the scenario of identifying such platform-level risks, to achieve neither directly infringing the data privacy of the tenants nor overstepping the boundaries of the tenants' internal operations, but also to timely deliver effective and actionable risk information to the tenants who may have been affected or potentially threatened, and to coordinate or guide the tenants to take appropriate protective or mitigation measures to effectively prevent the threat from further spreading within the platform, while ensuring the accuracy of the alarm and the timeliness of the response.
[0065] Specifically, in the step of aggregating and analyzing the abnormal event reports to determine the terminal threat information in step S110, it specifically includes:
[0066] S111: receiving the abnormal event reports uploaded by the terminals and extracting the key data from the abnormal event reports.
[0067] When the tenants as the terminals monitor the existence of terminal threat information during the running process, an abnormal event report is generated and uploaded to the cloud environment provider as the server side. The terminal threat information is obtained by the tenant analyzing its virtual network traffic, security device logs and virtual machine internal security events, or the tenant analyzes the security device logs corresponding to the attack signs when it monitors new attacks with high concealment and potential horizontal diffusion capability. When any tenant monitors the terminal threat information, it directly uploads the original security logs or network packet capture data that may contain its business data to the global analysis and notification to other tenants. This way is absolutely unacceptable, so in the embodiments of the present application, the abnormal event report generated by the tenant needs to be desensitized.
[0068] Specifically, the network information security management monitoring system in the application designs a set of standardized desensitization time templates containing predefined fields for tenants to report terminal threat information. The template content focuses on behavior patterns, affected component general types and other non-sensitive information.
[0069] The template contains fields such as: approximate time window of event occurrence, event identification reported by tenant (non-tenant internal sensitive ID), general type of affected component (for example: web application server, relational database service, specific type of virtual machine image), observed abnormal behavior pattern classification (for example: abnormal external network connection attempt pattern, atypical resource consumption pattern, detection behavior characteristics of specific type of known vulnerability), and optional desensitized attack indicators (for example: hash value of malicious sample, ASN information or reputation label of suspicious domain name). The template strictly excludes sensitive information such as tenant-specific IP addresses, internal hostnames, user accounts, and business data.
[0070] In the implementation process, the cloud environment provider provides an abnormal event report upload tool or service interface to the tenant. When the tenant security administrator discovers abnormal events captured by the local monitoring system but cannot be accurately evaluated or handled by existing policies, they can refer to the pre-set standardized desensitized event template to fill in the key features of the event through the guided interface. The module provides input suggestions and desensitization verification functions, such as prompting the user to convert specific IP addresses to IP home location or network type. The tenant can choose whether to report anonymously or associate their tenant identity to receive subsequent targeted intelligence.
[0071] After the tenant generates an abnormal event report based on the template requirements, the abnormal event report is uploaded to the server of the cloud environment provider through wireless communication. The server receives the abnormal event report in real time or at a fixed time, aggregates and analyzes the received abnormal event report, and extracts the key data.
[0072] S112: Data processing is performed on the key data, which includes data cleaning and data normalization processing.
[0073] S113: The key data after data processing is aggregated and analyzed to determine the terminal threat information.
[0074] In the specific aggregation and analysis process, statistical analysis methods are used to aggregate each field in the abnormal event report, for example, to count the number and geographical distribution of tenants reporting "specific component type" attacked by "specific abnormal behavior pattern" within a specific time period. Through association rule analysis, potential connections between different desensitized events are found, for example, multiple tenants report multiple desensitized events of different stages that conform to a certain attack sequence. In addition, it is necessary to monitor the abnormal growth trend of the number of reports of specific desensitized event patterns.
[0075] S120: Based on the confidence of the terminal threat information, filter the terminal threat information higher than the preset confidence as the platform-level security threat information.
[0076] Based on the analysis results, combined with historical threat data and available external threat intelligence, the identified potential platform-level terminal threats are evaluated for confidence, and the terminal threat information higher than the preset confidence is filtered as the platform-level security threat information.
[0077] S130: According to the platform-level security threat information, generate structured threat intelligence containing corresponding platform-level security threat information handling suggestions.
[0078] The content of the structured threat intelligence includes: general description of the threat, possible attack source characteristics (de-sensitization), main affected component or service type, recommended detection method for tenants (e.g. configure detection rules for specific de-sensitization behavior patterns in their local monitoring system), and general mitigation or hardening suggestions.
[0079] Step S130 specifically includes:
[0080] S131: Obtain the portrait information of the terminal, which includes asset profile data, technical capability assessment data or information preference setting data for characterizing the terminal.
[0081] Each tenant as a terminal needs to transmit its tenant information to the server of the cloud environment provider for storage when establishing contact with the cloud environment provider. When the server of the cloud environment provider receives the abnormal event report of the tenant, it searches for the stored tenant information in the server and extracts the asset profile data, technical capability assessment data or information preference setting data for characterizing the terminal as the portrait information of the tenant.
[0082] The ways to obtain the portrait information of the target tenant include: obtaining the portrait information of the terminal from the data source reflecting the current state of the terminal; monitoring changes in the data source; updating the portrait information of the terminal according to the changes when changes in the data source are monitored; and using the updated terminal portrait information.
[0083] S132: Organize the platform-level security threat information and the corresponding handling suggestion content into multiple independently selected information units.
[0084] By aggregating and analyzing the abnormal event reports and filtering them for confidence, the platform-level terminal threats are determined and the corresponding platform-level security threat information handling suggestions are generated. The platform-level security threat information and the corresponding handling suggestion content are organized into multiple independently selected information units.
[0085] S133: Select one or more information units matched with the portrait information from the plurality of information units according to the platform-level security threat information and the portrait information of the terminal, and construct the structured threat intelligence.
[0086] In step S133, it is necessary to monitor whether the tenant portrait information or the platform-level security threat information changes in real time. When it is monitored that the portrait information changes, the updated portrait information is obtained as the portrait information on which the current selection is based; when it is monitored that the platform-level security threat information changes, the updated platform-level security threat information is obtained as the platform-level security threat information on which the current selection is based. According to the updated platform-level security threat information and the portrait information, one or more information units matched with the portrait information are selected from the plurality of information units, and the selected one or more information units contain descriptions of the platform-level security threats and at least one handling suggestion for the terminal to execute within the operation permission range thereof.
[0087] Specifically, a plurality of preset association rules between information units are obtained, the preset association rules are used to represent the association relationship between the information units, including the dependency relationship, the mutual exclusion relationship or the execution order relationship; based on the platform-level security threat information and the portrait information, one or more information units matched with the portrait information preference setting data are selected from the plurality of information units to form a candidate information unit set; when the candidate information unit set includes a plurality of information units, the candidate information unit set is adjusted according to the preset association rules to handle the conflicts between the information units in the candidate information unit set or to satisfy the dependencies between the information units in the candidate information unit set, thereby forming a final information unit selection, the final information unit selection contains descriptions of the platform-level security threats and at least one handling suggestion for the terminal to execute within the operation permission range thereof; according to the execution order relationship represented in the association rules or the preset presentation logic, each information unit in the final information unit selection is sorted to determine the presentation order of each information unit in the final information unit selection in the structured threat intelligence.
[0088] When there are multiple adjustment operation sequences, and the candidate information unit set meets the preset association rule, the multiple adjustment operation sequences are identified as candidate adjustment operation sequences; for each candidate adjustment operation sequence, the candidate information unit set is adjusted, conflicts between information units in the candidate information unit set are handled, or dependencies between information units in the candidate information unit set are met, and a temporary final information unit selection corresponding to each candidate adjustment operation sequence is generated; for each temporary final information unit selection, utility measure values in at least two preset evaluation dimensions are calculated; the types of the preset evaluation dimensions include association information completeness, terminal preference compliance, and expected treatment effect; according to the utility measure values and a preset decision rule, an optimal adjustment operation sequence is determined from the multiple candidate adjustment operation sequences; the optimal adjustment operation sequence is used to adjust the candidate information unit set according to the preset association rule, handle conflicts between information units in the candidate information unit set, or meet dependencies between information units in the candidate information unit set, thereby forming a final information unit selection, and the final information unit selection contains a description of a platform-level security threat and at least one treatment suggestion for a tenant to execute within the scope of its operation authority.
[0089] According to the coverage of the key description elements of the platform-level security threat contained in the temporary final information unit selection and the completeness of the clarity and operability description of the treatment suggestion, a quantitative value corresponding to the information completeness dimension is determined; according to the matching of the content expression style, technical term complexity level, and information presentation detail level of the temporary final information unit selection with the technical ability level recorded in the portrait information of the target tenant, historical information feedback, or preset information receiving preference, a quantitative value corresponding to the terminal preference compliance dimension is determined; based on the estimation of the degree to which the treatment suggestion contained in the temporary final information unit selection can alleviate or eliminate the platform-level security threat, a quantitative value corresponding to the expected treatment effect dimension is determined; the utility measure value is calculated by combining the quantitative values determined for at least two of the preset evaluation dimensions.
[0090] Specifically, the quantitative values determined for the three dimensions in the preset evaluation dimensions are set with corresponding weight parameters; based on the quantitative values determined for the three dimensions in the preset evaluation dimensions and the corresponding weight parameters, the utility measure value is calculated through a preset aggregation calculation method.
[0091] S140: According to the confirmation degree and influence range of the platform-level security threat information, the structured threat intelligence is shared to specific or all terminals in a hierarchical sharing structure.
[0092] According to the severity of the threat, the breadth of the impact range and the confirmation degree, the intelligence will be shared in stages: for example, for a threat that has been confirmed to affect a specific version of software, it will be pushed to the tenant group that uses that version of software; for a high-risk threat that is universal, a security notice will be issued to all tenants. The sharing channels include the cloud platform security center, email notification and API interface provided for the tenant automation system.
[0093] After receiving the threat intelligence, the tenant can report whether it is confirmed to be affected, the disposal measures taken or planned and the disposal results through the feedback channel provided by the server of the cloud environment provider. The cloud environment provider security team assesses the overall risk control situation according to the feedback information of the tenant, and can update the threat intelligence or provide further disposal guidance. For some key threats with high risk of spread, if a specific tenant does not respond for a long time after receiving clear intelligence and disposal suggestions, and its environment continues to exhibit high-risk behavior, the cloud environment provider can take measures such as temporarily isolating high-risk network ports of the affected tenant part within the framework of the service terms agreed with the tenant in advance, based on the aggregated intelligence shared that proves the overall risk faced by the platform, to protect the security of other tenants and the platform.
[0094] In an embodiment of the present application, by defining a standardized desensitization event template, it is ensured that when the tenant shares security event information, it can effectively strip sensitive data and only provide abstract, non-sensitive threat indicators such as behavior patterns and general types of affected components. The tenant uses this template to report suspicious events discovered locally that are difficult to qualify or not covered by the strategy. Subsequently, the cloud environment provider receives and processes standardized event reports from multiple tenants, using techniques such as pattern matching, correlation analysis and trend judgment to identify potential new attack activities, especially those with cross-tenant propagation risks, from a large number of seemingly isolated desensitized events. Once a high-confidence platform-level threat is identified, the system generates structured threat intelligence and shares it with specific or all tenants in stages according to the degree of confirmation and the scope of the threat, including specific disposal recommendations. Finally, through a coordinated disposal process, the tenant can feedback the disposal status, and the cloud environment provider can provide support according to the overall situation or take limited blocking measures as necessary according to the agreement. The entire process, while protecting the tenant's data privacy and operational autonomy, improves the ability to discover, accurately assess and respond to platform-level security threats in a timely manner by aggregating the wisdom of the crowd.
[0095] The following is a specific use embodiment provided by the present application:
[0096] Suppose in a multi-tenant cloud environment, there are tenant A (a financial technology company), tenant B (a personal developer) and tenant C (an e-commerce platform).
[0097] Scenario 1: Without this solution
[0098] Tenant A has very strict customized security policies, but mainly focuses on its core payment system. Its edge web servers are subjected to low-frequency probes exploiting a new 0day vulnerability. Since the probing behavior does not directly touch the core system and the frequency is low, Tenant A's policy does not mark it as a high-priority event, and the security team might ignore it.
[0099] Tenant B's blog website is also subjected to similar probes. Since its security policy is relatively lenient, and the probes do not directly cause service interruption, this event might not be alarmed at all by its local system.
[0100] Tenant C's e-commerce platform also observes similar minor abnormal traffic, but its security team classifies it as routine background noise.
[0101] At this time, the cloud environment provider's global monitoring system may also observe some sporadic, scattered weak abnormal signals in different tenants, but due to the lack of effective, privacy-protecting information aggregation mechanisms, it is difficult to correlate these isolated signals to determine whether there is a potential threat to the entire platform. Even if the cloud environment provider suspects a problem, it cannot confirm the nature and scope of the threat without infringing on tenant privacy (such as directly accessing Tenant A, B, and C's detailed logs), nor can it effectively warn all potentially affected tenants. The threat may continue to exist and escalate until a tenant is actually compromised, causing losses.
[0102] Scenario 2: With this solution
[0103] 1. Standardized desensitized event templates and tenant-side reporting:
[0104] The template includes fields such as: "Event Time Window", "Affected Component General Type" (e.g., Web Server, API Gateway, Specific Open Source Framework), "Observed Abnormal Behavior Pattern Classification" (e.g., abnormal login attempts, atypical resource scanning, probes targeting specific paths), "Desensitized Attack Indicator" (e.g., ASN information of probe source IP, pattern of specific non-standard strings in User-Agent).
[0105] Tenant A's security administrator notices a previously unseen probing behavior against a less commonly used API endpoint in its web server logs. While its existing policies do not rate it as high risk, the administrator feels suspicious. Through the "incident reporting module" provided by the cloud environment provider, selecting "affected component general type: web server", filling in "observed abnormal behavior pattern classification: probing against specific path", and describing the specific non-standard HTTP header pattern (e.g., containing a specific format of random string) contained in the probing request in the "de-identification attack indicator", but hides the specific source IP and complete request URL. The module checks that the content filled in meets the de-identification requirements.
[0106] Tenant B may not actively report.
[0107] Tenant C's security team also discovers similar probing against its API gateway and reports a de-identified event through the reporting module, describing a similar non-standard HTTP header pattern.
[0108] 2. Cloud environment provider de-identified event aggregation analysis platform:
[0109] The cloud environment provider's de-identified event aggregation analysis platform receives the de-identified event reports submitted by tenants A and C.
[0110] Through the aggregation analysis of the "observed abnormal behavior pattern classification" and "de-identified attack indicator" fields, it is found that multiple tenants (A and C) have reported probing behavior against web servers or API gateways with similar "non-standard HTTP header patterns" in a short period of time.
[0111] Further correlation analysis finds that although the source IPs are different, the ASN attribution of these probing behaviors has certain concentration, and although the target paths of the probes are different, they all point to a certain type of business logic interface.
[0112] Combined with the external threat intelligence library (possibly there are rumors about a new vulnerability in a certain web framework but the details have not been disclosed), these aggregated information is determined to be an early probing activity against a specific type of web application vulnerability with potential widespread impact, with high confidence.
[0113] 3. Threat intelligence generation and hierarchical sharing:
[0114] Based on the analysis results, the cloud environment provider security team generates a structured threat intelligence: "A new type of probing activity targeting XX type web application framework (or specific business logic interface pattern) is discovered, characterized by the inclusion of [described non-standard HTTP header pattern] in HTTP requests. It is recommended that tenants using the framework check relevant component logs for similar request characteristics and consider temporary access control or enhanced input validation for related interfaces. Possible attack source characteristics: ASN concentrated in [certain region / certain ASN]."
[0115] This intelligence is pushed to all tenants registered in the asset list of the cloud platform security center and mail, including tenant B who has not reported before, using the type of web application framework.
[0116] 4. Collaborative handling process support:
[0117] After receiving the intelligence, tenants A and C confirm that the previously reported incidents are related to this threat, and according to the recommendations, they strengthen the protection and feedback the handling status through the platform.
[0118] After receiving the intelligence, tenant B checks its system and finds that there are indeed such probing behaviors, and immediately takes mitigation measures and also provides feedback.
[0119] According to the feedback of each tenant, the cloud environment provider evaluates the overall control of the threat in the platform. If subsequent discoveries still have tenants that have not responded and their environment (indirectly observed through global desensitization indicators) continues to be exposed to this risk, the cloud environment provider can temporarily restrict the in-bound rules for specific high-risk ports of the affected components of the tenant within the agreed framework, and notify the tenant again.
[0120] Through this solution, the originally isolated and possibly ignored early threat signals are effectively aggregated and analyzed. Without infringing on the privacy of tenants, the cloud environment provider can timely identify platform-level risks and provide actionable early warning and handling recommendations to all potentially affected tenants, effectively preventing the further spread of threats and improving the overall security level of the cloud platform.
[0121] This technical solution introduces standardized desensitization event templates and builds a multi-party collaboration mechanism, which brings the following significant technical effects:
[0122] 1. Enhance platform-level threat awareness capabilities: By aggregating desensitized security event information from multiple tenants, the cloud environment provider can more accurately identify new types of attack activities that have cross-tenant propagation risks, overcoming the information limitations of a single tenant perspective.
[0123] 2. Protect tenant data privacy and operational autonomy: Standardized de-identification processing ensures that sensitive business data and internal details of tenants are not leaked during information sharing and analysis, while risk handling mainly relies on information sharing and collaborative guidance rather than direct intervention, respecting the operational autonomy of tenants.
[0124] 3. Improve the timeliness and effectiveness of threat response: Structured threat intelligence and clear handling recommendations can be timely delivered to potentially affected tenants, helping them quickly understand risks and take effective protection or mitigation measures, shortening the overall response time.
[0125] 4. Fill the gap in tenant security capabilities: Provide professional threat analysis results and action guidelines for tenants with relatively weak security capabilities, helping them deal with complex threats that are difficult for them to identify and handle, and improve the overall security shortcomings of the cloud platform.
[0126] 5. Promote the construction of a safe ecological environment: Encourage tenants to participate in the construction of platform security, form positive feedback through information sharing, and improve the security resilience of the entire cloud environment.
[0127] 6. Effectively balance customization and global security: While allowing tenants to customize security policies to meet individual needs, the cloud environment provider maintains a global security baseline by providing independent threat information aggregation and analysis channels.
[0128] In other embodiments of the present invention, in a multi-tenant cloud environment, the cloud environment provider's de-identified event aggregation and analysis platform analyzes a plurality of standardized de-identified events reported by tenants and identifies a new attack pattern that targets a specific type of database service (e.g., an open-source NoSQL database with version X.Y) and exploits a known vulnerability (number CVE-YYYY-NNNN) that has not been patched for long. The characteristics of this attack pattern include: initial low-frequency version detection through a specific protocol port, followed by sending malicious query statements, and finally returning the stolen data in batches to a number of dynamic domain names controlled by the attacker through an encrypted channel. The cloud environment provider's security team confirms that this attack pattern has high confidence and has observed early signs in a few tenant environments.
[0129] According to the foregoing embodiments, after the cloud environment provider's platform generates structured threat intelligence, the cloud platform faces the decision of how to perform hierarchical sharing. There are thousands of tenants on the cloud platform, and a part of the tenants explicitly register in the asset list that they use the type of database service, but the specific version information may not be updated in time or be incomplete. Another part of the tenants may actually use the database service, but they do not accurately register in the platform asset list. There is also a part of the tenants who may not use the database service, but their business systems interact with other systems that use the database service.
[0130] If the cloud environment provider only publishes this threat intelligence to the tenants (assuming tenant group A) that explicitly register in the asset list that they use the affected version of the database, those tenants (tenant group B) that do not accurately register asset information but actually use the database will not receive the warning and continue to be exposed to risk. If the cloud environment provider publishes to all tenants that register to use the type of database (regardless of version) (tenant group A+C, C is a tenant that uses a non-vulnerable version), tenant group C may receive an alert that is not directly related to them, increasing the burden of their security team to distinguish. If the cloud environment provider broadcasts to all tenants (tenant group A+B+C+D, D is a tenant that does not use the database but may be indirectly affected, and completely unrelated tenant E), it will cause greater range of alert interference, reduce the trust and response priority of tenants to platform security notifications.
[0131] Further, assuming that a tenant A1 in tenant group A has a high dependence on the database in its business system, and its internal security team has weak technical capabilities and cannot independently complete the database upgrade or the configuration of complex detection rules. Another tenant A2 in tenant group A has a professional security team and a mature automated operation system, and can quickly respond and implement mitigation measures. If the same threat notification containing only general disposal suggestions is pushed to A1 and A2, A1 may continue to be in a high-risk state due to the inability to effectively implement the suggestions, while A2 may feel that the intelligence is not instructive enough.
[0132] In addition, if the dynamic domain name used by the new attack pattern in the data backhaul stage has the characteristic of rapid change, the cloud environment provider may only master part of the early domain name features when generating the initial threat intelligence. As the attack continues, the cloud environment provider's aggregation analysis platform may capture more new domain names associated with this attack pattern. At this time, how to effectively supplement these updated and more specific threat indicators (such as a new list of malicious domain names) to the published threat intelligence, and ensure that relevant tenants can obtain and apply these updates in time, is also a challenge. If each update is published in the form of a completely new notification, it may cause information fragmentation and tenant fatigue.
[0133] Further existing technical problems: In a multi-tenant cloud environment, when the cloud environment provider generates structured threat intelligence for a specific component vulnerability (such as CVE-YYYY-NNNN of a specific version of a database) based on the aggregation analysis results, when performing a hierarchical sharing mechanism to publish threat notifications to a large number of tenants, considering that the tenant's affected component information (such as the specific version number) registered in its cloud platform asset list may be incomplete, inaccurate or not updated in time, and the security technology capabilities, operation autonomy and tolerance to information interference of different tenants are significantly different, and the threat indicators (such as dynamic domain names used by attackers) themselves have the characteristics of rapid change, how to design a threat intelligence distribution and presentation method that can ensure the maximum coverage of all potential affected tenants (including those tenants whose asset information registration is inaccurate) under the premise of providing differentiated and easy-to-understand and operate disposal guidance for tenants with different security capabilities and needs, and seamlessly integrating dynamically updated threat indicators into intelligence to improve the continuous effectiveness of intelligence, reduce the alarm fatigue of irrelevant tenants, and ultimately improve the overall threat disposal efficiency and effect.
[0134] Based on the above problems, the present application also provides the following embodiments for accurate and personalized intelligence delivery. Specifically, it includes:
[0135] 1. Threat intelligence atomization and fragment library construction:
[0136] The cloud environment provider decomposes a complete structured threat intelligence (such as a database vulnerability attack for CVE-YYYY-NNNN) into several intelligence fragments. For example:
[0137] “Fragment A_Vulnerability Description”: contains CVE number, vulnerability principle abstract, affected database type and version range (can support fuzzy matching, such as “X.Y series and earlier versions”). Metadata: technical difficulty-low.
[0138] “Fragment B_Asset Self-check Guide”: provides various methods to help tenants confirm whether they use the affected database version, for example: view through the cloud platform console (if the information is accurate), execute specific commands to check the version number in the virtual machine (provide command examples), scan the internal network to find database instances, etc. Metadata: technical difficulty-medium; applicable conditions-tenant has the right to execute commands or perform internal scanning.
[0139] “Fragment C_Probe Behavior Characteristics”: describes the typical network behavior patterns of attackers probing vulnerabilities (such as specific ports, specific request formats). Metadata: technical difficulty-medium.
[0140] "Fragment D_Malicious Query Structure": Describes the general structure or key features of a malicious query statement that exploits the vulnerability (de-identified). Metadata: Technical Difficulty - High.
[0141] "Fragment E_Data Exfiltration Channel Features": Describes the encryption protocol type, target domain name ASN information, and known dynamic domain name list for data exfiltration (this fragment content can be dynamically updated). Metadata: Technical Difficulty - Medium.
[0142] "Fragment F1_Basic Mitigation_Update Patch": Guides the update of the database to a fixed version, provides official patch links and general update steps. Metadata: Technical Difficulty - Medium; Disposition Capability Requirement - Possesses database patch management capabilities.
[0143] "Fragment F2_Temporary Mitigation_Firewall Rule": Guides blocking outgoing connections related to known malicious domain ASNs on the firewall or restricting access to specific database ports. Metadata: Technical Difficulty - Medium; Disposition Capability Requirement - Possesses network firewall configuration capabilities.
[0144] "Fragment G_Advanced Detection Script": Provides a script or rule configuration example that can be used to detect specific attack patterns in network intrusion detection systems or host logs. Metadata: Technical Difficulty - High; Disposition Capability Requirement - Can execute custom scripts and has log analysis capabilities.
[0145] These fragments are stored in a central intelligence fragment library, and each fragment can be independently versioned and updated.
[0146] 2. Tenant Disposition Capability Tagging and Profile Maintenance:
[0147] The cloud environment provider maintains a profile for each tenant on the cloud platform, where "disposition capability tags" allow tenants to choose or be preliminarily recommended by the system based on their historical behavior (such as ticket types, service usage). Tag examples: "Possesses database patch management capabilities", "Can only perform simple configuration through console", "Can write and execute Shell scripts", "Has full-time security operation personnel", "Low sensitivity to alarm information (i.e., does not want to receive too many non-directly related alarms)". Asset information section, even if the tenant does not explicitly register the database version, if it registers "NoSQL database of type X", it will be recorded.
[0148] 3. On-demand intelligence dynamic assembly engine:
[0149] When the cloud environment provider decides to release threat intelligence on CVE-YYYY-NNNN vulnerability attacks, the engine performs the following operations for each potential target tenant:
[0150] Initial screening of fragments: According to the threat core (CVE-YYYY-NNNN against X.Y version NoSQL database), select fragments A, C, D, E, F1, F2, G as candidates. Since asset information may not be accurate, fragment B_asset self-check guide is usually included.
[0151] Secondary screening and adjustment combined with tenant profiling:
[0152] For tenant A1 (weak security capability, labeled "only simple configuration through console" and "low sensitivity to alarm information"):
[0153] Keep fragment A (may provide a more popular description version).
[0154] Highlight fragment B and may prefer to show the method of checking assets through the cloud platform console.
[0155] Fragments C, D, and E may be presented in summary form or with a hint that they are high-risk but technical details can be skipped.
[0156] In the mitigation measures, fragment F1 may be downgraded or replaced with "contact cloud environment provider support for upgrade" if it involves complex command line operations; fragment F2 may provide a link to the console firewall configuration page and a simple rule example if it involves firewall rules.
[0157] Fragment G will be basically excluded.
[0158] For tenant A2 (strong security capability, labeled "Shell scripts can be written and executed" and "dedicated security and operation personnel"):
[0159] All candidate fragments are kept and may provide more detailed technical versions.
[0160] Fragment G will be highlighted.
[0161] Fragment B may focus more on command line checks and automated scanning methods.
[0162] Finally, a metadata description of a "customized intelligence package" containing several ordered intelligence fragments is generated for each tenant (i.e., fragment list and order).
[0163] 4. Guided response interface:
[0164] Instead of a static email, the tenant receives a link to its personal guided response interface through the cloud platform security center. The interface dynamically loads and organizes intelligence fragments based on its "customized intelligence package" metadata.
[0165] The interface first presents segment A (vulnerability description) and segment B (asset self-check guide). The tenant needs to confirm whether there is an affected asset. If it is confirmed, the next step is entered. If it is confirmed that there is no, the process ends and its feedback is recorded (which can be used to optimize subsequent push).
[0166] If it is confirmed to be affected, the interface will display the relevant probes, exploit characteristics segments (C, D, E) in turn, and then the mitigation measures segment (such as F1, F2). For each mitigation measure segment, the tenant can choose "implemented", "planned implementation", "not applicable / cannot be implemented", and can add notes. The system records its selection.
[0167] If the tenant selects a certain mitigation measure, the interface can provide more detailed operation steps or link to related documents / tools.
[0168] 5. Intelligence segment dynamic update and association mechanism:
[0169] When the cloud environment provider's aggregation analysis platform captures a new list of malicious domain names associated with the CVE-YYYY-NNNN attack pattern, the security team only needs to update the segment E_data return channel feature in the intelligence segment library. All custom intelligence packages that have been pushed to tenants, which contain segment E, in their corresponding guided response interface, when the tenant accesses again or the system actively refreshes, will automatically load the updated segment E content, ensuring that the tenant sees the latest list of malicious domain names. The system can highlight the updated part.
[0170] The technical solution divides threat intelligence into atomized, combinable "intelligence segments" on demand, and combines the tenant's "disposal ability label" and asset portrait, dynamically generates and presents "customized intelligence packages" and guided response interfaces for each tenant. This method enables cloud environment providers to achieve accurate threat intelligence push, differentiated guidance, and continuous update in complex scenarios where tenant asset information is incomplete, security capabilities are different, and threat indicators are dynamically changing, thereby maximizing the overall threat disposal efficiency and effectiveness of the multi-tenant cloud environment.
[0171] As shown in Figure 2 The present application proposes a network security information monitoring management system 200, which comprises:
[0172] The aggregation analysis module 210 is used for receiving and performing aggregation analysis on the abnormal event reports uploaded by the terminal, and determining the terminal threat information contained therein;
[0173] The screening module 220 is used for screening the terminal threat information higher than the preset confidence as platform-level security threat information based on the confidence of the terminal threat information;
[0174] The structured threat intelligence module 230 is configured to generate structured threat intelligence containing disposition suggestions for the corresponding platform-level security threat information according to the platform-level security threat information.
[0175] The output module 240 is configured to share the structured threat intelligence to specific or all terminals hierarchically according to the confirmation degree and the influence range of the platform-level security threat information.
[0176] In the description of the present specification, the description of the terms "one embodiment", "some embodiments", "an example", "a specific example", or "some examples" and the like means that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present application. In the present specification, the illustrative description of the terms does not necessarily refer to the same embodiment or example. Also, the specific features, structures, materials or characteristics described can be combined in any appropriate manner in any one or more embodiments or examples. In addition, the person skilled in the art can combine and combine the different embodiments or examples described in the present specification and the features of the different embodiments or examples, without contradiction.
[0177] In addition, the terms "first", "second" are only for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined with "first", "second" can explicitly or implicitly include at least one of the features. In the description of the present application, the meaning of "a plurality of" is at least two, for example, two, three, etc., unless otherwise explicitly specified.
[0178] Any process or method descriptions or any other descriptions in flow charts or otherwise described herein can be understood as representing code modules, segments, or portions of code which include one or more executable instructions for implementing specific logic functions (or steps) in the process, and the various embodiments of the present application include additional implementations in which the order of steps can differ from those shown or discussed, including a step can occur at the same time as other steps or can be performed in reverse order or can be performed in an order different from that shown or discussed, all of which are intended to be within the scope of the application.
[0179] The above description of disclosed embodiments enables a person skilled in the art to implement or use the present application. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but will conform to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A network security information monitoring management method characterized by, The method comprises the following steps: receiving and aggregating abnormal event reports uploaded by terminals to determine terminal threat information contained therein; screening terminal threat information higher than a preset confidence level based on the confidence level of the terminal threat information as platform-level security threat information; generating structured threat intelligence containing handling suggestions corresponding to the platform-level security threat information according to the platform-level security threat information, comprising: obtaining portrait information of the terminal, which includes asset profile data, technical capability evaluation data, or information preference setting data for characterizing the terminal; organizing the platform-level security threat information and the corresponding handling suggestion content into multiple independently selected information units; monitoring whether the portrait information or the platform-level security threat information has changed; when it is monitored that the portrait information has changed, obtaining the updated portrait information as the current selected portrait information; when it is monitored that the platform-level security threat information has changed, obtaining the updated platform-level security threat information as the current selected platform-level security threat information; selecting one or more information units matching the portrait information from the multiple information units according to the updated platform-level security threat information and the portrait information, the selected one or more information units containing a description of the platform-level security threat and at least one handling suggestion for the terminal to execute within its operating authority range; sharing the structured threat intelligence with specific or all terminals according to the confirmation degree and influence range of the platform-level security threat information; selecting one or more information units matching the portrait information from the multiple information units according to the updated platform-level security threat information and the portrait information, the selected one or more information units containing a description of the platform-level security threat and at least one handling suggestion for the terminal to execute within its operating authority range, comprising: obtaining a preset association rule between the multiple information units, the preset association rule being used to represent the association relationship between the information units, including a dependency relationship, a mutual exclusion relationship, or an execution order relationship; selecting one or more information units matching the portrait information preference setting data from the multiple information units based on the platform-level security threat information and the portrait information to form a candidate information unit set; when the candidate information unit set includes multiple information units, adjusting the candidate information unit set according to the preset association rule to handle conflicts between information units in the candidate information unit set or to meet the dependencies between information units in the candidate information unit set, thereby forming a final information unit selection, the final information unit selection containing a description of the platform-level security threat and at least one handling suggestion for the terminal to execute within its operating authority range; According to the execution order relationship represented in the association rule or the preset presentation logic, each information unit in the final information unit selection is sorted to determine the presentation order of each information unit in the structured threat intelligence.
2. The network security information monitoring management method of claim 1, wherein, The abnormal event reports uploaded by the terminals are received and aggregated for analysis to determine terminal threat information, including: The abnormal event reports uploaded by the terminals are received, and key data is extracted from the abnormal event reports; The key data is processed, including data cleaning and data normalization processing; The key data after data processing is aggregated for analysis to determine the terminal threat information.
3. The network security information monitoring management method of claim 1, wherein, According to the preset association rule, the candidate information unit set is adjusted to handle the conflicts between information units in the candidate information unit set or to meet the dependencies between information units in the candidate information unit set. When there are multiple adjustment operation sequences that make the candidate information unit set meet the preset association rule, the method comprises: Identify the multiple adjustment operation sequences as candidate adjustment operation sequences; For each candidate adjustment operation sequence, adjust the candidate information unit set to handle the conflicts between information units in the candidate information unit set or to meet the dependencies between information units in the candidate information unit set, and generate a temporary final information unit selection corresponding to each candidate adjustment operation sequence; For each temporary final information unit selection, calculate the utility measure value in at least two preset evaluation dimensions; The types of the preset evaluation dimensions include association information completeness, terminal preference compliance, and expected handling effect; According to the utility measure value and the preset decision rule, determine the optimal adjustment operation sequence from the multiple candidate adjustment operation sequences; Using the optimal adjustment operation sequence, adjust the candidate information unit set according to the preset association rule to handle the conflicts between information units in the candidate information unit set or to meet the dependencies between information units in the candidate information unit set, thereby forming the final information unit selection, which contains descriptions of the platform-level security threats and at least one handling suggestion for tenants to execute within their operational authority.
4. The network security information monitoring management method of claim 3, wherein, For each temporary final information unit selection, calculate the utility measure value in at least two preset evaluation dimensions, including: According to the coverage of key description elements of the platform-level security threats contained in the temporary final information unit selection and the completeness of the clarity and operability descriptions of the handling suggestions, determine the quantized value corresponding to the information completeness dimension; According to the matching of the content expression style, technical term complexity level, and information presentation detail level of the temporary final information unit selection with the technical capability level recorded in the portrait information, historical information feedback, or preset information reception preference, determine the quantized value corresponding to the terminal preference compliance dimension; determine a quantized value corresponding to the expected handling effect dimension based on an estimation of a degree to which a handling suggestion contained in the temporary final information unit selection can alleviate or eliminate the platform-level security threat; combine the quantized values determined for at least two of the three preset evaluation dimensions, i.e., the information completeness dimension, the terminal preference compliance dimension, and the expected handling effect dimension, to obtain the utility measure value.
5. The network security information monitoring management method of claim 4, wherein, combining the quantized values determined for at least two of the preset evaluation dimensions to obtain the utility measure value includes: setting corresponding weight parameters for the quantized values determined for the three of the preset evaluation dimensions; based on the quantized values determined for the three of the preset evaluation dimensions and the corresponding weight parameters, obtaining the utility measure value through a preset aggregation calculation manner.
6. The network security information monitoring management method of claim 1, wherein, obtaining the portrait information of the target tenant includes: obtaining the portrait information of the terminal from a data source reflecting a current state of the terminal; monitoring changes in the data source; updating the portrait information of the terminal according to the changes when the changes in the data source are monitored; using the updated portrait information of the terminal.
7. A network security information monitoring management system characterized by comprising: includes: an aggregation analysis module configured to receive and perform aggregation analysis on abnormal event reports uploaded by terminals, and determine terminal threat information contained therein; a screening module configured to screen, based on a confidence level of the terminal threat information, the terminal threat information with a confidence level higher than a preset confidence level as platform-level security threat information; a structured threat intelligence module configured to generate, according to the platform-level security threat information, structured threat intelligence containing handling suggestions corresponding to the platform-level security threat information, including: obtaining portrait information of the terminal, the portrait information including asset profile data, technical capability evaluation data, or information preference setting data for characterizing the terminal; organizing the platform-level security threat information and corresponding handling suggestion contents into a plurality of independently selected information units; monitoring whether the portrait information or the platform-level security threat information has changed; when it is monitored that the portrait information has changed, obtaining the updated portrait information as the portrait information on which the current selection is based; and when it is monitored that the platform-level security threat information has changed, obtaining the updated platform-level security threat information as the platform-level security threat information on which the current selection is based; selecting, according to the updated platform-level security threat information and the portrait information, one or more information units from the plurality of information units that match the portrait information, the selected one or more information units containing descriptions of the platform-level security threat and at least one handling suggestion for the terminal to execute within its operation authority scope; and further configured to obtain preset association rules between the plurality of information units, the preset association rules being used to represent association relationships between the information units, including dependency relationships, mutual exclusion relationships, or execution order relationships; selecting one or more information units from the plurality of information units based on the platform-level security threat information and the profiling information, to form a candidate information unit set, wherein the candidate information unit set matches the profiling information preference setting data; when the candidate information unit set includes a plurality of information units, adjusting the candidate information unit set according to the preset association rule, to handle conflicts among information units in the candidate information unit set or to satisfy dependencies among information units in the candidate information unit set, thereby forming a final information unit selection, wherein the final information unit selection includes descriptions of the platform-level security threat and at least one handling suggestion for the terminal to execute within the operating permission range of the terminal; sequencing each information unit in the final information unit selection according to an execution order relationship represented in the association rule or a preset presentation logic, to determine a presentation order of each information unit in the final information unit selection in the structured threat intelligence; an output module configured to share the structured threat intelligence to specific or all terminals in a hierarchical manner according to a confirmation degree and an influence range of the platform-level security threat information.
Citation Information
Patent Citations
Threat intelligence and terminal detection response method and system in big data environment
CN113259356A